Industrial safety data anomaly analysis method and system

By building an event tree and event branch chain, combined with the decomposition status of industrial Internet of Things monitoring data, the problem that industrial security monitoring systems in the existing technology is difficult to deal with large-scale data, and the accuracy and reliability of analysis are improved.

CN119719875BActive Publication Date: 2025-05-13CHINA TOBACCO SICHUAN IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510228293.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-13
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

Existing industrial safety monitoring systems are difficult to effectively process large-scale and high-dimensional industrial IoT monitoring data, and the analysis results are easily affected by subjective factors, resulting in insufficient accuracy and reliability.

Method used

By extracting multiple monitoring events from the industrial IoT monitoring data set, an event tree is built to describe the event involvement logic between reference monitoring events, the decomposed state monitoring data is jointly analyzed with the event tree, and the event branch is built for abnormal analysis.

Benefits of technology

It improves the accuracy and reliability of abnormal analysis of industrial security data, enhances the traceability and trust of abnormal analysis results, and allows a deeper understanding of potential safety hazards in the industrial environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119719875B_ABST
    Figure CN119719875B_ABST
Patent Text Reader

Abstract

The present invention provides an industrial safety data anomaly analysis method and system, extracting multiple monitoring events from an industrial Internet of Things monitoring data set; obtaining an event tree for describing the event involvement logic between multiple reference monitoring events, obtaining reference monitoring events respectively involved in multiple monitoring events as involved reference monitoring events in multiple reference monitoring events; sequentially accessing and obtaining reference monitoring event groups covering involved reference monitoring events as start reference monitoring events and involved reference monitoring events as end reference monitoring events in multiple involved reference monitoring events; obtaining event involvement description information, constructing an event branch chain covering start reference monitoring events, event involvement description information and end reference monitoring events; performing anomaly analysis on the industrial Internet of Things monitoring data set according to the event branch chain, and obtaining anomaly analysis results of the industrial Internet of Things monitoring data set. The present invention can increase the accuracy of the anomaly analysis results, and can increase traceability and reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing, and in particular, to a method and system for analyzing anomaly in industrial safety data. Background Art

[0002] With the rapid development of industrial Internet of Things technology, the amount of data in industrial environments has exploded. These data contain rich information such as equipment status, production processes, environmental parameters, etc., which are of great significance for industrial safety monitoring and anomaly detection. Traditional industrial safety monitoring methods often rely on manual experience and rule setting, which makes it difficult to effectively process large-scale, high-dimensional industrial Internet of Things monitoring data, and the analysis results are easily affected by subjective factors, resulting in insufficient accuracy and reliability.

[0003] Existing industrial safety monitoring systems usually use a single event analysis method when processing industrial Internet of Things monitoring data, that is, they only focus on a single monitoring event itself, while ignoring the complex associations and logical chains between events. This analysis method may be effective when dealing with simple scenarios, but it is often difficult to capture potential safety hazards and abnormal patterns when facing complex and changing industrial environments. For example, on a tobacco production line, the failure of a single device may only be a superficial phenomenon, and behind it may be problems in multiple links such as raw material supply, equipment maintenance, and production processes. If only a single device failure is analyzed and the association with other events is ignored, it is difficult to accurately determine the root cause and potential impact of the failure. Summary of the invention

[0004] The object of the present invention is to provide an industrial safety data anomaly analysis method and system.

[0005] This application is implemented as follows:

[0006] In a first aspect, the present application provides an industrial safety data anomaly analysis method, comprising: extracting multiple monitoring events from an industrial Internet of Things monitoring data set; obtaining an event tree for describing the event involvement logic between multiple reference monitoring events, and obtaining the reference monitoring events respectively involved in the multiple monitoring events from the multiple reference monitoring events as involved reference monitoring events; among the multiple involved reference monitoring events, sequentially accessing and obtaining a reference monitoring event group covering the involved reference monitoring event as a start reference monitoring event and the involved reference monitoring event as an end reference monitoring event; the start reference monitoring event is inconsistent with the end reference monitoring event; sequentially accessing the event tree, obtaining event involvement description information for describing the start reference monitoring event and the end reference monitoring event, and constructing an event branch chain covering the start reference monitoring event, the event involvement description information and the end reference monitoring event; performing anomaly analysis on the industrial Internet of Things monitoring data set based on the event branch chain to obtain anomaly analysis results of the industrial Internet of Things monitoring data set.

[0007] In a second aspect, the present application provides a computer system comprising: one or more processors; a memory; one or more computer programs; wherein the one or more computer programs are stored in the memory and configured to be executed by the one or more processors, and when the one or more computer programs are executed by the processors, the method as described above is implemented.

[0008] The present invention extracts multiple monitoring events from an industrial Internet of Things monitoring data set. Based on an event tree used to describe the event involvement logic between multiple reference monitoring events, reference monitoring events respectively involved in multiple monitoring events can be obtained as involved reference monitoring events. The decomposed industrial Internet of Things monitoring data set is combined with the event tree. Among the multiple involved reference monitoring events, a reference monitoring event group covering involved reference monitoring events as start reference monitoring events and involved reference monitoring events as end reference monitoring events is accessed in sequence to obtain reference monitoring event groups. If the start reference monitoring event is inconsistent with the end reference monitoring event, the event tree is accessed in sequence to obtain event involvement description information used to describe the start reference monitoring event and the end reference monitoring event, and an event branch chain covering the start reference monitoring event, event involvement description information and end reference monitoring event is constructed. According to the event branch chain, an abnormal analysis is performed on the industrial Internet of Things monitoring data set to obtain an abnormal analysis result of the industrial Internet of Things monitoring data set, and the abnormal situation of the industrial Internet of Things monitoring data set is determined. The event branch chain includes both reference monitoring events and event description information. Therefore, the present invention can not only increase the accuracy of abnormal analysis results, but also increase traceability and trust. Accurate abnormal analysis results help to achieve reliable industrial safety monitoring. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in describing the embodiments of the present application are briefly introduced below.

[0010] Figure 1 It is a flow chart of an industrial safety data anomaly analysis method provided in an embodiment of the present application.

[0011] Figure 2 It is a schematic diagram of the composition of a computer system provided in an embodiment of the present application.

[0012] Reference numerals: computer system - 100 ; processor - 101 ; bus - 102 ; memory - 103 ; transceiver - 104 . DETAILED DESCRIPTION

[0013] The following describes the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. The terms used in the implementation method part of the embodiments of the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application.

[0014] The execution subject of the industrial safety data anomaly analysis method in the embodiment of the present application is a computer system, including but not limited to servers, personal computers, laptops, tablet computers, smart phones, etc. The computer system includes user devices and network devices. Among them, user devices include but are not limited to computers, smart phones, PADs, etc.; the server can be but is not limited to a single network server, a server group composed of multiple network servers, or a cloud composed of a large number of computers or network servers in cloud computing, wherein cloud computing is a kind of distributed computing, a super virtual computer composed of a group of loosely coupled computer sets. Among them, the computer system can be run alone to implement this application, and it can also be connected to the network and implement this application through interactive operations with other computer systems in the network. Among them, the network where the computer system is located includes but is not limited to the Internet, wide area network, metropolitan area network, local area network, VPN network, etc.

[0015] like Figure 1 As shown, the method for analyzing abnormal industrial safety data in the embodiment of the present application includes:

[0016] Step S110: extracting multiple monitoring events from the industrial Internet of Things monitoring data set.

[0017] In industrial environments, IoT technology is widely used to monitor the operating status of various equipment and processes. These monitoring devices will continuously generate a large amount of data, including but not limited to physical quantities such as temperature, pressure, flow, vibration, as well as the working status of the equipment, alarm information, etc. These data are aggregated into an industrial IoT monitoring data set, forming a huge data warehouse. This data set contains information on all important events that occur in the industrial environment and is an important basis for industrial safety monitoring and analysis.

[0018] In step S110, the computer system extracts multiple monitoring events from the data set. A monitoring event is composed of a series of data items, which together describe a specific event. For example, a monitoring event may be "the temperature of device A at time point T1 exceeds the preset threshold value", and this event contains multiple data items such as device name (device A), time point (T1), physical quantity (temperature) and threshold value (preset threshold value).

[0019] In order to effectively extract monitoring events, the computer system uses a series of data processing technologies. First, it cleans and preprocesses the raw data to remove noise and outliers to ensure the accuracy and reliability of the data. Then, it identifies monitoring events from the cleaned data based on predefined rules or algorithms. These rules or algorithms may be based on the characteristics of the event, the conditions for occurrence, or the relationship with other events.

[0020] In the process of identifying monitoring events, a computer system can use machine learning models to improve the accuracy and efficiency of identification. For example, it can use a clustering algorithm to cluster similar events into classes, making it easier to identify specific types of events. Or, it can use a classification algorithm to classify events, placing each event into a predefined category. These machine learning models are usually trained to work effectively, and the training process involves using historical data to adjust the parameters of the model so that it can accurately identify monitoring events.

[0021] For example, suppose that on a tobacco production line, there are multiple sensors used to monitor the operating status of the equipment. These sensors will continuously generate data, such as temperature, vibration, etc. In step S110, the computer system first cleans the useful information from these raw data, such as removing abnormal values ​​caused by sensor failure. Then, it can identify monitoring events according to predefined rules. For example, if the temperature of a certain device continues to rise and exceeds the preset safety threshold, the computer system can identify an "equipment overheating" event. This event contains multiple data items such as the device name, time point, temperature value, and safety threshold.

[0022] When identifying monitoring events, the computer system can also use the correlation between events to assist in judgment. For example, if a device has experienced abnormal vibration before overheating, there may be a causal relationship between the two events. The computer system can more accurately identify monitoring events by analyzing this correlation and build a logical chain between events.

[0023] In addition, in order to process large-scale data more efficiently, the computer system can also use distributed computing technology to speed up the data extraction process. By dividing the data into blocks and distributing them to multiple computing nodes for processing, the speed and efficiency of data extraction can be significantly improved. At the same time, in order to ensure the consistency and integrity of the data, the computer system also uses data synchronization and verification mechanisms to ensure that the data on each node is consistent.

[0024] Step S120: obtaining an event tree for describing the event involvement logic between a plurality of reference monitoring events, and obtaining, from the plurality of reference monitoring events, reference monitoring events respectively involved in the plurality of monitoring events as involved reference monitoring events.

[0025] In step S120, the computer system first obtains an event tree (Event Tree Analysis, ETA), which describes the event involvement logic between multiple reference monitoring events. Subsequently, the computer system uses this event tree to find reference monitoring events involved in the current multiple monitoring events from multiple reference monitoring events. These found reference monitoring events are called involved reference monitoring events.

[0026] An event tree is a graphical tool for representing the logical relationships and causal chains between events. In the embodiment of the present application, an event tree is used to describe the mutual influence and association between different events, thereby helping to understand and predict the behavior of the system. In step S120, the event tree obtained by the computer system is a pre-built model that includes multiple reference monitoring events and the involved logic between these events. These involved logics may include causal relationships, sequential relationships, concurrent relationships, etc. between events.

[0027] For example, in a tobacco production line, the event tree may contain multiple reference monitoring events, such as "insufficient raw material supply", "equipment failure", "production line shutdown", etc. There may be complex logical relationships between these events, such as "insufficient raw material supply" may lead to "equipment failure", and "equipment failure" may lead to "production line shutdown". The event tree graphically displays the relationship between these events, allowing the computer system to intuitively understand the logic involved between them.

[0028] After obtaining the event tree, the computer system starts to execute the core task of step S120: finding reference monitoring events respectively involved in the current multiple monitoring events from the multiple reference monitoring events. To achieve this goal, the computer system uses a series of data processing and analysis technologies.

[0029] The computer system analyzes the current multiple monitoring events and extracts their key information, such as event type, occurrence time, location, etc. This information will serve as the basis for subsequent analysis. Then, the computer system uses the event involvement logic described in the event tree to start traversing multiple reference monitoring events. For each reference monitoring event, the computer system checks whether it has an involvement relationship with any of the current multiple monitoring events. This involvement relationship may be based on causal relationships, sequential relationships, or concurrent relationships between events.

[0030] When determining the involvement relationship, the computer system can calculate the similarity or distance between events to determine whether they are close enough to constitute an involvement relationship. This calculation may involve the comparison of feature vectors, the application of statistical models, etc.

[0031] Taking the feature vector as an example, assume that each event can be represented as a feature vector, which contains the key attribute information of the event. The computer system can calculate the Euclidean distance or cosine similarity between the feature vectors of the current multiple monitoring events and the feature vectors of each reference monitoring event. If the distance between the feature vector of a reference monitoring event and the feature vector of an event in the current multiple monitoring events is small enough (or the similarity is high enough), then it can be considered that there is a relationship between the two events.

[0032] During the calculation process, the computer system can use some optimization algorithms to speed up the calculation process, such as K-nearest neighbor algorithm, support vector machine, etc. These algorithms can help the computer system quickly find a few key events involved in the current multiple monitoring events from a large number of reference monitoring events. Once the reference monitoring events involved are found, the computer system records them as basic data for subsequent analysis. These reference monitoring events not only contain information about the event itself, but also imply the logical relationship and causal chain between them and the current multiple monitoring events. By conducting in-depth analysis of these events, the computer system can reveal potential safety hazards in the industrial environment and provide strong support for anomaly detection and safety monitoring.

[0033] Step S130: among a plurality of reference monitoring events, sequentially access and obtain a reference monitoring event group including a reference monitoring event as a start reference monitoring event and a reference monitoring event as an end reference monitoring event; the start reference monitoring event is inconsistent with the end reference monitoring event.

[0034] The computer system has completed steps S110 and S120, i.e., extracting multiple monitoring events from the industrial Internet of Things monitoring data set, and finding reference monitoring events (i.e., involved reference monitoring events) respectively involved with these monitoring events based on the event tree. Now, the computer system further processes these involved reference monitoring events to reveal the internal connections and logical order between them.

[0035] The core of step S130 is to traverse multiple reference monitoring events involved and construct a reference monitoring event group covering specific start and end reference monitoring events. The "start reference monitoring event" and "end reference monitoring event" here are artificially set, and they represent the starting point and end point of interest in the analysis process. The inconsistency of these two events means that the analysis process will focus on the entire chain of events from the starting point to the end point, rather than a single isolated event.

[0036] In order to construct such a reference monitoring event group, the computer system adopts a systematic method to traverse the reference monitoring events involved. One feasible method is to use graph traversal algorithms such as depth-first search (DFS) or breadth-first search (BFS). These algorithms can help the computer system systematically visit each reference monitoring event involved and explore the connection relationship between them.

[0037] Taking depth-first search as an example, the computer system can start from any reference monitoring event and explore downward along the connection relationship in the event tree until it reaches the predetermined end reference monitoring event or cannot continue to explore. During the exploration process, the computer system will record each reference monitoring event that has passed through to form a reference monitoring event group. Then, the computer system will go back to the previous node and try other possible exploration paths until all possible paths have been explored.

[0038] Alternatively, in another possible strategy, the reference monitoring event group can be constructed by combining the structural characteristics of the event tree and the logical relationship between events. For example, the computer system can first identify the key nodes in the event tree (such as branch points, convergence points, etc.), and then construct the reference monitoring event group based on the characteristics of these nodes and the connection relationship between them. During the construction process, the computer system can take into account the causal relationship, sequential relationship, concurrent relationship, etc. between events to ensure that the constructed reference monitoring event group can accurately reflect the logical chain between events.

[0039] In addition, the computer system can also use machine learning models to assist in building reference monitoring event groups. For example, it can use a clustering algorithm to cluster similar reference monitoring events into classes, and then build reference monitoring event groups based on the characteristics of the classes and the associations between them. Alternatively, it can use a classification algorithm to classify reference monitoring events, and then build reference monitoring event groups with specific attributes based on the classification results.

[0040] In the process of constructing the reference monitoring event group, the computer system also pays attention to the selection of the start reference monitoring event and the end reference monitoring event. The selection of these two events will directly affect the characteristics of the constructed reference monitoring event group and the accuracy of the analysis results. Therefore, the computer system reasonably selects these two events according to the specific analysis requirements and the characteristics of the industrial Internet of Things monitoring data set.

[0041] For example, suppose that in a tobacco production line, the computer system focuses on the entire production process from "raw materials entering the warehouse" to "finished products leaving the warehouse". In this scenario, it can set the "raw materials entering the warehouse" event as the starting reference monitoring event and the "finished products leaving the warehouse" event as the ending reference monitoring event. Then, by traversing the reference monitoring events involved and constructing a reference monitoring event group, the computer system can reveal the various links in the production process and the logical relationships between them.

[0042] In the process of building a reference monitoring event group, the computer system may encounter some challenges and difficulties. For example, due to the complexity and diversity of industrial IoT monitoring data sets, the correlation between different events may be very complex and difficult to identify directly. In addition, due to data quality issues (such as noise, missing values, etc.), the computer system may use some data preprocessing and cleaning techniques to improve the accuracy and reliability of the data. Finally, due to the limitation of computing resources, the computer system may use some optimization algorithms to speed up the construction process and improve computing efficiency. Based on this, the computer system can use feature engineering technology to extract and select meaningful event features in order to better describe and distinguish different events. Or use data fusion technology to integrate information from different data sources in order to more comprehensively understand the correlation between events.

[0043] Step S140: Access the event tree in sequence, obtain event-related description information used to describe the start reference monitoring event and the end reference monitoring event, and construct an event branch chain covering the start reference monitoring event, the event-related description information and the end reference monitoring event.

[0044] In step S140, the computer system sequentially accesses the event tree. When accessing the event tree, the computer system systematically accesses each node and edge according to a certain traversal strategy (such as depth-first search, breadth-first search, etc.) to ensure that no important information is missed.

[0045] The purpose of accessing the event tree is to obtain the event-related description information that describes the relationship between a specific start reference monitoring event and an end reference monitoring event. This information usually includes the attributes of the event, the conditions for occurrence, the scope of influence, the consequences, etc., which together form the basis of the event branch chain. The event branch chain is a logical chain that organically connects the start reference monitoring event, the event-related description information, and the end reference monitoring event, revealing the internal connection and logical order between them.

[0046] To construct a chain of events, a computer system can perform the following key operations:

[0047] 1. Determine the start reference monitoring event and the end reference monitoring event: These two events are the starting point and end point of the event branch chain. Their selection will directly affect the construction and analysis results of the event branch chain. In practical applications, these two events are usually determined based on the analysis requirements and the characteristics of the industrial Internet of Things monitoring data set.

[0048] 2. Search for related nodes in the event tree: The computer system will search for nodes related to the start reference monitoring event and the end reference monitoring event in the event tree. These nodes may include directly connected nodes, indirectly connected nodes, or nodes connected through a certain logical path. During the search process, the computer system will use the structural characteristics and traversal strategy of the event tree to ensure the accuracy and completeness of the search.

[0049] 3. Extract event-related description information: For each relevant node found, the computer system will extract the event-related description information associated with it. This information may include event attributes (such as type, name, timestamp, etc.), occurrence conditions (such as pre-events, trigger conditions, etc.), impact range (such as affected equipment, regions, etc.) and consequences (such as caused failures, losses, etc.). The extracted information will be used to build event branches and describe the logical relationship between events.

[0050] 4. Constructing event branches: After extracting all necessary information, the computer system will start to construct event branches. An event branch is an ordered sequence that connects the starting reference monitoring event, the event-related description information, and the ending reference monitoring event in a logical order. During the construction process, the computer system will ensure that each event and description information is accurately placed in the correct position and clearly express the logical relationship between them.

[0051] For example, suppose that on a tobacco production line, the computer system focuses on the event chain from "insufficient raw material supply" to "production line shutdown". In this scenario, it can set the "insufficient raw material supply" event as the starting reference monitoring event and the "production line shutdown" event as the ending reference monitoring event. Then, by accessing the event tree and extracting relevant information, the computer system can construct the following event branch chain:

[0052] Start with reference to monitoring events: insufficient supply of raw materials;

[0053] Description of the incident 1: Due to insufficient supply of raw materials, the inventory of raw materials on the production line gradually decreased.

[0054] Intermediate event 1: Raw material inventory is lower than the safety threshold;

[0055] Event description information 2: When the raw material inventory is lower than the safety threshold, the system will trigger an alarm and notify the operator.

[0056] Intermediate event 2: The operator did not handle the alarm in time;

[0057] Event description information 3: Since the operator did not handle the alarm in time, the raw materials on the production line were further reduced.

[0058] End reference monitoring event: production line shutdown;

[0059] In this event chain, each event and description information clearly expresses the logical relationship and time sequence between them. By building such an event chain, the computer system can more deeply understand the complex association and logical chain of events in the industrial Internet of Things monitoring data set, providing strong support for subsequent abnormal analysis and safety monitoring.

[0060] During the execution of step S140, when extracting the event-related description information, the computer system may use natural language processing technology to understand the text information; when constructing the event branch chain, it may use graph theory algorithms to optimize the connection paths between events. In addition, due to the complexity and diversity of the industrial Internet of Things monitoring data set, the execution process of step S140 may also be flexibly adjusted and optimized in combination with actual conditions.

[0061] Step S150: performing anomaly analysis on the industrial Internet of Things monitoring data set according to the event branch chain to obtain an anomaly analysis result of the industrial Internet of Things monitoring data set.

[0062] In step S150, the computer system performs an abnormal analysis on the industrial Internet of Things monitoring data set based on the event chain. The event chain is a logical chain that covers all key events and event-related description information from the start reference monitoring event to the end reference monitoring event. This information provides the computer system with rich context and background knowledge, which helps it to more accurately understand the events in the data set and the relationships between them.

[0063] In order to perform anomaly analysis, the computer system parses and understands the event chain. It analyzes key information such as the attributes, occurrence conditions, and impact range of each event, as well as the logical relationship and time sequence between events. Through in-depth analysis of the event chain, the computer system can establish a comprehensive event model that can reflect the complex associations and dynamic changes of events in the industrial Internet of Things monitoring data set.

[0064] Next, the computer system compares and analyzes the constructed event model with the industrial IoT monitoring data set. It traverses each event in the data set and checks whether they match an event or combination of events in the event model. If an event or combination of events is significantly different from the expected behavior in the event model, the computer system will mark it as an anomaly.

[0065] The process of anomaly analysis can, for example, use statistical analysis methods to calculate the frequency, distribution and other statistical characteristics of events in a data set and compare them with the expected values ​​in the event model. If the statistical characteristics of an event deviate significantly from the expected value, it may be considered an anomaly. In addition, computer systems can also use machine learning algorithms (such as classifiers, clusterers, etc.) to train models to automatically identify abnormal patterns in data sets. These algorithms can learn the characteristics of normal behavior from large amounts of data and identify events that do not match these characteristics as anomalies.

[0066] For example, suppose that in a tobacco production line, the computer system has built an event branch chain from "insufficient raw material supply" to "production line downtime". Now, it performs anomaly analysis on the industrial IoT monitoring data set to detect whether there is a potential risk that may cause the production line to stop.

[0067] During the analysis process, the computer system focuses on events and data related to the event branch chain. For example, it checks the monitoring data of the raw material supply system to determine whether the inventory level of raw materials is lower than the safety threshold; it also checks the operating status data of the production line to observe whether there is any equipment failure or abnormal operation. If the computer system finds that the raw material inventory is indeed lower than the safety threshold and some equipment on the production line shows signs of failure, it will match these events with the "insufficient raw material supply" and "equipment failure" events in the event branch chain.

[0068] Next, the computer system evaluates the impact of these events on the risk of production line downtime. It infers the causal relationship and logical sequence between events based on the event description information in the event branch chain. For example, it believes that "insufficient raw material supply" may lead to "reduction of raw materials on the production line" and "equipment failure" may further aggravate this trend and eventually lead to "production line downtime". Based on this inference, the computer system calculates the contribution of each event to the risk of production line downtime and comprehensively evaluates the degree of abnormality of the entire data set.

[0069] If the computer system finds that the degree of anomaly in the data set exceeds the preset threshold, it will trigger the alarm mechanism and send an alarm message to relevant personnel. These alarm messages may include detailed information of the abnormal event, possible scope of impact, recommended response measures, etc., to help relevant personnel respond and deal with potential risks and threats in a timely manner.

[0070] During the execution of step S150, when calculating the contribution of the event to the risk of production line downtime, the computer system may use algorithms such as weighted summation and Bayesian network to comprehensively consider the influence of multiple factors. In addition, due to the complexity and diversity of the industrial Internet of Things monitoring data set, the execution process of step S150 may also be flexibly adjusted and optimized in combination with actual conditions.

[0071] In one implementation, the plurality of monitoring events include monitoring event E i , i is not greater than the number of the plurality of monitoring events; the step S120, obtaining the reference monitoring events respectively involved in the plurality of monitoring events from the plurality of reference monitoring events as involved reference monitoring events, comprises:

[0072] Step S121: Determine the monitoring event E i The event co-occurrence frequency between each reference monitoring event in the plurality of reference monitoring events;

[0073] Step S122: acquiring H event co-occurrence frequencies from a plurality of event co-occurrence frequencies, where H is less than the number of the plurality of event co-occurrence frequencies; the H event co-occurrence frequencies are greater than an additional event co-occurrence frequency; the additional event co-occurrence frequency includes event co-occurrence frequencies other than the H event co-occurrence frequencies from the plurality of event co-occurrence frequencies;

[0074] Step S123: Among the multiple reference monitoring events, determine the reference monitoring event corresponding to the H event co-occurrence frequencies as the monitoring event E. i Temporary reference monitoring events;

[0075] Step S124: Determine the monitoring event E ia matching score between the temporary reference monitoring event and the temporary reference monitoring event, and obtaining a maximum matching score among the matching scores;

[0076] Step S125: Determine the temporary reference monitoring event corresponding to the maximum matching score as the monitoring event E i of reference monitoring events involved.

[0077] In step S121, the computer system focuses on calculating each monitoring event E i The event co-occurrence frequency between multiple reference monitoring events. The event co-occurrence frequency refers to the number of times two events occur simultaneously in the same time period, which reflects the concurrency and correlation between events. In order to calculate this frequency, the computer system traverses the entire industrial Internet of Things monitoring data set and records each monitoring event E i The timestamps of the events are compared with each reference monitoring event and compared to see if they fall within the same time window.

[0078] For example, suppose the monitoring event E i It means "device A's temperature is abnormal", while the reference monitoring events include "device B's current fluctuation", "device C's vibration abnormality", etc. The computer system will check the timestamps of these events in the data set, and calculate the number of times "device A's temperature abnormality" and "device B's current fluctuation" occur at the same time, and the number of times "device C's vibration abnormality" occur at the same time. These numbers are the event co-occurrence frequencies.

[0079] In step S122, the computer system screens the event co-occurrence frequencies calculated in step S121 to find H events with higher frequencies. These high-frequency events are considered to be related to the monitoring event E. i Has stronger relevance. H is a preset threshold that determines how many high-frequency events to retain. Usually, the value of H is adjusted according to the size and complexity of the data set to ensure that the events screened are representative but not too many.

[0080] Continuing with the above example, assume that the computer system calculates that the event co-occurrence frequency of "device A temperature anomaly" and "device B current fluctuation" is 100 times, and the event co-occurrence frequency with "device C vibration anomaly" is 80 times, while the event co-occurrence frequency with other reference monitoring events is less than 50 times. If H is set to 2, the computer system will select "device B current fluctuation" and "device C vibration anomaly" as high-frequency events because their event co-occurrence frequency is higher than other events.

[0081] In step S123, the computer system marks the corresponding reference monitoring event as monitoring event E according to the high-frequency event screened out in step S122. iThese temporary reference monitoring events are the focus of subsequent analysis because they are considered to be related to monitoring event E. i There is a closer connection.

[0082] Continuing with the above example, if "current fluctuation of device B" and "abnormal vibration of device C" are selected as high-frequency events, then the reference monitoring events corresponding to these two events ("current fluctuation of device B" and "abnormal vibration of device C") are determined as monitoring event E. i (“Temperature abnormality of device A”) is a temporary reference monitoring event.

[0083] In step S124, the computer system further evaluates the monitoring event E i The degree of match between each temporary reference monitoring event. To achieve this, the computer system can use various matching algorithms or models, such as similarity calculation based on feature vectors, classification models based on machine learning, etc. The purpose of matching scoring is to quantify the degree of match between the monitoring event E and the reference monitoring event E. i The strength of association with the temporary reference monitoring events is evaluated in order to select the most relevant reference monitoring events.

[0084] Assume that the computer system uses feature vector-based similarity calculation as a matching algorithm. First, it constructs a feature vector for each monitoring event and reference monitoring event, which contains key attribute information of the event, such as event type, occurrence time, impact range, etc. Then, it calculates the monitoring event E i The similarity between the feature vector of and the feature vector of each temporary reference monitoring event (such as cosine similarity, Euclidean distance, etc.). The higher the similarity, the better the match between the two events.

[0085] In the above example, the computer system will calculate the monitoring event E i The similarity between the feature vector of the temporary reference monitoring events (“current fluctuation of device B” and “abnormal vibration of device C”) is calculated as follows:

[0086] In step S125, the computer system selects the temporary reference monitoring event with the highest matching score as monitoring event E according to the matching score calculated in step S124. i The reference monitoring event involved is considered to be related to the monitoring event E. i It has the strongest correlation and is the focus of subsequent anomaly analysis.

[0087] Continuing with the above example, if “current fluctuation of device B” receives the highest match score (0.8), it is identified as monitoring event E. i (“Temperature anomaly of device A”) is a reference monitoring event involved. This means that in the subsequent analysis, the computer system will focus on the correlation and mutual influence between “Temperature anomaly of device A” and “Current fluctuation of device B”.

[0088] By executing the above steps S121 to S125, the computer system can effectively filter out the monitoring event E from multiple reference monitoring events. i The most relevant reference monitoring events. This process not only considers the concurrency and correlation between events (through event co-occurrence frequency), but also the degree of match between events (through match score), thus ensuring that the selected reference monitoring events are both representative and accurate.

[0089] In one implementation, the step S121 determines the monitoring event E i The event co-occurrence frequency between each reference monitoring event in the multiple reference monitoring events includes:

[0090] Step S1211: according to the length of the mobile access frame, in the monitoring event E i In order to obtain the monitoring event E i The corresponding monitoring sub-event; the number of sub-events of the monitoring sub-event is equal to the scale length of the mobile access frame;

[0091] Step S1212: Obtain reference monitoring sub-events corresponding to the multiple reference monitoring events respectively; the multiple reference monitoring events include reference monitoring event R j , j is less than or equal to the number of the plurality of reference monitoring events; the plurality of reference monitoring sub-events includes the reference monitoring event R j The corresponding reference monitoring sub-event;

[0092] Step S1213: The monitoring sub-event and the reference monitoring event R j The corresponding reference monitoring sub-events are subjected to sub-event co-occurrence analysis to obtain the monitoring event E i The reference monitoring event R j The frequency of events occurring simultaneously.

[0093] In step S1211, the computer system uses the mobile access frame technology to traverse the monitoring event E i , and extract a series of monitoring sub-events. The mobile access frame can be regarded as a sliding window, which iThe moving access frame moves in a time series, with a fixed scale length (i.e., window size) each time. After each move, the data in the moving access frame is regarded as a monitoring sub-event. By continuously moving the moving access frame, the computer system can extract multiple monitoring sub-events, and the length of each sub-event is equal to the scale length of the moving access frame.

[0094] For example, suppose the monitoring event E i represents "temperature change of device A", which is a time series data, including the temperature value of device A at different time points. If the length of the mobile access frame is set to 5 time points, the computer system will monitor event E in turn. i Move the window upwards, extracting 5 consecutive temperature values ​​each time as a monitoring sub-event. i If the data contains 100 time points, the computer system will extract 20 monitoring sub-events (because 100 divided by 5 equals 20, the last window may contain less than 5 data points, depending on the relationship between the total length of the data and the window size).

[0095] In step S1212, the computer system uses the same method as step S1211 to monitor multiple reference monitoring events (R j , where j represents the number of the reference monitoring event) to extract their corresponding reference monitoring sub-events. This means that for each reference monitoring event R j , computer systems will apply the moving access frame technology to move the window on its time series data and extract multiple sub-events. The length of these sub-events is also equal to the length of the moving access frame.

[0096] Continuing with the above example, assume there are three reference monitoring events: R_1 represents "current change of device B", R_2 represents "vibration change of device C", and R_3 represents "ambient humidity change". For each reference monitoring event, the computer system uses the same reference monitoring event E. i The same moving access frame is used to extract the reference monitoring sub-events with the same length (e.g., 5 time points). Thus, for each reference monitoring event, the computer system will obtain a series of reference monitoring sub-events with the same length as the monitoring sub-event.

[0097] In step S1213, the computer system performs sub-event co-occurrence analysis on the monitoring sub-events and reference monitoring sub-events extracted in steps S1211 and S1212. The purpose of sub-event co-occurrence analysis is to calculate the number of times the monitoring sub-event occurs simultaneously with each reference monitoring sub-event, that is, the event co-occurrence frequency. This is achieved by comparing the timestamps of the monitoring sub-event and the reference monitoring sub-event. If the timestamps of the two sub-events fall within the same time window (that is, they have some or all of their time points overlap), the two sub-events are considered to have occurred simultaneously.

[0098] Continuing with the above example, assume that the monitoring event E has been extracted i The computer system will now compare the timestamps of each monitoring sub-event with those of each reference monitoring sub-event to calculate the frequency of co-occurrence between them. i The computer system will check whether the first monitoring sub-event (containing data from time points 1 to 5) of the reference monitoring events R_1, R_2 and R_3 (also containing data from time points 1 to 5) occurs at the same time. If a matching reference monitoring sub-event is found, the event co-occurrence frequency is increased. This process will be repeated for all monitoring sub-events and reference monitoring sub-events to calculate the monitoring event E i The frequency of event co-occurrences with each reference monitoring event.

[0099] The calculation of event co-occurrence frequency may be affected by many factors, such as the scale length of the mobile access frame, the time resolution of the data, and the time characteristics of the event. The selection of scale length is crucial for the calculation of event co-occurrence frequency because it determines the time range and granularity of sub-events. A smaller scale length can capture more event details, but it may also increase noise and computational complexity; a larger scale length may simplify the calculation, but may ignore some important event details. In practical applications, the scale length can be reasonably selected according to the characteristics of the data and the analysis requirements.

[0100] In one implementation, the number of monitoring sub-events is m, and the m monitoring sub-events include monitoring sub-event G k , k is not greater than m. In step S1213, the monitoring sub-event and the reference monitoring event R j The corresponding reference monitoring sub-events are subjected to sub-event co-occurrence analysis to obtain the monitoring event E i The reference monitoring event R j The frequency of events occurring simultaneously between

[0101] Step S12131: The monitoring sub-event G kThe reference monitoring event R j The corresponding reference monitoring sub-events are compared;

[0102] Step S12132: When the reference monitoring event R j The corresponding reference monitoring sub-events include the monitoring sub-event G k The same reference monitoring sub-event will be compared with the monitoring sub-event G k The number of the same reference monitoring sub-events is determined as the monitoring sub-event G k The corresponding event co-occurrence frequency;

[0103] Step S12133: The statistical result of the event co-occurrence frequency corresponding to the m monitoring sub-events is determined as the monitoring event E i The reference monitoring event R j The frequency of events occurring simultaneously.

[0104] In step S12131, the computer system converts each monitoring sub-event G k (where k represents the number of the monitoring sub-event, and k is not greater than the total number of monitoring sub-events m) and the reference monitoring event R j The purpose of the comparison is to compare the monitoring sub-event G k Whether the monitoring sub-event is consistent or similar in time and content to the reference monitoring sub-event. Since both the monitoring sub-event and the reference monitoring sub-event are extracted from the original event data based on the moving access frame (sliding window) technology, they have the same time length and data structure. This makes the comparison process relatively direct and efficient.

[0105] For example, suppose the monitoring event E i is about the temperature change of device A, while the reference monitoring event R j It is about the current change of device B. Through the mobile access frame technology, multiple monitoring sub-events and reference monitoring sub-events have been extracted from these two events. Now, the computer system will extract the monitoring sub-events G one by one. k (For example, the temperature data of device A from time t1 to t5) and the reference monitoring event R j The comparison may be performed by comparing the data values ​​of two sub-events within the time window to see whether they match or are similar (for example, whether the temperature value and the current value are similar within a preset threshold range), or comparing their changing trends to see whether they are consistent (for example, whether the temperature increases with the increase of the current).

[0106] In step S12132, the computer system checks whether there is any reference monitoring sub-event that matches the monitoring sub-event G in the reference monitoring sub-event compared in step S12131. k The same or similar sub-events. The same or similar judgment criteria may be based on the matching degree of data values, the consistency of change trends, or other predefined rules. k When the same reference monitoring sub-event is encountered, the computer system will count the number of these same sub-events and regard this number as the monitoring sub-event G k The corresponding event co-occurrence frequency.

[0107] Continuing with the above example, suppose that during the comparison process, the computer system finds that the reference monitoring event R j A reference monitoring sub-event (e.g., the current data of device B from time points t1 to t5) and the monitoring sub-event G k (Temperature data of device A from time point t1 to t5) are highly consistent in both data value and change trend. This means that the two sub-events occurred at the same time, or there is some correlation between them. Therefore, the computer system will count the number of such identical sub-events and use them as monitoring sub-event G. k With reference monitoring event R j The frequency of events occurring simultaneously.

[0108] Note that the "same" here does not require that the two sub-events be exactly the same in data value, but rather that a certain difference or tolerance range is allowed. This is because in practical applications, due to the influence of various factors (such as measurement errors, environmental interference, etc.), it may be difficult for completely identical sub-events to occur. Therefore, computer systems usually set a threshold or tolerance range to determine whether two sub-events are "close enough" to be considered the same.

[0109] In step S12133, the computer system calculates each monitoring sub-event G calculated in step S12132. k The corresponding event co-occurrence frequency is counted to obtain the monitoring event E i With reference monitoring event R j The total event co-occurrence frequency between them. The statistical method may be a simple summation operation, that is, adding up the event co-occurrence frequencies of all monitored sub-events to get a total number. This total number represents the monitored event E. i With reference monitoring event R j The number of co-occurrences or strength of association over the entire analysis period.

[0110] Continuing with the above example, assume that each monitoring sub-event G has been calculated k (k=1,2,...,m) and the reference monitoring event R jNow, the computer system will sum these frequencies to obtain the monitoring event E i With reference monitoring event R j The higher the frequency, the more frequent the monitoring event E is. i With reference monitoring event R j The stronger the correlation between them, the greater the possibility that they will occur at the same time. This has important reference value for subsequent event involvement analysis and anomaly detection.

[0111] By executing the above steps S12131 to S12133, the computer system can effectively calculate the monitoring event E i With reference monitoring event R j This process not only takes into account the temporal characteristics and concurrency of events, but also realizes the quantitative evaluation of event correlation through sub-event co-occurrence analysis. This provides important data support for the subsequent event involvement logic construction and anomaly analysis. At the same time, by adjusting the parameters such as the length of the mobile access frame and the judgment criteria of the comparison, the computer system can also flexibly adapt to the changes in different application scenarios and analysis needs.

[0112] In one implementation, the step S124 determines the monitoring event E i The matching score with the temporary reference monitoring event includes:

[0113] Step S1241: Obtain a feature construction algorithm to generate the monitoring event E i A first description array of, and a second description array of the temporary reference monitoring events;

[0114] Step S1242: Determine the matching score between the first description array and the second description array as the monitoring event E i The matching score between the temporary reference monitoring event and the temporary reference monitoring event.

[0115] In step S1241, the computer system selects or obtains a suitable feature construction algorithm. The purpose of this algorithm is to convert the monitoring event E i The temporary reference monitoring events are converted into a unified and comparable form, namely the description array. The description array is a feature representation that contains key information of the event, such as timestamp, attribute value, category label, etc. This information helps the computer system understand the nature and characteristics of the event.

[0116] The choice of feature construction algorithm depends on the specific application scenario and analysis requirements. In practical applications, commonly used feature construction algorithms include statistical methods (such as calculation of statistical quantities such as mean, standard deviation, maximum value, minimum value, etc.), machine learning methods (such as principal component analysis PCA, linear discriminant analysis LDA, neural network, etc.) and domain knowledge-based methods (such as defining features based on expert experience).

[0117] Taking neural network as an example, assume that a multi-layer perceptron (MLP) is used as the feature construction algorithm. This neural network will receive monitoring events E i The neural network takes the monitoring event and the temporary reference monitoring event as input, and extracts and learns the features of the event through a series of hidden layers. At the output layer, the neural network will generate two description arrays: monitoring event E i The first description array of the temporary reference monitoring event and the second description array of the temporary reference monitoring event. These two description arrays contain the feature values ​​of the event in different dimensions, which reflect the location and distribution of the event in the attribute space.

[0118] For example, suppose the monitoring event E i is about the temperature anomaly of device A, while the temporary reference monitoring event is about the current fluctuation of device B. Through the neural network feature construction algorithm, two description arrays can be generated. i , its first description array may contain characteristic values ​​such as the degree, duration, and frequency of temperature anomaly; for temporary reference monitoring events, its second description array may contain characteristic values ​​such as the amplitude, frequency, and phase of current fluctuations. These characteristic values ​​together constitute the representation of the event in the feature space, providing a basis for subsequent matching scores.

[0119] In step S1242, the computer system calculates a matching score between the first description array and the second description array to quantify the monitoring event E. i The degree of association with the temporary reference monitoring event. The calculation method of the matching score depends on the specific content and structure of the description array. In practical applications, commonly used matching scoring methods include cosine similarity, Euclidean distance, Manhattan distance, Jaccard similarity coefficient, etc.

[0120] Taking cosine similarity as an example, assume that the first description array and the second description array are represented as vector A and vector B respectively. Cosine similarity evaluates the similarity between two vectors by calculating the cosine value of the angle between them. The closer the cosine value is to 1, the more similar the two vectors are; the closer the cosine value is to -1, the more opposite the two vectors are; and the cosine value of 0 indicates that the two vectors are orthogonal. The specific calculation formula is as follows:

[0121] ;

[0122] in, represents the dot product of vector A and vector B, and Represent the modulus of vector A and vector B respectively.

[0123] Continuing with the above example, assume that the monitoring event E has been generated by the neural network feature construction algorithm i The computer system will now calculate the cosine similarity between these two vectors as the matching score between them. If the cosine similarity is high (e.g., close to 1), it means that the monitoring event E i If the directions of the temporary reference monitoring events in the feature space are similar, the correlation between them is strong; if the cosine similarity is low (for example, close to 0 or -1), it means that the correlation between them is weak or opposite.

[0124] By executing the above steps S1241 to S1242, the computer system can effectively generate the monitoring event E i The description array of the temporary reference monitoring event is used to calculate the matching score between them. This process not only takes into account the feature representation and similarity measurement of the event, but also realizes the quantitative evaluation of the event correlation through the feature construction algorithm and matching scoring method. This provides important data support and decision-making basis for the subsequent event involvement logic construction and anomaly analysis.

[0125] In one implementation, before obtaining the feature construction algorithm in step S1241, the method provided by the present application further includes a training process of the feature construction algorithm, specifically including the following steps S124A to S124D:

[0126] Step S124A: Acquire multiple first monitoring event group samples; the multiple first monitoring event group samples include the first monitoring event group sample M o , o is less than or equal to the number of the plurality of first monitoring event group samples; wherein each first monitoring event group sample includes a monitoring event learning sample and a reference monitoring event involved in the monitoring event learning sample, and the reference monitoring events in each first monitoring event group sample belong to the event tree;

[0127] Step S124B: Obtain an initial feature construction algorithm to generate the first monitoring event group sample M o The first prediction description array of the monitoring event learning sample in, and the first monitoring event group sample M o a second prediction description array of a first reference monitoring event in the event tree, wherein the first reference monitoring event belongs to the event tree;

[0128] Step S124C: Determine the first prediction description array and the second prediction description array as the first monitoring event group sample M o A collection of prediction description arrays;

[0129] Step S124D: According to the prediction description array sets corresponding to the plurality of first monitoring event group samples, the algorithm configuration variables in the initial feature construction algorithm are modified to obtain the feature construction algorithm.

[0130] In step S124A, the computer system collects multiple first monitoring event group samples as training samples. These samples are positive samples, which means that they contain useful information related to the actual monitoring events. Each first monitoring event group sample includes a monitoring event learning sample and a reference monitoring event that is involved in the sample. These reference monitoring events all belong to the event tree, that is, there is a clear logical relationship and causal chain between them.

[0131] For example, suppose that training samples are collected on a tobacco production line. A possible first monitoring event group example M o It may include the monitoring event learning sample "Equipment A Overheating" (this is the actual monitored event), as well as the reference monitoring events "Insufficient Raw Material Supply" and "Equipment B Failure" that are involved in this event (these two events are logically related to "Equipment A Overheating" in the event tree). The collection of these samples is based on domain knowledge and historical data to ensure that they can accurately reflect the actual monitoring events and the logical relationships between them.

[0132] In step S124B, the computer system obtains an initial feature construction algorithm. This algorithm can be any machine learning model that can generate event description arrays, such as neural networks, support vector machines, or decision trees. The purpose of the algorithm is to convert monitoring event learning samples and reference monitoring events into description arrays that contain key feature information of the events.

[0133] For each first monitoring event group sample M o , the initial feature construction algorithm will generate two prediction description arrays: one is the first prediction description array of the monitoring event learning sample, and the other is the second prediction description array of the reference monitoring event. These prediction description arrays are a representation of the event features by the algorithm, and they will be used for subsequent matching scores and algorithm optimization.

[0134] Continuing with the above example, assume that a neural network is used as the initial feature construction algorithm. For the first monitoring event group sample M o, the neural network will receive "equipment A overheating" as input and generate a first prediction description array containing multiple feature values ​​(for example, the degree of temperature anomaly, duration, impact range, etc.). Similarly, for the reference monitoring events "insufficient raw material supply" and "equipment B failure", the neural network will generate the corresponding second prediction description array.

[0135] In step S124C, the computer system combines the first prediction description array and the second prediction description array generated in step S124B into a prediction description array set. This set is a binary set that includes the description arrays of the monitoring event learning sample and the reference monitoring event. This set will be used for subsequent correction and optimization of the initial feature construction algorithm.

[0136] Continuing with the above example, for the first monitoring event group sample M o , the first prediction description array of "equipment A overheating" is combined with the second prediction description arrays of "insufficient raw material supply" and "equipment B failure" into a prediction description array set. This set will be used as part of the training data to adjust and optimize the parameters of the neural network.

[0137] In step S124D, the computer system uses the prediction description array set corresponding to the plurality of first monitoring event group samples to correct and optimize the algorithm configuration variables in the initial feature construction algorithm. This process usually involves training and optimization steps in machine learning, such as gradient descent, back propagation, etc. By iteratively adjusting the algorithm parameters, the computer system can gradually improve the accuracy and effectiveness of the algorithm's representation of event features.

[0138] The goal of optimization is to enable the feature construction algorithm to generate a more accurate description array, thereby improving the accuracy and reliability of subsequent matching scores. To achieve this goal, the computer system can use a loss function to quantify the difference between the predicted description array and the true description array, and adjust the algorithm parameters by minimizing the loss function.

[0139] Continuing with the above example, assume that the mean square error (MSE) is used as the loss function to measure the difference between the predicted description array and the true description array. During the training process, the neural network will continuously adjust its weights and bias terms to minimize the MSE loss function. Through multiple iterations of training, an optimized feature construction algorithm can be obtained, which can more accurately generate description arrays of monitoring events and reference monitoring events.

[0140] By executing the above steps S124A to S124D, the computer system can prepare and optimize the feature construction algorithm, providing a solid foundation for the subsequent generation of description arrays of monitoring events and temporary reference monitoring events and calculation of matching scores between them. This process not only takes into account the feature representation and similarity measurement of events, but also improves the accuracy and effectiveness of the algorithm through machine learning training and optimization techniques.

[0141] In one implementation, the step S124D, based on the prediction description array sets corresponding to the plurality of first monitoring event group samples, respectively, modifies the algorithm configuration variables in the initial feature construction algorithm to obtain the feature construction algorithm, including:

[0142] Step S124D1: determining a first array distance between the first prediction description array and the second prediction description array;

[0143] Step S124D2: Obtain the first monitoring event group sample M from the plurality of first monitoring event group samples. o a second reference monitoring event in a first monitoring event group sample other than the first monitoring event group, wherein the second reference monitoring event belongs to the event tree;

[0144] Step S124D3: in the prediction description array sets corresponding to the plurality of first monitoring event group samples respectively, determining the prediction description array corresponding to the second reference monitoring event as the third prediction description array;

[0145] Step S124D4: determining a second array distance between the first prediction description array and the third prediction description array;

[0146] Step S124D5: According to the first array distance and the second array distance, the algorithm configuration variables in the initial feature construction algorithm are modified to obtain the feature construction algorithm.

[0147] In step S124D1, the computer system calculates the distance between the first prediction description array of the monitoring event learning sample and the second prediction description array of the reference monitoring event in each first monitoring event group sample. This distance measures the similarity or difference between the two description arrays in the feature space, which is an important basis for subsequent algorithm optimization.

[0148] Distance can be calculated using a variety of methods, such as Euclidean distance, Manhattan distance, cosine similarity, etc. Taking Euclidean distance as an example, assuming that the first prediction description array is vector A and the second prediction description array is vector B, the Euclidean distance between them can be calculated using the following formula:

[0149] ;

[0150] Among them, n is the dimension of the description array, A i and B i are the values ​​of vector A and vector B in the i-th dimension respectively.

[0151] For example, suppose there is a first monitoring event group sample M o , where the first prediction description array of the monitoring event learning sample "equipment A overheating" is vector A=[2.5,1.2,0.8], and the second prediction description array of the reference monitoring event "raw material supply shortage" is vector B=[2.0,1.5,0.5]. The distance between them is calculated using the Euclidean distance formula:

[0152] ;

[0153] In step S124D2, the computer system selects a comparison sample from the training data set. Specifically, it selects a comparison sample from the plurality of first monitoring event group samples except the sample M currently being processed. o Reference monitoring events in other samples other than sample M are used as comparison samples. These comparison samples should be o There is a certain degree of difference in the monitoring event learning examples in , so as to evaluate the algorithm's ability to distinguish different types of events in subsequent steps.

[0154] For example, suppose there are three first monitoring event group samples: M_1 (including monitoring event "equipment A overheating" and reference monitoring event "insufficient raw material supply"), M_2 (including monitoring event "equipment B failure" and reference monitoring event "ambient temperature is too high"), and M_3 (including monitoring event "production line shutdown" and reference monitoring event "equipment C aging"). When processing sample M_1, the computer system will select the reference monitoring events "ambient temperature is too high" and "equipment C aging" in samples M_2 and M_3 as comparison samples.

[0155] In step S124D3, the computer system obtains the prediction description arrays corresponding to the comparison sample (i.e., the second reference monitoring event) selected in step S124D2, and refers to these arrays as third prediction description arrays. These third prediction description arrays will be compared with the sample M o The first predictions in the description array are compared to evaluate the performance of the algorithm.

[0156] Continuing with the above example, when processing sample M_1, the computer system will obtain the prediction description arrays corresponding to the reference monitoring events "ambient temperature is too high" and "device C aging" in samples M_2 and M_3, respectively recorded as vector C and vector D. These vectors will be used as the third prediction description array to be compared with the first prediction description array in sample M_1.

[0157] In step S124D4, the computer system calculates the distance (such as Euclidean distance, cosine distance, Chebyshev distance, etc.) between the first prediction description array and each third prediction description array. These distances will be used to evaluate the algorithm's ability to distinguish different types of events and serve as a basis for subsequent algorithm optimization.

[0158] Continuing with the above example, the computer system will calculate the distances between vector A (the first prediction description array in sample M_1) and vector C (the third prediction description array in sample M_2) and vector D (the third prediction description array in sample M_3). These distances represent the similarity or difference between "device A overheating" and "ambient temperature too high" and "device C aging" in the feature space.

[0159] In step S124D5, the computer system corrects and optimizes the algorithm configuration variables in the initial feature construction algorithm according to the distances calculated in steps S124D1 and S124D4. This process usually involves training and optimization algorithms in machine learning, such as gradient descent, back propagation, etc.

[0160] The goal of optimization is to enable the algorithm to generate more accurate and discriminative description arrays, thereby improving the accuracy and reliability of subsequent matching scores. To achieve this goal, the computer system can use a loss function to quantify the difference between the predicted description array and the true description array (or the expected description array), and adjust the algorithm parameters by minimizing the loss function.

[0161] During the optimization process, the computer system can consider a variety of factors, such as the relative size between the first array distance and the second array distance, the difference between different event types, etc. For example, if the first array distance (i.e., the distance between the monitoring event learning sample and the reference monitoring event) is much smaller than the second array distance (i.e., the distance between the monitoring event learning sample and the comparison sample), it means that the algorithm can already distinguish these two types of events well, and the algorithm may not be adjusted significantly at this time. On the contrary, if the first array distance is not much different from the second array distance, it means that the algorithm has difficulty distinguishing different types of events, and the algorithm's ability to distinguish is increased at this time.

[0162] To achieve this goal, the computer system can adjust the configuration variables of the algorithm, such as the weights and biases of the neural network, the kernel function and parameters of the support vector machine, etc. These adjustments will be made based on the gradient information of the loss function or other optimization criteria to ensure that the algorithm can gradually approach the optimal solution.

[0163] By executing the above steps S124D1 to S124D5, the computer system can correct and optimize the algorithm configuration variables in the initial feature construction algorithm, thereby obtaining a more accurate and effective feature construction algorithm. This process not only takes into account the feature representation and similarity measurement of events, but also improves the accuracy and discrimination of the algorithm through machine learning training and optimization technology. This provides important data support and decision-making basis for subsequent event-involved logic construction and anomaly analysis.

[0164] In one implementation, the step S124D5, based on the first array distance and the second array distance, modifies the algorithm configuration variables in the initial feature construction algorithm to obtain the feature construction algorithm, including:

[0165] Step S124D51: Determine the first monitoring event group sample M for updating the initial feature construction algorithm o an attention coefficient of the attention of the corresponding second monitoring event group sample, wherein the second monitoring event group sample is composed of the monitoring event learning sample and the second reference monitoring event;

[0166] Step S124D52: determining a first division result between the first array distance and the attention coefficient, and determining a second division result between the second array distance and the attention coefficient;

[0167] Step S124D53: construct a loss function based on the first division result and the second division result, modify the algorithm configuration variables in the initial feature construction algorithm, and obtain the feature construction algorithm.

[0168] In step S124D51, the computer system determines an attention coefficient for adjusting the initial feature construction algorithm for the first monitoring event group sample M o and the attention of the corresponding second monitoring event group samples. The attention coefficient is an important hyperparameter, such as a weight parameter, which determines the degree of attention that the algorithm should pay when processing different samples.

[0169] The determination of the attention coefficient can be based on a variety of factors, such as the importance of the sample, the similarity between samples, the rarity of the sample, etc. In practical applications, the attention coefficient is usually determined through experiments and experience to ensure that the algorithm can efficiently process the training data and avoid overfitting or underfitting problems.

[0170] For example, suppose there are three first monitoring event group samples: M_1 (including monitoring event "equipment A overheating" and reference monitoring event "insufficient raw material supply"), M_2 (including monitoring event "equipment B failure" and reference monitoring event "ambient temperature is too high"), M_3 (including monitoring event "production line shutdown" and reference monitoring event "equipment C aging"). When processing sample M_1, if "equipment A overheating" is considered to be an important and feasible event, and "insufficient raw material supply" is a relatively minor event, then a higher attention coefficient can be assigned to sample M_1 so that the algorithm pays more attention to it when processing the sample.

[0171] In step S124D52, the computer system calculates the first division result between the first array distance (i.e., the distance between the monitoring event learning sample and the reference monitoring event) and the attention coefficient, and the second division result between the second array distance (i.e., the distance between the monitoring event learning sample and the comparison sample) and the attention coefficient. These division results will be used for the subsequent construction of the loss function and the correction of the algorithm parameters.

[0172] The calculation of the division result can be regarded as a normalization of the distance, which eliminates the inconsistency of the distance scale between different examples, allowing the algorithm to compare the differences between different examples more fairly. At the same time, by introducing the attention coefficient, the division result also reflects the attention of the algorithm to different examples, allowing the algorithm to process training data more flexibly.

[0173] Continuing with the above example, assume that the first array distance (denoted as d1) and the second array distance (denoted as d2) in sample M_1 have been calculated, and an attention coefficient (denoted as α) has been assigned to sample M_1. Then, the first division result will be d1 / α, and the second division result will be d2 / α. These division results will be used to construct the loss function in subsequent steps.

[0174] In step S124D53, the computer system constructs a loss function based on the first division result and the second division result, and corrects the algorithm configuration variables in the initial feature construction algorithm by minimizing the loss function. The loss function is an important indicator for measuring the performance of the algorithm, which reflects the degree of difference between the algorithm prediction result and the actual result. By minimizing the loss function, the algorithm can gradually approach the optimal solution, thereby improving its accuracy and effectiveness.

[0175] When constructing loss functions, computer systems can use a variety of methods, such as mean squared error (MSE), cross entropy loss, logarithmic loss, etc. These loss functions are usually calculated based on the difference between the predicted value and the true value, and various mathematical transformations are used to enhance the algorithm's ability to distinguish and robustness.

[0176] Taking cross entropy loss as an example, assume that the first division result (denoted as p1) and the second division result (denoted as p2) in sample M_1 have been calculated, and a threshold (denoted as t) is defined to distinguish positive samples from negative samples. Then, the loss function corresponding to sample M_1 can be:

[0177] ;

[0178] Among them, e is the base of the natural logarithm. This loss function calculates the predicted probability of the positive sample based on the softmax function, and quantifies the difference between the predicted probability and the true label through logarithmic loss.

[0179] In practical applications, the computer system usually calculates the loss function for multiple first monitoring event group samples respectively, and uses their sum as the total loss function corresponding to the initial feature construction algorithm. Then, the total loss function is minimized through gradient descent or other optimization algorithms, thereby gradually correcting the algorithm configuration variables, such as the weights and bias terms of the neural network, the kernel function and parameters of the support vector machine, etc.

[0180] By executing the above steps S124D51 to S124D53, the computer system can construct an effective loss function and correct and optimize the algorithm configuration variables in the initial feature construction algorithm by minimizing the loss function. This process not only takes into account the feature representation and similarity measurement of events, but also improves the accuracy and robustness of the algorithm through the construction of the attention mechanism and loss function.

[0181] In one implementation, the event-related description information includes first event-related description information. The step S140 sequentially accesses the event tree to obtain event-related description information for describing the start reference monitoring event and the end reference monitoring event, and constructs an event branch chain covering the start reference monitoring event, the event-related description information, and the end reference monitoring event, including:

[0182] Step S141: in the event tree, obtaining a first reference monitoring event set that is related to the start reference monitoring event;

[0183] Step S142: when the first reference monitoring event set includes the end reference monitoring event, in the event tree, obtaining the first event involvement description information for describing the involvement relationship between the start reference monitoring event and the end reference monitoring event;

[0184] Step S143: sequentially constructing a first event branch chain with the start reference monitoring event, the first event-related description information, and the end reference monitoring event;

[0185] Step S144: discarding the end reference monitoring event in the first reference monitoring event set to obtain a second reference monitoring event set;

[0186] Step S145: sequentially access the second reference monitoring event set to generate an event branch chain including the first event branch chain.

[0187] In step S141, the computer system focuses on other reference monitoring events in the event tree that are directly involved with the starting reference monitoring event. These events are called the first reference monitoring event set, and they are connected to the starting reference monitoring event through the edges in the event tree. These edges may represent causal relationships, sequential relationships, concurrent relationships, or other types of logical relationships.

[0188] For example, suppose we analyze an event branch chain on a tobacco production line. The starting reference monitoring event may be "Insufficient raw material supply", and other reference monitoring events connected to it in the event tree may include "Equipment A downtime", "Equipment B abnormal operation", etc. These events are directly related to "Insufficient raw material supply" for some reason (such as insufficient raw material supply causing the equipment to fail to operate normally), so they are selected as the first reference monitoring event set.

[0189] In step S142, the computer system checks whether the first reference monitoring event set contains the end reference monitoring event. If it does, it means that there is a direct path from the start reference monitoring event to the end reference monitoring event, and the computer system can find information describing the relationship between all events on this path in the event tree. This information is called the first event involvement description information, which may include the attributes, occurrence conditions, impact range, consequences, etc. of the event.

[0190] Continuing with the above example, assume that the end reference monitoring event is "production line downtime". If the first reference monitoring event set includes "production line downtime", the computer system will find information describing all the event relationships between "insufficient raw material supply" and "production line downtime" in the event tree. This information may include "insufficient raw material supply causes equipment A to stop", "equipment A downtime further causes production line downtime", etc.

[0191] In step S143, the computer system combines the start reference monitoring event, the first event involved description information, and the end reference monitoring event according to their logical order in the event tree to form a preliminary event branch chain, namely, the first event branch chain. This branch chain intuitively shows the key nodes of the entire event chain from the beginning to the end and the logical relationship between them.

[0192] Continuing with the above example, the computer system uses "insufficient raw material supply" as the starting reference monitoring event, "insufficient raw material supply causing equipment A to shut down, equipment A shut down further causing production line shut down" as the first event-involved description information, and "production line shut down" as the ending reference monitoring event, and combines them in sequence into a preliminary event branch chain.

[0193] In step S144, the computer system removes the end reference monitoring event from the first reference monitoring event set to obtain a new reference monitoring event set, namely, the second reference monitoring event set. The purpose of this step is to explore other possible paths besides the direct path to construct a more complete event branch chain.

[0194] Continuing with the above example, if "production line shutdown" is the ending reference monitoring event in the first reference monitoring event set, the computer system will remove it from the set, and the remaining reference monitoring events (such as "equipment A shutdown", "equipment B operating abnormally", etc.) will constitute the second reference monitoring event set.

[0195] In step S145, the computer system sequentially accesses each event in the second reference monitoring event set and attempts to connect them with the start reference monitoring event and / or the events in the first event branch. This process may involve multiple traversals of the event tree and construction of temporary event branches. For each temporary event branch, the computer system checks whether it contains the end reference monitoring event and merges it into the final event branch accordingly.

[0196] Continuing with the above example, assume that the second reference monitoring event set includes "Equipment A downtime" and "Equipment B abnormal operation". The computer system will access these two events in turn and try to connect them with "Insufficient raw material supply" and / or the first event branch. For example, it can be found that "Equipment B abnormal operation" is also caused by "Insufficient raw material supply" and further affects other parts of the production line. Therefore, the computer system can construct a new event branch that includes "Insufficient raw material supply", "Equipment B abnormal operation" and the relationship between them, and merge it into the final event branch.

[0197] In the process of constructing event branches, the computer system may encounter a variety of situations. For example, a reference monitoring event may be involved with multiple events, resulting in multiple possible paths. In this case, the computer system may use heuristic search algorithms or graph theory algorithms to find the optimal or suboptimal path. In addition, if the event tree is very large and complex, the computer system may use distributed computing or parallel processing technology to improve processing efficiency.

[0198] By executing the above steps S141 to S145, the computer system can build a complete and accurate event branch chain, which covers all key nodes and the logical relationships between them from the start reference monitoring event to the end reference monitoring event. This event branch chain is of great value for subsequent abnormal analysis, risk assessment and decision support. At the same time, by optimizing the traversal algorithm of the event tree and the construction strategy of the event branch chain, the computer system can further improve processing efficiency and accuracy to cope with more complex and large-scale application scenarios.

[0199] In one implementation, the step S145 of sequentially accessing the second reference monitoring event set to generate an event branch chain including the first event branch chain includes:

[0200] Step S1451: when in the event tree, the second reference monitoring event set does not have any reference monitoring event involved, determining the first event branch as an event branch;

[0201] Step S1452: When, in the event tree, the second reference monitoring event set includes reference monitoring events with an involvement relationship, the reference monitoring events with an involvement relationship in the second reference monitoring event set are determined as a third reference monitoring event set; the third reference monitoring event set includes reference monitoring events S x , x is less than or equal to the number of reference monitoring events in the third reference monitoring event set;

[0202] Step S1453: In the event tree, obtain the event S x A fourth reference monitoring event set having an involvement relationship, wherein the fourth reference monitoring event set does not include the start reference monitoring event;

[0203] Step S1454: access the fourth reference monitoring event set in sequence to generate an event branch chain including the first event branch chain.

[0204] In step S1451, the computer system checks whether there are any reference monitoring events in the second reference monitoring event set that are involved with other events. If the second reference monitoring event set is empty, or all events therein are no longer involved with other events, the computer system will assume that all possible event paths have been found, and determine the current first event branch as the final event branch.

[0205] For example, suppose that when analyzing an event branch chain on a tobacco production line, the starting reference monitoring event is "insufficient raw material supply" and the ending reference monitoring event is "production line shutdown". In the previous step, a first event branch chain containing a direct path from "insufficient raw material supply" to "production line shutdown" has been constructed. Now, if the second reference monitoring event set does not contain any events that are directly or indirectly related to "insufficient raw material supply" or "production line shutdown", the computer system will consider this first event branch chain to be sufficiently complete and determine it as the final event branch chain.

[0206] If there are still reference monitoring events in the second reference monitoring event set that are involved in other events, the computer system will continue to traverse these events and determine them as a third reference monitoring event set. This set contains all reference monitoring events that are further explored in order to build a more complete event branch chain.

[0207] Continuing with the above example, suppose that in the second reference monitoring event set, an event is found that is indirectly related to "insufficient raw material supply", namely "equipment B failure". Although this event does not directly lead to "production line shutdown", it may be caused by "insufficient raw material supply" and further affects other parts of the production line. Therefore, the computer system determines "equipment B failure" as an element in the third reference monitoring event set (i.e., S x ), and is ready to further explore its involvement with other events.

[0208] In step S1453, the computer system focuses on each event in the third reference monitoring event set (such as S x ), and search for other reference monitoring events related to them in the event tree. These newly found events will constitute the fourth reference monitoring event set. Note that the fourth reference monitoring event set should not contain the starting reference monitoring event to avoid duplication and looping.

[0209] Continuing with the above example, let's assume that we are now focusing on "equipment B failure" in the third reference monitoring event set. In the event tree, it is found that "equipment B failure" is related to the two events "equipment C overheating" and "production line speed reduction". Therefore, "equipment C overheating" and "production line speed reduction" are determined as elements in the fourth reference monitoring event set. At the same time, it is noted that neither of these two new events contains the starting reference monitoring event "insufficient raw material supply", which meets the requirements.

[0210] In step S1454, the computer system sequentially accesses each event in the fourth reference monitoring event set and attempts to connect them with the events in the first event branch. This process may involve multiple traversals of the event tree and construction of temporary event branches. For each temporary event branch, the computer system checks whether it contains the ending reference monitoring event and merges it into the final event branch accordingly.

[0211] Continuing with the above example, we will now visit "Equipment C Overheating" and "Production Line Speed ​​Reduction" in the fourth reference monitoring event set in turn. For "Equipment C Overheating", it is found that it has a direct involvement relationship with "Equipment B Failure" in the event tree, and may further lead to "Production Line Shutdown" (although this is not the only path). Therefore, a new event branch chain containing "Insufficient Raw Material Supply", "Equipment B Failure", "Equipment C Overheating" and the involvement relationship between them can be constructed and merged with the first event branch chain. Similarly, for "Production Line Speed ​​Reduction", its involvement relationship with "Equipment B Failure" and other events can also be found in the event tree, and the corresponding event branch chain can be constructed. Finally, all related event branches are merged into a complete event branch chain, which covers all possible paths and involvement relationships from the start reference monitoring event to the end reference monitoring event.

[0212] By executing the above steps S1451 to S1454, the computer system can build a more complete and accurate event chain. This process not only considers the direct event path, but also explores the indirect path and involvement relationship by traversing the second reference monitoring event set and the fourth reference monitoring event set. This makes the event chain more comprehensively reflect the complexity and relevance of events in the industrial Internet of Things monitoring data set, and provides strong support for subsequent abnormal analysis and decision support.

[0213] In one implementation, the event-related description information also includes second event-related description information and third event-related description information. The step S1454, sequentially accessing the fourth reference monitoring event set to generate an event branch chain including the first event branch chain, includes:

[0214] Step S14541: When the fourth reference monitoring event set includes the end reference monitoring event, in the event tree, obtain a sequence of events used to describe the start reference monitoring event and the reference monitoring event S x The second event involving description information of the involvement relationship between the reference monitoring event S x and the third event involvement description information of the involvement relationship between the end reference monitoring events;

[0215] Step S14542: The start reference monitoring event, the second event involving description information, the reference monitoring event S x , the third event involves description information and an end reference monitoring event, which sequentially constitute a second event branch chain;

[0216] Step S14543: discarding the end reference monitoring event in the fourth reference monitoring event set to obtain a fifth reference monitoring event set;

[0217] Step S14544: access the fifth reference monitoring event set in sequence to generate an event branch chain including the first event branch chain and the second event branch chain.

[0218] In one implementation of step S1454, the computer system further expands and improves the event branch chain through a series of detailed steps, which already includes the start reference monitoring event, the first event involved description information, and the end reference monitoring event. This process involves traversing the fourth reference monitoring event set, obtaining the event involved description information, and constructing a new event branch chain.

[0219] In step S14541, the computer system checks whether the fourth reference monitoring event set contains an ending reference monitoring event. If it does, it means that there is a new path from the starting reference monitoring event to the ending reference monitoring event, and the path passes through the reference monitoring event S x (The elements in the third reference monitoring event set) are connected. In order to fully describe this new path, the computer system searches and obtains two key event-related description information in the event tree: the second event-related description information and the third event-related description information.

[0220] The second event involves description information describing the start reference monitoring event and the reference monitoring event S x This relationship may include causal relationships, sequential relationships, concurrent relationships, etc., which reveals the S x How is it triggered by or associated with the start reference monitoring event.

[0221] The third event involves description information describing the reference monitoring event S x The relationship between S and the end reference monitoring event. Similarly, this relationship may also include multiple types, which reveals how the end reference monitoring event is caused by S x Triggering or associated with.

[0222] For example, suppose that when analyzing an event branch chain on a tobacco production line, the starting reference monitoring event is "insufficient raw material supply" and the ending reference monitoring event is "production line shutdown". In the previous step, a first event branch chain containing a direct path has been constructed. Now, in the fourth reference monitoring event set, a new event "equipment B overheating" is found, which is directly related to the ending reference monitoring event "production line shutdown". In order to construct an event branch chain containing this new path, the computer system searches and obtains the following information in the event tree:

[0223] The second event involves descriptive information: information describing how "insufficient raw material supply" causes "overheating of equipment B", such as "insufficient raw material supply causes the cooling system of equipment B to fail, which in turn causes overheating of equipment B".

[0224] The third event involves descriptive information: information describing how "device B overheating" causes "production line shutdown", such as "device B overheating triggers the safety protection mechanism, causing the production line to automatically shut down."

[0225] In step S14542, the computer system stores all the key information obtained in step S14541 (the start reference monitoring event, the second event description information, the reference monitoring event S x , the third event involving description information and the end reference monitoring event) are combined in their logical order in the event tree to form a new event branch, namely the second event branch. This branch intuitively shows a new path from the start reference monitoring event to the end reference monitoring event, as well as the involvement relationship between all events on the path.

[0226] Continuing with the above example, the computer system uses "insufficient raw material supply" as the starting reference monitoring event, "insufficient raw material supply leads to failure of the cooling system of device B, which in turn causes overheating of device B" as the second event description information, and "overheating of device B" as the reference monitoring event S x "Device B overheating triggered the safety protection mechanism, causing the production line to automatically shut down" as the third event involving description information, and "production line shutdown" as the end reference monitoring event, which are combined in sequence into a new event branch.

[0227] In step S14543, the computer system removes the end reference monitoring event from the fourth reference monitoring event set to obtain a new reference monitoring event set, namely the fifth reference monitoring event set. The purpose of this step is to explore other possible paths besides the known paths to build a more complete event branch chain. Since the end reference monitoring event has been considered in the newly constructed event branch chain, it no longer appears in the subsequent traversal process.

[0228] Continuing with the above example, if "production line downtime" is the ending reference monitoring event in the fourth reference monitoring event set, the computer system removes it from the set. The remaining reference monitoring events (if any) will constitute the fifth reference monitoring event set for further traversal and construction of new event branches in subsequent steps.

[0229] In step S14544, the computer system sequentially accesses each event in the fifth reference monitoring event set and attempts to connect them with the starting reference monitoring event, the first event branch, and the events in the second event branch. This process may involve multiple traversals of the event tree and the construction of temporary event branches. For each temporary event branch, the computer system checks whether it contains new and valuable information and merges it into the final event branch accordingly.

[0230] Continuing with the above example, assume that the fifth reference monitoring event set contains a new event "equipment C failure". The computer system will try to connect this event with events such as "insufficient raw material supply", "equipment B overheating" and "production line shutdown" to explore whether there is a new event path connected by "equipment C failure". If such a path exists and the path provides additional and valuable information (such as revealing that "equipment C failure" is indirectly caused by "insufficient raw material supply" and further affects the stability of the production line), then the computer system will construct a new event branch chain and merge it with the first event branch chain and the second event branch chain to form a more complete and comprehensive event branch chain.

[0231] By executing the above steps S14541 to S14544, the computer system can build a more complete and accurate event branch chain. This process not only takes into account the direct event path, but also explores the indirect path and involvement relationship by traversing the fourth reference monitoring event set and the fifth reference monitoring event set. This makes the event branch chain more comprehensively reflect the complexity and relevance of events in the industrial Internet of Things monitoring data set, and provides strong support for subsequent abnormal analysis and decision support. At the same time, by continuously optimizing the traversal algorithm of the event tree and the construction strategy of the event branch chain, the computer system can further improve processing efficiency and accuracy to cope with more complex and large-scale application scenarios.

[0232] The present application embodiment provides a computer system, such as Figure 2 As shown, the computer system 100 includes: a processor 101 and a memory 103. The processor 101 and the memory 103 are connected, such as through a bus 102. Optionally, the computer system 100 may also include a transceiver 104. It should be noted that in actual applications, the transceiver 104 is not limited to one, and the structure of the computer system 100 does not constitute a limitation on the embodiments of the present application.

[0233] An embodiment of the present application provides a computer system, and the computer system in the embodiment of the present application includes: one or more processors; a memory; one or more computer programs, wherein the one or more computer programs are stored in the memory and configured to be executed by the one or more processors, and when the one or more programs are executed by the processor, the industrial safety data anomaly analysis method in the above embodiment of the present application is implemented.

Claims

1. A method for analyzing abnormality of industrial safety data, characterized in that: include: Extract multiple monitoring events from the industrial Internet of Things monitoring data set; a monitoring event is composed of a series of data items, which together describe an event; the data items are generated by sensors on the tobacco production line, including temperature and vibration; Obtain an event tree for describing the event involvement logic between multiple reference monitoring events, wherein the multiple monitoring events include monitoring event E i , i is not greater than the number of the plurality of monitoring events; according to the length of the mobile access frame, in the monitoring event E i In order to obtain the monitoring event E i The corresponding monitoring sub-event; the number of sub-events of the monitoring sub-event is equal to the scale length of the mobile access frame; Obtain reference monitoring sub-events corresponding to the multiple reference monitoring events respectively; the multiple reference monitoring events include reference monitoring event R j , j is less than or equal to the number of the plurality of reference monitoring events; the plurality of reference monitoring sub-events includes the reference monitoring event R j The corresponding reference monitoring sub-event; For the monitoring sub-event and the reference monitoring event R j The corresponding reference monitoring sub-events are subjected to sub-event co-occurrence analysis to obtain the monitoring event E i The reference monitoring event R j The frequency of events occurring simultaneously between Obtain H event co-occurrence frequencies from a plurality of event co-occurrence frequencies, where H is less than the number of the plurality of event co-occurrence frequencies; the H event co-occurrence frequencies are greater than an additional event co-occurrence frequency; the additional event co-occurrence frequency includes event co-occurrence frequencies other than the H event co-occurrence frequencies from the plurality of event co-occurrence frequencies; Among the multiple reference monitoring events, the reference monitoring event corresponding to the H event co-occurrence frequencies is determined as the monitoring event E. i Temporary reference monitoring events; Determine the monitoring event E i a matching score between the temporary reference monitoring event and the temporary reference monitoring event, and obtaining a maximum matching score among the matching scores; The temporary reference monitoring event corresponding to the maximum matching score is determined as the monitoring event E i of reference monitoring events involved; Among a plurality of reference monitoring events, sequentially accessing and acquiring a reference monitoring event group including a reference monitoring event as a start reference monitoring event and a reference monitoring event as an end reference monitoring event; the start reference monitoring event is inconsistent with the end reference monitoring event; Access the event tree in sequence, obtain event-related description information used to describe the start reference monitoring event and the end reference monitoring event, and construct an event branch chain covering the start reference monitoring event, the event-related description information, and the end reference monitoring event; wherein the event-related description information includes event attributes, occurrence conditions, impact scope, and consequences; Performing an abnormality analysis on the industrial Internet of Things monitoring data set according to the event branch chain to obtain an abnormality analysis result of the industrial Internet of Things monitoring data set; The event-related description information includes first event-related description information; sequentially accessing the event tree to obtain event-related description information used to describe the start reference monitoring event and the end reference monitoring event, and constructing an event branch chain covering the start reference monitoring event, the event-related description information, and the end reference monitoring event, including: In the event tree, obtaining a first reference monitoring event set that is related to the start reference monitoring event; When the first reference monitoring event set includes the end reference monitoring event, in the event tree, obtaining the first event involvement description information for describing the involvement relationship between the start reference monitoring event and the end reference monitoring event; The start reference monitoring event, the first event-related description information, and the end reference monitoring event are sequentially used to form a first event branch chain; Discarding the end reference monitoring event in the first reference monitoring event set to obtain a second reference monitoring event set; When, in the event tree, the second reference monitoring event set does not have any reference monitoring event involved, determining the first event branch chain as an event branch chain; When, in the event tree, the second reference monitoring event set includes reference monitoring events with an involvement relationship, the reference monitoring events with an involvement relationship in the second reference monitoring event set are determined as a third reference monitoring event set; the third reference monitoring event set includes reference monitoring events S x , x is less than or equal to the number of reference monitoring events in the third reference monitoring event set; In the event tree, obtain the reference monitoring event S x A fourth reference monitoring event set having an involvement relationship, wherein the fourth reference monitoring event set does not include the start reference monitoring event; The event-related description information also includes the second event-related description information and the third event-related description information; when the fourth reference monitoring event set includes the end reference monitoring event, in the event tree, obtain the information used to describe the start reference monitoring event and the reference monitoring event S x The second event involving description information of the involvement relationship between the reference monitoring event S x and the third event involvement description information of the involvement relationship between the end reference monitoring events; The start reference monitoring event, the second event involving description information, the reference monitoring event S x , the third event involves description information and an end reference monitoring event, which sequentially constitute a second event branch chain; Discarding the end reference monitoring event in the fourth reference monitoring event set to obtain a fifth reference monitoring event set; The fifth reference monitoring event set is accessed in sequence to generate an event branch chain including the first event branch chain and the second event branch chain.

2. The method according to claim 1, characterized in that The number of monitoring sub-events is m, and the m monitoring sub-events include monitoring sub-event G k , k is not greater than m; The monitoring sub-event and the reference monitoring event R j The corresponding reference monitoring sub-events are subjected to sub-event co-occurrence analysis to obtain the monitoring event E i The reference monitoring event R j The frequency of events occurring simultaneously between The monitoring sub-event G k The reference monitoring event R j The corresponding reference monitoring sub-events are compared; When the reference monitoring event R j The corresponding reference monitoring sub-events include the monitoring sub-event G k The same reference monitoring sub-event will be compared with the monitoring sub-event G k The number of the same reference monitoring sub-events is determined as the monitoring sub-event G k The corresponding event co-occurrence frequency; The statistical result of the event co-occurrence frequency corresponding to the m monitoring sub-events is determined as the monitoring event E i The reference monitoring event R j The frequency of events occurring simultaneously between The determining of the monitoring event E i The matching score with the temporary reference monitoring event includes: Obtain feature construction algorithm to generate the monitoring event E i A first description array of, and a second description array of the temporary reference monitoring events; The matching score between the first description array and the second description array is determined as the monitoring event E. i The matching score between the temporary reference monitoring event and the temporary reference monitoring event.

3. The method according to claim 2, characterized in that Before obtaining the feature construction algorithm, the method further includes: Acquire multiple first monitoring event group samples; the multiple first monitoring event group samples include the first monitoring event group sample M o , o is less than or equal to the number of the plurality of first monitoring event group samples; wherein each first monitoring event group sample includes a monitoring event learning sample and a reference monitoring event involved in the monitoring event learning sample, and the reference monitoring events in each first monitoring event group sample belong to the event tree; Obtain the initial feature construction algorithm to generate the first monitoring event group sample M o The first prediction description array of the monitoring event learning sample in, and the first monitoring event group sample M o a second prediction description array of a first reference monitoring event in the event tree, wherein the first reference monitoring event belongs to the event tree; The first prediction description array and the second prediction description array are determined as the first monitoring event group sample M o A collection of prediction description arrays; According to the prediction description array sets respectively corresponding to the multiple first monitoring event group samples, the algorithm configuration variables in the initial feature construction algorithm are modified to obtain the feature construction algorithm.

4. The method according to claim 3, characterized in that The method of modifying the algorithm configuration variables in the initial feature construction algorithm according to the prediction description array sets respectively corresponding to the plurality of first monitoring event group samples to obtain the feature construction algorithm includes: Determining a first array distance between the first prediction description array and the second prediction description array; From the plurality of first monitoring event group samples, obtain the first monitoring event group sample M o a second reference monitoring event in a first monitoring event group sample other than the first monitoring event group, wherein the second reference monitoring event belongs to the event tree; In the prediction description array sets respectively corresponding to the plurality of first monitoring event group samples, determining the prediction description array corresponding to the second reference monitoring event as a third prediction description array; Determining a second array distance between the first prediction description array and the third prediction description array; Determine the method for updating the initial feature construction algorithm for the first monitoring event group sample M o an attention coefficient of the attention of the corresponding second monitoring event group sample, wherein the second monitoring event group sample is composed of the monitoring event learning sample and the second reference monitoring event; Determine a first division result between the first array distance and the attention coefficient, and determine a second division result between the second array distance and the attention coefficient; A loss function is constructed according to the first division result and the second division result, and the algorithm configuration variables in the initial feature construction algorithm are modified to obtain the feature construction algorithm.

5. A computer system, characterized in that: include: one or more processors; Memory; one or more computer programs; The one or more computer programs are stored in the memory and configured to be executed by the one or more processors, and when the one or more computer programs are executed by the processors, the method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Safety protection method for ubiquitous power Internet of Things terminal in specific attack scene

    CN111404914A

  • Equipment state monitoring method and monitoring system based on edge cloud collaboration and storage medium

    CN112947290A