C2F Application Data Abnormal Detection Model Training Method, Abnormal Detection Method and Related Devices
By dividing and processing time series data in C2F application scenarios, generating prompt word prefixes and answers, and training anomaly detection model, the problem of low detection accuracy in traditional methods is solved, and more efficient and accurate abnormal detection is achieved.
Patent Information
- Application Number
- CN202510350973.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-03-24
AI Technical Summary
In C2F application scenarios, traditional data abnormality detection methods are low in detection accuracy due to the single detection sample and limited data volume, and cannot effectively analyze the correlation between time sequence data.
By dividing time series data based on the preset sliding step length, missing data filling, normalization processing and variable mask processing are performed, prompt word prefix and answers are generated, and C2F is used to train the data anomaly detection model to improve the accuracy of detection.
It improves the accuracy and reliability of abnormal detection of C2F application data, enhances the processing ability of complex industrial data, and can better cope with complex industrial environments with multiple protocols and multiple data types.
Smart Images

Figure CN119884759B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and in particular to a method for training a C2F application data anomaly detection model, an anomaly detection method, and related devices. Background Art
[0002] With the development of society, a new business model of customer to factory (C2F) has emerged. In this model, customers can place orders directly through a digital platform, and factories produce and deliver according to the order requirements. By directly connecting consumers and manufacturers, it eliminates intermediate links, thereby improving efficiency, reducing costs, and providing more personalized customization services. In the C2F model, factories need to respond to consumers' order requirements in real time and be able to quickly adjust the production line to meet personalized needs. This not only requires factories to have efficient production processes but also strong and flexible hardware infrastructure to support high-speed data transmission and processing.
[0003] In order to effectively handle the large amount of transmitted data flow in the C2F model, many information layer switches are usually set at the factory end. These information layer switches need to process and transfer the huge data flow of various industrial devices and business management systems. However, since there are too many types of transmission protocols and complex data sources in the transmitted data, it is necessary to perform anomaly detection on the transmitted data during the data transmission process of C2F applications to ensure data transmission security.
[0004] In related technologies, in order to improve the security of factory application data, multiple specific data detection points are usually set in the factory data transmission process, and corresponding data anomaly detection conditions are formulated in advance for these several data detection points. During the actual factory data transmission process, data anomaly detection is performed at these specific data detection points using the corresponding data anomaly detection conditions. However, due to the extremely diverse types and sources of application data in the C2F scenario, only using fixed data anomaly detection conditions cannot comprehensively analyze the correlation between time series in C2F application data, so it is impossible to accurately perform appropriate anomaly detection on this C2F application data. Moreover, when collecting C2F application data at fixed data detection points for detection, there are problems such as single detection samples and limited detection data volume, resulting in a relatively low detection accuracy when using traditional factory data detection methods to perform anomaly detection on C2F application data. Summary of the Invention
[0005] Embodiments of this application provide a method for training a C2F application data anomaly detection model, an anomaly detection method, and related devices, which can improve the accuracy of anomaly detection of application data in the C2F scenario.
[0006] To achieve the above object, a first aspect of the embodiments of the present application proposes a method for training a C2F application data anomaly detection model, and the method includes:
[0007] Based on a preset sliding step, multiple consecutive C2F application data sequences are obtained according to multiple consecutive time series data;
[0008] Perform variable masking processing on each of the C2F application data sequences one by one to obtain a prompt word prefix and a prompt word answer corresponding to each of the C2F application data sequences, and the prompt word prefix and the prompt word answer are complementary to each other;
[0009] Input the prompt word prefix into the C2F application data anomaly detection model for data prediction to generate predicted prompt data;
[0010] Calculate a loss value according to each predicted prompt data and the corresponding prompt word answer, and perform model training on the C2F application data anomaly detection model based on the loss value. The trained C2F application data detection model is used to perform anomaly detection on C2F application data.
[0011] In some embodiments, the multiple time series data includes the total length of the time series. The performing variable masking processing on each of the C2F application data sequences to obtain a prompt word prefix and a prompt word answer corresponding to each of the C2F application data sequences includes:
[0012] Obtain a mask matrix, and the mask matrix includes a mask ratio parameter;
[0013] Generate the prompt word prefix based on the Hadamard product of the mask matrix and the C2F application data sequence;
[0014] Generate the prompt word answer based on the Hadamard product of the complement of the mask matrix and the C2F application data sequence. The prompt word prefix and the prompt word answer satisfy the complementary data condition, and the complementary data condition is generated based on the mask ratio parameter and the total length of the time series.
[0015] In some embodiments, the time series data includes multiple feature data, and the complementary data condition includes a first mask condition, a second mask condition, and a mask complement condition. The generating step of the complementary data condition includes:
[0016] Based on one minus the mask ratio parameter, multiply the total length of the time series and the number of features of the feature data cumulatively to obtain a first mask data value, and generate the first mask condition based on the numerical relationship between the first matrix norm of the prompt word prefix and the first mask data value;
[0017] Multiply by the mask ratio parameter, the total length of the time series, and the number of features to obtain a second masked data value, and generate the second masking condition based on the numerical relationship between the second matrix norm of the prompt word answer and the second masked data value;
[0018] Multiply by the total length of the time series and the number of features to obtain a complementary masked data value, and generate the mask complementary condition based on the numerical relationship between the first matrix norm, the second matrix norm, and the complementary masked data value.
[0019] In some embodiments, the inputting the prompt word prefix into the C2F application data anomaly detection model for data prediction to generate predicted prompt data includes:
[0020] Perform padding processing on the prompt word prefix to obtain a padded masked data sequence;
[0021] Input the padded masked data sequence into the C2F application data anomaly detection model for mapped data prediction processing to obtain the predicted prompt data.
[0022] In some embodiments, the C2F application data anomaly detection model includes a normalization layer and a feed-forward layer. The calculating a loss value based on each predicted prompt data and the corresponding prompt word answer, and training the C2F application data anomaly detection model based on the loss value includes:
[0023] Based on the difference between each predicted prompt data and the corresponding prompt word answer, perform matrix two-norm processing to obtain the data sequence loss value corresponding to each C2F application data sequence;
[0024] Adjust the normalization layer parameters of the normalization layer and / or the feed-forward layer parameters of the feed-forward layer based on at least one of the data sequence loss values.
[0025] In some embodiments, the obtaining a plurality of consecutive C2F application data sequences based on a plurality of consecutive time series data according to a preset sliding step length includes:
[0026] Obtain a plurality of consecutive time series data in the C2F application data;
[0027] Perform missing data filling operation on the plurality of time series data to obtain filled time series data;
[0028] Perform normalization processing on the filled time series data to obtain normalized time series data;
[0029] Based on the preset sliding step size, partition the multiple normalized time series data according to the time sorting in the normalized time series data to obtain the multiple consecutive C2F application data sequences.
[0030] To achieve the above object, a second aspect of the embodiments of the present application proposes an abnormal detection method for C2F application data, and the method includes:
[0031] Obtain target C2F application data;
[0032] Perform masking processing on the target C2F application data to obtain a target prompt word prefix and a target prompt word answer;
[0033] Input the target prompt word prefix into the C2F application data abnormal detection model obtained after training as described in the first aspect for data prediction processing to obtain target prediction prompt data;
[0034] Based on the loss value between the target prediction prompt data and the target prompt word answer, obtain the target abnormal detection result of the target C2F application data.
[0035] To achieve the above object, a third aspect of the embodiments of the present application proposes a training device for a C2F application data abnormal detection model, and the device includes:
[0036] A data sequence partitioning module, configured to obtain multiple consecutive C2F application data sequences based on a preset sliding step size according to multiple consecutive time series data;
[0037] A mask generation module, configured to perform variable masking processing on each of the C2F application data sequences one by one to obtain a prompt word prefix and a prompt word answer corresponding to each of the C2F application data sequences, and the prompt word prefix and the prompt word answer are complementary to each other;
[0038] A prediction data generation module, configured to input the prompt word prefix into the C2F application data abnormal detection model for data prediction to generate prediction prompt data;
[0039] A model training module, configured to calculate a loss value according to each of the prediction prompt data and the corresponding prompt word answer, and perform model training on the C2F application data abnormal detection model based on the loss value.
[0040] To achieve the above object, a fourth aspect of the embodiments of the present application proposes an electronic device, and the electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the C2F application data abnormal detection model training method as described in the first aspect or the abnormal detection method for C2F application data as described in the second aspect.
[0041] To achieve the above object, a fifth aspect of the embodiments of the present application proposes a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the C2F application data anomaly detection model training method described in the first aspect above or the anomaly detection method for C2F application data described in the second aspect above.
[0042] The C2F application data anomaly detection model training method, anomaly detection method and related devices proposed by the embodiments of the present application include: First, based on a preset sliding step, multiple consecutive C2F application data sequences are obtained from multiple consecutive time series data; then, variable masking processing is performed on each C2F application data sequence one by one to obtain a prompt word prefix and a prompt word answer corresponding to each C2F application data sequence, and the prompt word prefix and the prompt word answer are complementary to each other; next, the prompt word prefix is input into the C2F application data anomaly detection model for data prediction to generate predicted prompt data; finally, a loss value is calculated based on each predicted prompt data and the corresponding prompt word answer, and the C2F application data anomaly detection model is trained based on the loss value. The trained C2F application data detection model is used to detect anomalies in C2F application data. The embodiments of the present application train the C2F application data anomaly detection model for multiple consecutive C2F application data without restricting the data detection time, so as to increase the amount of detection data and the temporal correlation of the detection samples, and use the preset sliding step to divide the time series data in time series, so as to reduce the amount of data processed each time while maintaining the temporal correlation of the data, so as to reduce the data processing duration, thereby improving the training efficiency of model training; then, using variable-based masking processing to mask and divide each C2F application data sequence after continuous time series division to obtain complementary prompt word prefixes and prompt word answers, and further using the loss value between the predicted prompt data output by the C2F application data anomaly detection model for the prompt word prefix and the prompt word answer to train the C2F application data anomaly detection model, so that the C2F application data anomaly detection model can learn the correlation of complementary data in normal C2F application data, so that when using the trained C2F application data anomaly detection model to perform security detection on C2F application data in actual application, the C2F application data correlation can be calculated using the loss value between the complementary data obtained by masking processing in the C2F application data, and then the anomaly detection result of the C2F application data can be accurately obtained using the C2F application data correlation, so as to greatly improve the accuracy and reliability of C2F application data anomaly detection.
[0043] Other features and advantages of the present application will be described in the subsequent specification, and in part will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the specification, claims, and drawings. Description of the Drawings
[0044] Figure 1 It is an organizational structure diagram of a C2F production mode operation provided by an embodiment of the present application.
[0045] Figure 2 It is a flowchart of a method for training a C2F application data anomaly detection model provided by another embodiment of the present application.
[0046] Figure 3 Is Figure 2 The flowchart of step 201 in
[0047] Figure 4 Is Figure 2 The flowchart of step 202 in
[0048] Figure 5 It is a flowchart for generating complementary data conditions provided by another embodiment of the present application.
[0049] Figure 6 Is Figure 2 The flowchart of step 203 in
[0050] Figure 7 Is Figure 2 The flowchart of step 204 in
[0051] Figure 8 It is a schematic flowchart of training a C2F application data anomaly detection model provided by another embodiment of the present application.
[0052] Figure 9 It is a flowchart of an anomaly detection method for C2F application data provided by another embodiment of the present application.
[0053] Figure 10 It is an architecture diagram of an industrial data anomaly detection device for a C2F scenario provided by another embodiment of the present application.
[0054] Figure 11 It is a schematic structural diagram of a C2F application data anomaly detection model training device provided by another embodiment of the present application.
[0055] Figure 12 It is a schematic hardware structure diagram of an electronic device provided by another embodiment of the present application. Detailed Embodiments
[0056] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0057] It should be noted that although functional modules are divided in the device schematic diagram and the logical sequence is shown in the flowchart, in some cases, the steps shown or described may be executed in a different module division in the device or a different order in the flowchart.
[0058] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0059] With the development of society, a new business model, customer to factory (C2F), has emerged. In this model, customers can place orders directly through a digital platform, and the factory produces and delivers according to the order requirements. By directly connecting consumers and manufacturers, it eliminates the intermediate links, thereby improving efficiency, reducing costs, and providing more personalized customization services.
[0060] The C2F model is applied in many industries such as clothing, footwear, furniture, and automobiles. For example, some clothing brands allow customers to online select the styles, fabrics, and colors of clothing and then place orders directly for production at the factory. This model is becoming increasingly popular with the development of e-commerce and digital technologies. With the progress of 3D printing and intelligent manufacturing technologies, the potential of the C2F model will be further explored.
[0061] Refer to Figure 1 , which is an organizational structure diagram of the operation of a C2F production model provided by an embodiment of the present application. As shown in Figure 1 , consumers place orders through a shopping website at the C end (i.e., the client side). The order will be dispatched to the C2F platform, and then the C2F platform decomposes the order into production tasks and issues them to the factory, i.e., the F end. After a series of production processes at the F end, after the product is produced, it is delivered to the C end, i.e., the consumer. The C2F platform also needs to monitor the production process at the F end, and the F end needs to collect real-time production data for the C2F platform for the C2F platform to make intelligent decisions and issue correct production control instructions.
[0062] At both ends of C2F are the C end and the F end, namely the consumer and the producer. The C end operates on the IT side, and the F end operates on the OT side. In the C2F model, the goal is to break through the technical barriers between the information technology (IT) field and the operational technology (OT) field and integrate these two technical fields. Ultimately, the data at the C end should be accurately reflected at the F end so that the F end can realize the ideas of the C end, and the industrial data at the F end can be accurately fed back to the C end, enabling the C end to make correct judgments on the responses of the F end.
[0063] In the traditional industrial model, the F end mass-produces goods, and the C end purchases goods according to its own preferences. In the C2F industrial model, the demands of the C end are flexibly changing, which requires the F end to have the ability to produce in small batches with multiple varieties, that is, flexible manufacturing.
[0064] In the C2F model, the factory needs to respond in real time to the order demands of consumers and be able to quickly adjust the production line to meet personalized needs. This not only requires the factory to have an efficient production process but also a powerful and flexible hardware infrastructure to support the high-speed transmission and processing of data.
[0065] To effectively handle the large and complex transmission data stream in the C2F model, many information layer switches are usually set up at the factory end. These information layer switches need to process and transfer the huge data streams of various industrial devices and business management systems. However, due to the excessive types of transmission protocols and complex data sources in the transmitted data, it is necessary to perform anomaly detection on the transmitted data during the data transmission process in C2F applications to ensure data transmission security.
[0066] In addition, the complex requirements in the C2F scenario have had a greater impact on industrial data. In the information technology (IT) field, the communication protocols of data all follow the standard Ethernet protocol. In the operational technology (OT) field, there is no unified industrial field protocol, that is, multiple protocols coexist. Currently, there are more than a dozen commonly used industrial field protocols. In the traditional industrial model, when a factory introduces a certain production line, it may only involve one or two industrial field protocols, and there is no need for interconnection between multiple industrial protocols, let alone data interconnection between the IT and OT fields. In the C2F industrial model, these problems have become prominent, and industrial data of multiple different protocols need to communicate, and there is also a communication need for OT and IT data.
[0067] When OT data communicates in the IT field, it also faces security issues. Industrial data in the OT field is relatively secure, but data security in the IT field has been a thorny issue since the advent of the Internet. How to ensure the secure and reliable transmission of industrial data in the IT field has become a research hotspot in recent years.
[0068] In related technologies, to improve the security of factory application data, usually multiple specific data detection points are set in the factory data transmission process, corresponding data anomaly detection conditions are formulated in advance for these several data detection points, and in the actual factory data transmission process, data anomaly detection is performed at these specific data detection points using the corresponding data anomaly detection conditions. However, due to the extremely diverse types and sources of application data in the C2F scenario, only using fixed data anomaly detection conditions cannot comprehensively analyze the correlation between continuous time-series data in C2F application data, thus unable to accurately perform appropriate anomaly detection on this C2F application data. Moreover, when collecting C2F application data at fixed data detection points for detection, there are problems such as single detection samples and limited detection data volume, resulting in a relatively low detection accuracy when using traditional factory data detection methods to perform anomaly detection on C2F application data.
[0069] To improve the anomaly detection accuracy of application data in the C2F scenario, the embodiments of this application train a C2F application data anomaly detection model for multiple consecutive C2F application data without restricting the defined data detection moments, so as to increase the detection data volume and time-series correlation of detection samples, and use a preset sliding step size to perform time-series partitioning on time-series data, so as to reduce the data volume processed each time while maintaining the time-series correlation of the data, thereby reducing the data processing duration and improving the training efficiency of model training; then, use variable-based mask processing to perform mask partitioning on each time-series partitioned C2F application data sequence to obtain complementary prompt prefixes and prompt answers, and further use the loss value between the predicted prompt data output by the C2F application data anomaly detection model for the prompt prefix and the prompt answer to train the C2F application data anomaly detection model, so that the C2F application data anomaly detection model can learn the correlation of complementary data in normal C2F application data, enabling the use of the loss value between the complementary data obtained by mask processing in C2F application data to calculate the C2F application data correlation when using the trained C2F application data anomaly detection model to perform security detection on C2F application data in actual applications, and then accurately obtaining the anomaly detection result of C2F application data using this C2F application data correlation, greatly improving the accuracy and reliability of C2F application data anomaly detection.
[0070] Next, the C2F application data anomaly detection model training method, anomaly detection method, and related devices provided by the embodiments of this application will be further described. First, the C2F application data anomaly detection model training method provided by the embodiments of this application will be described. Refer to Figure 2 , which is an optional flowchart of the C2F application data anomaly detection model training method provided by the embodiments of this application.Figure 2 The method in Figure 2 may include but is not limited to steps 201 to 204. It can also be understood that this embodiment does not specifically limit the order of steps 201 to 204 in
[0071] Step 201: Based on a preset sliding step, obtain multiple consecutive C2F application data sequences according to multiple consecutive time series data.
[0072] The following will describe step 201 in detail.
[0073] In some embodiments, in order to achieve accurate anomaly detection of complex C2F application data, it is necessary to obtain a sample data set X in the C2F application scenario in advance. This sample data set X includes multiple consecutive time series data, so as to facilitate subsequent training of the C2F application data anomaly detection model using these consecutive time series data, in order to obtain a C2F application data anomaly detection model that can effectively and accurately detect anomalies in complex C2F application data.
[0074] Then, in order to further improve the training efficiency of the C2F application data anomaly detection model, the sample data set X (i.e., multiple consecutive time series data) will also be divided based on a preset sliding step k in time order to obtain multiple consecutive C2F application data sequences, so that the amount of data for each model training is reduced to reduce data processing time.
[0075] Moreover, in order to further improve the reliability of data processing, before dividing the continuous time series data, it is also necessary to perform corresponding data preprocessing on the input sample data set X, and then perform the division of the continuous time series data, which is described in detail as follows.
[0076] Referring to Figure 3 , based on a preset sliding step, obtaining multiple consecutive C2F application data sequences according to multiple consecutive time series data includes the following steps 301 to 304.
[0077] Step 301: Obtain multiple consecutive time series data in the C2F application data.
[0078] Step 302: Perform a missing data filling operation on the multiple time series data to obtain filled time series data.
[0079] Step 303: Normalize the filled time series data to obtain normalized time series data.
[0080] Step 304: Based on a preset sliding step size, sort the time in the normalized time series data, and divide multiple normalized time series data to obtain multiple consecutive C2F application data sequences.
[0081] The following is a detailed description of Steps 301 to 304.
[0082] In some embodiments, for the sample data set X corresponding to the C2F application data in the C2F scenario, first perform a missing data filling operation on all the time series data with continuous time in the sample data set, and use all the time series data in the sample data set X after the missing data filling operation as the filled time series data, so as to avoid affecting the model training efficiency of the C2F application data anomaly detection model due to data missing.
[0083] When implementing the missing data filling operation in the embodiments of the present application, based on the following rules, when the proportion of the number of missing values of the missing time series data in the sample data set X to the overall data samples of the sample data set X is small (such as within 3%), directly delete the missing time series data. When the proportion of the number of missing values of the missing time series data in the sample data set X to the overall data samples of the sample data set X reaches a certain threshold (such as reaching 3% or more), perform appropriate filling on the missing time series data, such as filling with zeros.
[0084] After performing the missing data filling operation on the sample data set X to obtain the filled time series data, in order to improve the distribution characteristics of the data and improve the training efficiency of the C2F application data anomaly detection model, it is also necessary to normalize the filled time series data, that is, scale all the filled time series data to the same specific numerical range to obtain the normalized time series data.
[0085] It can be understood that the specific numerical range can be a numerical range customized according to user needs, and how it is set does not affect the implementation of the C2F application data anomaly detection model training method provided by the present application.
[0086] After performing the missing data filling and normalization processing on the time series data, further based on the preset sliding step size k, sort the time in the normalized time series data, and perform a sliding time window division on multiple normalized time series data to obtain multiple consecutive C2F application data sequences, which are described in detail as follows.
[0087] Sliding time window partitioning is to divide continuous time series data into a series of time windows of a fixed size for analysis and processing. The main purpose of sliding time window partitioning is to capture local patterns and trends in time series data. By analyzing the data within each window, short-term patterns and anomalies can be identified. A sliding time window is a method of dividing time series data into multiple consecutive and overlapping time periods. Each time period is called a "window". The size of the window can be determined according to the analysis requirements. The preset sliding step (or the distance by which the window moves) determines the degree of overlap between windows. If the step is less than the window size, there will be overlap between windows; if the step is equal to the window size, there is no overlap between windows.
[0088] For time series analysis tasks, the contextual features between different timestamps are crucial. Therefore, the processed sample data set X will be transformed into a C2F application data sequence corresponding to multiple sliding windows as shown in the following formulas (1) and (2).
[0089]
[0090]
[0091] Where k is the preset sliding step (which is also the window size), and k is also the number of time points included in each C2F application data sequence. is the C2F application data sequence (which is the sliding window sequence). is the number of windows (which is the number of C2F application data sequences), and it is obtained by dividing the total length t of the time series of the sample data set X by the window size k and taking the floor value. refers to the index of the C2F application data sequence.
[0092] C2F application data sequence is a data matrix that contains multiple features (or variables) extracted from the time series data. represents the feature data of the first k time points of the first feature in the j-th window. represents the feature data of the first k time points of the second feature in the j-th window. And so on, until which represents the feature data of the first k time points of the d-th feature in the j-th window.
[0093] Through the above steps 301 to 304, by obtaining multiple consecutive time series data in the C2F application data, and successively performing missing data filling, normalization processing, and sliding time window partitioning, the integrity of the data is ensured by the missing data filling operation, avoiding abnormal detection errors caused by data missing and improving the reliability of detection; secondly, the data is scaled to a unified range by the normalization processing, improving the distribution characteristics of the data and accelerating the convergence speed of subsequent abnormal detection algorithms, enhancing the detection efficiency; finally, the continuous time series data is segmented into multiple fixed-size windows by the sliding time window partitioning, which can effectively capture local patterns and trends in the data, enhancing the sensitivity and accuracy of abnormal detection. These steps work together to make the industrial data abnormal detection in the C2F scenario more efficient and accurate, and better able to handle the complex industrial environment with multiple protocols and multiple data types.
[0094] Step 202: Perform variable masking processing on each C2F application data sequence one by one to obtain the prompt prefix and prompt answer corresponding to each C2F application data sequence.
[0095] The following is a detailed description of step 202.
[0096] In some embodiments, after obtaining multiple consecutive C2F application data sequences one by one will perform variable masking processing on each C2F application data sequence to obtain the prompt prefix and prompt answer corresponding to each C2F application data sequence. Among them, the prompt prefix and the prompt answer are complementary to each other. So as to facilitate subsequent input of the prompt prefix into the C2F application data abnormal detection model for prediction to obtain predicted prompt data and use the loss value between the predicted prompt data and the prompt answer to train the C2F application data abnormal detection model.
[0097] This random masking operation is expressed as: { , } = (W), where the first output value is the prompt input of the C2F application data abnormal detection model OLM (industrial large model), and the second is the prompt.
[0098] Next, how to perform masking processing on the C2F application data sequence will be further described.
[0099] Refer to Figure 4, variable masking is performed on each C2F application data sequence to obtain a prompt prefix and a prompt answer corresponding to each C2F application data sequence, including the following steps 401 to 403.
[0100] Step 401: Obtain a mask matrix.
[0101] Step 402: Generate a prompt prefix based on the Hadamard product of the mask matrix and the C2F application data sequence.
[0102] Step 403: Generate a prompt answer based on the Hadamard product of the complement of the mask matrix and the C2F application data sequence.
[0103] The following provides a detailed description of steps 401 to 403.
[0104] In the embodiments of the present application, the prompt prefix and the prompt answer generated after masking the C2F application data sequence enable the optimization and adjustment of the model output without relying on specific text prompts. In the present application, the specific implementation of this method obtains the prompt prefix and the prompt answer through variable random masking. The unmasked part is the prompt prefix, and the masked part is the prompt answer. Different from the traditional text-based prompt method, the textless prompt method does not require a prompt template.
[0105] By randomly generating a random Boolean mask matrix B (i.e., the mask matrix) with a masking ratio , and then based on the Hadamard product of the mask matrix B and the C2F application data sequence , a prompt prefix is generated as shown in the following formula (3).
[0106]
[0107] Among them, represents the Hadamard product. Next, based on the Hadamard product of the complement of the mask matrix (1 - B) and the C2F application data sequence, a prompt answer is generated as shown in the following formula (4).
[0108]
[0109] Among them, the prompt prefix and the prompt answer are -order data matrices; and the prompt prefix and the prompt answer satisfy the complementary data condition, which is generated based on the masking ratio parameter and the total length of the time series. The complementary data condition includes the first masking condition, the second masking condition, and the mask complementarity condition. How to generate this complementary data condition will be further described below.
[0110] Refer to Figure 5, the steps for generating complementary data conditions include the following steps 501 to 503.
[0111] Step 501: Based on one minus the masking ratio parameter, multiply it by the total length of the time series and the number of features of the feature data, and then round up to obtain the first masked data value. Based on the numerical relationship between the first matrix norm of the prefix prompt and the first masked data value, generate the first masking condition.
[0112] Step 502: Multiply the masking ratio parameter, the total length of the time series, and the number of features, and then round down to obtain the second masked data value. Based on the numerical relationship between the second matrix norm of the answer prompt and the second masked data value, generate the second masking condition.
[0113] Step 503: Multiply the total length of the time series and the number of features to obtain the complementary masked data value. Based on the numerical relationship between the first matrix norm, the second matrix norm, and the complementary masked data value, generate the masking complementary condition.
[0114] The following provides a detailed description of steps 501 to 503.
[0115] In some embodiments, based on one minus the masking ratio parameter , multiply it by the total length of the time series and the number of features of the feature data , and then round up to obtain the first masked data value , and based on the numerical relationship between the first matrix norm of the prefix prompt and the first masked data value, generate the first masking condition as shown in the following formula (5).
[0116]
[0117] Wherein, is the ceiling symbol.
[0118] Multiply the masking ratio parameter , the total length of the time series and the number of features , and then round down to obtain the second masked data value , and based on the numerical relationship between the second matrix norm of the answer prompt and the second masked data value, generate the second masking condition as shown in the following formula (6).
[0119]
[0120] Wherein, is the floor symbol.
[0121] Multiply the total length of the time series and the number of features , a complementary mask data value td is obtained, and a mask complementary condition is generated based on the numerical relationship among the first matrix norm, the second matrix norm, and the complementary mask data value, as shown in the following formula (7).
[0122]
[0123] Through the above steps 401 to 403, and steps 501 to 503, the introduction of the mask matrix enables the generation of the prompt prefix and the prompt answer without relying on a specific text prompt template, simplifies the modeling process, reduces the dependence of the model on specific text prompts, and enhances the generality and flexibility of the model; secondly, the Hadamard product operation ensures the complementarity of the prompt prefix and the prompt answer, enabling the model to perform data segmentation without losing key information, improving the accuracy and robustness of anomaly detection; finally, the generation of the complementary data condition ensures the balance of the prompt prefix and the prompt answer in terms of data volume through the calculation of the mask ratio parameter and the total length of the time series, avoiding the data skew problem and further optimizing the training effect of the model. These steps work together to enable the industrial data anomaly detection method in the C2F scenario to more efficiently process complex industrial data with multiple protocols and multiple data types, improving the accuracy and efficiency of anomaly detection.
[0124] In addition, this textless prompt method eliminates the text-related prompt template between the initial input and the prompt response.
[0125] Step 203: Input the prompt prefix into the C2F application data anomaly detection model for data prediction to generate predicted prompt data.
[0126] The following provides a detailed description of step 203.
[0127] In some embodiments, after obtaining the prompt prefix corresponding to the C2F application data sequence and the prompt answer , the prompt prefix is further input into the C2F application data anomaly detection model for data prediction to obtain the corresponding predicted prompt data , so that the subsequent loss value between the predicted prompt data and the prompt answer is used to train the C2F application data anomaly detection model.
[0128] However, since the input data of the C2F application data anomaly detection model OLM usually has dimensional limitations, relevant processing needs to be performed on the prompt prefix before inputting the prompt prefix into the C2F application data anomaly detection model for data prediction, as described below.
[0129] Reference Figure 6 ,input the prefix of the prompt word into the C2F application data anomaly detection model for data prediction to generate predicted prompt data, including the following steps 601 to step 602.
[0130] Step 601: Perform padding processing on the prefix of the prompt word to obtain a padded mask data sequence.
[0131] Step 602: Input the padded mask data sequence into the C2F application data anomaly detection model for mapped data prediction processing to obtain predicted prompt data.
[0132] The following is a detailed description of steps 601 to step 602.
[0133] In some embodiments, in order to be consistent with the input dimension of the pre-trained C2F application data anomaly detection model OLM, after obtaining the prefix of the prompt word After that, zero-padding processing will be performed on the prefix of the prompt word to obtain a padded mask data sequence as shown in the following formula (8).
[0134]
[0135] where PAD() refers to the zero-padding operation.
[0136] After performing zero-padding processing to obtain a padded mask data sequence After that, input the padded mask data sequence into the C2F application data anomaly detection model OLM for prediction processing to fill the empty prompt bits regarding the prefix of the prompt word so as to generate predicted prompt data as shown in the following formula (9).
[0137]
[0138] Through the above steps 601 to step 602, by performing padding processing on the prefix of the prompt word to generate a padded mask data sequence, the integrity and consistency of the input data are ensured. Inputting the padded mask data sequence into the C2F application data anomaly detection model for mapped data prediction processing can enable the model to better adapt to diverse industrial data scenarios. In this way, the model can more accurately capture the abnormal data in the data and improve its generalization ability in complex industrial environments.
[0139] Step 204: Calculate the loss value based on each predicted prompt data and the corresponding prompt word answer, and perform model training on the C2F application data anomaly detection model based on the loss value.
[0140] The following provides a detailed description of step 204.
[0141] In some embodiments, after obtaining the C2F application data sequence the corresponding prediction hint data and the hint word answer the loss value calculated based on each C2F application data sequence the corresponding prediction hint data and the hint word answer is used to train the C2F application data anomaly detection model OLM, which is described in detail as follows.
[0142] Referring to Figure 7 , the loss value is calculated based on each prediction hint data and the corresponding hint word answer, and the C2F application data anomaly detection model is trained based on the loss value, including the following steps 701 to step 702.
[0143] Step 701: Based on the difference between each prediction hint data and the corresponding hint word answer, matrix two-norm processing is performed to obtain the data sequence loss value corresponding to each C2F application data sequence.
[0144] Step 702: Adjust the normalization layer parameters of the normalization layer and / or the feedforward layer parameters of the feedforward layer based on at least one data sequence loss value.
[0145] The following provides a detailed description of steps 701 to 702.
[0146] In some embodiments, the training method of the C2F application data anomaly detection model is implemented by the mean squared error loss function (MSE) based on the prediction hint data and the hint word answer , and its corresponding loss function is shown in the following formula (10).
[0147]
[0148] Therefore, based on the above formula (10), based on the difference between each prediction hint data and the corresponding hint word answer matrix two-norm processing is performed to obtain the data sequence loss value corresponding to each C2F application data sequence.
[0149] Then, these data sequence loss values are used to finely tune the normalization layer parameters of the normalization layer and / or the feedforward layer parameters of the feedforward layer of the C2F application data anomaly detection model, so that the C2F application data anomaly detection model can fully learn the correlation between normal continuous time series data in the C2F scenario.
[0150] It is understandable that the reason why this anomaly detection model achieves ideal performance is that the fine-tuned industrial large model with normal behavior patterns cannot reconstruct the masked variables based on the anomaly variables. For the test timestamp, the input includes the root cause variables, which results in poor variable generation effect for the detection timestamp. In this embodiment, ∈W is labeled as =1. The first m variables = , ,.., contain the root cause variables, thus constructing the prompt.
[0151] As shown in the following formulas (11) and (12).
[0152]
[0153]
[0154] This expression means that for the I-th sample, its original data in dimensions m + 1 to d is not similar to the predicted data obtained through a certain model or method . This usually means that there are significant differences between the model's predictions and the actual data in these dimensions.
[0155] Through the above steps 701 to 702, by using the difference between the predicted prompt data and the actual answer processed by the matrix two-norm, the overall deviation of the data sequence can be measured from the multi-dimensional space. Compared with the single-point error calculation, it can better capture the global anomaly features in complex industrial data. By back-adjusting the distribution calibration parameters of the normalization layer and the feature extraction parameters of the feed-forward layer through the loss value, the self-adaptability of the model to the dynamic industrial environment is realized. The optimization of the normalization layer parameters can eliminate the influence of the multi-source data dimension differences on the model and ensure the distribution consistency of the integrated data in the IT / OT field. The iterative update of the feed-forward layer parameters enhances the expression ability of the industrial large model for the local patterns within the time window and the cross-protocol data features. Thus, the C2F application data anomaly detection model can fully learn the correlation between the continuous time data in the C2F scenario, and then facilitate the generation of accurate anomaly data detection results by using the C2F application data correlation when performing C2F application data anomaly detection in practical applications.
[0156] Referring to Figure 8 , it is a schematic flow diagram of training a C2F application data anomaly detection model provided by an embodiment of the present application. As Figure 8 shown in, for the C2F application data sequence obtained from multiple consecutive time series data, through the masking operation it is divided into the prompt prefix and the prompt answer Then, the C2F application data anomaly detection model OLM is used to generate a predicted prompt answer for the prefix of the prompt word Then, the predicted prompt answer is used and the prompt answer to fine-tune the C2F application data anomaly detection model OLM based on the loss value between them. In the figure, → represents the data flow direction. ⇆ represents the calculation of the loss function for the training algorithm. The symbol L() in the figure represents the loss function, which is used to measure the difference between the predicted value and the actual value of the model, and is represented as the mean square error (MSE) in the embodiments of the present application. Dimension Mapping is to transform the data from its original dimension to a new dimension space for better analysis and processing.
[0157] In addition, an embodiment of the present application also provides an anomaly detection method for C2F application data. Referring to Figure 9 which is an optional flowchart of the anomaly detection method for C2F application data provided by the embodiment of the present application Figure 9 The method in may include but is not limited to steps 901 to 904. At the same time, it can be understood that the present embodiment does not specifically limit the order of steps 901 to 904 in Figure 9 and the step order can be adjusted according to actual needs, or some steps can be reduced or added. The anomaly detection method for C2F application data provided in the embodiments of the present application can be applied to the server or intelligent terminal of the C2F platform carried in the C2F scenario, or to the server or intelligent terminal for detecting application data in the factory end (i.e., the F end), or to other control processors associated with the C2F scenario.
[0158] Step 901: Obtain the target C2F application data.
[0159] Step 902: Mask the target C2F application data to obtain the target prompt word prefix and the target prompt answer.
[0160] Step 903: Input the target prompt word prefix into the trained C2F application data anomaly detection model for data prediction processing to obtain the target predicted prompt data.
[0161] Step 904: Based on the loss value between the target predicted prompt data and the target prompt answer, obtain the target anomaly detection result of the target C2F application data.
[0162] The following will describe steps 901 to 904 in detail.
[0163] Referring to Figure 10 , which is an architecture diagram of an industrial data anomaly detection device for the C2F scenario provided by an embodiment of the present application. As Figure 10 shown, at the C-end, customers send user requirement data to the application layer according to their customized requirements. The application layer decomposes the customer's requirements to the F-end. Each actuator in the physical layer of the F-end is controlled by a PLC through a controller and closely cooperates on the production line for production operations. Meanwhile, the real-time collected data is transmitted to the digital layer through the OPC UA communication architecture.
[0164] Then, during the data transmission process, the flowing target C2F application data is obtained in real time for anomaly detection, which includes masking the target C2F application data to obtain a target prompt word prefix and a target prompt word answer. Then, the target prompt word prefix is input into the trained C2F application data anomaly detection model for data prediction processing to obtain target prediction prompt data. Finally, based on the loss value between the target prediction prompt data and the target prompt word answer, the target anomaly detection result of the target C2F application data is obtained.
[0165] Next, a detection report is generated based on the target anomaly detection result. The detection report is sent to the application layer, and the application layer makes a decision according to the result of the anomaly detection to issue more efficient production control instructions according to the detection situation of the production process to improve the production efficiency.
[0166] The input data processed by the embodiment of the present application is the data to be detected collected at the factory end. Through a randomly generated mask matrix B, a prompt input and a prompt answer are obtained. The data targeted by the anomaly detection method of the present application is multiple continuous time series data, which is time series data collected simultaneously on multiple variables, including multiple variables, and each variable is a sequence that changes over time.
[0167] The prompting method provided by the present application is based on the phenomenon that the root cause of the observed anomaly will disrupt the interpolation process of normal variables. A fine-tuned large model with a normal behavior pattern cannot reconstruct the masked variable based on the abnormal variable. For the test timestamp, the input feed includes the root cause variable. Assuming the first m variables, including the root cause variable, a prompt is constructed. Assume that each abnormal timestamp has root cause variables. The prompting model provided by the present application masks variables. The probability that at least one root cause variable is not masked is shown in the following formula (13).
[0168]
[0169] If , then p = 1.
[0170] In summary, If the number is relatively small or does not meet certain conditions, effective detection cannot be achieved. The number of prompts in this application needs to be selected to exceed a certain unmasked variable to ensure effective detection.
[0171] An important innovation of this application is to modify the timestamp masking operation to a variable-based masking operation. The unmasked and masked variables are respectively recognized as prompt inputs and prompt answers, thus getting rid of the text-driven prompt template, minimizing the difference between the predicted prompt answer and the actual prompt answer to fine-tune the C2F application data anomaly detection model OLM, and only activating the feed-forward and normalization layers. In the test phase, if the output answer is far enough from the actual masked variable, an anomaly alarm will be triggered.
[0172] This application improves the masking operation to construct prompts. By masking variables instead of the traditional method (masking timestamp samples), this is called variable-level prompting. The unmasked variable serves as a prefix component, corresponding to the text-based prefix prompt template. OLM fills in the masked variable or blank by fine-tuning, while the activated feed-forward and normalization layers reduce the training burden and maintain an acceptable detection accuracy.
[0173] The C2F application data anomaly detection model training method, anomaly detection method and related devices proposed in the embodiments of the present application. The method includes: First, obtain multiple consecutive time series data in the C2F application data, perform missing data filling operations on the multiple time series data to obtain filled time series data, perform normalization processing on the filled time series data to obtain normalized time series data, and divide the multiple normalized time series data according to the time sorting in the normalized time series data based on a preset sliding step length to obtain multiple consecutive C2F application data sequences; Then, obtain a mask matrix one by one. The mask matrix includes a mask ratio parameter. Based on the Hadamard product of the mask matrix and the C2F application data sequence, generate a prompt word prefix. Based on the Hadamard product of the complement of the mask matrix and the C2F application data sequence, generate a prompt word answer. The prompt word prefix and the prompt word answer satisfy the complementary data condition. The complementary data condition generation includes multiplying the product of one minus the mask ratio parameter, the total length of the time series, and the number of features of the feature data to obtain a first mask data value, and generating a first mask condition based on the numerical relationship between the first matrix norm of the prompt word prefix and the first mask data value. Multiply the mask ratio parameter, the total length of the time series, and the number of features to obtain a second mask data value, and generate a second mask condition based on the numerical relationship between the second matrix norm of the prompt word answer and the second mask data value. Multiply the total length of the time series and the number of features to obtain a complementary mask data value, and generate a mask complement condition based on the numerical relationship between the first matrix norm, the second matrix norm, and the complementary mask data value. The prompt word prefix and the prompt word answer are complementary; Next, perform filling processing on the prompt word prefix to obtain a filled mask data sequence, input the filled mask data sequence into the C2F application data anomaly detection model for mapped data prediction processing to obtain predicted prompt data; Finally, based on the difference between each predicted prompt data and the corresponding prompt word answer, perform matrix two-norm processing to obtain the data sequence loss value corresponding to each C2F application data sequence, and adjust the normalization layer parameters of the normalization layer and / or the feedforward layer parameters of the feedforward layer based on at least one data sequence loss value. The trained C2F application data detection model is used to detect anomalies in the C2F application data.
[0174] Embodiments of this application perform model training on a C2F application data anomaly detection model for multiple consecutive C2F application data pairs without restricting the defined data detection time, so as to increase the amount of detection data and temporal correlation of detection samples, and use a preset sliding step size to perform temporal partitioning on time series data, so as to reduce the amount of data processed each time while maintaining the temporal correlation of the data, thereby reducing the data processing duration and improving the training efficiency of model training; then, using variable-based masking processing to mask partition each C2F application data sequence after temporal partitioning to obtain complementary prompt prefixes and prompt answers in the C2F scenario, and further using the loss value between the predicted prompt data output by the C2F application data anomaly detection model for the prompt prefix and the prompt answer to perform model training on the C2F application data anomaly detection model, so that the C2F application data anomaly detection model can learn the correlation of complementary data in normal C2F application data, so that when using the trained C2F application data anomaly detection model to perform security detection on C2F application data in actual applications, the C2F application data correlation can be calculated using the loss value between the complementary data obtained by masking processing in the C2F application data, and then the anomaly detection result of the C2F application data can be accurately obtained using the C2F application data correlation, greatly improving the accuracy and reliability of C2F application data anomaly detection; in addition, by obtaining multiple consecutive time series data in the C2F application data, and performing missing data filling, normalization processing, and sliding time window partitioning in sequence, the missing data filling operation ensures the integrity of the data, avoids anomaly detection errors caused by data loss, and improves the reliability of detection; secondly, using normalization processing to scale the data to a unified range improves the distribution characteristics of the data, accelerates the convergence speed of subsequent anomaly detection algorithms, and improves the detection efficiency; finally, using sliding time window partitioning to divide the continuous time series data into multiple fixed-size windows can effectively capture local patterns and trends in the data, enhancing the sensitivity and accuracy of anomaly detection. These steps work together to make the industrial data anomaly detection in the C2F scenario more efficient and accurate, and can better handle complex industrial environments with multiple protocols and multiple data types; and, the introduction of the mask matrix makes the generation of prompt prefixes and prompt answers independent of specific text prompt templates, simplifies the modeling process, reduces the dependence of the model on specific text prompts, and enhances the generality and flexibility of the model; secondly, the Hadamard product operation ensures the complementarity of the prompt prefix and the prompt answer, enabling the model to perform data segmentation without losing key information, improving the accuracy and robustness of anomaly detection; finally, the generation of complementary data conditions through the calculation of the mask ratio parameter and the total length of the time series ensures the balance of the prompt prefix and the prompt answer in terms of data volume, avoids the problem of data skew, and further optimizes the training effect of the model.These steps work together to enable the industrial data anomaly detection method in the C2F scenario to process complex industrial data with multiple protocols and multiple data types more efficiently, improving the accuracy and efficiency of anomaly detection. Moreover, by performing padding processing on the prefix of the prompt words to generate a padded mask data sequence, the integrity and consistency of the input data are ensured. Inputting the padded mask data sequence into the C2F application data anomaly detection model for mapped data prediction processing enables the model to better adapt to diverse industrial data scenarios. In this way, the model can more accurately capture the abnormal data in the data, enhancing its generalization ability in complex industrial environments. Additionally, using the difference between the predicted prompt data and the actual answer processed by the matrix two-norm can measure the overall deviation of the data sequence from multiple-dimensional spaces. Compared with single-point error calculation, it can better capture the global abnormal features in complex industrial data. By reversely adjusting the distribution calibration parameters of the normalization layer and the feature extraction parameters of the feedforward layer through the loss value, the self-adaptability of the model to the dynamic industrial environment is achieved. The optimization of the normalization layer parameters can eliminate the impact of the dimensional differences of multi-source data on the model, ensuring the distribution consistency of the integrated data in the IT / OT field. The iterative update of the feedforward layer parameters enhances the expression ability of the industrial large model for local patterns within the time window and cross-protocol data features. Thus, the C2F application data anomaly detection model fully learns the correlation between normal continuous time data in the C2F scenario. Furthermore, when performing C2F application data anomaly detection in practical applications, the correlation of C2F application data is utilized to generate accurate anomaly data detection results.
[0175] The embodiment of this application also provides a training device for the C2F application data anomaly detection model, which can implement the above-mentioned training method for the C2F application data anomaly detection model. Referring to Figure 11 , the device 1100 includes:
[0176] The data sequence division module 1110 is used to obtain multiple consecutive C2F application data sequences based on a preset sliding step size according to multiple consecutive time series data;
[0177] The mask generation module 1120 is used to perform variable mask processing on each C2F application data sequence one by one to obtain the corresponding prompt word prefix and prompt word answer for each C2F application data sequence, and the prompt word prefix and the prompt word answer are complementary to each other;
[0178] The predicted data generation module 1130 is used to input the prompt word prefix into the C2F application data anomaly detection model for data prediction to generate predicted prompt data;
[0179] The model training module 1140 is used to calculate the loss value according to each predicted prompt data and the corresponding prompt word answer, and perform model training on the C2F application data anomaly detection model based on the loss value.
[0180] In some embodiments, the mask generation module 1120 is further configured to:
[0181] Obtain a mask matrix, where the mask matrix includes a mask ratio parameter;
[0182] Generate a prompt prefix based on the Hadamard product of the mask matrix and the C2F application data sequence;
[0183] Generate a prompt answer based on the Hadamard product of the complement of the mask matrix and the C2F application data sequence, where the prompt prefix and the prompt answer satisfy complementary data conditions, and the complementary data conditions are generated based on the mask ratio parameter and the total length of the time series.
[0184] In some embodiments, the mask generation module 1120 is further configured to:
[0185] Multiply the total length of the time series and the number of features of the feature data by one minus the mask ratio parameter to obtain a first mask data value, and generate a first mask condition based on the numerical relationship between the first matrix norm of the prompt prefix and the first mask data value;
[0186] Multiply the mask ratio parameter, the total length of the time series, and the number of features to obtain a second mask data value, and generate a second mask condition based on the numerical relationship between the second matrix norm of the prompt answer and the second mask data value;
[0187] Multiply the total length of the time series and the number of features to obtain a complementary mask data value, and generate a mask complementary condition based on the numerical relationship between the first matrix norm, the second matrix norm, and the complementary mask data value.
[0188] In some embodiments, the prediction data generation module 1130 is further configured to:
[0189] Perform padding processing on the prompt prefix to obtain a padded mask data sequence;
[0190] Input the padded mask data sequence into the C2F application data anomaly detection model for mapped data prediction processing to obtain predicted prompt data.
[0191] In some embodiments, the model training module 1140 is further configured to:
[0192] Based on the difference between each predicted prompt data and the corresponding prompt answer, perform matrix two-norm processing to obtain a data sequence loss value corresponding to each C2F application data sequence;
[0193] Adjust the normalization layer parameters and / or the feed-forward layer parameters of the feed-forward layer based on at least one data sequence loss value.
[0194] In some embodiments, the data sequence partitioning module 1110 is further configured to:
[0195] Obtain multiple consecutive time series data in the C2F application data;
[0196] Perform a missing data filling operation on the multiple time series data to obtain filled time series data;
[0197] Perform a normalization process on the filled time series data to obtain normalized time series data;
[0198] Based on a preset sliding step, partition the multiple normalized time series data according to the time sorting in the normalized time series data to obtain multiple consecutive C2F application data sequences.
[0199] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not elaborated in a certain embodiment, the specific implementation manners of the C2F application data anomaly detection model training device are basically the same as those of the above C2F application data anomaly detection method, and will not be repeated here.
[0200] In the embodiments of the present application, the C2F application data anomaly detection model training device trains the C2F application data anomaly detection model for multiple consecutive C2F application data without restricting the specified data detection time, so as to increase the detection data volume and temporal correlation of the detection samples, and uses a preset sliding step size to perform temporal division on the time series data, so as to reduce the data volume for each data processing while maintaining the temporal correlation of the data, thereby reducing the data processing duration and improving the training efficiency of model training; then, using variable-based masking processing to mask-divide each temporally divided C2F application data sequence to obtain complementary prompt prefixes and prompt answers in the C2F scenario, and further using the loss value between the predicted prompt data output by the C2F application data anomaly detection model for the prompt prefix and the prompt answer to train the C2F application data anomaly detection model, so that the C2F application data anomaly detection model can learn the correlation of complementary data in normal C2F application data, so that when using the trained C2F application data anomaly detection model to perform security detection on C2F application data in actual application, the C2F application data correlation can be calculated using the loss value between the complementary data obtained by masking processing in the C2F application data, and then the anomaly detection result of the C2F application data can be accurately obtained using the C2F application data correlation, greatly improving the accuracy and reliability of C2F application data anomaly detection; in addition, by obtaining multiple consecutive time series data in the C2F application data, and performing missing data filling, normalization processing and sliding time window division in sequence, the missing data filling operation ensures the integrity of the data, avoids anomaly detection errors caused by data missing, and improves the reliability of detection; secondly, using normalization processing to scale the data to a unified range improves the distribution characteristics of the data, accelerates the convergence speed of subsequent anomaly detection algorithms, and improves the detection efficiency; finally, using sliding time window division to divide the continuous time series data into multiple fixed-size windows can effectively capture local patterns and trends in the data, enhancing the sensitivity and accuracy of anomaly detection.These steps work together to make the industrial data anomaly detection in the C2F scenario more efficient and accurate, enabling it to better handle the complex industrial environment with multiple protocols and multiple data types. Moreover, the introduction of the mask matrix makes the generation of the prompt prefix and the prompt answer independent of specific text prompt templates, simplifies the modeling process, reduces the model's dependence on specific text prompts, and enhances the generality and flexibility of the model. Secondly, the Hadamard product operation ensures the complementarity of the prompt prefix and the prompt answer, enabling the model to perform data segmentation without losing key information, improving the accuracy and robustness of anomaly detection. Finally, the generation of complementary data conditions, through the calculation of the mask ratio parameter and the total length of the time series, ensures the balance of the prompt prefix and the prompt answer in terms of data volume, avoids the data skew problem, and further optimizes the training effect of the model. These steps work together to enable the industrial data anomaly detection method in the C2F scenario to more efficiently process complex industrial data with multiple protocols and multiple data types, improving the accuracy and efficiency of anomaly detection. And by padding the prompt prefix to generate a padded mask data sequence, the integrity and consistency of the input data are ensured. Inputting the padded mask data sequence into the C2F application data anomaly detection model for mapped data prediction processing enables the model to better adapt to diverse industrial data scenarios. In this way, the model can more accurately capture the abnormal data in the data, enhancing its generalization ability in the complex industrial environment. Additionally, using the difference between the predicted prompt data and the actual answer processed by the matrix two-norm can measure the overall deviation of the data sequence from multiple dimensional spaces. Compared with single-point error calculation, it can better capture the global abnormal features in complex industrial data. By back-adjusting the distribution calibration parameters of the normalization layer and the feature extraction parameters of the feedforward layer through the loss value, the self-adaptability of the model to the dynamic industrial environment is achieved. The optimization of the normalization layer parameters can eliminate the impact of the dimensional differences of multi-source data on the model, ensuring the distribution consistency of the integrated data in the IT / OT field. The iterative update of the feedforward layer parameters enhances the industrial large model's ability to express local patterns and cross-protocol data features within the time window. Thus, the C2F application data anomaly detection model fully learns the correlation between consecutive time data in the C2F scenario, and then facilitates the generation of accurate abnormal data detection results by leveraging the C2F application data correlation when performing C2F application data anomaly detection in practical applications.
[0201] The embodiment of this application also provides an electronic device, including:
[0202] At least one memory;
[0203] At least one processor;
[0204] At least one program;
[0205] The program is stored in a memory, and the processor executes the at least one program to implement the C2F application data anomaly detection model training method described above in this application. The electronic device can be any intelligent terminal including a mobile phone, a tablet computer, a personal digital assistant (PDA for short), an in-vehicle computer, etc.
[0206] Please refer to Figure 12 , Figure 12 which illustrates the hardware structure of an electronic device according to another embodiment. The electronic device includes:
[0207] A processor 1201, which can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application;
[0208] A memory 1202, which can be implemented in forms such as a ROM (Read Only Memory), a static storage device, a dynamic storage device, or a RAM (Random Access Memory). The memory 1202 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1202 and are called by the processor 1201 to execute the C2F application data anomaly detection model training method of the embodiments of this application;
[0209] An input / output interface 1203, which is used to implement information input and output;
[0210] A communication interface 1204, which is used to implement communication interaction between this device and other devices. Communication can be achieved through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.);
[0211] A bus 1205, which transmits information between various components of the device (such as the processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204);
[0212] Among them, the processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204 achieve communication connections with each other inside the device through the bus 1205.
[0213] The embodiments of the present application also provide a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned C2F application data anomaly detection model training method is implemented.
[0214] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0215] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art will know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0216] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0217] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0218] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0219] In the description of the present application and the above-mentioned accompanying drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0220] It should be understood that in the present application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expression means any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0221] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0222] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0223] In addition, in each embodiment of the present application, the functional units may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0224] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store programs.
[0225] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of the present application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the rights of the embodiments of the present application.
Claims
1. A C2F application data anomaly detection model training method, characterized in that: The method comprises: Based on a preset sliding step, a plurality of continuous C2F application data sequences are obtained according to a plurality of continuous time series data; Performing variable masking processing on each of the C2F application data sequences one by one to obtain a prompt word prefix and a prompt word answer corresponding to each of the C2F application data sequences, wherein the prompt word prefix and the prompt word answer are complementary to each other; Inputting the prompt word prefix into the C2F application data anomaly detection model to perform data prediction and generate prediction prompt data; A loss value is calculated according to each of the predicted prompt data and the corresponding prompt word answer, and a C2F application data anomaly detection model is trained based on the loss value. The trained C2F application data detection model is used to perform anomaly detection on the C2F application data; The plurality of time series data include a total length of the time series, and the variable masking process is performed on each of the C2F application data sequences to obtain a prompt word prefix and a prompt word answer corresponding to each of the C2F application data sequences, including: Obtaining a mask matrix, wherein the mask matrix includes a mask ratio parameter; generating the prompt word prefix based on the Hadamard product of the mask matrix and the C2F application data sequence; generating the prompt word answer based on the Hadamard product of the complement of the mask matrix and the C2F application data sequence, wherein the prompt word prefix and the prompt word answer satisfy a complementary data condition, and the complementary data condition is generated based on the mask ratio parameter and the total length of the time series; The time series data includes a plurality of feature data, the complementary data condition includes a first mask condition, a second mask condition and a mask complementary condition, and the steps of generating the complementary data condition include: Based on one minus the mask ratio parameter, multiplying the total length of the time series and the number of features of the feature data, a first mask data value is obtained, and based on the numerical relationship between the first matrix norm of the prompt word prefix and the first mask data value, the first mask condition is generated; Multiplying the mask ratio parameter, the total length of the time series and the number of features to obtain a second mask data value, and generating the second mask condition based on the numerical relationship between the second matrix norm of the prompt word answer and the second mask data value; The total length of the time series and the number of features are multiplied to obtain a complementary mask data value, and the mask complementarity condition is generated based on a numerical relationship among the first matrix norm, the second matrix norm and the complementary mask data value.
2. The C2F application data anomaly detection model training method according to claim 1, characterized in that: The step of inputting the prompt word prefix into the C2F application data anomaly detection model for data prediction to generate prediction prompt data includes: Performing padding processing on the prompt word prefix to obtain a padding mask data sequence; The filling mask data sequence port is input into the C2F application data anomaly detection model to perform mapping data prediction processing to obtain the prediction prompt data.
3. The C2F application data anomaly detection model training method according to claim 1, characterized in that: The C2F application data anomaly detection model includes a normalization layer and a feedforward layer, and the loss value is calculated according to each of the predicted prompt data and the corresponding prompt word answer, and the C2F application data anomaly detection model is trained based on the loss value, including: Based on the difference between each predicted prompt data and the corresponding prompt word answer, matrix bi-norm processing is performed to obtain a data sequence loss value corresponding to each C2F application data sequence; A normalization layer parameter of the normalization layer and / or a feed-forward layer parameter of the feed-forward layer are adjusted based on at least one of the data sequence loss values.
4. The C2F application data anomaly detection model training method according to claim 1, characterized in that: The method of obtaining a plurality of continuous C2F application data sequences based on a preset sliding step size and a plurality of continuous time series data comprises: Obtain multiple continuous time series data in C2F application data; Performing a missing data filling operation on a plurality of the time series data to obtain filled time series data; Normalizing the filled time series data to obtain normalized time series data; Based on the preset sliding step size, the multiple normalized time series data are divided according to the time order in the normalized time series data to obtain the multiple continuous C2F application data sequences.
5. A method for detecting anomalies in C2F application data, characterized in that: The method comprises: Get the target C2F application data; Masking the target C2F application data to obtain a target prompt word prefix and a target prompt word answer; Inputting the target prompt word prefix into the C2F application data anomaly detection model obtained after training as claimed in claim 1 to perform data prediction processing to obtain target prediction prompt data; Based on the loss value between the target prediction prompt data and the target prompt word answer, a target anomaly detection result of the target C2F application data is obtained.
6. A C2F application data anomaly detection model training device, characterized in that: The device comprises: A data sequence partitioning module, used for obtaining a plurality of continuous C2F application data sequences according to a plurality of continuous time series data based on a preset sliding step size; a mask generation module, configured to perform variable mask processing on each of the C2F application data sequences one by one, to obtain a prompt word prefix and a prompt word answer corresponding to each of the C2F application data sequences, wherein the prompt word prefix and the prompt word answer are complementary to each other; A prediction data generation module, used for inputting the prompt word prefix into the C2F application data anomaly detection model to perform data prediction and generate prediction prompt data; A model training module, used to calculate a loss value according to each of the predicted prompt data and the corresponding prompt word answer, and perform model training on the C2F application data anomaly detection model based on the loss value; The plurality of time series data include a total length of the time series, and the variable masking process is performed on each of the C2F application data sequences to obtain a prompt word prefix and a prompt word answer corresponding to each of the C2F application data sequences, including: Obtaining a mask matrix, wherein the mask matrix includes a mask ratio parameter; generating the prompt word prefix based on the Hadamard product of the mask matrix and the C2F application data sequence; generating the prompt word answer based on the Hadamard product of the complement of the mask matrix and the C2F application data sequence, wherein the prompt word prefix and the prompt word answer satisfy a complementary data condition, and the complementary data condition is generated based on the mask ratio parameter and the total length of the time series; The time series data includes a plurality of feature data, the complementary data condition includes a first mask condition, a second mask condition and a mask complementary condition, and the steps of generating the complementary data condition include: Based on one minus the mask ratio parameter, multiplying the total length of the time series and the number of features of the feature data, a first mask data value is obtained, and based on the numerical relationship between the first matrix norm of the prompt word prefix and the first mask data value, the first mask condition is generated; Multiplying the mask ratio parameter, the total length of the time series and the number of features to obtain a second mask data value, and generating the second mask condition based on the numerical relationship between the second matrix norm of the prompt word answer and the second mask data value; The total length of the time series and the number of features are multiplied to obtain a complementary mask data value, and the mask complementarity condition is generated based on a numerical relationship among the first matrix norm, the second matrix norm and the complementary mask data value.
7. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the C2F application data anomaly detection model training method according to any one of claims 1 to 4 or the C2F application data anomaly detection method according to claim 5 is implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the C2F application data anomaly detection model training method according to any one of claims 1 to 4 or the C2F application data anomaly detection method according to claim 5 is implemented.
Citation Information
Patent Citations
Method and device for determining battery anomaly detection model and electronic equipment
CN117269813A
Time sequence anomaly detection method and system based on time sequence and multiple variables
CN117313015A