Abnormal behavior recognition method based on deep learning and big data analysis

By adopting deep learning and big data analysis technology in an abnormal behavior recognition system, combined with dynamic thresholds and multi-model integration, the problem of degradation of detection accuracy in seasonal fluctuations is solved, and more efficient abnormal pattern capture and recognition is achieved.

CN119989226APending Publication Date: 2025-05-13HEPTAGON (SUZHOU) TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510094802.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When existing identification systems process seasonal fluctuating data, static thresholds are difficult to adapt to data trend changes, resulting in a decrease in the accuracy of anomaly detection and a single model cannot capture all anomaly patterns in the data.

Method used

The abnormal behavior recognition method based on deep learning and big data analysis is adopted, and the data flow is monitored in real time through dynamic threshold and control chart technology, and the multi-model integration is carried out by combining density-based local outlier factors and cluster-based K-means models. A single-layer LSTM is used to process time series data, and a weighted loss function is designed to improve the accuracy of abnormal detection.

Benefits of technology

Real-time adaptation to data changes is achieved, real-time and accuracy of abnormal detection is improved, and multiple abnormal patterns in the data can be captured more effectively, and abnormal behavior recognition is adapted to different scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989226A_ABST
    Figure CN119989226A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal behavior identification method based on deep learning and big data analysis, and relates to the technical field of network abnormal behavior identification, and the method comprises the following steps: 1, monitoring a data flow in real time, calculating a threshold value through a dynamic threshold value method, and supplementing noise and an abnormal value processing mechanism; 2, selecting two different types of anomaly detection models of a density-based local outlier factor and a clustering-based K-means, analyzing data from different angles, and verifying a parameter selection and adjustment strategy; according to the method, the data flow is monitored in real time through a dynamic threshold method and a control chart technology, data changes can be adapted, and the real-time performance and accuracy of anomaly detection are improved. Two different types of anomaly detection models, namely a density-based local outlier factor and a clustering-based K-means, are adopted, data are analyzed from different angles, and multi-model integration is realized. And detection results are fused by adopting weighted fusion, so that the effective utilization rate of the features and the detection accuracy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network abnormal behavior identification, and specifically to an abnormal behavior identification method based on deep learning and big data analysis. Background Art

[0002] Anomaly detection is the process of identifying data points, events, or patterns in a data set that are inconsistent with normal patterns or expected behaviors. These anomalies may indicate errors, fraud, system failures, rare events, or other situations that require further investigation.

[0003] Many data sets in existing recognition systems have seasonal fluctuations. When using static thresholds, normal behavior may be mistakenly identified as abnormal during seasonal peaks or troughs, or vice versa. Data may show an increasing or decreasing trend over time, and static thresholds cannot adapt to such trend changes, often resulting in outdated thresholds that are no longer applicable to new data patterns. And because different models may be sensitive to different types of anomalies, relying on a single model for anomaly detection cannot capture all abnormal patterns in the data.

[0004] Therefore, we proposed an abnormal behavior identification method based on deep learning and big data analysis to solve the above problems. Summary of the invention

[0005] The purpose of the present invention is to provide an abnormal behavior identification method based on deep learning and big data analysis to solve the current market problems raised by the above background technology.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A method for identifying abnormal behavior based on deep learning and big data analysis, comprising the following steps:

[0008] Step 1: Monitor the data stream in real time, calculate the threshold using the dynamic threshold method, and add noise and outlier processing mechanisms;

[0009] Step 2: Select two different types of anomaly detection models: density-based local outlier factor and clustering-based K-means, analyze the data from different angles, and verify the parameter selection and adjustment strategy;

[0010] Step 3: Select different feature subsets according to feature importance and relevance, and fuse the detection results using weighted fusion;

[0011] Step 4: Use a single-layer LSTM to identify abnormal behaviors, describe the network structure and training process, and handle the problem of inconsistent sequence lengths of time series data;

[0012] Step 5: Select the most uncertain samples of the model for annotation and generate new query samples;

[0013] Step 6: Design a weighted loss function, clarify the weight allocation strategy for abnormal samples, and the mechanism by which the loss function value increases significantly when the difference between the predicted result and the true label exceeds a certain threshold.

[0014] Preferably, in step 1, a Cusum graph and an EWMA graph are selected as control graph types; the Cusum graph is used to monitor the changing trend of data, and the EWMA graph is used to monitor the slight changes of data.

[0015] Preferably, in step 2, user behavior data is collected and preprocessed and feature extracted, and the preprocessed data is used to train LOF and K-means models respectively, and the neighbor number parameter k is set in LOF, and the number of clusters K is set in K-means;

[0016] The trained LOF model is used to calculate the LOF score of each data point. The higher the score, the more likely the data point is an outlier. The trained K-means model is used to cluster the data and assign a higher anomaly score to data points that do not belong to any cluster. The LOF score and the K-means score are weighted averaged to obtain the final anomaly score for each data point. The anomaly score threshold is set. When the final anomaly score exceeds the threshold, the data point is considered an outlier and an alarm is triggered.

[0017] Preferably, in step three, the formula used for mutual information is:

[0018]

[0019] Among them, p(x,y) is the joint probability of feature X and category Y, p(x) and p(y) are the marginal probabilities of X and Y respectively;

[0020] In the weighted fusion strategy, the formula used for the probability weighted sum is:

[0021]

[0022] Among them, p is the probability after fusion, pi is the probability that the i-th model predicts an abnormality, and w i is the corresponding weight;

[0023] Based on the fusion of decision rules, the formula used is:

[0024]

[0025] Among them, D is the final decision, S i is the score of the i-th model, θ iis the corresponding threshold, and T is the threshold in the decision rule.

[0026] Preferably, in step 4, PyTorch is used to define the LSTM layer and specify the number of neurons in the LSTM layer, an output layer is defined, the number of neurons in the output layer is determined by an anomaly detection method, the LSTM layer and the output layer are connected, and a complete LSTM model is constructed.

[0027] Preferably, in step six, the prediction uncertainty of the model for each sample is evaluated by the prediction variance, and the variance of the prediction result of the model for each sample is calculated. The larger the variance, the more uncertain the model is. Based on the selection of diversity, the samples with the highest uncertainty are selected for manual labeling, the newly labeled data are added to the training set, and the model is retrained;

[0028] Through error analysis, the model is prone to misjudge rare abnormal behaviors as normal behaviors. Adversarial sample generation technology is used to generate rare abnormal behavior samples that can deceive the model, and adversarial samples are used to train the LSTM model.

[0029] Compared with the prior art, the present invention has the following beneficial effects:

[0030] The present invention uses dynamic threshold method and control chart technology to monitor data flow in real time, which can adapt to data changes and improve the real-time and accuracy of anomaly detection. Two different types of anomaly detection models, density-based local outlier factor and clustering-based K-means, are used to analyze data from different angles and realize multi-model integration. And weighted fusion is used to fuse the detection results, which can improve the effective utilization rate of features and the accuracy of detection.

[0031] The present invention uses a single-layer LSTM to handle the problem of inconsistent sequence lengths in time series data, and effectively captures the long-term dependencies in time series data by designing the network structure and training process, and selects the most uncertain samples of the model for annotation, generates new query samples, and effectively utilizes limited annotation resources. At the same time, a weighted loss function is designed to clarify the weight allocation strategy for abnormal samples, and significantly increase the loss function value when the difference between the predicted result and the true label exceeds a specific threshold.

[0032] The present invention dynamically adjusts the weights in the loss function according to the prediction error, and sets a specific threshold to amplify the loss value of abnormal samples, which can better adapt to abnormal behavior recognition in different scenarios.

[0033] The above summary is for illustrative purposes only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments and features described above, further aspects, embodiments and features of the present invention will be readily apparent by reference to the accompanying drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 A flowchart of using CUSUM for the present invention;

[0035] Figure 2 This is a flowchart of step 2 of the present invention. DETAILED DESCRIPTION

[0036] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0037] Embodiment 1

[0038] See also Figure 1 , Figure 2 , an abnormal behavior identification method based on deep learning and big data analysis, comprising the following steps:

[0039] Step 1: Monitor the data stream in real time, calculate the threshold using the dynamic threshold method, and add noise and outlier processing mechanisms;

[0040] Select Cusum chart and EWMA chart as the control chart type; Cusum chart is used to monitor the changing trend of data, and EWMA chart is used to monitor the slight changes of data.

[0041] Positive and negative Cusum values ​​calculate the cumulative sum in the positive and negative directions respectively, and the formula is:

[0042] Positive Cusum Value: in,

[0043] Negative Cusum Value: in,

[0044] Among them, C + and C - are the positive and negative Cusum values ​​at the tth time point, x t is the data value at the tth time point, and μ is the mean of the data.

[0045] Set the control limit, the control limit calculation formula is:

[0046]

[0047] Among them, σ is the standard deviation of the data. When the Cusum value exceeds the positive control limit or the negative control limit, it is considered that abnormal behavior has occurred.

[0048] According to the speed of data change and the need for abnormal behavior identification, set the appropriate update frequency and use the sliding window method to calculate the Cusum value and control limit in the recent period.

[0049] Specific embodiment: Monitor the data of user login time and use Cusum graph to perform anomaly detection.

[0050] First, calculate the mean and standard deviation of the user login time, use the formula to calculate the positive and negative control limits, and use the formula to calculate the positive and negative Cusum values ​​at each time point. When the Cusum value exceeds the positive control limit or the negative control limit, it is considered that abnormal behavior has occurred. Update the Cusum value and control limit every hour.

[0051] Step 2: Select two different types of anomaly detection models: density-based local outlier factor and clustering-based K-means, analyze the data from different angles, and verify the parameter selection and adjustment strategy;

[0052] Collect user behavior data, perform preprocessing and feature extraction, use the preprocessed data to train LOF and K-means models respectively, set the neighbor number parameter k in LOF, and set the number of clusters K in K-means.

[0053] The trained LOF model is used to calculate the LOF score of each data point. The higher the score, the more likely the data point is an outlier. The trained K-means model is used to cluster the data and assign a higher anomaly score to data points that do not belong to any cluster. The LOF score and the K-means score are weighted averaged to obtain the final anomaly score for each data point. The anomaly score threshold is set. When the final anomaly score exceeds the threshold, the data point is considered an outlier and an alarm is triggered.

[0054] More specifically, the formula used for local reachability density is:

[0055]

[0056] Among them, avg(k-dist(p)) is the average reachable distance from point p to its kth nearest neighbor. The formula used is

[0057] The formula used for reachable distance is:

[0058] reach-dist(p,o)=max(k-dist(o),d(p,o))

[0059] Among them, d(p,o) is the distance between point p and point o, and k-dist(o) is the distance to the kth nearest neighbor of point o.

[0060] K-means clustering based, centroid initialization, select k initial centroids, and randomly select data points.

[0061] Centroid assignment, for each data point x i , assign it to the nearest centroid c j :

[0062]

[0063] Among them, ||x i -c j || is the data point x i and the centroid c j The Euclidean distance between .

[0064] Recalculate each centroid c j As the mean of all data points assigned to it:

[0065]

[0066] Among them, S j is assigned to the centroid c j A collection of data points.

[0067] Specific implementation example: Monitor the data of user login time and use LOF and K-means for anomaly detection.

[0068] First, collect user login time data, perform preprocessing and feature extraction, use LOF and K-means to train models respectively, calculate the LOF score of each data point in LOF, and use K-means to cluster the data, assign a higher anomaly score to data points that do not belong to any cluster, calculate the LOF score of each data point using LOF, and use K-means to cluster the data, and assign a higher anomaly score to data points that do not belong to any cluster. When the final anomaly score exceeds the threshold, the data point is considered an anomaly and an alarm is triggered. The model is updated regularly with new data, and the parameters and weights of the model are adjusted according to the actual situation.

[0069] Step 3: Select different feature subsets according to feature importance and relevance, and fuse the detection results using weighted fusion;

[0070] The features are divided into different subsets, each of which represents a different behavioral dimension. Anomaly detection is performed independently on each feature subset, and the detection results of different feature subsets are combined to obtain the final result through logical combination method.

[0071] Specifically, the formula used for mutual information is:

[0072]

[0073] Where p(x,y) is the joint probability of feature X and category Y, and p(x) and p(y) are the marginal probabilities of X and Y respectively.

[0074] In the weighted fusion strategy, the formula used for the probability weighted sum is:

[0075]

[0076] Among them, p is the probability after fusion, pi is the probability that the i-th model predicts an abnormality, and w i is the corresponding weight.

[0077] Based on the fusion of decision rules, the formula used is:

[0078]

[0079] Among them, D is the final decision, S i is the score of the i-th model, θ i is the corresponding threshold, and T is the threshold in the decision rule.

[0080] Specific implementation example: Monitor user behavior data on the platform to identify potential fraudulent behavior.

[0081] The features are grouped as follows: Feature subset 1: user’s login time, login IP address, login device type; Feature subset 2: user’s purchased product type, purchase amount, and purchase frequency; Feature subset 3: user’s browsed product type, browsing time, and browsing frequency.

[0082] The feature sets were tested independently. Feature subset 1: Unidirectional CUSUM was used for anomaly detection, focusing on abnormal changes in user login time, login IP address, and login device type, such as frequent login, abnormal login IP address, and abnormal login device type; Feature subset 2: K-means was used for anomaly detection, focusing on the clustering of user purchase behaviors, such as abnormal purchase product types, abnormal purchase amounts, and abnormal purchase frequencies; Feature subset 3: One-Class SVM was used for anomaly detection, focusing on abnormal patterns of user browsing behaviors, such as abnormal browsed product types, abnormal browsing duration, and abnormal browsing frequencies.

[0083] The results are integrated and the detection results of the three feature subsets are combined using logical AND operations. Only when all three feature subsets detect anomalies, it is finally judged as abnormal behavior. The anomaly scores of the three feature subsets are weighted averaged, and the weights are adjusted according to the importance of the feature subsets.

[0084] When a user logs in frequently in a short period of time and the login IP address is abnormal, but the operation and browsing behavior are normal. In this case, UC will detect the abnormality of the login information, K-means and One-Class SVM will not detect the abnormality, so the logical AND operation will be judged as normal behavior, but the weighted average may judge the user's behavior as potential abnormal behavior based on the weight of the login information.

[0085] Step 4: Use a single-layer LSTM to identify abnormal behaviors, describe the network structure and training process, and handle the problem of inconsistent sequence lengths of time series data;

[0086] Use PyTorch to define the LSTM layer and specify the number of neurons in the LSTM layer. Define the output layer. The number of neurons in the output layer is determined by the anomaly detection method. Connect the LSTM layer and the output layer to build a complete LSTM model.

[0087] More specifically, in the LSTM network structure, the formula used by the forget gate is:

[0088] f t =σ(W f ·[h t-1 ,x t ]+b f )

[0089] Among them, f t is the output of the forget gate, W f is the weight of the forget gate, b f is the bias of the forget gate, h t-1 is the hidden state of the previous time step, x t is the input of the current time step, and σ is the sigmoid activation function.

[0090] The formula used by the input gate is:

[0091] i t =σ(W i ·[h t-1 ,x t ]+b i )

[0092]

[0093] Among them, i t is the input gate output, is the candidate cell state, W i and W C are the weights of the input gate and candidate cell state, respectively, and b i and b C is the corresponding bias and tanh is the hyperbolic tangent activation function.

[0094] The formula used to update the cell state is:

[0095]

[0096] Among them, C t is the new cell state, Represents element-wise product.

[0097] The formula used by the output gate is:

[0098] o t =σ(W o ·[h t-1 ,x t ]+b o )

[0099] Among them, t is the output gate output, W o is the weight of the output gate, b o is the bias of the output gate.

[0100] The formula used for the hidden state is:

[0101]

[0102] Among them, h t is the hidden state at the current time step.

[0103] To deal with the problem of inconsistent sequence length, the formula used for filling is:

[0104] x padded =pad(x,length)

[0105] Among them, x is the original sequence, x padded is the padded sequence, length is the target sequence length, and pad is the padding operation.

[0106] The formula used for truncation is:

[0107] x truncated =x[0:length]

[0108] Among them, x truncated is the truncated sequence.

[0109] Specific implementation: Use TensorFlow to define an LSTM layer with 64 neurons and use a dropout layer to prevent overfitting. Define a linear layer with 1 neuron to calculate the anomaly score for each time step. Connect the LSTM layer and the output layer, and use a serialization layer to process sequence data. Set the number of neurons in the hidden layer to 64, the learning rate to 0.001, the optimizer to Adam, the loss function to mean square error, use TensorFlow's compile method to compile the LSTM model, and use historical data to train the LSTM model.

[0110] Step 5: Select the most uncertain samples of the model for annotation and generate new query samples;

[0111] Specifically, for the maximum probability principle in uncertainty measurement:

[0112]

[0113] Here, p(i|x) is the probability that the model predicts that input x belongs to category i.

[0114] In sample selection, for uncertainty sampling, select the N samples with the highest entropy for labeling:

[0115] S={x1,x2,...,x N}|H(x i ) is among the highestNvalues

[0116] Among them, S is the selected sample set.

[0117] Step 6: Design a weighted loss function, clarify the weight allocation strategy for abnormal samples, and the mechanism by which the loss function value increases significantly when the difference between the predicted result and the true label exceeds a certain threshold.

[0118] The prediction variance is used to evaluate the uncertainty of the model's prediction for each sample. The variance of the model's prediction results for each sample is calculated. The larger the variance, the more uncertain the model is. Based on the diversity selection, the samples with the highest uncertainty are selected for manual labeling. The newly labeled data are added to the training set and the model is retrained.

[0119] Through error analysis, the model is prone to misjudge rare abnormal behaviors as normal behaviors. Adversarial sample generation technology is used to generate rare abnormal behavior samples that can deceive the model, and adversarial samples are used to train the LSTM model to improve its ability to recognize rare abnormal behaviors.

[0120] More specifically, for the weight assignment of abnormal samples, the weight of abnormal samples is assigned based on their rarity or prediction error, and the formula used is:

[0121]

[0122] Among them, α is a constant greater than 1, which is used to increase the weight of abnormal samples.

[0123] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code that includes one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present invention includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present invention belong.

[0124] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, which can be embodied in any computer-readable medium for use by an instruction execution system, apparatus or device (such as a computer-based system, a system including a processor or other system that can fetch instructions from an instruction execution system, apparatus or device and execute instructions), or used in combination with these instruction execution systems, apparatuses or devices.

[0125] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0126] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.

[0127] In addition, each functional unit in each embodiment of the present invention may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0128] Although the embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and are not to be construed as limitations of the present invention. A person skilled in the art may change, modify, replace and vary the above embodiments within the scope of the present invention.

Claims

1. A method for identifying abnormal behavior based on deep learning and big data analysis, characterized in that: The following steps are involved: Step 1: Monitor the data stream in real time, calculate the threshold using the dynamic threshold method, and add noise and outlier processing mechanisms; Step 2: Select two different types of anomaly detection models: density-based local outlier factor and clustering-based K-means, analyze the data from different angles, and verify the parameter selection and adjustment strategy; Step 3: Select different feature subsets according to feature importance and relevance, and fuse the detection results using weighted fusion; Step 4: Use a single-layer LSTM to identify abnormal behaviors, describe the network structure and training process, and handle the problem of inconsistent sequence lengths of time series data; Step 5: Select the most uncertain samples of the model for annotation and generate new query samples; Step 6: Design a weighted loss function, clarify the weight allocation strategy for abnormal samples, and the mechanism by which the loss function value increases significantly when the difference between the predicted result and the true label exceeds a certain threshold.

2. The abnormal behavior identification method based on deep learning and big data analysis according to claim 1 is characterized by: In step 1, select Cusum chart and EWMA chart as the control chart type; Cusum chart is used to monitor the changing trend of data, and EWMA chart is used to monitor the slight changes of data.

3. The abnormal behavior identification method based on deep learning and big data analysis according to claim 1 is characterized by: In step 2, user behavior data is collected and preprocessed and feature extracted, and the preprocessed data is used to train the LOF and K-means models respectively, the neighbor number parameter k is set in LOF, and the number of clusters K is set in K-means; The trained LOF model is used to calculate the LOF score of each data point. The higher the score, the more likely the data point is an outlier. The trained K-means model is used to cluster the data and assign a higher anomaly score to data points that do not belong to any cluster. The LOF score and the K-means score are weighted averaged to obtain the final anomaly score for each data point. The anomaly score threshold is set. When the final anomaly score exceeds the threshold, the data point is considered an outlier and an alarm is triggered.

4. The abnormal behavior identification method based on deep learning and big data analysis according to claim 1 is characterized in that: In step 3, the formula used for mutual information is: Among them, p(x,y) is the joint probability of feature X and category Y, p(x) and p(y) are the marginal probabilities of X and Y respectively; In the weighted fusion strategy, the formula used for the probability weighted sum is: Among them, p is the probability after fusion, pi is the probability that the i-th model predicts an abnormality, and w i is the corresponding weight; Based on the fusion of decision rules, the formula used is: Among them, D is the final decision, S i is the score of the i-th model, θ i is the corresponding threshold, and T is the threshold in the decision rule.

5. The abnormal behavior identification method based on deep learning and big data analysis according to claim 1 is characterized in that: In step 4, use PyTorch to define the LSTM layer and specify the number of neurons in the LSTM layer. Define the output layer. The number of neurons in the output layer is determined by the anomaly detection method. Connect the LSTM layer and the output layer to build a complete LSTM model.

6. The abnormal behavior identification method based on deep learning and big data analysis according to claim 1 is characterized by: In step 6, the prediction uncertainty of the model for each sample is evaluated by the prediction variance. The variance of the model's prediction results for each sample is calculated. The larger the variance, the more uncertain the model is. Based on the diversity selection, the samples with the highest uncertainty are selected for manual labeling. The newly labeled data are added to the training set and the model is retrained. Through error analysis, the model is prone to misjudge rare abnormal behaviors as normal behaviors. Adversarial sample generation technology is used to generate rare abnormal behavior samples that can deceive the model, and adversarial samples are used to train the LSTM model.

Citation Information

Cited By

  • Multi-mode intelligent data acquisition system and method for monitoring smell of automotive trim

    CN121994307A