Time series data anomaly detection method and device oriented to power sensor and network
By adopting a combination of security risk hierarchical structure and prediction model in power sensors and networks, the problems of timing data security and abnormal detection accuracy are solved, and more efficient abnormal detection and data security guarantee are achieved.
Patent Information
- Application Number
- CN202411984350.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-30
AI Technical Summary
Power sensors and networks operate in hostile and dangerous environments, and face the challenges of resource limitations and unattended deployment. The security of the timing data generated by them is seriously threatened. The existing encryption schemes have high computational complexity and are difficult to meet real-time performance. The false alarm rate of intrusion detection systems is high, making it difficult to accurately identify abnormal data.
Based on the preset power sensor and the security risk hierarchical structure of the network, security risk data is collected and time-series index data is obtained through time scale quantization. Use historical security risk data to build a prediction model, and perform abnormal detection by comparing actual data and predicting data.
It realizes more accurate identification of power sensors and timing data in the network, reduces false alarm rates and missed alarm rates, improves the accuracy and accuracy of abnormal detection, and enhances data security.
Smart Images

Figure CN120067928A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of application security in information security, and particularly relates to a method and device for detecting abnormal time-series data for power sensors and networks. Background Art
[0002] As a key technology in the 21st century, wireless sensor networks are revolutionary in information sensing, data transmission, and data analysis, and are an important bridge connecting the logical information field and the physical environment. The power sensors and networks, as their applications in the power system, have attracted wide attention. The power system is a complex network composed of transmission lines, substations, and other facilities, and its core function is to efficiently transmit electric power from power plants to end users. The smart grid uses power sensors and networks to achieve real-time monitoring of information such as power equipment, grid operation status, and energy metering, providing basic data for the digital transformation of energy. On the power generation side, the application of sensor arrays has improved the fault diagnosis and health monitoring capabilities of renewable energy power generation equipment such as wind energy and photovoltaic systems. On the transmission grid side, the wide deployment of sensors provides data support for the production and operation activities of the grid. On the consumer side, the popularization of sensors and measurement devices has promoted the development of smart power consumption and smart home technologies.
[0003] However, as a wireless self-organizing system, power sensors and networks operate in hostile and dangerous environments and face challenges of resource limitations and unattended deployment, and the security of the time-series data they generate is severely threatened. Some existing power sensor network security patent technologies, such as the schemes based on encryption technology, have high computational complexity and are difficult to meet the real-time requirements; the schemes based on intrusion detection systems have high false alarm rates and are difficult to accurately identify abnormal data. Summary of the Invention
[0004] To overcome the problems existing in the above related technologies, the present invention provides a method and device for detecting abnormal time-series data for power sensors and networks.
[0005] According to the first aspect of the embodiments of the present invention, a method for detecting abnormal time-series data for power sensors and networks is provided, including:
[0006] Collecting security risk data of power sensors and networks at a first sampling time and a second sampling time based on a preset hierarchical structure of security risks of power sensors and networks;
[0007] Performing time-scale quantization on the security risk data at the first sampling time and the second sampling time respectively to obtain first target time-series index data and second target time-series index data;
[0008] Using the second target time-series index data as the input of a pre-established prediction model and outputting predicted time-series index data;
[0009] Use the first target time series index data and the predicted time series index data to perform anomaly detection on the first target time series index data;
[0010] Among them, the prediction model is constructed using historical security risk data, and the second sampling time is earlier than the first sampling time.
[0011] Preferably, the preset hierarchical structure of security risks for the power sensor and network includes: various security risks and their corresponding indicators;
[0012] The various security risks at least include the following four types: perception layer risk, network layer risk, edge computing layer risk, and other risks;
[0013] The indicators of the perception layer risk include: electromagnetic tampering, laser tampering, acoustic tampering, and service life;
[0014] The indicators of the network layer risk include: data theft and node impersonation;
[0015] The indicators of the edge computing layer risk include: data leakage, storage tampering, and denial of service;
[0016] The indicators of the other risks include: environmental threats, natural disasters, and management risks.
[0017] Preferably, the time-scale quantization of the security risk data for the first sampling time and the second sampling time respectively includes:
[0018] Based on the security risk data at the first sampling time, use the expert scoring method to score each indicator in each security risk to obtain the indicator scores of each indicator at the first sampling time;
[0019] Quantize the indicator scores of each indicator at the first sampling time on a time scale to obtain the first target time series index data.
[0020] Preferably, the time-scale quantization of the security risk data for the first sampling time and the second sampling time respectively further includes:
[0021] Based on the security risk data at the second sampling time, use the expert scoring method to score each indicator in each security risk to obtain the indicator scores of each indicator at the second sampling time;
[0022] Quantize the indicator scores of each indicator at the second sampling time on a time scale to obtain the second target time series index data.
[0023] Preferably, the establishment process of the prediction model includes:
[0024] Collect historical security risk data of power sensors and networks at historical times based on a preset hierarchical structure of security risks of power sensors and networks.
[0025] Quantify the historical security risk data on a time scale to obtain historical time series index data.
[0026] Use the historical time series index data to train a long short-term memory network model with a residual connection mechanism to obtain the prediction model.
[0027] Preferably, the quantifying the historical security risk data on a time scale to obtain historical time series index data includes:
[0028] Based on the historical security risk data, use the expert scoring method to score each index in each security risk to obtain the index scores of each historical index.
[0029] Quantify the index scores of each historical index on a time scale to obtain the historical time series index data.
[0030] Preferably, the using the historical time series index data to train a long short-term memory network model with a residual connection mechanism to obtain the prediction model includes:
[0031] Select multiple historical time series index data with a time span of τ from historical times as input data, and select the historical time series index data at the next moment after the last moment in the time span τ as output data, where τ = [1, 2, …, t″′], and t″′ is the last moment in the time span τ.
[0032] Use the input data as the training samples of the input layer of the long short-term memory network model with a residual connection mechanism, and use the output data as the training samples of the output layer of the long short-term memory network model with a residual connection mechanism to train the long short-term memory network model with a residual connection mechanism to obtain a trained long short-term memory network model with a residual connection mechanism.
[0033] The trained long short-term memory network model with a residual connection mechanism is the prediction model.
[0034] Preferably, the using the first target time series index data and the predicted time series index data to perform anomaly detection on the first target time series index data includes:
[0035] Based on the first target time series index data and the predicted time series index data, use the K-sigma criterion to determine whether there is an anomaly in the first target time series index data.
[0036] Preferably, based on the first target time series index data and the predicted time series index data, using the K-sigma criterion to determine whether there is an abnormality in the first target time series index data, including:
[0037] Calculating the average value and variance of the predicted time series index data;
[0038] Using the average value, the variance and the parameters of the K-sigma criterion to determine the detection condition;
[0039] If the first target time series index data meets the detection condition, the first target time series index data is a normal value; if the first target time series index data does not meet the detection condition, the first target time series index data is an abnormal value.
[0040] Preferably, the detection condition includes:
[0041] [μ(T′)-Kσ(T′),μ(T′)+Kσ(T′)], where μ(T′) is the average value of the predicted time series index data, σ(T′) is the variance of the predicted time series index data, T′ is the total time of the second sampling time, and K is the parameter of the K-sigma criterion.
[0042] Preferably, the calculation formula of the first target time series index data includes:
[0043]
[0044] Among them, the calculation formula of the first target time series index data corresponding to the i-th index at the t-th moment includes:
[0045]
[0046] In the above formula, i ∈ [1, m], m is the total number of indexes in the safety risk level; t ∈ [1, T], T is the total time of the first sampling time; is the first target time series index data at the t-th moment, is the first target time series index data corresponding to the 1st index at the t-th moment, is the first target time series index data corresponding to the 2nd index at the t-th moment, is the first target time series index data corresponding to the i-th index at the t-th moment, is the first target time series index data corresponding to the m-th index at the t-th moment; n ∈ [1, N], N is the total number of experts; x n (t) is the scoring vector of the n-th expert for all indexes at the t-th moment, x n (t) = [x n(t,1),x n (t,2),…,x n (t,i),…,x n (t,m)],x n (t,1) is the scoring vector of the nth expert for the first indicator at the tth moment, x n (t,2) is the scoring vector of the nth expert for the second indicator at the tth moment, x n (t,i) is the scoring vector of the nth expert for the ith indicator at the tth moment, x n (t,m) is the scoring vector of the nth expert for the mth indicator at the tth moment.
[0047] Preferably, the calculation formula for the average value of the predicted time-series indicator data includes:
[0048]
[0049] The calculation formula for the variance of the predicted time-series indicator data includes:
[0050]
[0051] In the above formula, i ∈ [1, m], m is the total number of indicators in the security risk level; t' ∈ [1, T'], T' is the total moment of the second sampling time; μ(T') is the average value of the predicted time-series indicator data, is the predicted time-series indicator data corresponding to the ith indicator at the t'th moment, and σ(T') is the variance of the predicted time-series indicator data.
[0052] According to the second aspect of the embodiments of the present invention, a time-series data anomaly detection device for power sensors and networks is provided, including:
[0053] An acquisition unit for acquiring security risk data of power sensors and networks at the first sampling time and the second sampling time based on a preset security risk hierarchical structure of power sensors and networks;
[0054] A quantization unit for respectively performing time-scale quantization on the security risk data at the first sampling time and the second sampling time to obtain first target time-series indicator data and second target time-series indicator data;
[0055] A prediction unit for using the second target time-series indicator data as the input of a pre-established prediction model and outputting predicted time-series indicator data;
[0056] A detection unit for using the first target time-series indicator data and the predicted time-series indicator data to perform anomaly detection on the first target time-series indicator data;
[0057] Among them, the prediction model is constructed using historical security risk data, and the second sampling time is earlier than the first sampling time.
[0058] Preferably, the preset hierarchical structure of security risks of the power sensor and network includes: various security risks and their corresponding indicators;
[0059] The various security risks at least include the following four types: perception layer risk, network layer risk, edge computing layer risk, and other risks;
[0060] The indicators of the perception layer risk include: electromagnetic tampering, laser tampering, acoustic wave tampering, and service life;
[0061] The indicators of the network layer risk include: data theft and node impersonation;
[0062] The indicators of the edge computing layer risk include: data leakage, storage tampering, and denial of service;
[0063] The indicators of the other risks include: environmental threats, natural disasters, and management risks.
[0064] Preferably, the quantization unit includes:
[0065] A first acquisition module, configured to score each indicator in each security risk based on the security risk data at the first sampling time by using the expert scoring method, and obtain the indicator scores of each indicator at the first sampling time;
[0066] A first quantization module, configured to perform quantization on the time scale of the indicator scores of each indicator at the first sampling time, and obtain the first target time series indicator data.
[0067] Preferably, the quantization unit further includes:
[0068] A second acquisition module, configured to score each indicator in each security risk based on the security risk data at the second sampling time by using the expert scoring method, and obtain the indicator scores of each indicator at the second sampling time;
[0069] A second quantization module, configured to perform quantization on the time scale of the indicator scores of each indicator at the second sampling time, and obtain the second target time series indicator data.
[0070] Preferably, it further includes: a building unit, configured to build the prediction model; the building unit includes:
[0071] An acquisition module, configured to collect historical security risk data of the power sensor and network at historical times based on the preset hierarchical structure of security risks of the power sensor and network;
[0072] A third quantization module, configured to perform time-scale quantization on historical security risk data to obtain historical time-series index data;
[0073] A training module, configured to train a long short-term memory network model with a residual connection mechanism by using the historical time-series index data to obtain the prediction model.
[0074] Preferably, the third quantization module is specifically configured to:
[0075] Based on the historical security risk data, use the expert scoring method to score each index in each security risk to obtain the index scores of each historical index;
[0076] Perform time-scale quantization on the index scores of each historical index to obtain the historical time-series index data.
[0077] Preferably, the training module is specifically configured to:
[0078] Select multiple pieces of historical time-series index data with a time span of τ from historical time as input data, and select the historical time-series index data at the next moment after the last moment in the time span τ as output data, where τ = [1, 2,..., t″′], and t″′ is the last moment in the time span τ;
[0079] Use the input data as the input layer training samples of the long short-term memory network model with a residual connection mechanism, and use the output data as the output layer training samples of the long short-term memory network model with a residual connection mechanism to train the long short-term memory network model with a residual connection mechanism to obtain a trained long short-term memory network model with a residual connection mechanism;
[0080] The trained long short-term memory network model with a residual connection mechanism is the prediction model.
[0081] Preferably, the detection unit includes:
[0082] A judgment module, configured to judge whether there is an abnormality in the first target time-series index data by using the K-sigma criterion based on the first target time-series index data and the predicted time-series index data.
[0083] Preferably, the judgment module is specifically configured to:
[0084] Calculate the average value and variance of the predicted time-series index data;
[0085] Use the average value, the variance and the parameters of the K-sigma criterion to determine the detection condition;
[0086] If the first target timing index data meets the detection condition, the first target timing index data is a normal value; if the first target timing index data does not meet the detection condition, the first target timing index data is an abnormal value.
[0087] Preferably, the detection condition includes:
[0088] [μ(T′)-Kσ(T′), μ(T′)+Kσ(T′)], where μ(T′) is the average value of the predicted timing index data, σ(T′) is the variance of the predicted timing index data, T′ is the total time of the second sampling time, and K is the parameter of the K-sigma criterion.
[0089] Preferably, the calculation formula of the first target timing index data includes:
[0090]
[0091] Among them, the calculation formula of the first target timing index data corresponding to the i-th index at the t-th moment includes:
[0092]
[0093] In the above formula, i ∈ [1, m], m is the total number of indicators in the safety risk level; t ∈ [1, T], T is the total time of the first sampling time; is the first target timing index data at the t-th moment, is the first target timing index data corresponding to the 1st index at the t-th moment, is the first target timing index data corresponding to the 2nd index at the t-th moment, is the first target timing index data corresponding to the i-th index at the t-th moment, is the first target timing index data corresponding to the m-th index at the t-th moment; n ∈ [1, N], N is the total number of experts; x n (t) is the scoring vector of the n-th expert for all indicators at the t-th moment, x n (t) = [x n (t, 1), x n (t, 2), …, x n (t, i), …, x n (t, m)], x n (t, 1) is the scoring vector of the n-th expert for the 1st index at the t-th moment, x n (t, 2) is the scoring vector of the n-th expert for the 2nd index at the t-th moment, x n (t, i) is the scoring vector of the n-th expert for the i-th index at the t-th moment, x n(t, m) is the scoring vector of the nth expert for the mth indicator at the tth moment.
[0094] Preferably, the calculation formula for the average value of the predicted time-series indicator data includes:
[0095]
[0096] The calculation formula for the variance of the predicted time-series indicator data includes:
[0097]
[0098] In the above formula, i ∈ [1, m], where m is the total number of indicators in the safety risk level; t' ∈ [1, T'], where T' is the total moment of the second sampling time; μ(T') is the average value of the predicted time-series indicator data, is the predicted time-series indicator data corresponding to the ith indicator at the t'th moment, and σ(T') is the variance of the predicted time-series indicator data.
[0099] According to the third aspect of the embodiments of the present invention, there is provided an electronic device, including: at least one processor and a memory; the memory and the processor are connected by a bus;
[0100] The memory is used to store one or more programs;
[0101] When the one or more programs are executed by the at least one processor, the time-series data anomaly detection method for power sensors and networks as described above is implemented.
[0102] According to the fourth aspect of the embodiments of the present invention, there is provided a readable storage medium, on which an execution program is stored, and when the execution program is executed, the time-series data anomaly detection method for power sensors and networks as described above is implemented.
[0103] The technical solution provided by the present invention has the following beneficial effects:
[0104] The method and device for detecting abnormal time-series data for power sensors and networks provided by the present invention collect security risk data of power sensors and networks at a first sampling time and a second sampling time based on a preset hierarchical structure of security risks for power sensors and networks, and perform time-scale quantization on the security risk data at the first sampling time and the second sampling time respectively to obtain first target time-series index data and second target time-series index data, which can more accurately identify security risks in power sensors and networks; by using the second target time-series index data as the input of a pre-established prediction model to output predicted time-series index data, and by using the first target time-series index data and the predicted time-series index data to perform abnormal detection on the first target time-series index data, flexible detection of abnormal data is realized, the false alarm rate and the missed alarm rate can be effectively reduced, the accuracy and precision of abnormal detection are improved, which provides a planning guide for data security detection in future power sensors and networks and helps to promote the safe development of power sensors and networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0105] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.
[0106] Figure 1 is a flowchart of the method for detecting abnormal time-series data for power sensors and networks provided by the embodiments of the present invention;
[0107] Figure 2 is a schematic diagram of the hierarchical structure of security risks for power sensors and networks provided by the embodiments of the present invention;
[0108] Figure 3 is a flowchart of the method for detecting abnormal time-series data for power sensors and networks provided by the embodiments of the present invention;
[0109] Figure 4 is the training process of the prediction model based on the improved LSTM provided by the embodiments of the present invention;
[0110] Figure 5 is a block diagram of the structure of the device for detecting abnormal time-series data for power sensors and networks provided by the embodiments of the present invention;
[0111] Figure 6 is a block diagram of the structure of an electronic device provided by the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0112] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Apparently, the following embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0113] Embodiment 1
[0114] The present invention provides a method for detecting abnormal time-series data for power sensors and networks, as Figure 1 shown, which includes the following steps:
[0115] Step 11: Based on the preset hierarchical structure of security risks for power sensors and networks, collect the security risk data of power sensors and networks at the first sampling time and the second sampling time;
[0116] Step 12: Respectively perform time-scale quantization on the security risk data at the first sampling time and the second sampling time to obtain the first target time-series index data and the second target time-series index data;
[0117] Step 13: Use the second target time-series index data as the input of the pre-established prediction model to output the predicted time-series index data;
[0118] Step 14: Use the first target time-series index data and the predicted time-series index data to perform abnormal detection on the first target time-series index data;
[0119] Among them, the prediction model is constructed using historical security risk data, and the second sampling time is earlier than the first sampling time.
[0120] For example, the first sampling time is January 18, 2024, and the second sampling time is from January 1 to January 7, 2024.
[0121] Furthermore, as Figure 2 shown, the preset hierarchical structure of security risks for power sensors and networks includes: various security risks and their corresponding indicators;
[0122] The various security risks include at least the following four types: perception layer risk, network layer risk, edge computing layer risk, and other risks;
[0123] The indicators of the perception layer risk include: electromagnetic tampering, laser tampering, acoustic tampering, and service life;
[0124] The indicators of the network layer risk include: data theft and node impersonation;
[0125] The indicators of risks at the edge computing layer include: data leakage, storage tampering, and denial of service;
[0126] The indicators of other risks include: environmental threats, natural disasters, and management risks.
[0127] It should be noted that electromagnetic tampering refers to changing the sensed data of a power sensor by sending electromagnetic waves or adding an external magnetic field; laser tampering is using a laser with a specific frequency to irradiate the power sensor, thereby changing the sensed data of the power sensor; acoustic wave tampering is using ultrasonic waves and other attack means to change the sensed data of the power sensor or send control commands; service life refers to the life of a power sensor node under long-term working conditions, which directly reflects one of the main indicators of sensor reliability;
[0128] Data theft is obtaining the data transmitted over the network through eavesdropping, thereby compromising data confidentiality; node impersonation means that a malicious node impersonates a power sensor to send false information to the network, or a malicious node impersonates an aggregation node to deceive power sensor data;
[0129] Data leakage is obtaining the service data stored in the edge terminal device through network attacks, device intrusion, etc.; storage tampering refers to attacking the memory of the edge terminal device by means of magnetism, laser, etc., and then changing the service and management data stored inside the memory; denial of service is causing the edge terminal device to stop serving the power sensor by continuously sending data to the edge terminal device;
[0130] Environmental threat refers to the degree to which sensors, cameras, and other devices are vulnerable to human damage due to the complexity and variability of their environments; natural disasters refer to the losses caused by floods, fires, earthquakes, and other natural disasters; management risk refers to the threat to the quality and integrity of management systems, supervision mechanisms, national policies, laws, and regulations.
[0131] A power sensor and network security risk hierarchical structure proposed by the present invention divides security risks into different levels and quantifies them into time-series index data according to the time scale. This structure can effectively perform hierarchical analysis and time-series quantification on the sensed data in the power sensor and network, realizing the visualization of sensed security risks.
[0132] Further, step 12 includes:
[0133] Step 121: Based on the security risk data at the first sampling time, use the expert scoring method to score each indicator in each security risk to obtain the indicator scores of each indicator at the first sampling time;
[0134] Step 122: Quantify the indicator scores of each indicator at the first sampling time according to the time scale to obtain the first target time-series indicator data;
[0135] Specifically, the calculation formula for the first target time-series index data includes:
[0136]
[0137] Among them, the calculation formula for the first target time-series index data corresponding to the i-th index at the t-th moment includes:
[0138]
[0139] In the above formula, i ∈ [1, m], where m is the total number of indicators in the safety risk level; t ∈ [1, T], where T is the total number of moments of the first sampling time; is the first target time-series index data at the t-th moment, is the first target time-series index data corresponding to the 1st index at the t-th moment, is the first target time-series index data corresponding to the 2nd index at the t-th moment, is the first target time-series index data corresponding to the i-th index at the t-th moment, is the first target time-series index data corresponding to the m-th index at the t-th moment; n ∈ [1, N], where N is the total number of experts; x n (t) is the scoring vector of the n-th expert for all indicators at the t-th moment, x n (t) = [x n (t, 1), x n (t, 2), …, x n (t, i), …, x n (t, m)], x n (t, 1) is the scoring vector of the n-th expert for the 1st index at the t-th moment, x n (t, 2) is the scoring vector of the n-th expert for the 2nd index at the t-th moment, x n (t, i) is the scoring vector of the n-th expert for the i-th index at the t-th moment, x n (t, m) is the scoring vector of the n-th expert for the m-th index at the t-th moment.
[0140] Furthermore, step 12 further includes:
[0141] Step 123: Based on the safety risk data of the second sampling time, use the expert scoring method to score each indicator in each safety risk to obtain the indicator scores of each indicator at the second sampling time;
[0142] Step 124: Quantify the indicator scores of each indicator at the second sampling time in terms of time scale to obtain the second target time-series index data;
[0143] Specifically, the calculation formula for the second target time series index data includes:
[0144]
[0145] Among them, the calculation formula for the second target time series index data corresponding to the i-th index at the t'-th moment includes:
[0146]
[0147] In the above formula, i ∈ [1, m], where m is the total number of indexes in the security risk level; t' ∈ [1, T'], where T' is the total moment of the second sampling time; is the second target time series index data at the t'-th moment, is the second target time series index data corresponding to the first index at the t'-th moment, is the time series index data corresponding to the second index at the t'-th moment, is the second target time series index data corresponding to the i-th index at the t'-th moment, is the second target time series index data corresponding to the m-th index at the t'-th moment; n ∈ [1, N], where N is the total number of experts; x' n (t') is the scoring vector of the n-th expert for all indexes at the t'-th moment, x' n (t') = [x' n (t', 1), x' n (t', 2), …, x' n (t', i), …, x' n (t', m)], x' n (t', 1) is the scoring vector of the n-th expert for the first index at the t'-th moment, x' n (t', 2) is the scoring vector of the n-th expert for the second index at the t'-th moment, x' n (t', i) is the scoring vector of the n-th expert for the i-th index at the t'-th moment, x' n (t', m) is the scoring vector of the n-th expert for the m-th index at the t'-th moment.
[0148] Furthermore, the method further includes: Step 10: Establish a prediction model; Step 10 includes:
[0149] Step 101: Based on the preset hierarchical structure of the security risks of power sensors and networks, collect the historical security risk data of power sensors and networks in historical time;
[0150] Step 102: Quantify the historical security risk data on a time scale to obtain historical time series index data;
[0151] Step 103: Train a long short-term memory network model with a residual connection mechanism using historical time series index data to obtain a prediction model.
[0152] Further, step 102 includes:
[0153] Step 1021: Based on historical safety risk data, use the expert scoring method to score each index in each safety risk to obtain the index scores of each historical index;
[0154] Step 1022: Quantify the index scores of each historical index on a time scale to obtain historical time series index data;
[0155] Specifically, the calculation formula of historical time series index data includes:
[0156]
[0157] Among them, the calculation formula of the historical time series index data corresponding to the i-th index at the t″-th moment includes:
[0158]
[0159] In the above formula, i ∈ [1, m], where m is the total number of indexes in the safety risk level; t″ ∈ [1, T″], where T″ is the total number of historical time moments; is the historical time series index data at the t″-th moment, is the historical time series index data corresponding to the first index at the t″-th moment, is the historical time series index data corresponding to the second index at the t″-th moment, is the historical time series index data corresponding to the i-th index at the t″-th moment, is the historical time series index data corresponding to the m-th index at the t″-th moment; n ∈ [1, N], where N is the total number of experts; x″ n (t″) is the scoring vector of the n-th expert for all indexes at the t″-th moment, x″ n (t″) = [x″ n (t″, 1), x″ n (t″, 2), …, x″ n (t″, i), …, x″ n (t″, m)], x″ n (t″, 1) is the scoring vector of the n-th expert for the first index at the t″-th moment, x″ n (t″, 2) is the scoring vector of the n-th expert for the second index at the t″-th moment, x″ n (t″, i) is the scoring vector of the n-th expert for the i-th index at the t″-th moment, x″ n$(t'', m)$ is the scoring vector of the $n$-th expert for the $m$-th indicator at the $t''$-th moment.
[0160] For example, select $N$ experts with professional knowledge and experience in the fields of power sensors and network data security. To ensure diversity and representativeness, the number of experts is between 5 and 15. Independently score 12 underlying security risk indicators, with the scoring range for the indicators being 1 - 5 points. The smaller the score, the lower the risk coefficient; otherwise, the risk coefficient is higher.
[0161] Further, step 103 includes:
[0162] Step 1031: Select multiple historical time - series indicator data with a time span of $\tau$ from historical time as input data, and select the historical time - series indicator data at the next moment after the last moment in the time span $\tau$ as output data, where $\tau=[1, 2, \cdots, t''' ]$ and $t'''$ is the last moment in the time span $\tau$.
[0163] Step 1032: Use the input data as the training samples for the input layer of the long short - term memory network model with a residual connection mechanism, and use the output data as the training samples for the output layer of the long short - term memory network model with a residual connection mechanism to train the long short - term memory network model with a residual connection mechanism, and obtain the trained long short - term memory network model with a residual connection mechanism.
[0164] Step 1033: The trained long short - term memory network model with a residual connection mechanism is the prediction model.
[0165] When the traditional long short - term memory network (LSTM) model processes power sensor network time - series data, there are problems such as insufficient data feature extraction and insufficient model generalization ability. Therefore, the present invention improves the traditional LSTM algorithm, introduces a residual connection mechanism, and by reasonably setting the number of residual blocks, the number of LSTM units, and the convolutional kernel size, enhances the network's learning ability for time - series dependence relationships, and realizes the improvement of the model's feature extraction ability and generalization ability for power sensor network time - series data.
[0166] Further, step 14 includes:
[0167] Step 141: Based on the first target time - series indicator data and the predicted time - series indicator data, use the K - sigma criterion to determine whether there are abnormalities in the first target time - series indicator data.
[0168] Further, step 141 includes:
[0169] Step 1411: Calculate the mean and variance of the predicted time - series indicator data.
[0170] Specifically, the calculation formula for the mean of the predicted time series index data includes:
[0171]
[0172] The calculation formula for the variance of the predicted time series index data includes:
[0173]
[0174] In the above formula, i ∈ [1, m], where m is the total number of indicators in the security risk level; t' ∈ [1, T'], where T' is the total number of moments of the second sampling time; μ(T') is the mean of the predicted time series index data, is the predicted time series index data corresponding to the i-th indicator at the t'-th moment, and σ(T') is the variance of the predicted time series index data.
[0175] Step 1412: Determine the detection conditions using the mean, variance, and parameters of the K-sigma criterion;
[0176] Specifically, the detection conditions include:
[0177] [μ(T') - Kσ(T'), μ(T') + Kσ(T')], where μ(T') is the mean of the predicted time series index data, σ(T') is the variance of the predicted time series index data, T' is the total number of moments of the second sampling time, and K is the parameter of the K-sigma criterion;
[0178] Step 1413: If the first target time series index data meets the detection conditions, the first target time series index data is a normal value; if the first target time series index data does not meet the detection conditions, the first target time series index data is an abnormal value.
[0179] The traditional K-sigma method relies on data distribution assumptions and is sensitive to abnormal data, resulting in inaccurate detection results and a high false alarm rate. Therefore, the present invention constructs a K-sigma anomaly judgment criterion based on the LSTM prediction results to achieve flexible detection of abnormal data through flexible adjustment of the K parameter. This criterion overcomes the shortcomings of the traditional K-sigma method that relies on data distribution assumptions and is sensitive to abnormal data, improving the accuracy and robustness of anomaly detection.
[0180] The present invention conducts a timeline quantitative analysis on the security risks of power sensors and networks, constructs an improved LSTM prediction model based on the quantified time series data, and in actual tests, compares the prediction result errors between the data to be measured and the output data of the LSTM prediction model in combination with the K-sigma criterion to determine the abnormal state of the data to be measured. This method aims to improve the data security and reliability of power sensors and networks in complex environments and provide a strong guarantee for their practical applications.
[0181] To further illustrate the above-mentioned time-series data anomaly detection method for power sensors and networks, the present invention also provides a specific example, as Figure 3 shown, including the following steps:
[0182] Step 21: Quantify the time-series security risk index data:
[0183] For power sensors and networks, hierarchically analyze the security risks of the sensed data to obtain the hierarchical structure of the security risks of power sensors and networks. The hierarchical structure of the security risks is as Figure 2 shown.
[0184] According to the hierarchical structure of the security risks of power sensors and networks, through the expert scoring method, quantify the underlying security risks in the hierarchical structure according to the time scale. To ensure diversity and representativeness, 15 experts with professional knowledge and experience in the field of power sensor and network data security are selected to independently score 12 underlying security risk indicators. The scoring range of the indicators is 1-5 points. The smaller the score, the lower the risk coefficient; otherwise, the risk coefficient is higher. On this basis, summarize the expert's indicator scoring results. The time-series indicator data at time stamp t 1 is defined as Specifically, it can be expressed as:
[0185]
[0186] In the above formula, i ∈ [1, m], where m is the total number of indicators in the security risk hierarchy; is the time-series indicator data at time stamp t 1 , is the time-series indicator data corresponding to the first indicator at time stamp t 1 , is the time-series indicator data corresponding to the second indicator at time stamp t 1 , is the time-series indicator data corresponding to the 12th indicator at time stamp t 1 , is the time-series indicator data corresponding to the i-th indicator at time stamp t 1 ; x n (t 1 ) is the scoring vector of the n-th expert for all indicators at time stamp t 1 , x n (t 1 ) = [x n (t 1 , 1), x n (t 1 , 2), …, x n (t 1,12)], x n (t 1 , 1) is the scoring vector of the nth expert for the first indicator at time stamp t 1 when, and x n (t 1 , 2) is the scoring vector of the nth expert for the second indicator at time stamp t 1 when, and x n (t 1 , 12) is the scoring vector of the 12th expert for the ith indicator at time stamp t 1 .
[0187] Step 22: Establish a prediction model based on the improved LSTM:
[0188] In the LSTM model, introduce the residual connection mechanism. During the training stage of the prediction model, use the normal time-series indicator data to train the improved LSTM model so that the network model can learn the variation law of the normal data. The specific process is as Figure 4 shown.
[0189] First, quantify the normal time-series indicator data using the method in Step 21; then, determine the time window τ, and take the continuous time-series indicator data within the time span as the training data set is the time-series indicator data corresponding to the first moment in the time window τ, is the time-series indicator data corresponding to the second moment in the time window τ, is the time-series indicator data corresponding to the first moment in the time window t″′; when τ = 200, Introduce a residual connection mechanism, pre-train the improved LSTM prediction model, and output the prediction result at timestamp \(t'''+1\), \(y(t'''+1)=[y(t'',1),y(t'',2),\cdots,y(t'',12)]\), where \(y(t'',1)\) is the predicted time-series index data corresponding to the first index in time window \(t''\), \(y(t'',2)\) is the predicted time-series index data corresponding to the second index in time window \(t''\), and \(y(t'',12)\) is the predicted time-series index data corresponding to the 12th index in time window \(t''\). Among them, reasonably set the number of residual blocks, the number of LSTM units, and the convolutional kernel size to improve the network's learning ability for the time-series dependence relationship. Then, compare the prediction result \(y(t'''+1)\) with the data of the index to be measured at timestamp \(t'''+1\), \(z(t'''+1)=[z(t'',1),z(t'',2),\cdots,z(t'',12)]\) (\(z(t'',1)\) is the time-series index data to be measured corresponding to the first index in time window \(t''\), \(z(t'',2)\) is the time-series index data to be measured corresponding to the second index in time window \(t''\), and \(z(t'',12)\) is the time-series index data to be measured corresponding to the 12th index in time window \(t''\)) for anomaly comparison. If the data of the index to be measured is a normal value, use the data to be measured as the latest training data to construct a new training data set with a time window of \(\tau\). It can be understood that when the time window \(\tau = 200\), if the data of the index to be measured is an abnormal value, use the prediction result as the latest training data to construct a training data set when the time window \(\tau = 200\), Finally, re-train the improved LSTM prediction model and output the prediction result at timestamp \(t'''+2\). Repeat the above steps to continuously perform anomaly judgment on the data to be measured and update the training of the prediction model.
[0190] Step 23: Use the K-sigma criterion to judge the state anomaly:
[0191] Through pre-training, the prediction model based on the improved LSTM covers the variation law of normal time-series index data along the time dimension. Therefore, if the data of the index to be measured at timestamp \(t\) 2 +1, \(z(t\) 2 +1), is normal data, its characteristics should be very close to the prediction result of the prediction model; but if the data \(z(t\) 2 +1) is abnormal, it will deviate from the prediction result of the prediction model. Use the K-sigma criterion to judge the anomaly state of the data of the index to be measured \(z(t\) 2 +1). Calculate the mean and variance of the data in the training data set at timestamp \(t\) 2 as follows:
[0192] The timestamp is t 2 The calculation formula for the average value of the data in the training data set includes:
[0193]
[0194] The timestamp is t 2 The calculation formula for the variance of the data in the training data set is:
[0195]
[0196] In the above formula, i∈[1,m], m is the total number of indicators in the security risk hierarchy; a∈[1,t 2 ];μ(t 2 ) is the timestamp t 2 is the average value of the data in the training data set, σ(t 2 ) is the timestamp t 2 is the average value of the data in the training data set, τ is the time window, is the time series indicator data corresponding to the ith indicator at the ath moment;
[0197] If μ(t 2 )-Kσ(t 2 )≤z(t 2 +1,i)≤μ(t 2 )+Kσ(t 2 ), then the index data to be measured z(t 2 +1) is a normal value; otherwise, the index data z(t 2 +1) is an outlier; K represents the K-sigma criterion parameter,
[0198] Specifically, according to the hierarchical structure of power sensors and network security risks, the index value of normal time series data is defined to be between 1 and 2, and the index value of abnormal time series data is defined to be between 2 and 5. 200 sets of normal time series index data are randomly generated as pre-training data and The prediction model based on the improved LSTM is trained, and the prediction result y(201) with the timestamp of 201 is output. Abnormal time series indicator data and normal time series indicator data are randomly generated, and the proposed method is cyclically tested and trained. The test results are shown below.
[0199] Table 1 Results of time series data anomaly detection methods
[0200] Parameter K Accuracy Precision Recall F1 Score 0.12 0.685 0.813 0.520 0.635 0.18 0.687 0.872 0.572 0.612 0.24 0.611 0.994 0.261 0.413 0.30 0.560 1.0 0.162 0.279 0.36 0.524 1.0 0.093 0.171
[0201] As can be seen from Table 1, the overall accuracy of a method for detecting abnormal time-series data for power sensors and networks provided by the present invention achieves the best performance at the parameter K = 0.18. The recall rate and F1 score decrease as the parameter K increases and finally approach 0, indicating that the parameter K is too high at this time, resulting in the model being unable to identify abnormal data. From the results of judging abnormal time-series data of power sensors and networks, it is more appropriate to take the value of the parameter K around 0.18, which effectively reduces the misjudgment of the normal area and the abnormal area is relatively clear.
[0202] The present invention also provides a method for detecting abnormal time-series data for power sensors and networks. Through hierarchical analysis and time-series quantization, it can more accurately identify security risks in power sensors and networks; based on the K-sigma abnormal judgment criterion of the LSTM prediction result, it can effectively reduce the false alarm rate and missed alarm rate and improve the accuracy and precision of abnormal detection.
[0203] The present invention improves the LSTM algorithm by introducing residual connections, which can better capture the complex features of time-series data of power sensor networks, improve the generalization ability of the model, and avoid overfitting.
[0204] Based on the K-sigma abnormal judgment criterion of the LSTM prediction result, through flexible adjustment of the K parameter, flexible detection of abnormal data can be realized according to different application scenarios and requirements, improving the applicability and practicability of the method.
[0205] The present invention provides a planning guide for data security detection in future power sensors and networks, which helps to promote the safe development of power sensors and networks.
[0206] Embodiment 2
[0207] The present invention also provides a device for detecting abnormal time-series data for power sensors and networks, as Figure 5 shown, including:
[0208] An acquisition unit for acquiring security risk data of power sensors and networks at the first sampling time and the second sampling time based on a preset hierarchical structure of security risks of power sensors and networks;
[0209] A quantization unit for respectively performing time-scale quantization on the security risk data at the first sampling time and the second sampling time to obtain first target time-series index data and second target time-series index data;
[0210] A prediction unit for taking the second target time-series index data as the input of a pre-established prediction model and outputting predicted time-series index data;
[0211] A detection unit for performing anomaly detection on the first target time-series metric data by using the first target time-series metric data and the predicted time-series metric data;
[0212] Wherein, the prediction model is constructed by using historical security risk data, and the second sampling time is earlier than the first sampling time.
[0213] Furthermore, the preset hierarchical structure of security risks of power sensors and networks includes: various security risks and their corresponding metrics;
[0214] The various security risks include at least the following four types: perception layer risks, network layer risks, edge computing layer risks, and other risks;
[0215] The metrics of perception layer risks include: electromagnetic tampering, laser tampering, acoustic tampering, and service life;
[0216] The metrics of network layer risks include: data theft and node impersonation;
[0217] The metrics of edge computing layer risks include: data leakage, storage tampering, and denial of service;
[0218] The metrics of other risks include: environmental threats, natural disasters, and management risks.
[0219] Furthermore, the quantization unit includes:
[0220] A first acquisition module for scoring each metric in each security risk by using the expert scoring method based on the security risk data at the first sampling time, to obtain the metric scores of each metric at the first sampling time;
[0221] A first quantization module for quantizing the metric scores of each metric at the first sampling time on a time scale, to obtain the first target time-series metric data.
[0222] Furthermore, the quantization unit further includes:
[0223] A second acquisition module for scoring each metric in each security risk by using the expert scoring method based on the security risk data at the second sampling time, to obtain the metric scores of each metric at the second sampling time;
[0224] A second quantization module for quantizing the metric scores of each metric at the second sampling time on a time scale, to obtain the second target time-series metric data.
[0225] Furthermore, it further includes: a building unit for building a prediction model; the building unit includes:
[0226] The acquisition module is used to acquire the historical security risk data of the power sensor and the network based on the preset hierarchical structure of the security risks of the power sensor and the network in the historical time;
[0227] The third quantization module is used to perform time-scale quantization on the historical security risk data to obtain historical time-series index data;
[0228] The training module is used to train a long short-term memory network model with a residual connection mechanism using the historical time-series index data to obtain a prediction model.
[0229] Furthermore, the third quantization module is specifically used for:
[0230] Based on the historical security risk data, use the expert scoring method to score each index in each security risk to obtain the index scores of each historical index;
[0231] Perform time-scale quantization on the index scores of each historical index to obtain historical time-series index data.
[0232] Furthermore, the training module is specifically used for:
[0233] Select multiple historical time-series index data with a time span of τ from the historical time as input data, and select the historical time-series index data at the next moment after the last moment in the time span τ as output data, where τ = [1, 2,..., t″′], and t″′ is the last moment in the time span τ;
[0234] Use the input data as the training samples of the input layer of the long short-term memory network model with a residual connection mechanism, and use the output data as the training samples of the output layer of the long short-term memory network model with a residual connection mechanism to train the long short-term memory network model with a residual connection mechanism to obtain the trained long short-term memory network model with a residual connection mechanism;
[0235] The trained long short-term memory network model with a residual connection mechanism is the prediction model.
[0236] Furthermore, the detection unit includes:
[0237] The judgment module is used to judge whether the first target time-series index data is abnormal based on the first target time-series index data and the predicted time-series index data using the K-sigma criterion.
[0238] Furthermore, the judgment module is specifically used for:
[0239] Calculate the average value and variance of the predicted time-series index data;
[0240] Determine the detection conditions using the parameters of the average value, variance, and K-sigma criterion;
[0241] If the first target time series index data meets the detection conditions, the first target time series index data is normal; if the first target time series index data does not meet the detection conditions, the first target time series index data is an outlier.
[0242] Further, the detection conditions include:
[0243] [μ(T′)-Kσ(T′),μ(T′)+Kσ(T′)], where μ(T′) is the average value of the predicted time series index data, σ(T′) is the variance of the predicted time series index data, T′ is the total time of the second sampling time, and K is the parameter of the K-sigma criterion.
[0244] Further, the calculation formula of the first target time series index data includes:
[0245]
[0246] Among them, the calculation formula of the first target time series index data corresponding to the i-th index at the t-th moment includes:
[0247]
[0248] In the above formula, i ∈ [1, m], m is the total number of indicators in the safety risk level; t ∈ [1, T], T is the total time of the first sampling time; is the first target time series index data at the t-th moment, is the first target time series index data corresponding to the 1st index at the t-th moment, is the first target time series index data corresponding to the 2nd index at the t-th moment, is the first target time series index data corresponding to the i-th index at the t-th moment, is the first target time series index data corresponding to the m-th index at the t-th moment; n ∈ [1, N], N is the total number of experts; x n (t) is the scoring vector of the n-th expert for all indicators at the t-th moment, x n (t) = [x n (t, 1), x n (t, 2), …, x n (t, i), …, x n (t, m)], x n (t, 1) is the scoring vector of the n-th expert for the 1st index at the t-th moment, x n (t, 2) is the scoring vector of the n-th expert for the 2nd index at the t-th moment, x n(t, i) is the scoring vector of the nth expert for the ith indicator at the tth moment, x n (t, m) is the scoring vector of the nth expert for the mth indicator at the tth moment.
[0249] Furthermore, the calculation formula for the second target time-series indicator data includes:
[0250]
[0251] Among them, the calculation formula for the second target time-series indicator data corresponding to the ith indicator at the t'th moment includes:
[0252]
[0253] In the above formula, i ∈ [1, m], where m is the total number of indicators in the safety risk level; t' ∈ [1, T'], where T' is the total number of moments of the second sampling time; is the second target time-series indicator data at the t'th moment, is the second target time-series indicator data corresponding to the 1st indicator at the t'th moment, is the time-series indicator data corresponding to the 2nd indicator at the t'th moment, is the second target time-series indicator data corresponding to the ith indicator at the t'th moment, is the second target time-series indicator data corresponding to the mth indicator at the t'th moment; n ∈ [1, N], where N is the total number of experts; x' n (t') is the scoring vector of the nth expert for all indicators at the t'th moment, x' n (t') = [x' n (t', 1), x' n (t', 2), …, x' n (t', i), …, x' n (t', m)], x' n (t', 1) is the scoring vector of the nth expert for the 1st indicator at the t'th moment, x' n (t', 2) is the scoring vector of the nth expert for the 2nd indicator at the t'th moment, x' n (t', i) is the scoring vector of the nth expert for the ith indicator at the t'th moment, x' n (t', m) is the scoring vector of the nth expert for the mth indicator at the t'th moment.
[0254] Furthermore, the calculation formula for the historical time-series indicator data includes:
[0255]
[0256] Among them, the calculation formula for the historical time-series index data corresponding to the $i$-th index at the $t''$-th moment includes:
[0257]
[0258] In the above formula, $i\in[1,m]$, where $m$ is the total number of indicators in the safety risk level; $t''\in[1,T'']$, where $T''$ is the total number of moments in historical time; is the historical time-series index data at the $t''$-th moment, is the historical time-series index data corresponding to the first index at the $t''$-th moment, is the historical time-series index data corresponding to the second index at the $t''$-th moment, is the historical time-series index data corresponding to the $i$-th index at the $t''$-th moment, is the historical time-series index data corresponding to the $m$-th index at the $t''$-th moment; $n\in[1,N]$, where $N$ is the total number of experts; $x''$ n (t'') is the scoring vector of the $n$-th expert for all indicators at the $t''$-th moment, $x''$ n (t'') = [x'' n (t'',1), x'' n (t'',2), …, x'' n (t'',i), …, x'' n (t'',m)], x'' n (t'',1) is the scoring vector of the $n$-th expert for the first indicator at the $t''$-th moment, $x''$ n (t'',2) is the scoring vector of the $n$-th expert for the second indicator at the $t''$-th moment, $x''$ n (t'',i) is the scoring vector of the $n$-th expert for the $i$-th indicator at the $t''$-th moment, $x''$ n (t'',m) is the scoring vector of the $n$-th expert for the $m$-th indicator at the $t''$-th moment.
[0259] Furthermore, the calculation formula for the average value of the predicted time-series index data includes:
[0260]
[0261] The calculation formula for the variance of the predicted time-series index data includes:
[0262]
[0263] In the above formula, $i\in[1,m]$, where $m$ is the total number of indicators in the safety risk level; $t'\in[1,T']$, where $T'$ is the total number of moments of the second sampling time; $\mu(T')$ is the average value of the predicted time-series index data, Let \(y_{i}(t')\) be the predicted time - series index data corresponding to the \(i\) - th index at time \(t'\), and \(\sigma(T')\) be the variance of the predicted time - series index data.
[0264] It can be understood that the above - provided device embodiments correspond to the above - mentioned method embodiments, and the corresponding specific content can be referred to each other, and will not be elaborated here.
[0265] It can be understood that the same or similar parts in the above embodiments can be referred to each other, and the content not detailed in some embodiments can be referred to the same or similar content in other embodiments.
[0266] Embodiment III
[0267] As Figure 6 shown, the present invention also provides an electronic device, which may be a computer device, a single - chip microcomputer device, a smart mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, the processor, and the transceiver component are connected through a bus; the memory can be used to store an execution program, and the exemplary execution program may include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, and the data can be called and / or modified when the instructions are executed.
[0268] The processor may be a Central Processing Unit (CPU), or may also be other general - purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field - Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the storage medium to implement the corresponding method flow or corresponding function, so as to implement the steps of a time - series data anomaly detection method for power sensors and networks in the above embodiments.
[0269] Embodiment IV
[0270] Based on the same inventive concept, the present invention also provides a readable storage medium, specifically an electronic device-readable storage medium (Memory). The electronic device-readable storage medium is a memory device in the electronic device and is used to store programs and data. It can be understood that the storage medium here can include both the built-in storage medium in the electronic device and, of course, the extended storage medium supported by the electronic device. The storage medium provides a storage space, and this storage space stores the operating system of the terminal. And, in this storage space, there is also stored one or more instructions suitable for being loaded and executed by the processor. These instructions can be one or more execution programs (including program codes). It should be noted that the storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. By the processor loading and executing one or more instructions stored in the storage medium, the steps of a method for detecting abnormal timing data for a power sensor and network in the above embodiments can be implemented.
[0271] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0272] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the function specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0273] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and this instruction device implements the function in Figure 1 one flow or multiple flows and / or blocks Figure 1The functions specified in one or more boxes.
[0274] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in one Figure 1 one process or more processes and / or boxes Figure 1 step of the functions specified in one box or more boxes.
[0275] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present invention. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A time series data anomaly detection method for power sensors and networks, characterized in that: include: Based on the preset hierarchical structure of security risks of power sensors and networks, security risk data of power sensors and networks at a first sampling time and a second sampling time are collected; Perform time scale quantization on the security risk data of the first sampling time and the second sampling time respectively to obtain first target time series indicator data and second target time series indicator data; Taking the second target time series indicator data as input of a pre-established prediction model, outputting predicted time series indicator data; Using the first target time series indicator data and the predicted time series indicator data, performing anomaly detection on the first target time series indicator data; The prediction model is constructed using historical safety risk data, and the second sampling time is earlier than the first sampling time.
2. The method according to claim 1, characterized in that The preset safety risk hierarchical structure of the power sensor and network includes: multiple safety risks and their corresponding indicators; The multiple security risks include at least the following four: perception layer risk, network layer risk, edge computing layer risk and other risks; The indicators of the perception layer risk include: electromagnetic tampering, laser tampering, sonic tampering and service life; The indicators of network layer risks include: data theft and node impersonation; The indicators of the edge computing layer risks include: data leakage, storage tampering and denial of service; Indicators of other risks include: environmental threats, natural disasters and management risks.
3. The method according to claim 2, characterized in that The time scale quantification of the safety risk data of the first sampling time and the second sampling time respectively includes: Based on the security risk data of the first sampling time, scoring each indicator in each security risk by using an expert scoring method to obtain an indicator score of each indicator at the first sampling time; The indicator scores of each indicator at the first sampling time are quantified on a time scale to obtain the first target time series indicator data.
4. The method according to claim 2, characterized in that: The time scale quantification of the safety risk data of the first sampling time and the second sampling time respectively further includes: Based on the security risk data of the second sampling time, scoring each indicator in each security risk by using an expert scoring method to obtain an indicator score of each indicator at the second sampling time; The indicator score of each indicator at the second sampling time is quantified on a time scale to obtain the second target time series indicator data.
5. The method according to claim 2, characterized in that: The process of establishing the prediction model includes: Based on the preset hierarchical structure of security risks of power sensors and networks, collect historical security risk data of power sensors and networks in historical time; Quantify the time scale of historical security risk data to obtain historical time series indicator data; The historical time series indicator data is used to train a long short-term memory network model that introduces a residual connection mechanism to obtain the prediction model.
6. The method according to claim 5, characterized in that The historical security risk data is quantified on a time scale to obtain historical time series indicator data, including: Based on the historical security risk data, an expert scoring method is used to score each indicator in each security risk to obtain an indicator score of each historical indicator; The indicator scores of the historical indicators are quantified on a time scale to obtain the historical time series indicator data.
7. The method according to claim 5, characterized in that The method of using the historical time series indicator data to train the long short-term memory network model that introduces the residual connection mechanism to obtain the prediction model includes: From the historical time, select multiple historical time series indicator data with a time span of τ as input data, and select the historical time series indicator data of the next moment of the last moment in the time span τ as output data, where τ = [1,, 2, ..., t"'], t"' is the last moment in the time span τ; Taking the input data as input layer training samples of the long short-term memory network model introducing the residual connection mechanism, taking the output data as output layer training samples of the long short-term memory network model introducing the residual connection mechanism, training the long short-term memory network model introducing the residual connection mechanism, and obtaining the trained long short-term memory network model introducing the residual connection mechanism; The trained long short-term memory network model that introduces a residual connection mechanism is the prediction model.
8. The method according to claim 1, characterized in that The using the first target time series indicator data and the predicted time series indicator data to perform anomaly detection on the first target time series indicator data includes: Based on the first target time series indicator data and the predicted time series indicator data, a K-sigma criterion is used to determine whether the first target time series indicator data is abnormal.
9. The method according to claim 8, characterized in that The determining, based on the first target time series indicator data and the predicted time series indicator data, whether the first target time series indicator data is abnormal by using a K-sigma criterion includes: Calculating the mean and variance of the predicted time series indicator data; Determining detection conditions using the mean value, the variance, and parameters of the K-sigma criterion; If the first target timing indicator data meets the detection condition, the first target timing indicator data is a normal value; if the first target timing indicator data does not meet the detection condition, the first target timing indicator data is an abnormal value.
10. The method according to claim 9, characterized in that The detection conditions include: [μ(T′)-Kσ(T′),μ(T′)+Kσ(T′)], where μ(T′) is the average value of the predicted time series indicator data, σ(T′) is the variance of the predicted time series indicator data, T′ is the total moment of the second sampling time, and K is the parameter of the K-sigma criterion.
11. The method according to claim 3, characterized in that The calculation formula of the first target time series indicator data includes: Among them, the calculation formula of the first target time series indicator data corresponding to the i-th indicator at the t-th time includes: In the above formula, i∈[1,m], m is the total number of indicators in the security risk hierarchy; t∈[1,T], T is the total time of the first sampling time; is the first target time series indicator data at time t, is the first target time series indicator data corresponding to the first indicator at the tth time, is the first target time series indicator data corresponding to the second indicator at time t, is the first target time series indicator data corresponding to the i-th indicator at the t-th time, is the first target time series indicator data corresponding to the mth indicator at the tth time; n∈[1,N], N is the total number of experts; x n (t) is the scoring vector of all indicators by the nth expert at the tth moment, x n (t) = [x n (t,1),x n (t,2),…,x n (t,i),…,x n (t,m)],x n (t,1) is the score vector of the nth expert on the first indicator at the tth time, x n (t,2) is the score vector of the nth expert on the second indicator at the tth time, x n (t,i) is the score vector of the nth expert on the i-th indicator at the t-th time, x n (t,m) is the score vector of the nth expert on the mth indicator at the tth time.
12. The method according to claim 9, characterized in that The calculation formula for the average value of the predicted time series indicator data includes: The calculation formula for the variance of the predicted time series indicator data includes: In the above formula, i∈[1,m], m is the total number of indicators in the security risk hierarchy; t′∈[1,T′], T′ is the total time of the second sampling time; μ(T′) is the average value of the predicted time series indicator data, is the predicted time series indicator data corresponding to the i-th indicator at time t′, and σ(T′) is the variance of the predicted time series indicator data.
13. A time series data anomaly detection device for power sensors and networks, characterized in that: include: A collection unit, used to collect security risk data of the power sensor and the network at a first sampling time and a second sampling time based on a preset security risk hierarchical structure of the power sensor and the network; A quantization unit, configured to perform time-scale quantization on the security risk data of the first sampling time and the second sampling time, respectively, to obtain first target time series indicator data and second target time series indicator data; A prediction unit, configured to use the second target time series indicator data as an input of a pre-established prediction model and output predicted time series indicator data; a detection unit, configured to perform anomaly detection on the first target time series indicator data by using the first target time series indicator data and the predicted time series indicator data; The prediction model is constructed using historical safety risk data, and the second sampling time is earlier than the first sampling time.
14. The device according to claim 13, characterized in that The preset safety risk hierarchical structure of the power sensor and network includes: multiple safety risks and their corresponding indicators; The multiple security risks include at least the following four: perception layer risk, network layer risk, edge computing layer risk and other risks; The indicators of the perception layer risk include: electromagnetic tampering, laser tampering, sonic tampering and service life; The indicators of network layer risks include: data theft and node impersonation; The indicators of the edge computing layer risks include: data leakage, storage tampering and denial of service; Indicators of other risks include: environmental threats, natural disasters and management risks.
15. The device according to claim 14, characterized in that The quantization unit comprises: A first acquisition module is used to score each indicator in each security risk by using an expert scoring method based on the security risk data of the first sampling time, so as to obtain an indicator score of each indicator at the first sampling time; The first quantization module is used to quantify the indicator score of each indicator at the first sampling time on a time scale to obtain the first target time series indicator data.
16. The device according to claim 14, characterized in that The quantization unit further includes: A second acquisition module is used to score each indicator in each security risk by using an expert scoring method based on the security risk data of the second sampling time, so as to obtain an indicator score of each indicator at the second sampling time; The second quantization module is used to quantify the indicator score of each indicator at the second sampling time on a time scale to obtain the second target time series indicator data.
17. The device according to claim 14, characterized in that The method further comprises: an establishing unit, which is used to establish the prediction model; the establishing unit comprises: A collection module, for collecting historical security risk data of power sensors and networks at historical times based on a preset hierarchical structure of security risks of power sensors and networks; The third quantification module is used to quantify the time scale of historical security risk data to obtain historical time series indicator data; The training module is used to train the long short-term memory network model that introduces the residual connection mechanism using the historical time series indicator data to obtain the prediction model.
18. The device according to claim 17, characterized in that The third quantization module is specifically used for: Based on the historical security risk data, an expert scoring method is used to score each indicator in each security risk to obtain an indicator score of each historical indicator; The indicator scores of the historical indicators are quantified on a time scale to obtain the historical time series indicator data.
19. The device according to claim 17, characterized in that The training module is specifically used for: From the historical time, select multiple historical time series indicator data with a time span of τ as input data, and select the historical time series indicator data of the next moment of the last moment in the time span τ as output data, where τ = [1,, 2, ..., t"'], t"' is the last moment in the time span τ; Taking the input data as input layer training samples of the long short-term memory network model introducing the residual connection mechanism, taking the output data as output layer training samples of the long short-term memory network model introducing the residual connection mechanism, training the long short-term memory network model introducing the residual connection mechanism, and obtaining the trained long short-term memory network model introducing the residual connection mechanism; The trained long short-term memory network model that introduces a residual connection mechanism is the prediction model.
20. The device according to claim 13, characterized in that The detection unit comprises: A judgment module is used to judge whether the first target time series indicator data is abnormal based on the first target time series indicator data and the predicted time series indicator data by using the K-sigma criterion.
21. The device according to claim 20, characterized in that The judgment module is specifically used for: Calculating the mean and variance of the predicted time series indicator data; Determining detection conditions using the mean value, the variance, and parameters of the K-sigma criterion; If the first target timing indicator data meets the detection condition, the first target timing indicator data is a normal value; If the first target timing indicator data does not meet the detection condition, the first target timing indicator data is an abnormal value.
22. The device according to claim 21, characterized in that The detection conditions include: [μ(T′)-Kσ(T′),μ(T′)+Kσ(T′)], where μ(T′) is the average value of the predicted time series indicator data, σ(T′) is the variance of the predicted time series indicator data, T′ is the total moment of the second sampling time, and K is the parameter of the K-sigma criterion.
23. The device according to claim 15, characterized in that The calculation formula of the first target time series indicator data includes: Among them, the calculation formula of the first target time series indicator data corresponding to the i-th indicator at the t-th time includes: In the above formula, i∈[1,m], m is the total number of indicators in the security risk hierarchy; t∈[1,T], T is the total time of the first sampling time; is the first target time series indicator data at time t, is the first target time series indicator data corresponding to the first indicator at the tth time, is the first target time series indicator data corresponding to the second indicator at time t, is the first target time series indicator data corresponding to the i-th indicator at the t-th time, is the first target time series indicator data corresponding to the mth indicator at the tth time; n∈[1,N], N is the total number of experts; x n (t) is the scoring vector of all indicators by the nth expert at the tth moment, x n (t) = [x n (t,1),x n (t,2),…,x n (t,i),…,x n (t,m)],x n (t,1) is the score vector of the nth expert on the first indicator at the tth time, x n (t,2) is the score vector of the nth expert on the second indicator at the tth time, x n (t,i) is the score vector of the nth expert on the i-th indicator at the t-th time, x n (t,m) is the score vector of the nth expert on the mth indicator at the tth time.
24. The device according to claim 21, characterized in that The calculation formula for the average value of the predicted time series indicator data includes: The calculation formula for the variance of the predicted time series indicator data includes: In the above formula, i∈[1,m], m is the total number of indicators in the security risk hierarchy; t′∈[1,T′], T′ is the total time of the second sampling time; μ(T′) is the average value of the predicted time series indicator data, is the predicted time series indicator data corresponding to the i-th indicator at time t′, and σ(T′) is the variance of the predicted time series indicator data.
25. An electronic device, characterized in that: include: at least one processor and memory; The memory and the processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the time series data anomaly detection method for power sensors and networks as described in any one of claims 1 to 12 is implemented.
26. A readable storage medium, characterized in that: An execution program is stored thereon, and when the execution program is executed, the time series data anomaly detection method for power sensors and networks as described in any one of claims 1 to 12 is implemented.