Abnormal event detection method in cloud edge fusion environment

By building a cloud-edge fusion environment in the Internet of Things system, screening the main attributes and building the optimal data collection path, the problems of abnormal event detection delay, energy consumption and accuracy in the Internet of Things system are solved, and the abnormal event detection effect with low latency, low energy consumption and high accuracy is achieved.

CN120075220APending Publication Date: 2025-05-30HEBEI UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510126294.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In IoT systems, it is difficult for the prior art to realize abnormal event detection with low latency, low energy consumption and high accuracy, especially in the network congestion and delay problems caused by massive data processing and long-distance transmission.

Method used

By building a cloud-edge fusion environment, the main attributes closely related to abnormal events are screened out using the CRITIC method, the optimal data collection path is constructed, reliability constraints and data fusion are performed, preliminary abnormal event detection is completed, and exception information is transmitted to the cloud for decision-making.

Benefits of technology

It realizes abnormal event detection with low latency, low energy consumption and high accuracy, reduces the delay and energy consumption of data collection and transmission, improves detection accuracy, and is suitable for multi-scene abnormal event detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075220A_ABST
    Figure CN120075220A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal event detection method in a cloud edge fusion environment. According to the method, the CRITIC method is used for screening out main attributes closely related to abnormal event occurrence, and time and energy consumption of unrelated attribute collection is avoided; then reliability constraint is carried out on data collected by the main attribute device, and data interference generated by instability of the device due to physical or human factors is eliminated; constructing an optimal data collection path for the reliable main attribute equipment by utilizing a minimum spanning tree principle, eliminating redundant data and enabling the data transmission cost to be minimum; and finally, carrying out weighted fusion on an edge layer, completing preliminary abnormal event detection, and carrying out cloud layer decision making on an abnormal condition. The method has the advantages of low time delay, low energy consumption and high accuracy, redundant and unreliable information is filtered, and data collection and transmission integration time delay is reduced, so that the time and energy consumption of overall abnormal event detection are reduced, the detection accuracy is improved, and the multi-scene abnormal event detection requirement is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of the Internet of Things, and specifically relates to a method for detecting abnormal events in a cloud-edge fusion environment. Background Art

[0002] With the advent of the 5G and Internet of Things eras, the generation of massive data has had a great impact on existing networks. Internet of Things devices are widely used in various fields of production and life, bringing severe challenges to device data management and security management while monitoring and collecting useful information. The Internet of Things system is widely used in environmental monitoring due to its low cost and easy deployment characteristics, such as forest fire monitoring, ocean climate monitoring, etc. It is precisely because of the complex variety, large quantity, and wide distribution of Internet of Things devices that it brings many challenges to network operation and maintenance, computing storage, etc. The proposal of cloud computing has alleviated the network congestion problem and the current situation of tight computing and storage resources to a certain extent. It provides wide and on-demand access to virtual shared configurable computing and storage resources and is an excellent platform for processing massive data and computing tasks. Nevertheless, cloud computing also has certain limitations in the field of the Internet of Things. The centralized processing of a large amount of data may lead to serious network congestion, and long-distance transmission will also cause latency problems. The academic and industrial communities have proposed to migrate the cloud platform to the network edge, that is, edge computing, and place simple processes that require real-time computing and analysis closer to the terminal devices to ensure the real-time nature of data processing. Therefore, edge computing technology has been quickly incorporated into large-scale Internet of Things systems.

[0003] Many domestic and foreign scholars have conducted a large amount of research on edge computing in the field of anomaly detection. To ensure the normal operation of industrial equipment, a large number of sensors are usually deployed for the equipment to monitor its operating status in real time, and the abnormal state of the equipment is inferred by detecting the abnormal patterns of sensor data. However, transmitting all the sensed data will cause a large amount of time and energy consumption. This algorithm detects and comprehensively analyzes sensors with location correlation, but all the data at the sensor end needs to be uploaded to the base station end instead of selectively uploading to the base station, and a large amount of energy is consumed in this process. And if the reliability of the main attribute data collection is not considered, when there are situations such as equipment failures and noise effects, the detection accuracy will be very low. Therefore, there is an urgent need for a method for detecting abnormal events with low latency, low energy consumption, and high accuracy. Summary of the Invention

[0004] Aiming at the deficiencies of the prior art, the technical problem to be solved by the present invention is to provide a method for detecting abnormal events in a cloud-edge fusion environment.

[0005] The technical solution for the present invention to solve the above technical problem is to provide a method for detecting abnormal events in a cloud-edge fusion environment, which is characterized in that the method includes the following steps:

[0006] Step 1: Build a cloud-edge integration environment;

[0007] The cloud-edge integration environment includes a cloud layer, an edge layer, and a device layer; the device layers, the edge layers, the device layer and the edge layer, and the edge layer and the cloud layer are all communicatively connected; the device layer is used to collect the attribute information of relevant events and upload the collected attribute information to the edge layer; the edge layer is responsible for collecting the attribute information of a certain event in each sub-region of the device layer and calculating the fusion value of the main attributes of relevant events; the cloud layer is used to identify the main attributes of events and further process the abnormal results of the edge layer;

[0008] Step 2: Screen out m main attributes that play a decisive role in the event:

[0009] Step 3: Generate the minimum spanning tree of each device in a certain type of main attribute, and then select the minimum spanning tree with the smallest weight sum from all the generated minimum spanning trees as the optimal coverage path of the main attribute device. The main attribute device is used to collect the main attribute data; according to the optimal coverage path of the main attribute device constructed, obtain the optimal collection path of the main attribute data;

[0010] Step 4: Collect the main attribute data through the optimal collection path of the main attribute data obtained in Step 3, and then transmit the collected main attribute data to the edge layer for weighted fusion to complete the preliminary abnormal event detection and judge whether an abnormality occurs; if an abnormality occurs, then transmit the abnormal information to the cloud layer for decision-making.

[0011] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0012] (1) The present invention uses the CRITIC method to screen out the main attributes closely related to the occurrence of abnormal events, avoiding the time and energy consumption of collecting irrelevant attributes; then, the data collected by the main attribute device is subjected to reliability constraints to exclude data interference caused by physical or human factors that lead to device instability; furthermore, the reliable main attribute device uses the minimum spanning tree principle to construct the optimal data collection path, excluding redundant data and minimizing the data transmission cost; finally, weighted fusion is performed in the edge layer to complete the preliminary abnormal event detection, and for abnormal situations, it is then handed over to the cloud layer for decision-making.

[0013] (2) The present invention has the advantages of low latency, low energy consumption, and high accuracy, filtering out redundant and unreliable information, reducing the integration latency of data collection and transmission, thereby reducing the time and energy consumption of overall abnormal event detection, and improving the detection accuracy, meeting the requirements of multi-scenario abnormal event detection.

[0014] (3) The present invention uses the CRITIC method to screen out multiple main attributes that play a decisive role in events. When the device layer collects the attributes of an event, it only needs to collect the main attributes, avoiding the time and energy consumption of collecting and uploading all attributes, improving the accuracy of detecting abnormal events with multiple attributes in the Internet of Things environment, and at the same time making up for the deficiency of low accuracy when determining abnormalities through a single attribute.

[0015] (4) The present invention uses a Gaussian model to constrain the reliability of data, avoiding data distortion caused by unstable devices, natural wear, etc., and improving the reliability of the collected data.

[0016] (5) The present invention uses a minimum spanning tree to complete the coverage of main attribute devices, selects the optimal main attribute data integration path, reduces data redundancy, reduces the delay energy consumption of data transmission, and thus reduces the overall detection delay.

[0017] (6) The present invention fuses all main attribute information at the edge layer and determines whether an abnormal event occurs through data fusion. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is an architecture diagram of the cloud-edge fusion environment of the present invention;

[0019] Figure 2 is a schematic diagram of the connection of main attribute devices in Embodiment 1 of the present invention;

[0020] Figure 3 is a main attribute collection path diagram generated starting from the slave device (1, 3) in Embodiment 1 of the present invention;

[0021] Figure 4 is a main attribute collection path diagram generated starting from the slave device (1, 2) in Embodiment 1 of the present invention;

[0022] Figure 5 is a main attribute collection path diagram generated starting from the slave device (1, 2) in Embodiment 1 of the present invention;

[0023] Figure 6 is a change curve diagram of the detection time and the number of Internet of Things devices of the method of the present invention and the existing method in Embodiment 1;

[0024] Figure 7 is a change curve diagram of the energy consumption and the number of Internet of Things devices of the method of the present invention and the existing method in Embodiment 1;

[0025] Figure 8 is a change curve diagram of the accuracy of abnormal detection and the number of Internet of Things devices of the method of the present invention and the existing method in Embodiment 1. DETAILED DESCRIPTION OF THE INVENTION

[0026] Specific embodiments of the present invention are given below. The specific embodiments are only used to further illustrate the present invention in detail and do not limit the protection scope of the present invention.

[0027] The present invention provides an abnormal event detection method in a cloud-edge fusion environment (hereinafter referred to as the method), which is characterized in that the method includes the following steps:

[0028] Step 1: Build a cloud-edge fusion environment;

[0029] The cloud-edge fusion environment includes a cloud layer, an edge layer (edge server layer), and a device layer (Internet of Things device layer); the device layers, the edge layers, the device layer and the edge layer, and the edge layer and the cloud layer are all communicatively connected; the device layer is used to collect the attribute information of relevant events and upload the collected attribute information to the edge layer; the edge layer is responsible for collecting the attribute information of a certain event in each sub-region of the device layer and calculating the fusion value of the main attributes of the relevant events; the cloud layer is used to identify the main attributes of the events and further process the abnormal results of the edge layer.

[0030] Preferably, in step 1, the device layers are communicatively connected through a wireless network, the device layer and the edge layer are communicatively connected through a wireless network, the edge layers are communicatively connected through a wired network, and the edge layer and the cloud layer are communicatively connected through a wired network.

[0031] Preferably, in step 1, the device layer is the bottom layer of the system architecture, including multiple detection devices, each detection device is responsible for sensing different attributes in the environment, used to collect the attribute information of relevant events, and upload the collected attribute information to the edge layer; the edge layer has functions such as computing, communication, and providing resources, and also has a large amount of memory; the edge layer includes multiple edge devices, each edge device is an edge node, and each edge node is responsible for managing a sub-region of the device layer and collecting the attribute information of a certain event in a sub-region. The attribute information includes the device for sensing the attribute, time, attribute type, attribute sensing value, etc.; the cloud layer has huge computing and storage capabilities, used to identify the main attributes of the events and further process the abnormal results of the edge layer.

[0032] Step 2: Screen out m main attributes that play a decisive role in the event:

[0033] Preferably, the specific steps of step 2 are as follows:

[0034] S21: Establish a sample index value matrix X for the initial attribute data in the management area, as shown in formula (1):

[0035]

[0036] In formula (1), x ij represents the jth sample index value of the ith type of attribute;

[0037] S22. Normalize each sample index value in the sample index value matrix X to obtain a normalized sample index value matrix;

[0038] Preferably, in step S22, according to the attribute characteristics of the sample index value, the normalization process adopts positive normalization or reverse normalization; for positive indicators, positive normalization is adopted as shown in formula (2), and for reverse indicators, reverse normalization is adopted as shown in formula (3):

[0039]

[0040]

[0041] In formulas (2) and (3), x i ′ j represents the j-th sample index value of the i-th type of attribute after normalization, max(x i ), min(x i ) represent the maximum and minimum values of the i-th type of attribute;

[0042] S23. According to the normalized sample index value matrix, calculate the fluctuation S i of the attribute and the conflict R i between attributes by the CRITIC method (evaluation factor method);

[0043] Preferably, in step S23, the formula for calculating the fluctuation S i of the attribute is as shown in formula (4):

[0044] The standard deviation is used to represent the fluctuation of the sample values of each type of attribute; the larger the standard deviation, the greater the fluctuation of the sample values of the attribute, reflecting more information and playing a greater role in abnormal events;

[0045]

[0046] In formula (4), S i represents the standard deviation of the i-th type of attribute, represents the sample mean of the i-th type of attribute, h represents the total number of attribute types; t represents the total number of samples of the i-th type of attribute.

[0047] Preferably, in step S23, the formula for calculating the conflict R i between attributes is as shown in formula (5):

[0048] The correlation coefficient is used to represent the conflict between attributes; the stronger the correlation with other attributes, the smaller the conflict between this attribute and other attributes, the more the same information is reflected, and the greater the redundancy. Therefore, its influence on abnormal events will be appropriately reduced;

[0049]

[0050] In formula (5), r iq represents the correlation coefficient between the i-th type of attribute and the q-th type of attribute, as shown in formula (6):

[0051]

[0052] In formula (6), x i ′ j and x′ qj respectively represent the j-th sample index value of the i-th type of attribute after normalization and the j-th sample index value of the q-th type of attribute after normalization; and respectively represent the sample mean of the i-th type of attribute and the sample mean of the q-th type of attribute.

[0053] S24. According to the fluctuation S i of the attribute and the conflict R i between attributes, calculate the information content C i of the attribute; the greater the information content, the greater the role and influence of the i-th type of attribute in the whole process of the event occurrence, and it is determined as the main attribute. Continuing the research on the basis of the main attribute subsequently can improve the performance of the whole anomaly detection time.

[0054] Preferably, in step S24, the calculation formula of the information content C i of the attribute is as shown in formula (7):

[0055] C i = S i R i

[0056] (7).

[0057] Step 3. Generate the minimum spanning tree of each device in a certain type of main attribute respectively, and then select the minimum spanning tree with the minimum weight sum from all the generated minimum spanning trees as the optimal coverage path of the main attribute device. The main attribute device is used to collect the main attribute data; according to the optimal coverage path of the constructed main attribute device, obtain the optimal collection path of the main attribute data;

[0058] Preferably, in step 3, the Prim algorithm is used to generate a minimum spanning tree. Specifically, each device of the same type of main attribute device is used as a starting point, and the edges of the tree are gradually expanded to construct their respective minimum spanning trees. The weight value of the edge represents the time delay energy consumption consumed by the communication between two main attribute devices. The main attribute devices connected by the expanded edge should satisfy the reliability constraint on the data collected by the device while ensuring the minimum weight value. An ε is selected based on historical experience, and the Gaussian distribution probability p(x) = ε is used as the decision boundary. When p(x) > ε, the predicted data is considered credible, and the main attribute device is retained; otherwise, the data is not credible, and the main attribute device is excluded.

[0059] Preferably, in step 3, the calculation formula of the Gaussian distribution probability p(x) is shown in Equation (8):

[0060]

[0061] In Equation (8), x represents the main attribute sample index value, σ represents the standard deviation of the main attribute sample index; μ represents the average value of the main attribute sample index as shown in Equation (9), and σ 2 represents the variance of the main attribute sample index as shown in Equation (10):

[0062]

[0063] In Equations (9) and (10), x i represents the i-th sample index value of the main attribute; k represents the total number of this type of main attribute.

[0064] Preferably, the specific steps of step 3 are as follows:

[0065] S3.1. Select several devices of a type of main attribute device as the starting point for constructing the minimum spanning tree;

[0066] S3.2. For each starting device, taking the selected main attribute category device as an example, starting from the device, add the device to the set S of visited vertices;

[0067] S3.3. Then select the device with the smallest distance (i.e., weight) from the remaining devices to the set S, visit and add it to the set S. During the visit process, devices of the same main attribute category need to be excluded, and at the same time meet the reliability constraint to ensure that there are no duplicate device categories in the set and credible main attribute data is collected;

[0068] S3.4. Repeat S3.3 until all main attributes are included in the set, stop visiting, and complete the construction of the minimum spanning tree corresponding to each device and including different main attribute types;

[0069] S3.5. Select the minimum spanning tree of different primary attribute devices with the smallest cost as the optimal coverage path of the primary attribute devices;

[0070] S3.6. Collect data along the optimal coverage path of the primary attribute devices, so as to obtain the optimal collection path of the primary attribute data.

[0071] Step 4. Collect the primary attribute data through the optimal collection path of the primary attribute data obtained in Step 3, then transmit the collected primary attribute data to the edge layer, perform weighted fusion in the edge layer, complete the preliminary abnormal event detection, and judge whether an abnormality occurs; if an abnormality occurs, then transmit the abnormal information to the cloud layer for decision-making.

[0072] Preferably, in Step 4, the process flow of the preliminary abnormal event detection is as follows:

[0073] D41. Calculate the fusion weight ω of each type of primary attribute f , as shown in Equation (11):

[0074]

[0075] In Equation (11), ω f is the weight of the f-th primary attribute for the abnormal event; is the variance of the f-th primary attribute; m represents the total number of primary attribute types;

[0076] D42. Let the actual sensed value of the f-th primary attribute be z f , and substitute it into Equation (12) to obtain the fusion value w:

[0077]

[0078] D43. Compare the fusion value w with the threshold range [thvI i , thv I j to observe whether it is within the threshold range; the threshold range is the empirical value for judging the abnormal event, where thvI i is the left interval of the threshold, i.e., the minimum value, and thvI j is the right interval of the threshold, i.e., the maximum value; if it is within the threshold range, it means that there is no abnormality in the sub-region managed by this edge node; if it is not within the threshold range, it means that there is an abnormality in the sub-region managed by this edge node.

[0079] The present invention also provides an electronic device, including a processor and a memory communicatively connected to the processor and used for storing instructions executable by the processor, characterized in that: the processor is used to execute the abnormal event detection method in the cloud-edge fusion environment.

[0080] The present invention also provides a computer-readable storage medium storing a computer program, characterized in that: when the computer program is executed by a processor, the abnormal event detection method in the cloud-edge fusion environment is implemented.

[0081] Embodiment 1:

[0082] Taking smoke abnormality as an example, this embodiment includes the following steps:

[0083] Step 1, build a cloud-edge fusion environment;

[0084] Step 2, select a set of historical smoke data, and select data points at 1-minute intervals from the historical data of detection devices in a spatial area according to the time series to obtain an original attribute information sequence; the attributes include ambient temperature, humidity, total volatile organic compound level (TVOC), estimated carbon dioxide concentration (eCO 2 ), original hydrogen (H 2 ), original ethanol, pressure, PM1.0, PM2.5, NC0.5, NC1.0, and NC2.5 (representing different particulate matter concentrations). According to the CRITIC attribute recognition algorithm, temperature, humidity, TVOC, original hydrogen, original ethanol, and pressure are identified as the main attributes affecting smoke abnormal events. The CRITIC attribute recognition algorithm identifies temperature, humidity, TVOC, original hydrogen, original ethanol, and pressure as the main attributes affecting smoke abnormal events, that is, m = 6;

[0085] Step 3, based on the 6 main attributes obtained in Step 2, construct a minimum spanning tree under the condition of the true value constraint in Step 3:

[0086] (1) Select a type with the smallest total number of devices from the 6 main attribute types as the starting device of the minimum spanning tree;

[0087] (2) Construct a minimum spanning tree from a main attribute device of the selected starting type, so that it includes devices with all main attribute types but no duplicate types;

[0088] (3) Repeat the above step (2) to implement all minimum spanning trees of each device of this main attribute type;

[0089] (4) Select the minimum spanning tree with the lowest communication cost as the best main attribute collection path.

[0090] As Figure 2As shown in the figure, it is the distribution map of the main attribute devices under all edge server management areas. Among them, the label (a, b) of the main attribute device indicates the type of the main attribute, where a = 1, 2, 3; b represents the number of the main attribute device of this type, b = 1, 2, 3; the MEC server represents the mobile computing server at the edge layer. Randomly start from the main attribute devices of type 1. Since there are three main attribute devices of type 1, namely (1, 1), (1, 2), and (1, 3), three minimum spanning trees need to be constructed through an algorithm, and the construction results are as Figure 3 , Figure 4 , Figure 5 shown. Finally, since the minimum spanning tree composed of (1, 3), (2, 3), and (3, 3) has the smallest weighted sum, it is selected as the optimal collection path for the main attribute data.

[0091] Step 4: Each edge node will first make a preliminary judgment on the collected main attribute information to observe whether a fire will occur in this sub-region. In the Internet of Things, each edge device manages a sub-region; the edge device analyzes and processes the received main attribute information, that is, it performs weighted fusion on the weights and actual sensed values of each main attribute to obtain a fusion value; the weight of each main attribute is obtained by normalizing the regression coefficient corresponding to each main attribute, and m = 6 is substituted into Equation (11).

[0092] After the weighted fusion calculation, the fusion value w is compared with the smoke anomaly threshold range to determine whether a smoke anomaly occurs. If it is determined that an abnormal event occurs, the abnormal information will be uploaded to the cloud for further analysis and a final decision will be made.

[0093] Figure 6 , Figure 7 and Figure 8 are respectively the schematic diagrams of the energy consumption, detection time, and accuracy of abnormal detection of the method of the present invention and the existing methods under the condition of different numbers of devices. Among them, PTLAD represents the method of the present invention, MFGAD represents an abnormal detection method that uses a hybrid metric to calculate the fuzzy relationship of data, BLDOD represents an unsupervised local abnormal detection method, and LSTM-Markov represents an efficient abnormal detection method in the Internet of Things environment. DIF represents a deep isolation forest abnormal detection method.

[0094] At Figure 6In it, as the number of IoT devices increases, the amount of attribute data collected also increases, resulting in an increase in the detection time of all methods. Observing the experimental results, compared with MFGAD, BLDOD, LSTM-MARKOV, and DIF, the detection time of the PTLAD method of the present invention is reduced by at least 26%, 27%, 17%, and 31% respectively. This is mainly because the method of the present invention (i) identifies the original attributes related to abnormal events and uses the Gaussian mixture model to remove unreliable sensing data, avoiding the collection of unnecessary attributes and unreliable values, and (ii) collects and aggregates attribute data along the optimal path of PADCA, avoiding the transmission of redundant data and reducing the detection time. For the four comparison methods, they do not distinguish the main attribute classes closely related to the occurrence of abnormal events, so collecting data of all unimportant attributes will consume more time. The LSTM-MARKOV method filters out unreliable data, while the time is mainly spent on collecting other redundant data. Therefore, compared with MFGAD, BLDOD, and DIF, its detection time is reduced by at least 9%. These methods neither filter out unreliable data nor consider the main attribute type to eliminate redundant data collection.

[0095] In Figure 7 it, among all methods, the changing trend of energy consumption for abnormal event detection is similar to that of time consumption, increasing as the number of IoT devices increases. In the PTLAD method, reliable main attribute data is collected along the optimal PADCA path, avoiding the transmission of data that is untrue, redundant, and unimportant for the occurrence of abnormal events. Therefore, compared with MFGAD, BLDOD, LSTM-MARKOV, and DIF, the energy consumption is reduced by at least 44%, 40%, 31%, and 57% respectively. Similar to the comparison and analysis of detection time, the energy consumption of LSTM-MARKOV is also lower than that of MFGAD, BLDOD, and DIF, at least reduced by 9%.

[0096] In Figure 8Among them, the PTLAD method achieved an accuracy of over 0.9, while the accuracies of the other four methods were slightly lower. This is because the PTLAD method (i) accurately identified the main attributes and (ii) considered the deletion of unreliable attribute data. However, LSTM-MARKOV took steps to remove unreliable data, so its accuracy was relatively high compared to DIF, MFGAD, and BLOOD. Since DIF relied entirely on the neural network model for anomaly detection and had a high dependence on data, its detection accuracy was the worst among all methods. In the MFGAD method, although a hybrid metric was used to calculate the fuzzy relationship related to anomalies, unreliable data had a negative impact on its detection results. The BLDOD method set the boundaries of points through a bias parameter related to the standard deviation of the data distribution to obtain anomaly scores. The distribution of unreliable data would inevitably bias the sensing boundary, thereby reducing the accuracy of anomaly detection. Therefore, the PTLAD method proposed in this chapter effectively improved the anomaly detection performance.

[0097] In summary, the method of the present invention exhibits excellent performance in terms of detection time, energy consumption, and the accuracy of anomaly detection.

[0098] Matters not described in the present invention are applicable to the prior art.

Claims

1. A method for detecting abnormal events in a cloud-edge fusion environment, characterized in that: The method comprises the following steps: Step 1: Build a cloud-edge fusion environment; The cloud-edge fusion environment includes a cloud layer, an edge layer, and a device layer; the device layers, the edge layers, the device layer and the edge layer, and the edge layer and the cloud layer are all connected in communication; the device layer is used to collect attribute information of related events and upload the collected attribute information to the edge layer; the edge layer is responsible for collecting attribute information of an event in each sub-area of ​​the device layer and calculating the fusion value of the main attributes of the related events; the cloud layer is used to identify the main attributes of the event and further process the abnormal results of the edge layer; Step 2: Filter out m main attributes that play a decisive role in the event: Step 3: Generate a minimum spanning tree for each device in a certain type of main attribute, and then select the minimum spanning tree with the smallest weight from all the generated minimum spanning trees as the optimal coverage path of the main attribute device. The main attribute device is used to collect the main attribute data; according to the constructed optimal coverage path of the main attribute device, the optimal collection path of the main attribute data is obtained; Step 4: Collect the main attribute data through the optimal collection path of the main attribute data obtained in step 3, and then transmit the collected main attribute data to the edge layer, perform weighted fusion at the edge layer, complete preliminary abnormal event detection, and determine whether an abnormality occurs; if an abnormality occurs, transmit the abnormal information to the cloud layer for decision-making.

2. The abnormal event detection method in a cloud-edge fusion environment according to claim 1 is characterized in that: In step 1, the device layers are connected via wireless network communication, the device layer and the edge layer are connected via wireless network communication, the edge layers are connected via wired network communication, and the edge layer and the cloud layer are connected via wired network communication.

3. The abnormal event detection method in a cloud-edge fusion environment according to claim 1 is characterized in that: In step 1, the device layer is the bottom layer of the system architecture, which includes multiple detection devices. Each detection device is responsible for sensing different attributes in the environment, collecting attribute information of related events, and uploading the collected attribute information to the edge layer; the edge layer has functions such as computing, communication, and providing resources, and has a large amount of memory; the edge layer includes multiple edge devices, each of which is an edge node. Each edge node is responsible for managing a sub-area of ​​the device layer and collecting attribute information of an event in a sub-area. The attribute information includes the device, time, attribute type, attribute sensing value, etc. of the sensing attribute; The cloud layer has huge computing and storage capabilities, which are used to identify the main attributes of events and further process abnormal results in the edge layer.

4. The abnormal event detection method in a cloud-edge fusion environment according to claim 1 is characterized in that: The specific steps of step 2 are as follows: S21. Establish a sample index value matrix X for the initial attribute data in the management area, as shown in formula (1): In formula (1), x ij Represents the jth sample index value of the i-th attribute; S22, normalizing each sample index value in the sample index value matrix X to obtain a normalized sample index value matrix; S23. According to the normalized sample index value matrix, the fluctuation S of the attribute is calculated by the CRITIC method. i Conflicts between attributes R i ; S24, according to the fluctuation of attributes S i Conflicts between attributes R i , calculate the information content C of the attribute i The greater the information content, the greater the role and influence of the i-th attribute in the entire event process, and it is determined to be the main attribute.

5. The abnormal event detection method in a cloud-edge fusion environment according to claim 4 is characterized in that: In step S22, according to the attribute characteristics of the sample index value, the normalization process adopts the forward process or the reverse process; for the forward index, the forward process is adopted as shown in formula (2), and for the reverse index, the reverse process is adopted as shown in formula (3): In formulas (2) and (3), x′ ij represents the normalized index value of the jth sample of the i-th attribute, max(x i )、min(x i ) represents the maximum and minimum value of the i-th attribute.

6. The abnormal event detection method in a cloud-edge fusion environment according to claim 4 is characterized in that: In step S23, the fluctuation of the attribute S i The calculation formula is shown in formula (4): Use standard deviation to represent the fluctuation of sample values ​​of each attribute; the larger the standard deviation, the greater the fluctuation of sample values ​​of the attribute; In formula (4), S i represents the standard deviation of the i-th attribute, represents the sample mean of the i-th attribute, h represents the total number of attribute types; t represents the total number of samples of the i-th attribute; In step S23, the conflict between attributes R i The calculation formula is shown in formula (5): Use the correlation coefficient to represent the conflict between attributes; the stronger the correlation with other attributes, the smaller the conflict between the attribute and other attributes, the more the same information is reflected, and the greater the redundancy; In formula (5), r iq It represents the correlation coefficient between the i-th attribute and the q-th attribute, as shown in formula (6): In formula (6), x i ′ j and x ′ qj They represent the normalized j-th sample index value of the i-th attribute and the normalized j-th sample index value of the q-th attribute respectively; and They represent the sample mean of the i-th attribute and the sample mean of the q-th attribute respectively; In step S24, the information content C of the attribute i The calculation formula is shown in formula (7): C i =S i R i (7)。 7. The abnormal event detection method in a cloud-edge fusion environment according to claim 1 is characterized in that: In step 3, the prim algorithm is used to generate a minimum spanning tree. Specifically, each device of the same type of primary attribute device is taken as the starting point, and the edges of the tree are gradually expanded to construct their respective minimum spanning trees, where the weight value of the edge represents the delay energy consumption consumed by the communication between the two primary attribute devices. The primary attribute device connected by the expanded edge should use multivariate Gaussian distribution to constrain the reliability of the data collected by the device while ensuring the minimum weight value. An ε is selected based on historical experience, and the Gaussian distribution probability p(x) = ε is used as the judgment boundary; when p(x)>ε, the predicted data is credible and the primary attribute device is retained; otherwise, the data is unreliable and the primary attribute device is excluded.

8. The abnormal event detection method in a cloud-edge fusion environment according to claim 7 is characterized in that: In step 3, the calculation formula of Gaussian distribution probability p(x) is shown in formula (8): In formula (8), x represents the sample index value of the main attribute, σ represents the standard deviation of the sample index of the main attribute; μ represents the average value of the sample index of the main attribute as shown in formula (9), σ 2 The variance of the main attribute sample index is shown in formula (10): In formula (9) and formula (10), x i represents the i-th sample index value of the main attribute; k represents the total number of main attributes of this type.

9. The abnormal event detection method in a cloud-edge fusion environment according to claim 1, characterized in that: The specific steps of step 3 are as follows: S3.

1. Select several devices of a class of main attribute devices as the starting point for constructing the minimum spanning tree; S3.

2. For each starting device, take the main attribute category device as an example, starting from the device, add the device to the visited vertex set S; S3.3, then select the device with the shortest distance to the set S from the remaining devices, visit and add it to the set S. During the access process, devices with the same primary attribute category need to be excluded, and reliability constraints must be met to ensure that there are no repeated device categories in the set and that reliable primary attribute data is collected; S3.4, repeat S3.3 until all the primary attributes are included in the set, stop accessing, and complete the construction of the minimum spanning tree corresponding to each device and including different primary attribute types; S3.5, select the minimum spanning tree of different main attribute devices with the lowest cost as the optimal coverage path of the main attribute device; S3.

6. Collect data along the optimal coverage path of the main attribute device, so as to obtain the optimal collection path of the main attribute data.

10. The abnormal event detection method in a cloud-edge fusion environment according to claim 1, characterized in that: In step 4, the process flow of preliminary abnormal event detection is as follows: D41. Calculate the fusion weight ω of each main attribute f , as shown in formula (11): In formula (11), ω f is the weight of the fth main attribute for abnormal events; is the variance of the fth main attribute; m represents the total number of main attribute types; D42, let the actual sensed value of the fth main attribute be z f , substituting into formula (12) to obtain the fusion value w: D43, the fusion value w and the threshold range of abnormal events [thvI i ,thvI j ] to observe whether it is within the threshold range; the threshold range is the empirical value for judging the abnormal event of the event; if it is within the threshold range, it means that there is no abnormality in the sub-area managed by the edge node; If it is not within the threshold range, it means that an abnormality has occurred in the sub-area managed by the edge node.