An AI-based industrial Internet data security protection method and system

Through the combination of fractional firefly optimization algorithm and Logistic chaotic mapping, an abnormality detection model is built, which solves the real-time, accuracy and robustness of industrial Internet data anomaly detection problems, and realizes efficient data security protection.

CN120110769BActive Publication Date: 2025-09-02GUANGXI POLICE ACAD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510295846.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-09-02
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

The existing industrial Internet data anomaly detection methods have shortcomings in real-time, accuracy, robustness and interpretability, and are difficult to meet the needs of complex industrial scenarios. Especially in data environments with high dimensional, massive and time-series dynamic changes, traditional methods have high computational complexity, high error detection rate, high miss detection rate and are difficult to respond quickly.

Method used

The fractional-order firefly optimization algorithm is used to combine Logistic chaos mapping, and the abnormal detection model is constructed by performing feature extraction and model optimization on industrial Internet data. The dynamic memory of the fractional-order firefly optimization algorithm and the nonlinear perturbation of the Logistic chaos mapping are used to realize real-time monitoring and abnormal identification of industrial Internet data.

Benefits of technology

It improves the real-time and accuracy of industrial Internet data anomaly detection, reduces the error detection rate, enhances the robustness and interpretability of the model, can quickly respond to sudden abnormalities in complex environments, and ensures the stability and security of the production system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110769B_ABST
    Figure CN120110769B_ABST
Patent Text Reader

Abstract

The present invention discloses an AI-based industrial internet data security protection method and system, comprising the following steps: S1. constructing a standardized industrial internet data set; S2. constructing an industrial internet data feature matrix; S3. forming a preliminary anomaly detection model; S4. generating an optimized anomaly detection model; S5. monitoring the industrial internet data in real time based on the optimized anomaly detection model and generating preliminary anomaly detection results; S6. adjusting relevant parameters in the fractional-order firefly optimization algorithm and the logistic chaos map based on feedback results, updating the anomaly detection model, and forming a final anomaly detection result; and S7. linking the final anomaly detection result with the industrial internet data monitoring system to trigger an anomaly early warning mechanism. The present invention enables the anomaly detection model to have higher real-time performance, accuracy, and robustness, effectively improving the performance of industrial internet data anomaly detection, and providing strong support for intelligent manufacturing and industrial internet data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to an AI-based industrial Internet data security protection method and system. Background Art

[0002] With the rapid development of the Industrial Internet, the manufacturing, energy, transportation, and smart factory sectors are increasingly relying on real-time data monitoring and analysis to optimize production processes, improve equipment maintenance efficiency, and ensure system security. However, data in the Industrial Internet environment is high-dimensional, massive, and dynamically changing over time. Furthermore, during data transmission and collection, it is susceptible to equipment noise, communication interference, and environmental changes, making data anomalies prone to occur. Abnormal data can be caused by a variety of factors, including sensor failure, abnormal equipment operation, external network attacks, or process parameter deviations. Failure to identify and address these anomalies in a timely manner can directly impact the stability and security of production systems.

[0003] Existing industrial Internet data anomaly detection methods mainly include methods based on statistical analysis, machine learning, and deep learning. Traditional statistical analysis methods such as Z-score detection, principal component analysis, and K-means clustering mainly rely on the probability distribution characteristics of the data, have strong assumptions about the linear relationship of the data, and are difficult to handle complex nonlinear anomaly patterns. In addition, traditional methods usually require manual setting of thresholds, have low sensitivity to abnormal data, and are prone to false detection or missed detection. In addition, the computational complexity is high in high-dimensional data environments, making it difficult to meet real-time requirements.

[0004] In recent years, deep learning-based anomaly detection methods, including long short-term memory networks, variational autoencoders, and generative adversarial networks, have been widely used in industrial Internet data analysis. Deep learning can automatically learn the deep features of data and has a strong ability to capture abnormal patterns. However, deep learning methods consume a lot of computing resources, and the model training and inference processes require high-performance hardware support, which makes them difficult to deploy in edge computing and low-power industrial equipment environments. In addition, deep learning models have poor interpretability. In actual industrial applications, operation and maintenance personnel often find it difficult to understand the specific basis of the detection results, resulting in limited credibility of anomaly identification.

[0005] In summary, existing methods for detecting anomaly in industrial internet data have limitations in terms of real-time performance, accuracy, robustness, and interpretability, and cannot effectively meet the needs of complex industrial scenarios. Therefore, a new approach is urgently needed to improve the accuracy, real-time performance, and stability of anomaly detection by optimizing computational models, enhancing algorithm search efficiency, and enhancing data adaptability, thereby better ensuring the security and reliability of industrial internet data. Summary of the Invention

[0006] One purpose of the present invention is to propose an AI-based industrial Internet data security protection method and system. The present invention enables the anomaly detection model to have higher real-time, accuracy and robustness, can effectively improve the performance of industrial Internet data anomaly detection, and provide strong support for intelligent manufacturing and industrial Internet data security.

[0007] An AI-based industrial Internet data security protection method according to an embodiment of the present invention includes the following steps:

[0008] S1. Collect and preprocess real-time industrial Internet data to build a standardized industrial Internet dataset;

[0009] S2. Extract features from the industrial Internet data set and construct an industrial Internet data feature matrix;

[0010] S3. Build an anomaly detection model based on the industrial internet data feature matrix and globally optimize the anomaly detection model using the fractional-order firefly optimization algorithm to form a preliminary anomaly detection model;

[0011] S4. using a logistic chaotic map to perturb the fractional firefly population in the preliminary anomaly detection model and dynamically adjust its parameters to generate an optimized anomaly detection model;

[0012] S5. Monitor the industrial internet data in real time based on the optimized anomaly detection model, identify abnormal industrial internet data that deviates from the normal pattern by comparing the industrial internet data with the normal pattern defined in the optimized anomaly detection model, and generate preliminary anomaly detection results;

[0013] S6. Perform adaptive feedback processing on the preliminary anomaly detection results, adjust relevant parameters in the fractional-order firefly optimization algorithm and the logistic chaos map based on the feedback results, and update the anomaly detection model to form the final anomaly detection results;

[0014] S7. Link the final anomaly detection results with the industrial Internet data monitoring system to trigger the anomaly warning mechanism and achieve security protection of data in the industrial Internet environment.

[0015] Optionally, the S1 includes the following steps:

[0016] S11. Collect real-time data from the Industrial Internet, including data sources from sensor equipment, control systems, monitoring systems, and production management platforms. Set the collection time window and define the Industrial Internet dataset D. raw for:

[0017]

[0018] Among them, d i represents the i-th piece of industrial Internet data, N is the total number of collected industrial Internet data, t i is the timestamp of the industrial Internet data, v i is numerical information, s i is the device identifier of the industrial Internet data source, c i It is the category label of industrial Internet data;

[0019] S12. Clean the industrial internet dataset to remove invalid data, duplicate data, and abnormal data to obtain a cleaned industrial internet dataset;

[0020] S13. Perform data standardization on the industrial Internet data set, normalize the industrial Internet data to the interval [a, b], and obtain the standardized industrial Internet data set D norm ;

[0021] S14. Remove redundant information from the standardized industrial Internet dataset to construct the final standardized industrial Internet dataset D final , the redundant information removal includes feature selection based on correlation analysis, and defines the feature correlation matrix R:

[0022]

[0023] Among them, R i,j is the correlation coefficient of the industrial Internet data of the i-th dimension and the j-th dimension, M is the number of data samples, and is the mean of the industrial Internet data of the corresponding dimension, if R i,j If the redundancy threshold τ is exceeded, the highly redundant dimensional data will be removed, and finally a standardized industrial Internet dataset D will be formed. final :

[0024] ″″″′

[0025] D final ={d i ∣d i =(t i ,v i ,s i ,c i ),d i ∈D norm};

[0026] ″′″

[0027] Among them, v i Represents the numerical information after redundancy removal, d i represents the normalized data point, di Represents the data points after redundancy removal.

[0028] Optionally, S2 includes the following steps:

[0029] S21. Based on the standardized industrial Internet dataset D final Extract time series features from industrial Internet data and construct the time series feature matrix F time ,The time series characteristics include the changing trend, short-term volatility and long-term stability of industrial Internet data at different times;

[0030] S22. Based on the standardized industrial Internet dataset D final Extract the spatial distribution features of industrial Internet data and construct the spatial distribution feature matrix F space , the spatial distribution feature is used to characterize the correlation of data between devices;

[0031] S23. Based on the standardized industrial Internet dataset D final Extract correlation features from industrial Internet data and construct correlation feature matrix F corr , the correlation feature is used to measure the degree of correlation between different data;

[0032] S24. Based on the standardized industrial Internet dataset D final Extract abnormal pattern features from industrial Internet data and construct abnormal pattern feature matrix F anom , the abnormal pattern features are used to identify abnormal distribution of industrial Internet data;

[0033] S25. Combined with time series feature matrix F time , spatial distribution feature matrix F space , correlation feature matrix F corr and abnormal pattern feature matrix F anom , construct the industrial Internet data feature matrix F data :

[0034] F data ={F time ,F space ,F corr ,F anom}.

[0035] Optionally, S3 includes the following steps:

[0036] S31. Based on the Industrial Internet data feature matrix F data Build an anomaly detection model. The anomaly detection model aims to monitor abnormal changes in industrial Internet data in real time and defines the anomaly detection fitness function:

[0037]

[0038] Among them, f(X) is the value of the anomaly detection fitness function, which is used to measure the effectiveness of the anomaly detection model parameter combination X. data,i is the eigenvector of industrial Internet data of dimension i, F normal is the reference feature vector of the normal mode of industrial Internet data, ω i is the weight coefficient, which is set based on the importance of the industrial Internet data features, σ is the sensitivity adjustment factor, which is used to dynamically adjust the sensitivity of the industrial Internet data anomaly detection model, δ is the anomaly deviation threshold, and N is the dimension of the feature vector;

[0039] S32. Initialize the fractional firefly population and initialize the anomaly detection model parameters to the initial position of the fractional firefly optimization algorithm

[0040]

[0041] in, represents a set of initial solutions of anomaly detection model parameters corresponding to the j-th firefly individual, represents the initial value of the d-th dimension model parameter of the j-th firefly, which is used to set the sensitivity and threshold of the anomaly detection model. D is the total dimension of the parameters to be optimized in the anomaly detection model, and M1 is the population size.

[0042] S33. Set a unified fractional-order parameter ν and introduce a dynamic memory factor θ(t) based on the abnormal change trend of industrial Internet data. Define the dynamic memory factor as the ratio of the real-time abnormal level of industrial Internet data to the historical abnormal level, and adjust the historical memory length of the fractional-order firefly algorithm in real time:

[0043]

[0044] Among them, θ(t) is a dynamic memory factor, which is used to adaptively adjust the response speed of individual fireflies to abnormal changes in industrial Internet data in real time; and are the anomaly detection fitness function values ​​of the global optimal positions of the current and previous iterations, respectively, and ε is a minimum constant to prevent division by zero errors;

[0045] S34. The positions of individual fireflies are iteratively updated using a fractional-order firefly position update method based on a dynamic memory factor. The fractional-order firefly position update method is expressed as:

[0046]

[0047] in, is the new position of the j-th firefly individual after the t+1th iteration, that is, the optimized position of the anomaly detection model parameters, α is the step size factor, and θ(t) is the dynamic memory factor calculated based on the anomaly level of real-time data of the Industrial Internet. is the fractional-order differential coefficient determined by the fractional-order parameter ν, L is the maximum number of historical memory steps, β is the firefly attraction coefficient, γ is the attraction attenuation coefficient, r j,q is the Euclidean distance between the position of firefly individual j and the brighter individual q;

[0048] S35. Based on the evaluation results of the anomaly detection fitness function f(X) calculated in real time based on the industrial Internet data, the firefly population position is continuously updated iteratively. When the optimization stop condition is reached, the preliminary anomaly detection model parameter set X for industrial Internet data is obtained. optimal :

[0049]

[0050] S36. The representation of the preliminary anomaly detection model is the anomaly detection fitness function M after optimization based on the fractional-order firefly optimization algorithm. initial (X):

[0051]

[0052] Among them, M initial (X) represents the preliminary anomaly detection model, λ is the regularization coefficient, X optimal,d is the d-th dimension anomaly detection model parameter after fractional-order firefly optimization, X prev,d It is the d-th dimension anomaly detection model parameter obtained in the previous round of optimization.

[0053] Optionally, the S4 includes the following steps:

[0054] S41. Use Logistic chaotic mapping to perturb the fractional firefly population in the preliminary anomaly detection model and define the chaotic perturbation sequence

[0055]

[0056] in, is the chaotic perturbation value of the j-th firefly individual in the t+1 generation, μ is the control parameter of the Logistic chaotic mapping, is the disturbance value of the tth generation, the initial value Set by random distribution;

[0057] S42. Based on the Logistic chaos perturbation, the search step of fractional fireflies is adjusted to make the search step of fractional fireflies have higher population diversity:

[0058]

[0059] in, is the dynamic step length of the j-th firefly individual in the t+1 generation, α min and α max are the minimum and maximum values ​​of the step length respectively;

[0060] S43. Combining the theory of fractional calculus, the positions of individual fractional fireflies are adjusted based on chaotic perturbations. The disturbance-corrected fractional position update is defined as:

[0061]

[0062] in, is the optimized parameter of the j-th firefly individual in the t+2 generation;

[0063] S44. Logistic chaos mapping is used to adaptively balance global search and local search in the fractional-order firefly optimization algorithm, and a search adjustment factor is introduced:

[0064]

[0065] in, is the search adjustment factor of the j-th firefly individual in the t+1 generation, η1 is the smoothing control parameter, is the mean value of the chaotic disturbance of the current population;

[0066] S45. Use Logistic chaotic mapping to dynamically adjust parameters and define the dynamic adjustment function:

[0067]

[0068] in, is the optimized parameter of the j-th firefly individual in the t+2 generation, is the optimized parameter of the j-th firefly individual in the t+1 generation;

[0069] S46. After multiple iterations, when the anomaly detection model optimization converges, an optimized anomaly detection model M is generated. optimal (X).

[0070] Optionally, the S5 includes the following steps:

[0071] S51. Based on the optimized anomaly detection model M optimal (X) Industrial Internet data feature matrix F data Perform real-time monitoring and calculate the deviation d of each data point relative to the normal mode i ;

[0072] S52. Set an anomaly threshold τ and calculate the anomaly probability for each data point based on the historical anomaly distribution of industrial Internet data:

[0073]

[0074] in, is the abnormal probability of the i-th industrial Internet data, λ1 is the steepness adjustment factor of the abnormal probability curve, which controls the relationship between abnormal probability and deviation, and τ1 is the abnormal threshold;

[0075] S53. Based on abnormal probability Determine anomalies in industrial Internet data and set anomaly detection rules:

[0076]

[0077] Among them, A i is the abnormality judgment mark of the i-th industrial Internet data, if A i =1, the data is judged to be abnormal data, otherwise it is judged to be normal data, P th is the abnormal probability judgment threshold, which is used to distinguish normal data from abnormal data;

[0078] S54. Calculate the abnormal proportion of the entire industrial Internet data flow:

[0079]

[0080] Among them, R anom The abnormal proportion of the current industrial Internet data flow, indicating the proportion of abnormal data in the entire industrial Internet data flow;

[0081] S55. Combined with the abnormal proportion of industrial Internet data R anom and abnormal judgment result A i , generate preliminary anomaly detection results D anom :

[0082] D anom ={d i ∣A i =1,d i ∈F data}.

[0083] An AI-based industrial Internet data security protection system is used to implement an AI-based industrial Internet data security protection method, including:

[0084] The data acquisition module is used to collect real-time data from the Industrial Internet. The real-time data from the Industrial Internet includes data sources from sensor equipment, control systems, monitoring systems, and production management platforms, set the collection time window, and construct the Industrial Internet data set;

[0085] The data preprocessing module is used to preprocess the collected industrial Internet data, including data cleaning, data standardization and redundant information removal, in order to build a standardized industrial Internet data set;

[0086] The feature extraction module is used to extract data features from the standardized industrial Internet data set and construct an industrial Internet data feature matrix. Each feature dimension is used to characterize the dynamics, spatial correlation, and potential abnormal distribution patterns of industrial Internet data;

[0087] The anomaly detection model construction module is used to build an anomaly detection model based on the industrial Internet data feature matrix. The fractional-order firefly optimization algorithm is used to globally optimize the anomaly detection model. The initial anomaly detection model is formed by initializing the fractional-order firefly population and setting unified fractional-order parameters.

[0088] The anomaly detection model optimization module is used to optimize the preliminary anomaly detection model. It uses the Logistic chaos map to perturb the fractional firefly population and dynamically adjust the parameters to ultimately generate the optimized anomaly detection model.

[0089] The real-time monitoring and anomaly determination module is used to monitor industrial internet data in real time based on the optimized anomaly detection model. By comparing the industrial internet data with the normal pattern defined by the anomaly detection model, the deviation degree of the data is calculated, and anomaly determination is made based on the set anomaly threshold. This module identifies abnormal industrial internet data that deviates from the normal pattern and generates preliminary anomaly detection results.

[0090] The feedback optimization and anomaly warning module is used to perform adaptive feedback processing on the preliminary anomaly detection results, dynamically adjust the relevant parameters in the fractional-order firefly optimization algorithm and the logistic chaos map according to the feedback results, and update the anomaly detection model. At the same time, the final anomaly detection results are linked with the industrial Internet data monitoring system to trigger the anomaly warning mechanism and achieve security protection of data in the industrial Internet environment.

[0091] The beneficial effects of the present invention are:

[0092] (1) Based on the traditional firefly optimization algorithm, the present invention introduces the theory of fractional calculus and constructs a new position update mechanism through fractional derivatives, so that the algorithm can achieve a better balance between global search and local optimization. In the process of industrial Internet data anomaly detection, the fractional difference strategy enables the firefly individual to retain historical search information during the update process and dynamically adjust the step size to improve the diversity and flexibility of the search path.

[0093] (2) The present invention uses Logistic chaotic mapping to perturb the fractional-order firefly optimization algorithm, thereby improving the algorithm's global exploration capability in a complex industrial Internet data environment. By introducing Logistic chaotic perturbation, the positions of individual fireflies are nonlinearly and dynamically adjusted during the optimization process, making the individuals more evenly distributed in the high-dimensional data space and enhancing the algorithm's ability to escape local optimality. In addition, the introduction of Logistic chaotic mapping enables the model to adapt to the dynamic changes of the industrial Internet environment more quickly, and the optimized anomaly detection model has a faster response speed when facing sudden anomalies. BRIEF DESCRIPTION OF THE DRAWINGS

[0094] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0095] Figure 1 This is a flowchart of an AI-based industrial Internet data security protection method and system proposed by the present invention. DETAILED DESCRIPTION

[0096] The present invention will now be described in further detail with reference to the accompanying drawings, which are simplified schematic diagrams that illustrate the basic structure of the present invention in a schematic manner.

[0097] refer to Figure 1 , an AI-based industrial Internet data security protection method, including the following steps:

[0098] S1. Collect and preprocess real-time industrial Internet data to build a standardized industrial Internet dataset;

[0099] S2. Extract features from the Industrial Internet dataset and construct an Industrial Internet data feature matrix;

[0100] S3. Build an anomaly detection model based on the Industrial Internet data feature matrix and use the fractional-order firefly optimization algorithm to globally optimize the anomaly detection model to form a preliminary anomaly detection model.

[0101] S4. Use Logistic Chaos Mapping to perturb the fractional firefly population in the preliminary anomaly detection model and dynamically adjust its parameters to generate an optimized anomaly detection model.

[0102] S5. Monitor the Industrial Internet data in real time based on the optimized anomaly detection model. By comparing the Industrial Internet data with the normal pattern defined in the optimized anomaly detection model, identify abnormal Industrial Internet data that deviates from the normal pattern and generate preliminary anomaly detection results.

[0103] S6. Perform adaptive feedback processing on the preliminary anomaly detection results, adjust relevant parameters in the fractional-order firefly optimization algorithm and the logistic chaos map based on the feedback results, and update the anomaly detection model to form the final anomaly detection results;

[0104] S7. Link the final anomaly detection results with the industrial Internet data monitoring system to trigger the anomaly warning mechanism and achieve security protection of data in the industrial Internet environment.

[0105] In this embodiment, S1 includes the following steps:

[0106] S11. Collect real-time data from the Industrial Internet. The real-time data from the Industrial Internet includes data sources from sensor equipment, control systems, monitoring systems, and production management platforms. Set the collection time window and define the Industrial Internet data set D. raw for:

[0107]

[0108] Among them, d i represents the i-th piece of industrial Internet data, N is the total number of collected industrial Internet data, t i is the timestamp of the industrial Internet data, v i is numerical information, s i is the device identifier of the industrial Internet data source, c i It is the category label of industrial Internet data;

[0109] S12. Clean the industrial internet dataset to remove invalid data, duplicate data, and abnormal data, thereby obtaining a cleaned industrial internet dataset;

[0110] S13. Perform data standardization on the industrial Internet dataset and normalize the industrial Internet data to the interval [a, b] to obtain the standardized industrial Internet dataset D. norm ;

[0111] S14. Remove redundant information from the standardized industrial Internet dataset and construct the final standardized industrial Internet dataset D final , redundant information removal includes feature selection based on correlation analysis, defining the feature correlation matrix R:

[0112]

[0113] Among them, R i,j is the correlation coefficient of the industrial Internet data of the i-th dimension and the j-th dimension, M is the number of data samples, and is the mean of the industrial Internet data of the corresponding dimension, if Ri,j If the redundancy threshold τ is exceeded, the highly redundant dimensional data will be removed, and finally a standardized industrial Internet dataset D will be formed. final :

[0114] ″″″′

[0115] D final ={d i ∣d i =(t i ,v i ,s i ,c i ),d i ∈D norm};

[0116] ″′″

[0117] Among them, v i Represents the numerical information after redundancy removal, d i represents the normalized data point, d i Represents the data points after redundancy removal.

[0118] In this embodiment, S2 includes the following steps:

[0119] S21. Based on the standardized industrial Internet dataset D final Extract time series features from industrial Internet data and construct the time series feature matrix F time ,Time series characteristics include the changing trend, short-term volatility and long-term stability of ,Industrial Internet data at different times;

[0120] S22. Based on the standardized industrial Internet dataset D final Extract the spatial distribution features of industrial Internet data and construct the spatial distribution feature matrix F space ,Spatial distribution features are used to characterize the correlation of data between devices;

[0121] S23. Based on the standardized industrial Internet dataset D final Extract correlation features from industrial Internet data and construct correlation feature matrix F corr ,Correlation features are used to measure the degree of correlation between different data;

[0122] S24. Based on the standardized industrial Internet dataset D final Extract abnormal pattern features from industrial Internet data and construct abnormal pattern feature matrix F anom ,Abnormal pattern features are used to identify abnormal distribution of industrial Internet data;

[0123] S25. Combined with time series feature matrix F time, spatial distribution feature matrix F space , correlation feature matrix F corr and abnormal pattern feature matrix F anom , construct the industrial Internet data feature matrix F data :

[0124] F data ={F time ,F space ,F corr ,F anom}.

[0125] In this embodiment, S3 includes the following steps:

[0126] S31. Based on the Industrial Internet data feature matrix F data Build an anomaly detection model. The anomaly detection model aims to monitor abnormal changes in industrial Internet data in real time and defines the anomaly detection fitness function:

[0127]

[0128] Among them, f(X) is the value of the anomaly detection fitness function, which is used to measure the effectiveness of the anomaly detection model parameter combination X. data,i is the eigenvector of industrial Internet data of dimension i, F normal is the reference feature vector of the normal mode of industrial Internet data, ω i is the weight coefficient, which is set based on the importance of the industrial Internet data features, σ is the sensitivity adjustment factor, which is used to dynamically adjust the sensitivity of the industrial Internet data anomaly detection model, δ is the anomaly deviation threshold, and N is the dimension of the feature vector;

[0129] S32. Initialize the fractional firefly population and initialize the anomaly detection model parameters to the initial position of the fractional firefly optimization algorithm

[0130]

[0131] in, represents a set of initial solutions of anomaly detection model parameters corresponding to the j-th firefly individual, represents the initial value of the d-th dimension model parameter of the j-th firefly, which is used to set the sensitivity and threshold of the anomaly detection model. D is the total dimension of the parameters to be optimized in the anomaly detection model, and M1 is the population size.

[0132] S33. Set a unified fractional-order parameter ν and introduce a dynamic memory factor θ(t) based on the abnormal change trend of industrial Internet data. Define the dynamic memory factor as the ratio of the real-time abnormal level of industrial Internet data to the historical abnormal level. Adjust the historical memory length of the fractional-order firefly algorithm in real time:

[0133]

[0134] Among them, θ(t) is a dynamic memory factor, which is used to adaptively adjust the response speed of individual fireflies to abnormal changes in industrial Internet data in real time; and are the anomaly detection fitness function values ​​of the global optimal positions of the current and previous iterations, respectively, and ε is a minimum constant to prevent division by zero errors;

[0135] S34. The positions of individual fireflies are iteratively updated using a fractional-order firefly position update method based on a dynamic memory factor. The fractional-order firefly position update method is expressed as:

[0136]

[0137] in, is the new position of the j-th firefly individual after the t+1th iteration, that is, the optimized position of the anomaly detection model parameters, α is the step size factor, and θ(t) is the dynamic memory factor calculated based on the anomaly level of real-time data of the Industrial Internet. is the fractional-order differential coefficient determined by the fractional-order parameter ν, L is the maximum number of historical memory steps, β is the firefly attraction coefficient, γ is the attraction attenuation coefficient, r j,q is the Euclidean distance between the position of firefly individual j and the brighter individual q;

[0138] S35. Based on the evaluation results of the anomaly detection fitness function f(X) calculated in real time based on the industrial Internet data, the firefly population position is continuously updated iteratively. When the optimization stop condition is reached, the preliminary anomaly detection model parameter set X for industrial Internet data is obtained. optimal :

[0139]

[0140] S36. The representation of the preliminary anomaly detection model is the anomaly detection fitness function M after optimization based on the fractional-order firefly optimization algorithm. initial (X):

[0141]

[0142] Among them, M initial (X) represents the preliminary anomaly detection model, λ is the regularization coefficient, X optimal,d is the d-th dimension anomaly detection model parameter after fractional-order firefly optimization, X prev,d It is the d-th dimension anomaly detection model parameter obtained in the previous round of optimization.

[0143] In this embodiment, S4 includes the following steps:

[0144] S41. Use Logistic chaotic mapping to perturb the fractional firefly population in the preliminary anomaly detection model and define the chaotic perturbation sequence

[0145]

[0146] in, is the chaotic perturbation value of the j-th firefly individual in the t+1 generation, μ is the control parameter of the Logistic chaotic mapping, is the disturbance value of the tth generation, the initial value Set by random distribution;

[0147] S42. Based on the Logistic chaos perturbation, the search step of fractional fireflies is adjusted to make the search step of fractional fireflies have higher population diversity:

[0148]

[0149] in, is the dynamic step length of the j-th firefly individual in the t+1 generation, α min and α max are the minimum and maximum values ​​of the step length respectively;

[0150] S43. Combining the theory of fractional calculus, the positions of individual fractional fireflies are adjusted based on chaotic perturbations. The disturbance-corrected fractional position update is defined as:

[0151]

[0152] in, is the optimized parameter of the j-th firefly individual in the t+2 generation;

[0153] S44. Logistic chaos mapping is used to adaptively balance global search and local search in the fractional-order firefly optimization algorithm, and a search adjustment factor is introduced:

[0154]

[0155] in, is the search adjustment factor of the j-th firefly individual in the t+1 generation, η1 is the smoothing control parameter, is the mean value of the chaotic disturbance of the current population;

[0156] S45. Use Logistic chaotic mapping to dynamically adjust parameters and define the dynamic adjustment function:

[0157]

[0158] in, is the optimized parameter of the j-th firefly individual in the t+2 generation, is the optimized parameter of the j-th firefly individual in the t+1 generation;

[0159] S46. After multiple iterations, when the anomaly detection model optimization converges, an optimized anomaly detection model M is generated. optimal (X).

[0160] In this embodiment, S5 includes the following steps:

[0161] S51. Based on the optimized anomaly detection model M optimal (X) Industrial Internet data feature matrix F data Perform real-time monitoring and calculate the deviation d of each data point relative to the normal mode i ;

[0162] S52. Set an anomaly threshold τ and calculate the anomaly probability for each data point based on the historical anomaly distribution of industrial Internet data:

[0163]

[0164] in, is the abnormal probability of the i-th industrial Internet data, λ1 is the steepness adjustment factor of the abnormal probability curve, which controls the relationship between abnormal probability and deviation, and τ1 is the abnormal threshold;

[0165] S53. Based on abnormal probability Determine anomalies in industrial Internet data and set anomaly detection rules:

[0166]

[0167] Among them, A i is the abnormality judgment mark of the i-th industrial Internet data, if A i =1, the data is judged to be abnormal data, otherwise it is judged to be normal data, P th is the abnormal probability judgment threshold, which is used to distinguish normal data from abnormal data;

[0168] S54. Calculate the abnormal proportion of the entire industrial Internet data flow:

[0169]

[0170] Among them, R anom The abnormal proportion of the current industrial Internet data flow, indicating the proportion of abnormal data in the entire industrial Internet data flow;

[0171] S55. Combined with the abnormal proportion of industrial Internet data Ranom and abnormal judgment result A i , generate preliminary anomaly detection results D anom :

[0172] D anom ={d i ∣A i =1,d i ∈F data}.

[0173] An AI-based industrial Internet data security protection system is used to implement an AI-based industrial Internet data security protection method, including:

[0174] The data acquisition module is used to collect real-time data from the Industrial Internet. The real-time data of the Industrial Internet includes data sources from sensor equipment, control systems, monitoring systems and production management platforms, set the collection time window, and build the Industrial Internet data set;

[0175] The data preprocessing module is used to preprocess the collected industrial Internet data, including data cleaning, data standardization and redundant information removal, in order to build a standardized industrial Internet data set;

[0176] The feature extraction module is used to extract data features from the standardized industrial Internet data set and construct an industrial Internet data feature matrix. Each feature dimension is used to characterize the dynamics, spatial correlation, and potential abnormal distribution patterns of industrial Internet data;

[0177] The anomaly detection model construction module is used to build an anomaly detection model based on the industrial Internet data feature matrix. The fractional-order firefly optimization algorithm is used to globally optimize the anomaly detection model. The initial anomaly detection model is formed by initializing the fractional-order firefly population and setting unified fractional-order parameters.

[0178] The anomaly detection model optimization module is used to optimize the preliminary anomaly detection model. It uses the Logistic chaos map to perturb the fractional firefly population and dynamically adjust the parameters to ultimately generate the optimized anomaly detection model.

[0179] The real-time monitoring and anomaly determination module is used to monitor industrial internet data in real time based on the optimized anomaly detection model. By comparing the industrial internet data with the normal pattern defined by the anomaly detection model, the deviation degree of the data is calculated, and anomaly determination is made based on the set anomaly threshold. This module identifies abnormal industrial internet data that deviates from the normal pattern and generates preliminary anomaly detection results.

[0180] The feedback optimization and anomaly warning module is used to perform adaptive feedback processing on the preliminary anomaly detection results, dynamically adjust the relevant parameters in the fractional-order firefly optimization algorithm and the logistic chaos map according to the feedback results, and update the anomaly detection model. At the same time, the final anomaly detection results are linked with the industrial Internet data monitoring system to trigger the anomaly warning mechanism and achieve security protection of data in the industrial Internet environment.

[0181] Example 1:

[0182] On April 10, 2024, a large-scale intelligent manufacturing enterprise detected abnormal network traffic fluctuations on its industrial Internet platform. The enterprise has hundreds of networked intelligent CNC machine tools, robots and sensor equipment. All equipment is connected to the production management system, remote maintenance platform and cloud computing center through the industrial Internet. Due to the openness of the industrial Internet, networked devices are vulnerable to external attacks, including DDoS attacks, data tampering, and malicious code injection, resulting in production data leakage or abnormal equipment operation.

[0183] Traditional security detection methods rely on rule matching and simple statistical analysis to identify network attacks. However, with the continuous upgrading of attack methods, attackers often use hybrid attack methods to bypass existing security protection measures, making existing methods difficult to work when facing highly concealed and dynamically changing attack patterns. Therefore, the company decided to introduce this invention to improve the accuracy and real-time performance of anomaly detection and prevent network security risks.

[0184] April 10, 2024, 2:07 PM — Initial detection of abnormal network traffic:

[0185] In a factory's production network, the Industrial Internet Security Monitoring System detected abnormal traffic from a device with a source IP address of 192.168.1.100, a remotely controlled intelligent PLC (Programmable Logic Controller). Over the past 15 minutes, the device's outbound data packets had increased 4.3 times compared to normal, and its traffic anomaly score exceeded the system's threshold. The method, based on an optimized anomaly detection model, calculated the device's anomaly deviation to be 2.8, exceeding the set threshold of 1.5, identifying it as potentially abnormal traffic.

[0186] April 10, 2024, 2:08 PM — Enhanced detection of logistic chaos disturbances to accurately identify attack types:

[0187] To further confirm the abnormal behavior, the proposed method uses logistic chaos perturbations to enhance the global search capabilities of the anomaly detection model. The system analyzed 48 hours of historical traffic data within 2 seconds and discovered that the PLC device established a TCP connection with an unknown external IP address (45.77.89.210) between 04:00 and 06:30. This IP address had never appeared in the device's normal access history. This connection sent a large number of data packets in a short period of time, consistent with the characteristics of a data exfiltration attack.

[0188] After further analyzing the data packet characteristics, the system discovered that some of the PLC device's data packets contained suspicious Base64-encoded instruction fragments, suggesting a malicious attacker attempting to remotely control the device through an industrial protocol. Combining multiple indicators, the system identified this unusual behavior as a potential PLC remote hijacking attack.

[0189] Anomaly Detection Detail Report

[0190] Affected devices: PLC192.168.1.100;

[0191] Monitoring time: April 10, 2024, 14:08;

[0192] Abnormal type: PLC remote hijacking attack (data penetration + command injection);

[0193] Suspicious traffic source: 45.77.89.210;

[0194] Data packet anomaly score: 98.6% (average score under normal conditions: 4.5%);

[0195] Attack behavior characteristics: continuous high-frequency data packet transmission, abnormal remote connections, and suspicious Base64-encoded instructions;

[0196] System judgment: high risk;

[0197] April 10, 2024, 2:09 PM — A system alert is triggered, and the security team receives the following message:

[0198] After detecting a remote PLC hijacking attack, the system automatically triggers an abnormal warning mechanism and pushes alarm information to the security team in real time via SMS, email, and the industrial Internet security monitoring platform. At the same time, the system automatically executes a blocking strategy, isolates the TCP connection between 192.168.1.100 and 45.77.89.210, and records all suspicious data packets for subsequent security analysis.

[0199] April 10, 2024, 2:12 PM — The security team intervenes and verifies the attack:

[0200] Upon receiving the alert, the factory's security team immediately retrieved relevant logs from the Industrial Internet Security Monitoring Platform and conducted a deep inspection of the data packets using the traffic analysis tool Wireshark. This analysis confirmed that the attacker had exploited the Modbus-TCP ports open on the PLC devices for vulnerabilities over the previous three days and successfully bypassed the basic firewall at 04:10, establishing a covert remote control channel.

[0201] The attacker attempted to transmit control commands using Base64 encoding, attempting to change the PLC's logic control program and remotely control the automated assembly line. Fortunately, the method of the present invention identified and blocked the attack nine minutes before the attacker could execute the critical commands, avoiding a potential production safety accident.

[0202] To evaluate the detection effectiveness of the method of the present invention, the security team also used traditional security detection methods (based on SVM, LSTM, and rule-based intrusion detection system IDS) for comparison and recorded the detection efficiency and accuracy of each method. The data is shown in Table 1 below:

[0203] Table 1 Comparative experimental data of industrial Internet data security protection detection methods

[0204]

[0205] From the comparative data, it can be seen that the method of the present invention achieves a detection accuracy of 98.6%, which is 16.1% higher than the traditional rule-based IDS method and 7.4% higher than the LSTM method, and the false detection rate is only 2.8%, which is 77.6% lower than the SVM method and 62.2% lower than the LSTM method.

[0206] In addition, in terms of computing time, the method of the present invention only takes 13.2 seconds, which is 67.4% less than the LSTM method, achieving rapid detection and real-time warning, and successfully preventing remote hijacking attacks on PLC devices.

[0207] This embodiment successfully applied the method of the present invention in the industrial Internet environment to accurately detect and warn potential PLC remote hijacking attacks. Compared with traditional methods, the method of the present invention has higher detection accuracy, faster response speed and lower false detection rate. In actual application, it successfully identified the attack behavior 9 minutes in advance and blocked it before the attacker executed key control commands, avoiding possible production safety accidents, and proving the efficiency and practical value of the present invention in the field of industrial Internet data security protection.

[0208] Based on the traditional firefly optimization algorithm, this paper introduces fractional calculus theory and constructs a new position update mechanism through fractional derivatives, so that the algorithm can achieve a better balance between global search and local optimization. In the process of industrial Internet data anomaly detection, the fractional difference strategy enables the firefly individual to retain historical search information during the update process and dynamically adjust the step size to improve the diversity and flexibility of the search path.

[0209] This paper uses Logistic chaotic mapping to perturb the fractional-order firefly optimization algorithm, improving the algorithm's global exploration capability in complex industrial Internet data environments. By introducing Logistic chaotic perturbation, the positions of individual fireflies are nonlinearly and dynamically adjusted during the optimization process, making the individuals more evenly distributed in the high-dimensional data space and enhancing the algorithm's ability to escape local optimality. In addition, the introduction of Logistic chaotic mapping enables the model to adapt to dynamic changes in the industrial Internet environment more quickly, and the optimized anomaly detection model has a faster response speed when facing sudden anomalies.

[0210] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.

Claims

1. An AI-based industrial Internet data security protection method, characterized in that: The steps include: S1. Collect and preprocess real-time industrial Internet data to build a standardized industrial Internet dataset; S2. Extract features from the industrial Internet data set and construct an industrial Internet data feature matrix; S3. Build an anomaly detection model based on the industrial internet data feature matrix and globally optimize the anomaly detection model using the fractional-order firefly optimization algorithm to form a preliminary anomaly detection model; S4. using a logistic chaotic map to perturb the fractional firefly population in the preliminary anomaly detection model and dynamically adjust its parameters to generate an optimized anomaly detection model; S5. Monitor the Industrial Internet data in real time based on the optimized anomaly detection model, identify abnormal Industrial Internet data that deviates from the normal pattern by comparing the Industrial Internet data with the normal pattern defined in the optimized anomaly detection model, and generate preliminary anomaly detection results; S6. Perform adaptive feedback processing on the preliminary anomaly detection results, adjust relevant parameters in the fractional-order firefly optimization algorithm and the logistic chaos map based on the feedback results, and update the anomaly detection model to form the final anomaly detection results; S7. Link the final anomaly detection results with the industrial Internet data monitoring system to trigger the anomaly warning mechanism and achieve security protection of data in the industrial Internet environment.

2. The AI-based industrial Internet data security protection method according to claim 1 is characterized in that: Said S1 comprises the following steps: S11. Collect real-time data from the Industrial Internet, including data sources from sensor equipment, control systems, monitoring systems, and production management platforms. Set the collection time window and define the Industrial Internet dataset D. raw for: Among them, d i represents the i-th piece of industrial Internet data, N is the total number of collected industrial Internet data, t i is the timestamp of the industrial Internet data, v i is numerical information, s i is the device identifier of the industrial Internet data source, c i It is the category label of industrial Internet data; S12. Clean the industrial internet dataset to remove invalid data, duplicate data, and abnormal data to obtain a cleaned industrial internet dataset; S13. Perform data standardization on the industrial Internet data set, normalize the industrial Internet data to the interval [a, b], and obtain the standardized industrial Internet data set D norm ; S14. Remove redundant information from the standardized industrial Internet dataset to construct the final standardized industrial Internet dataset D final , the redundant information removal includes feature selection based on correlation analysis, and defines the feature correlation matrix R: Among them, R i,j is the correlation coefficient of the industrial Internet data of the i-th dimension and the j-th dimension, M is the number of data samples, and is the mean of the industrial Internet data of the corresponding dimension, if R i,j If the redundancy threshold τ is exceeded, the highly redundant dimensional data will be removed, and finally a standardized industrial Internet dataset D will be formed. final : ″″″′ D final ={d i ∣d i =(t i ,v i ,s i ,c i ),d i ∈D norm }; ″′″ Among them, v i Represents the numerical information after redundancy removal, d i represents the normalized data point, d i Represents the data points after redundancy removal.

3. The AI-based industrial Internet data security protection method according to claim 1 is characterized in that: The S2 comprises the following steps: S21. Based on the standardized industrial Internet dataset D final Extract time series features from industrial Internet data and construct the time series feature matrix F time ,The time series characteristics include the changing trend, short-term volatility and long-term stability of industrial Internet data at different times; S22. Based on the standardized industrial Internet dataset D final Extract the spatial distribution features of industrial Internet data and construct the spatial distribution feature matrix F space , the spatial distribution feature is used to characterize the correlation of data between devices; S23. Based on the standardized industrial Internet dataset D final Extract correlation features from industrial Internet data and construct correlation feature matrix F corr , the correlation feature is used to measure the degree of correlation between different data; S24. Based on the standardized industrial Internet dataset D final Extract abnormal pattern features from industrial Internet data and construct abnormal pattern feature matrix F anom , the abnormal pattern features are used to identify abnormal distribution of industrial Internet data; S25. Combined with time series feature matrix F time , spatial distribution feature matrix F space , correlation feature matrix F corr and abnormal pattern feature matrix F anom , construct the industrial Internet data feature matrix F data : F data ={F time ,F space ,F corr ,F anom }。 4. The AI-based industrial Internet data security protection method according to claim 1 is characterized in that: The S3 includes the following steps: S31. Based on the Industrial Internet data feature matrix F data Build an anomaly detection model. The anomaly detection model aims to monitor abnormal changes in industrial Internet data in real time and defines the anomaly detection fitness function: Among them, f(X) is the value of the anomaly detection fitness function, which is used to measure the effectiveness of the anomaly detection model parameter combination X. data,i is the eigenvector of industrial Internet data of dimension i, F normal is the reference eigenvector of the normal mode of industrial Internet data, ω i is the weight coefficient, which is set based on the importance of the industrial Internet data features, σ is the sensitivity adjustment factor, which is used to dynamically adjust the sensitivity of the industrial Internet data anomaly detection model, δ is the anomaly deviation threshold, and N is the dimension of the feature vector; S32. Initialize the fractional firefly population and initialize the anomaly detection model parameters to the initial position of the fractional firefly optimization algorithm in, represents a set of initial solutions of anomaly detection model parameters corresponding to the j-th firefly individual, represents the initial value of the d-th dimension model parameter of the j-th firefly, which is used to set the sensitivity and threshold of the anomaly detection model. D is the total dimension of the parameters to be optimized in the anomaly detection model, and M1 is the population size. S33. Set a unified fractional-order parameter ν and introduce a dynamic memory factor θ(t) based on the abnormal change trend of industrial Internet data. Define the dynamic memory factor as the ratio of the real-time abnormal level of industrial Internet data to the historical abnormal level, and adjust the historical memory length of the fractional-order firefly algorithm in real time: Among them, θ(t) is a dynamic memory factor, which is used to adaptively adjust the response speed of individual fireflies to abnormal changes in industrial Internet data in real time; and are the anomaly detection fitness function values ​​of the global optimal positions of the current and previous iterations, respectively, and ε is a minimum constant to prevent division by zero errors; S34. The positions of individual fireflies are iteratively updated using a fractional-order firefly position update method based on a dynamic memory factor. The fractional-order firefly position update method is expressed as: in, is the new position of the j-th firefly individual after the t+1th iteration, that is, the optimized position of the anomaly detection model parameters, α is the step size factor, and θ(t) is the dynamic memory factor calculated based on the anomaly level of real-time data of the Industrial Internet. is the fractional-order differential coefficient determined by the fractional-order parameter ν, L is the maximum number of historical memory steps, β is the firefly attraction coefficient, γ is the attraction attenuation coefficient, r j,q is the Euclidean distance between the position of firefly individual j and the brighter individual q; S35. Based on the evaluation results of the anomaly detection fitness function f(X) calculated in real time based on the industrial Internet data, the firefly population position is continuously updated iteratively. When the optimization stop condition is reached, the preliminary anomaly detection model parameter set X for industrial Internet data is obtained. optimal : S36. The representation of the preliminary anomaly detection model is the anomaly detection fitness function M after optimization based on the fractional-order firefly optimization algorithm. initial (X): Among them, M initial (X) represents the preliminary anomaly detection model, λ is the regularization coefficient, X optimal,d is the d-th dimension anomaly detection model parameter after fractional-order firefly optimization, X prev,d It is the d-th dimension anomaly detection model parameter obtained in the previous round of optimization.

5. The AI-based industrial Internet data security protection method according to claim 1 is characterized in that: The S4 comprises the following steps: S41. Use Logistic chaotic mapping to perturb the fractional firefly population in the preliminary anomaly detection model and define the chaotic perturbation sequence in, is the chaotic perturbation value of the j-th firefly individual in the t+1 generation, μ is the control parameter of the Logistic chaotic mapping, is the disturbance value of the tth generation, the initial value Set by random distribution; S42. Based on the Logistic chaos perturbation, the search step of fractional fireflies is adjusted to make the search step of fractional fireflies have higher population diversity: in, is the dynamic step length of the j-th firefly individual in the t+1 generation, α min and α max are the minimum and maximum values ​​of the step length respectively; S43. Combining the theory of fractional calculus, the positions of individual fractional fireflies are adjusted based on chaotic perturbations. The disturbance-corrected fractional position update is defined as: in, is the optimized parameter of the j-th firefly individual in the t+2 generation; S44. Logistic chaos mapping is used to adaptively balance global search and local search in the fractional-order firefly optimization algorithm, and a search adjustment factor is introduced: in, is the search adjustment factor of the j-th firefly individual in the t+1 generation, η1 is the smoothing control parameter, is the mean value of the chaotic disturbance of the current population; S45. Use Logistic chaotic mapping to dynamically adjust parameters and define the dynamic adjustment function: in, is the optimized parameter of the j-th firefly individual in the t+2 generation, is the optimized parameter of the j-th firefly individual in the t+1 generation; S46. After multiple iterations, when the anomaly detection model optimization converges, an optimized anomaly detection model M is generated. optimal (X).

6. The AI-based industrial Internet data security protection method according to claim 1 is characterized in that: The S5 comprises the following steps: S51. Based on the optimized anomaly detection model M optimal (X) Industrial Internet data feature matrix F data Perform real-time monitoring and calculate the deviation d of each data point relative to the normal mode i ; S52. Set an anomaly threshold τ and calculate the anomaly probability for each data point based on the historical anomaly distribution of industrial Internet data: in, is the abnormal probability of the i-th industrial Internet data, λ1 is the steepness adjustment factor of the abnormal probability curve, which controls the relationship between abnormal probability and deviation, and τ1 is the abnormal threshold; S53. Based on abnormal probability Determine anomalies in industrial Internet data and set anomaly detection rules: Among them, A i is the abnormality judgment mark of the i-th industrial Internet data, if A i =1, the data is judged to be abnormal data, otherwise it is judged to be normal data, P th is the abnormal probability judgment threshold, which is used to distinguish normal data from abnormal data; S54. Calculate the abnormal proportion of the entire industrial Internet data flow: Among them, R anom The abnormal proportion of the current industrial Internet data flow, indicating the proportion of abnormal data in the entire industrial Internet data flow; S55. Combined with the abnormal proportion of industrial Internet data R anom and abnormal judgment result A i , generate preliminary anomaly detection results D anom : D anom ={d i ∣A i =1,d i ∈F data }。 7. An AI-based industrial Internet data security protection system, used to execute an AI-based industrial Internet data security protection method according to any one of claims 1 to 6, characterized in that: include: The data acquisition module is used to collect real-time data from the Industrial Internet. The real-time data from the Industrial Internet includes data sources from sensor equipment, control systems, monitoring systems, and production management platforms, set the collection time window, and construct the Industrial Internet data set; The data preprocessing module is used to preprocess the collected industrial Internet data, including data cleaning, data standardization and redundant information removal, in order to build a standardized industrial Internet data set; The feature extraction module is used to extract data features from the standardized industrial Internet data set and construct an industrial Internet data feature matrix. Each feature dimension is used to characterize the dynamics, spatial correlation, and potential abnormal distribution patterns of industrial Internet data; The anomaly detection model construction module is used to build an anomaly detection model based on the industrial Internet data feature matrix. The fractional-order firefly optimization algorithm is used to globally optimize the anomaly detection model. The initial anomaly detection model is formed by initializing the fractional-order firefly population and setting unified fractional-order parameters. The anomaly detection model optimization module is used to optimize the preliminary anomaly detection model. It uses the Logistic chaos map to perturb the fractional firefly population and dynamically adjust the parameters to ultimately generate the optimized anomaly detection model. The real-time monitoring and anomaly determination module is used to monitor industrial internet data in real time based on the optimized anomaly detection model. By comparing the industrial internet data with the normal pattern defined by the anomaly detection model, the deviation degree of the data is calculated, and anomaly determination is made based on the set anomaly threshold. This module identifies abnormal industrial internet data that deviates from the normal pattern and generates preliminary anomaly detection results. The feedback optimization and anomaly warning module is used to perform adaptive feedback processing on the preliminary anomaly detection results, dynamically adjust the relevant parameters in the fractional-order firefly optimization algorithm and the logistic chaos map according to the feedback results, and update the anomaly detection model. At the same time, the final anomaly detection results are linked with the industrial Internet data monitoring system to trigger the anomaly warning mechanism and achieve security protection of data in the industrial Internet environment.

Citation Information

Patent Citations

  • Graphomer-based industrial control system anomaly detection method

    CN115034304A

  • Industrial internet security situation assessment system based on deep learning

    CN119324819A