Multi-dimensional flight data intelligent anomaly detection method
By using the feature encoding and decoding technology of deep learning networks in multidimensional flight data, establishing normal data models and identifying abnormal data, the limitations of the existing technology in the abnormal detection of multidimensional flight data are solved, and the level of intelligent detection is improved.
Patent Information
- Application Number
- CN202510189595.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-06-10
AI Technical Summary
The prior art is difficult to accurately capture complex feature relationships and dynamic change trends when processing multidimensional flight data, resulting in limitations in abnormal detection.
The similarity feature matrix of multidimensional flight data is generated through data preprocessing, and a deep learning network composed of feature encoding networks and feature decoding networks are used to establish a normal data model of multidimensional flight data and intelligently identify abnormal data.
The intelligence level of abnormal detection of multidimensional flight data has been improved, and anomaly data in multidimensional flight data can be more accurately identified.
Smart Images

Figure CN120123930A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an intelligent anomaly detection method for multi-dimensional flight data, belonging to the technical field of aviation flight data analysis. Background Art
[0002] With the rapid development of aviation technology, the dimension of flight data is constantly increasing. How to accurately identify abnormal states from these massive and multi-dimensional data is crucial for ensuring flight safety. At present, anomaly detection algorithms based on a convolutional neural network (CNN) and a long short-term memory network (LSTM) of a deep learning network are disclosed in the prior art. The above algorithms have limitations in processing multi-dimensional flight data with non-linear relationships and are difficult to accurately capture the complex feature relationships and dynamic change trends of multi-dimensional data.
[0003] Therefore, there is an urgent need to design an intelligent anomaly detection method for multi-dimensional flight data that can solve the above technical problems. Summary of the Invention
[0004] The purpose of the present invention is to overcome the deficiencies of the above prior art and provide an intelligent anomaly detection method for multi-dimensional flight data. By using multi-dimensional historical flight data of an aircraft, an algorithm is trained to establish a normal data model for multi-dimensional flight data, and the constructed model is used to intelligently identify abnormal data in multi-dimensional flight data, effectively improving the intelligent level of anomaly detection for multi-dimensional flight data.
[0005] An intelligent anomaly detection method for multi-dimensional flight data according to the present invention is characterized by including the following steps:
[0006] 1) Perform data preprocessing to complete data missing value filling, data normalization processing, and construction of a similarity feature matrix for multi-dimensional flight data;
[0007] 2) Train a normal data model. The normal data model training model consists of a feature encoding network and a feature decoding network. The feature encoding network consists of a multi-layer convolutional network, a long short-term memory (LSTM) network, and a weight assignment network based on an attention mechanism. The feature decoding network consists of a multi-layer transposed convolutional network. Calculate the residual matrix between the input multi-dimensional feature matrix and the output reconstructed feature matrix as the loss function, and backpropagate to continuously adjust and optimize the network to make the residual as small as possible. Construct the normal data model network, and set a reasonable threshold according to the loss distribution of the normal data;
[0008] 3) Perform intelligent anomaly detection. Input the multi-dimensional flight data to be detected into the trained normal data model network, calculate the loss value between the original input feature matrix and the reconstructed feature matrix. If the loss exceeds the preset threshold, it is determined as abnormal data.
[0009] Preferably, in the data preprocessing stage of step 1):
[0010] The specific steps for filling missing values are as follows: for missing values, fill them with the median of adjacent values;
[0011] The specific steps for data normalization are as follows: select one of the three common data normalization methods of Z-score, Min-max, and MaxAbs for normalization;
[0012] The specific steps for constructing the similarity feature matrix of multi-dimensional flight data are as follows: calculate the similarity of any two dimensions of data x i , x j at any time t, and construct the similarity feature matrix between multi-dimensional flight data as the input for training the network.
[0013] Preferably, the specific steps of step 1) are as follows:
[0014] Perform data preprocessing on the multi-dimensional flight data matrix X=(x 1 , x 2 ,…, x i ,…, x j ,…, x N ), complete the filling of data missing values, normalization processing, and construction of the similarity feature matrix. First, for the missing values in the flight data, fill them with the median of adjacent values. Then, to avoid the influence of the data range difference of each dimension on the calculation result of similarity, select one of the three common data normalization methods of Z-score, Min-max, and MaxAbs to perform normalization processing on the multi-dimensional flight data. Finally, construct the similarity feature matrix S=(s ij ) N×N as the input for training the network; the similarity of any two dimensions of flight data x i , x j at any time t is defined as the sum of the inner products of data within l time steps forward from time t, and the calculation formula (1):
[0015]
[0016] To better represent the similarity of any two dimensions of flight data x i , x j at any time t, calculate the similarity from l 1 , l 2 , l 3 time steps forward from time t respectively.
[0017] Preferably, the specific steps of step 2) are as follows:
[0018] The feature encoding network first extracts the local features of the multi-dimensional similarity matrix through multiple convolutional operations by a multi-layer convolutional network, then extracts the dependency relationships based on the time correlation law among the multi-dimensional flight data by a multi-layer LSTM network, and finally dynamically adjusts the importance weights of the features by a multi-layer attention mechanism to achieve efficient and accurate feature encoding;
[0019] The feature decoding network uses a deconvolution network to reverse reconstruct the feature encoding, generates a reconstructed feature matrix, calculates the residual matrix between the input original similarity feature matrix and the output reconstructed feature matrix as the loss function, and backpropagates to continuously adjust and optimize the network to make the residual as small as possible, constructs a normal data model network, and sets a reasonable threshold according to the loss distribution of the normal data;
[0020] Preferably, the convolutional network is a deep feedforward neural network composed of a convolutional layer, a pooling layer and a fully connected layer, which uses convolution instead of full connection to extract the local features of the data. The convolution formula (2) with a convolution depth of D and a convolution kernel size of F is:
[0021]
[0022] where, a i,j is the element at the i-th row and j-th column of the feature matrix after convolution, w d,m,n is the weight at the m-th row and n-th column of the d-th layer of the convolution kernel, x d,i+m,j+n represents the element at the (i + m)-th row and (j + n)-th column of the d-th layer of the matrix before convolution, w b is the bias term of the convolution kernel. Using f to represent the activation function, each layer of neurons is connected to some neurons in the previous layer using the same convolution kernel. Through the local connection and weight sharing of the convolutional network, feature extraction is achieved;
[0023] Preferably, the LSTM network is a recurrent neural network, and each neural network node is composed of 3 gates: a forget gate f, an input gate i and an output gate o; at time step t, the input vector of the LSTM hidden layer is x t , the output vector is h t , and the memory cell is c t , where, the forget gate formula (3):
[0024] f t = σ(W xf x t + W hf h t-1 + b f ) (3)
[0025] The input gate formula (4):
[0026] i t = σ(W xix t +W hi h t-1 +b i ) (4)
[0027]
[0028] Output gate formula (5):
[0029] o t =σ(W xo x t +W ho h t-1 +b o ) (5)
[0030]
[0031] where denotes element-wise multiplication of vectors; W represents weights; σ is the sigmoid function, b is the bias term, and tanh is the hyperbolic tangent function;
[0032] Preferably, the formula for calculating the probability of selecting the i-th piece of information from the information X for a given query vector q in the attention mechanism network is (6):
[0033]
[0034] where s(x i ,q) is the attention scoring function, which can be an additive calculation, dot product calculation, scaled dot product calculation, or bilinear calculation function. The probability vector α i constituted is called the attention distribution, indicating the degree of relevance between the i-th piece of information in the input information vector X and the query q. The input information is aggregated in a weighted average manner using the probability α i to obtain the Attention value formula (7):
[0035]
[0036] A multi-dimensional flight data intelligent anomaly detection method of the present invention is based on multi-dimensional historical flight data of an aircraft. After data preprocessing, a similarity feature matrix of multi-dimensional flight data is generated and input into a deep learning network composed of a feature encoding network and a feature decoding network. According to the residual matrix of the input feature matrix and the decoded and reconstructed feature matrix, the network is continuously adjusted and optimized to establish a normal data model for multi-dimensional flight data. The multi-dimensional flight data to be detected is input into the constructed deep learning network model. According to whether the residual data exceeds a set threshold, the abnormal data in the multi-dimensional flight data is intelligently identified, effectively improving the intelligent level of multi-dimensional flight data anomaly detection. Description of the Drawings
[0037] Figure 1 This is the flow chart of a multi - dimensional flight data anomaly detection method of the present invention;
[0038] Figure 2 This is the structure diagram of the LSTM network;
[0039] Figure 3 This is the change curve of the navigation altitude for six flights in Embodiment 2;
[0040] Figure 4 This is the detection result graph obtained using the same training and test data when the value of EPOCHS is 1;
[0041] Figure 5 This is the detection result graph obtained using the same training and test data when the value of EPOCHS is 10;
[0042] Figure 6 This is the detection result graph obtained using the same training and test data when the value of EPOCHS is 100. Detailed implementation manners
[0043] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0044] Embodiment 1
[0045] An intelligent anomaly detection method for multi - dimensional flight data in this embodiment is shown in the attached Figure 1 , and includes the following steps:
[0046] 1. Data pre - processing stage
[0047] Complete the filling of data missing values, normalization processing and construction of a similarity feature matrix.
[0048] The specific steps for filling the missing values are as follows: for the missing values, fill them with the median of the adjacent numerical values;
[0049] The specific steps for the data normalization processing are as follows: select one of the three common data normalization methods, namely Z - score, Min - max and MaxAbs, for normalization;
[0050] The calculation methods and applicable scopes of the three methods are shown in Table 1:
[0051] Table 1 Comparison table of data normalization methods
[0052]
[0053] Construct a multi-dimensional flight data similarity feature matrix as the input for training the network. For any two-dimensional flight data x i and x j The similarity at any time t is defined as the sum of the inner products of the data within l time steps forward from time t. The calculation formula (1) is:
[0054]
[0055] 2. Normal data model training stage
[0056] The normal data model training model consists of a feature encoding network and a feature decoding network. The feature encoding network consists of a multi-layer convolutional network, a Long Short-Term Memory (LSTM) network, and a weight assignment network based on the attention mechanism. The feature decoding network consists of a multi-layer transposed convolutional network. The network structure diagram is as shown in Figure 1 shown.
[0057] Among them, the feature encoding network first extracts the local features of the multi-dimensional similarity matrix through multiple convolutional operations by the multi-layer convolutional network, then extracts the dependency relationships based on the time correlation law between the multi-dimensional flight data by the multi-layer LSTM network, and finally dynamically adjusts the importance weights of the features by the multi-layer attention mechanism to achieve efficient and accurate feature encoding; the feature decoding network uses the transposed convolutional network to reverse reconstruct the feature encoding and generate a reconstructed feature matrix. Calculate the residual matrix between the input original similarity feature matrix and the output reconstructed feature matrix as the loss function, and backpropagate to continuously adjust and optimize the network to make the residual as small as possible. The normal data model network is constructed, and a reasonable threshold is set according to the loss distribution of the normal data.
[0058] Specifically, the convolutional network is a deep feedforward neural network composed of a convolutional layer, a pooling layer, and a fully connected layer. It uses convolution instead of full connection to extract the local features of the data. The convolution formula (2) with a convolution depth of D and a convolution kernel size of F is:
[0059]
[0060] where a i,j is the element in the i-th row and j-th column of the convolution result feature matrix, w d,m,n is the weight in the m-th row and n-th column of the d-th layer of the convolution kernel, x d,i+m,j+n represents the element in the (i + m)-th row and (j + n)-th column of the d-th layer of the matrix before convolution, w b is the bias term of the convolution kernel. Using f to represent the activation function, each layer of neurons is connected to some neurons in the previous layer using the same convolution kernel. Through the local connection and weight sharing of the convolutional network, feature extraction is achieved;
[0061] The LSTM network is a type of recurrent neural network. See the appendix Figure 2 , and each neural network node is composed of three gates: the forget gate f, the input gate i, and the output gate o. At time step t, the input vector of the LSTM hidden layer is x t , and the output vector is h t , and the memory cell is c t . Among them, the formula for the forget gate (3):
[0062] f t = σ(W xf x t + W hf h t-1 + b f ) (3)
[0063] The formula for the input gate (4):
[0064] i t = σ(W xi x t + W hi h t-1 + b i ) (4)
[0065]
[0066] The formula for the output gate (5):
[0067] o t = σ(W xo x t + W ho h t-1 + b o ) (5)
[0068]
[0069] Among them indicates element-wise multiplication of vectors; W represents weights; σ is the sigmoid function, b is the bias term, and tanh is the hyperbolic tangent function;
[0070] The formula for calculating the probability of selecting the i-th piece of information from the information X for a given query vector q in the attention mechanism network is (6):
[0071]
[0072] Among them, s(x i , q) is the attention scoring function, and this function can be an additive calculation, dot product calculation, scaled dot product calculation, or bilinear calculation function. The probability α iThe probability vector thus formed is called the attention distribution, indicating the degree of relevance between the i-th piece of information in the input information vector X and the query q. The probability α i The input information is aggregated in a weighted average manner to obtain the Attention value formula (7):
[0073]
[0074] 3. Intelligent anomaly detection stage
[0075] The multi-dimensional flight data to be detected is input into the trained normal data model network, and the loss values of the original input feature matrix and the reconstructed feature matrix are calculated. If the loss exceeds the preset threshold, it is determined as abnormal data.
[0076] In this embodiment, based on the multi-dimensional historical flight data of an aircraft, a similarity feature matrix of the multi-dimensional flight data is generated after data preprocessing and input into a deep learning network composed of a feature encoding network and a feature decoding network. According to the residual matrix of the input feature matrix and the decoded and reconstructed feature matrix, the network is continuously adjusted and optimized to establish a normal data model for the multi-dimensional flight data. The multi-dimensional flight data to be detected is input into the constructed deep learning network model, and abnormal data in the multi-dimensional flight data is intelligently identified according to whether the residual data exceeds the set threshold, effectively improving the intelligent level of the abnormal detection of the multi-dimensional flight data.
[0077] Embodiment 2
[0078] This embodiment conducts experiments using the shared flight data of the University of Minnesota laboratory in the United States. This data is the real flight data of a fixed-wing Thor-type unmanned aerial vehicle. Six flight data are selected for the experiment. The detailed information is shown in Table 2, in which the normal sample data of three flight data, namely flight97, flight98, and flight104, are used as the training data for the normal data model to train the abnormal detection deep learning network. The abnormal data samples of three flight data, namely flight111, flight112, and flight121, are used as the test data to evaluate the abnormal detection performance of the method proposed in the present invention.
[0079] Table 2 List of relevant information of the experimental data set
[0080]
[0081] The change curves of the navigation heights of the six flight data in the table over time are as Figure 3As shown. It can be seen from the figure that the changes in the navigation altitudes of the three flights, flight 97, flight 98, and flight 104, are all relatively smooth curves, indicating that the navigation altitudes of all three are within normal time series; while the red curve of flight 111 shows three altitude jumps, indicating that there are three abnormal sequences in the navigation altitude of flight 111, at time point intervals [5740, 6842], [8340, 8387], and [9967, 10035] respectively; the purple curve of flight 112 shows a bulge in the time point interval [6316, 6740], and the orange curve of flight 121 shows a bulge in the time point interval [8558, 8881], indicating that there is an abnormal sequence in the navigation altitude of both, and these abnormalities may be due to GPS errors or malfunctions in the navigation filter.
[0082] The parameter settings of each layer of the network in this embodiment are shown in Table 3:
[0083] Table 3 Network Parameter Settings Table
[0084]
[0085] As the number of iterations EPOCHS varies, the detection results of this method for the abnormal time points of UAV flight are different. Figure 4 、 5 Figures 4, 5, and 6 respectively show different detection result graphs obtained using the same training and test data when the EPOCHS value is 1, 10, and 100. The vertical axis represents the anomaly score, indicating the severity of the detected anomalies. It can be seen that as EPOCHS increases, the score range of the anomaly score rapidly shrinks. The red vertical lines mark the four true abnormal time points in the flight data of the above-mentioned two flights, 111 and 112. When EPOCHS is 100, the model can accurately predict 3 true abnormal time points from all 1000 time points of data.
[0086] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. An intelligent anomaly detection method for multi-dimensional flight data, characterized in that The following steps are involved: 1) Perform data preprocessing to complete data gap filling, data normalization and multi-dimensional flight data similarity feature matrix construction; 2) Perform normal data model training. The normal data model training model consists of a feature encoding network and a feature decoding network. The feature encoding network consists of a multi-layer convolutional network, a long short-term memory LSTM network, and a weight allocation network based on an attention mechanism. The feature decoding network consists of a multi-layer deconvolutional network. The residual matrix between the input multi-dimensional feature matrix and the output reconstructed feature matrix is calculated as the loss function, and the network is continuously adjusted and optimized by back propagation to make the residual as small as possible. The normal data model network is constructed, and a reasonable threshold is set according to the loss distribution of normal data. 3) Perform intelligent anomaly detection, input the multi-dimensional flight data to be detected into the trained normal data model network, calculate the loss value of the original input feature matrix and the reconstructed feature matrix, and if the loss exceeds the preset threshold, it is judged as abnormal data.
2. The intelligent anomaly detection method for multi-dimensional flight data of an aircraft according to claim 1 is characterized in that 1) In the data preprocessing stage: The specific steps of filling the missing values are: for the missing values, the median of the adjacent values is used to fill them; The specific steps of the data normalization process are: selecting one of the three common data normalization methods of Z-score, Min-max and MaxAbs for normalization; The specific steps of constructing the multi-dimensional flight data similarity feature matrix are: calculating any two-dimensional data x in the N-dimensional flight data i 、x j The similarity at any time t is used to construct the similarity feature matrix between N-dimensional flight data as the input of the training network.
3. The intelligent anomaly detection method for multi-dimensional flight data according to claim 2 is characterized in that The specific steps of step 1) are: The N-dimensional flight data matrix X=(x1,x2,…,x i ,…,x j ,…,x N ) to complete data preprocessing, fill in missing values, normalize and similarity feature matrix S = (s ij ) N×N First, for the missing values in the flight data, the median of the adjacent values is used to fill them. Then, in order to avoid the influence of the difference in the value range of each dimension data on the calculation result of similarity, one of the three common data normalization methods, Z-score, Min-max and MaxAbs, is selected to normalize the multidimensional flight data. Finally, the multidimensional flight data similarity feature matrix is constructed as the input of the training network. i 、x j The similarity at any time t is defined as the sum of the inner products of the data from time t to l time steps before, calculated using formula (1): In order to better characterize the two-dimensional flight data x i 、x j The similarity at any time t is calculated by moving l1, l2, and l3 time steps forward from time t.
4. The intelligent anomaly detection method for multi-dimensional flight data according to claim 1 is characterized in that The specific steps of step 2) are: The feature encoding network first uses a multi-layer convolutional network to extract local features of the multi-dimensional similarity matrix through multiple convolution operations, and then uses a multi-layer LSTM network to extract the dependency between multi-dimensional flight data based on the law of time correlation. Finally, the multi-layer attention mechanism dynamically adjusts the importance weights of the features to achieve efficient and accurate feature encoding; the feature decoding network uses a deconvolutional network to reversely reconstruct the feature encoding, generate a reconstructed feature matrix, calculate the residual matrix between the input original similarity feature matrix and the output reconstructed feature matrix as the loss function, and back-propagate to continuously adjust and optimize the network to make the residual as small as possible, complete the construction of the normal data model network, and set a reasonable threshold according to the loss distribution of normal data.
5. The intelligent anomaly detection method for multi-dimensional flight data according to claim 4 is characterized in that The convolutional network is a deep feedforward neural network composed of a convolutional layer, a pooling layer and a fully connected layer. Convolution is used instead of full connection to extract local features of data. The convolution formula (2) with a convolution depth of D and a convolution kernel size of F is: Among them, a i,j is the i-th row and j-th column element of the feature matrix after convolution, w d,m,n is the weight of the convolution kernel in the mth row and nth column of the dth layer, x d,i+m,j+n represents the element of the i+mth row and j+nth column of the dth layer matrix before convolution, w b is the bias term of the convolution kernel, and f represents the activation function. Each layer of neurons uses the same convolution kernel to connect with some neurons in the previous layer. Feature extraction is achieved through local connection and weight sharing of the convolution network.
6. The intelligent anomaly detection method for multi-dimensional flight data according to claim 4 is characterized in that The LSTM network is a recurrent neural network. Each neural network node consists of three gates: forget gate f, input gate i and output gate o. At time step t, the input vector of the LSTM hidden layer is x t , the output vector is h t , the memory unit is c t , where the forget gate formula (3) is: f t =σ(W xf x t +W hf h t-1 +b f ) (3) Input gate formula (4): i t =σ(W xi x t +W hi h t-1 +b i ) (4) Output gate formula (5): o t =σ(W xo x t +W ho h t-1 +b o ) (5) in represents the multiplication of vector elements; W represents the weight; σ is the sigmoid function, b is the bias term, and tanh is the hyperbolic tangent function.
7. The intelligent anomaly detection method for multi-dimensional flight data according to claim 4 is characterized in that The attention mechanism network is a calculation formula (6) for the probability of selecting the i-th information from the information X for a given query vector q: Among them, s(x i ,q) is the attention scoring function, which can be an additive calculation, dot product calculation, scaled dot product calculation or bilinear calculation function, and the probability α i The probability vector formed is called attention distribution, which indicates the relevance of the i-th information in the input information vector X to the query q. i The input information is summarized by weighted average to obtain the Attention value formula (7):