Industrial internet security supervision method and system

By calculating the uniformity of density of data points and dynamically adjusting the initial value, the problem that single-value abnormality detection is difficult to adapt to different operating states is solved, and the accuracy of abnormality detection and system reliability are improved.

CN120123949AActive Publication Date: 2025-06-10SHANXI NETCHINA INFORMATION IND CO LTD

Patent Information

Application Number
CN202510584691.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-06-10
Estimated Expiration
2045-05-08

AI Technical Summary

Technical Problem

In the prior art, a single value abnormality detection is difficult to meet data changes in different operating states, resulting in a decrease in the accuracy of abnormality detection.

Method used

By calculating the density uniformity of each data point and dynamically adjusting the initial value according to the ratio of the density uniformity to the preset density threshold, each data point is detected using significant values.

Benefits of technology

It improves the accuracy of abnormal detection, reduces false alarms and missed reports, optimizes the allocation of monitoring resources, and improves the reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120123949A_ABST
    Figure CN120123949A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data processing, in particular to an industrial internet security supervision method and system, and the method comprises the steps: obtaining the operation data of equipment in industrial internet security supervision, setting an initial k value for each data point in the operation data, obtaining the neighborhood data points of each data point, and setting an initial k value for each data point; calculating a reference weight of the neighborhood data points based on the Euclidean distance and the acquisition time sequence of the neighborhood data points, calculating a density uniformity degree of each data point according to the reference weight, and correcting the initial k value according to a ratio between the density uniformity degree of the data points and a preset density threshold value to obtain a significant k value; and performing LOF anomaly detection on each data point by using the significant k value to obtain the anomaly degree of each data point, and detecting corresponding abnormal equipment in the industrial internet. According to the method, the proper k value is adaptively selected according to the actual distribution characteristics of the data points, so that the abnormal data points are detected more accurately, and misinformation and missing report are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing. More specifically, the present invention relates to an industrial Internet security supervision method and system. Background Art

[0002] The industrial Internet is gradually transforming towards intelligence and digitization in various industries. Many industries such as manufacturing, energy, transportation, etc. are actively exploring and implementing effective security supervision methods and systems. The industrial Internet security supervision method and system are in a stage of rapid development. However, enterprises still need to face challenges during the implementation process and find effective solutions to ensure the stability and security of their systems. Currently, the LOF algorithm is usually used to detect abnormal data in the operation data of each device in the industrial Internet, and then obtain the possible abnormal risk factors in the industrial Internet.

[0003] The existing Chinese patent application document with the publication number CN119356197A discloses an industrial Internet device operation status monitoring method and system, including: a control terminal, which is the main control end of the system and is used to issue execution commands; a network configuration module, which is used to configure the local area network to serve all devices in the system and the area; an analysis module, which is used to analyze the operation parameters of the devices; a monitoring module, which is used to monitor the operation parameters of the acquisition devices in real time; a determination module, which is used to determine whether the device operation parameters obtained by the monitoring module are within the device safe operation parameter threshold range set by the setting unit of the lower-level sub-module of the analysis module.

[0004] This application document needs to collect the parameters of each device to set the device operation safety threshold range, and then obtain the working state during the device operation process to ensure that device failure problems can be sensed in advance and discovered in time. Currently, the LOF anomaly detection algorithm is usually used to perform anomaly detection on the operation data of industrial Internet devices. Since there are different operation states during the device operation process, a single value of anomaly detection is difficult to meet the data changes under different operation states. If the value is too large, the local reachability density of all data points will be relatively similar, making it difficult to detect abnormal data points. If the value is too small, it will be sensitive to the local density of data points, resulting in misdetection of some normal data points as abnormal. Summary of the Invention

[0005] To solve the problem that during the device operation process, there are different operation states, and a single value of anomaly detection is difficult to meet the data changes under different operation states and reduce the accuracy of anomaly detection, the present invention provides solutions in the following aspects.

[0006] In a first aspect, an industrial Internet security supervision method includes: obtaining the operation data of devices in industrial Internet security supervision, where the operation data includes: temperature, pressure, operation speed, device vibration frequency, and environmental temperature and humidity data; setting an initial value for each data point in the operation data, obtaining the neighborhood data points of each data point, and calculating the reference weight of the neighborhood data points based on the Euclidean distance and acquisition time sequence of the neighborhood data points; taking any data point as a marked data point, sorting all the neighborhood data points of the marked data point to obtain a neighborhood sorting sequence, calculating the difference between any item of data of the marked data point and the average value of the corresponding item of data of the neighborhood data points, and dividing by the absolute value after normalizing by the range of any item of data in the neighborhood data of the marked data point to obtain the relative position difference; calculating the absolute value of the difference between the difference between the corresponding item of data of two adjacent data in the neighborhood sorting sequence of the marked data point divided by the average distribution density and 1, obtaining the relative deviation, summing the relative deviation with the reference weight of the neighborhood data as the weight, and multiplying by the relative position difference to obtain the density uniformity of any item of data in the neighborhood data of the marked data point; taking the average value of the sum of the density uniformities of each item of data of the marked data point as the density uniformity of the marked data point; dividing the ratio between the density uniformity of the data point and the preset density threshold by the initial value to obtain a significant value; using the significant value to perform LOF anomaly detection on each data point to obtain the anomaly degree of each data point, and detecting the corresponding abnormal devices in the industrial Internet.

[0007] The effect is that by introducing the Euclidean distance and acquisition time sequence to calculate the reference weight, it can more accurately evaluate the influence of neighborhood data points on the current data point. Making the anomaly detection more refined, being able to better capture the changes in local data. By dynamically adjusting the value, it can not only more accurately identify abnormal data points, thereby optimizing the allocation of monitoring resources, concentrating resources to monitor the abnormal area more frequently, reducing the waste of resources in the normal area, but also more accurately identify abnormal data points, reducing false alarms and missed detections, and improving the monitoring efficiency and system reliability.

[0008] By analyzing the density uniformity of the marked data point, it reflects that the higher the density uniformity, the more uniform the distribution of the data point in the feature space, otherwise it indicates that the distribution is more uneven and there may be anomalies; by calculating the relative position difference and relative deviation, the relative position difference reflects the difference between the data point and the average value of its neighborhood data points, and the relative deviation reflects the local change situation between the neighborhood data points, improving the accuracy of anomaly detection.

[0009] Preferably, the reference weight includes: Taking any data point as the marked data point, calculate the initial number of neighborhood data points between the marked data point and other data points using the Euclidean distance, obtain the acquisition time series of the neighborhood data points, calculate the exponential decay terms of the Euclidean distance and the time series difference between the marked data point and each neighborhood data point respectively, and multiply them to obtain the original reference weight of the marked data point corresponding to the neighborhood data point. Sum the original reference weights of all neighborhood data points as the normalization factor, and divide the original reference weight of each neighborhood data point by the normalization factor to obtain the reference weight of each neighborhood data point. Its effect is that by introducing the exponential decay terms of the Euclidean distance and the time series difference, it can more accurately evaluate the influence of neighborhood data points on the current data point, dynamically adjust the reference weight, and adapt to data changes under different operating states.

[0010] Preferably, the reference weight further includes:

[0011] Taking any data point as the marked data point, calculate the linear decay term of the time series difference between the acquisition index of the marked data point and the acquisition index of the neighborhood data point, calculate the Euclidean distance between the marked data point and each neighborhood data point, multiply the Euclidean distance by the linear decay term to obtain the original reference weight, and divide the original reference weight of each neighborhood data point by the sum of the original reference weights of all neighborhood data points to obtain the normalized reference weight. Its effect is that by introducing the similarity of data points in the feature space and the correlation analysis of data points in time, it is more conducive to capturing the change trends of data points in time and space, so as to adapt to data changes under different operating states.

[0012] Preferably, the average distribution density is the ratio between the range of any item of data in the neighborhood data of the marked data point and the number of neighborhood data points.

[0013] Preferably, obtaining the degree of abnormality of each data point includes:

[0014] Input the running data and the significant value into the LOF algorithm, use the significant value to determine the range of neighborhood data points, calculate the local reachability distance between each data point and the neighborhood data points, calculate the local outlier factor of each data according to the local reachability distance, and obtain the degree of abnormality of the running data. Input the running data and the significant value into the LOF algorithm, use the significant value to determine the range of neighborhood data points, calculate the local reachability distance between each data point and the neighborhood data points, calculate the local outlier factor of each data according to the local reachability distance, and obtain the degree of abnormality of the running data.

[0015] In a second aspect, an industrial Internet security supervision system includes: a processor and a memory, and the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the above-mentioned industrial Internet security supervision method is implemented.

[0016] The present invention has the following effects: 1. By calculating the density uniformity of each data point and dynamically adjusting the initial value according to the ratio of the density uniformity to the preset density threshold, the present invention solves the problem that a single value in the traditional LOF algorithm is difficult to adapt to different operating states, and can adaptively select a suitable value according to the actual distribution characteristics of the data points, so as to more accurately detect abnormal data points, reduce false alarms and missed alarms. Especially in an industrial environment with complex and dynamically changing data distribution, the adaptability and accuracy of anomaly detection are significantly improved.

[0017] 2. By adaptively obtaining the value of the LOF algorithm for anomaly detection according to the density uniformity of other data points around each data point, the operation of anomaly detection is performed, so that each data point can perform anomaly detection through a suitable value to obtain a more accurate anomaly detection result. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] By referring to the following detailed description with reference to the accompanying drawings, the above and other objects, features and advantages of the exemplary embodiments of the present invention will become readily understood. In the drawings, several embodiments of the present invention are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals denote the same or corresponding parts, wherein: Figure 1 is a flowchart of the method of steps S1 - S3 in an industrial Internet security supervision method according to an embodiment of the present invention.

[0019] Figure 2 is a structural block diagram of an industrial Internet security supervision system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] Hereinafter, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0021] The following will describe in detail the specific embodiments of the present invention in conjunction with the accompanying drawings.

[0022] Referring to Figure 1 , an industrial Internet security supervision method includes steps S1 - S3, specifically as follows: S1: Obtain the operation data of the devices in industrial Internet security supervision, and the operation data includes: temperature, pressure, operation speed, device vibration frequency, ambient temperature and humidity data.

[0023] It should be noted that sensors are deployed on the device to collect various operation data in real time. That is to say, the th data collected by the th device is recorded as , and the data of each device can form a matrix. A total of devices are collected, and each device has data items. The collected data is processed, for example: data cleaning: denoising, filling missing values, correcting incorrect data; data dimensionality reduction: reducing the data dimension through the principal component analysis method to reduce the computational complexity.

[0024] S2: Set an initial value for each data point in the operation data, obtain the neighborhood data points of each data point, and calculate the reference weight of the neighborhood data points based on the Euclidean distance and acquisition time series of the neighborhood data points. Calculate the density uniformity degree of each data point according to the reference weight, and use the ratio between the density uniformity degree of the data point and the preset density threshold to correct the initial value to obtain a significant value.

[0025] It should be noted that for the operation state data of the device, if the data point is in a density-uniform area, a smaller value is required to capture the local detail feature changes. For areas with a relatively low local density uniformity degree, a larger value is used to improve the fault tolerance for normal data therein.

[0026] Furthermore, in the industrial Internet, the acquisition time (time series) of data points is a key factor. For neighborhood data points with a relatively large time series difference from the current data point, their reference value is relatively low because they may not accurately reflect the state of the current data point. For example, the device may be in different operation states at different times, so the data collected earlier may not be applicable to the evaluation of the current state. To avoid misleading the anomaly detection results by data points with a large time series difference, it is necessary to appropriately reduce the weight of these data points in the density uniformity degree calculation. The specific method is to adjust the reference weight of these data points by introducing a time series attenuation factor (such as exponential attenuation or linear attenuation). This can ensure that the anomaly detection depends more on the neighborhood data points close to the time series of the current data point, thereby improving the accuracy and reliability of the detection.

[0027] The steps to obtain the reference weight are as follows: Taking any data point as the marked data point, calculate the initial The neighborhood data points of the number of values are obtained, and the acquisition time sequence of the neighborhood data points is obtained. The Euclidean distance and the exponentially decaying term of the time sequence difference between the labeled data point and each neighborhood data point are calculated respectively, and the product is taken to obtain the original reference weight of the labeled data point corresponding to the neighborhood data point. The sum of the original reference weights of all neighborhood data points is used as the normalization factor, and the original reference weight of each neighborhood data point is divided by the normalization factor to obtain the reference weight of each neighborhood data point.

[0028] In this embodiment, the initial value is 17, and the implementer can adjust it according to the specific application scenario.

[0029] Specifically, the reference weight satisfies the following relational expression: ; In the formula, represents the reference weight of the th neighborhood data point of the th data point, represents the Euclidean distance between the th data point and the th neighborhood data point, represents the acquisition index of the data point, represents the th data point of the th neighborhood data point of the acquisition index, represents the number of neighborhood data points.

[0030] That is to say, reflects the similarity between the th data point and the th neighborhood data point in the feature space. The smaller the distance, the higher the similarity; reflects the correlation in time between the th data point and the th neighborhood data point. The smaller the time sequence difference, the stronger the correlation. Through normalization processing, the sum of the reference weights of all neighborhood data points is 1, maintaining the stability and comparability of the values. For any data point, the more uniform the distribution of the data between it and other surrounding data points, the more uniform the density of the surrounding data points of the data point.

[0031] In addition, in another embodiment, it further includes: Taking any data point as the marked data point, calculate the linear attenuation term of the time series difference between the acquisition index of the marked data point and the acquisition indexes of the neighboring data points, calculate the Euclidean distance between the marked data point and each neighboring data point, multiply the Euclidean distance by the linear attenuation term to obtain the original reference weight, and divide the original reference weight of each neighboring data point by the sum of the original reference weights of all neighboring data points to obtain the normalized reference weight.

[0032] Specifically, the reference weight satisfies the following relational expression: ; In the formula, represents the reference weight of the th neighboring data point of the th data point, represents the Euclidean distance between the th data point and the th neighboring data point, represents the acquisition index of the data point, represents the th neighboring data point of the th data point, represents the number of neighboring data points, represents the maximum value of the time series difference.

[0033] That is to say, represents the time series difference between the th data point and the th neighboring data point, that is, the distance in time between the two data points. By normalizing the time series difference with the maximum value among all time series differences, the smaller the value, the closer the two data points are in time; the larger the value, the farther the two data points are in time.

[0034] When (that is, the two data points are exactly the same in time), , the weight adjustment term is 1, representing the maximum weight; when (that is, the two data points are the farthest in time), , the weight adjustment term is 0, representing the minimum weight.

[0035] The steps to obtain the density uniformity degree are as follows: Taking any data point as the marked data point, sort all the neighboring data points of the marked data point to obtain a neighboring sorting sequence, calculate the difference between the average value of any item of data of the marked data point and the corresponding item of data of the neighboring data points, and divide by the absolute value of the normalized range of any item of data in the neighboring data of the marked data point to obtain the relative position difference; Calculate the absolute value of the difference between the quotient of the difference between the item data of two adjacent data points in the neighborhood sorting sequence of the marked data points divided by the average distribution density and 1, to obtain the relative deviation. Sum the relative deviations with the reference weights of the neighborhood data as the weights, and multiply by the relative position difference to obtain the density uniformity of any item data in the neighborhood data of the marked data points; Take the average value of the sum of the density uniformities of the item data of the marked data points as the density uniformity of the marked data points.

[0036] Specifically, the density uniformity of each item data in the neighborhood data of the marked data points satisfies the following relational expression: ; In the formula, represents the density uniformity of the th item data in the neighborhood data of the th data point, represents the th item data of the th data point, represents the average value of the th item data of the neighborhood data points of the th data point, represents the range of the th item data in the neighborhood data of the th data point, represents the reference weight of the th neighborhood data of the th data point, and respectively represent the th item data in the th data in the neighborhood sorting sequence of the th item data and the th item data in the th data in the neighborhood sorting sequence of the th data point,

[0037] That is to say, reflects the range of the th item data in the neighborhood data of the th data point, that is, the difference between the maximum value and the minimum value, reflects the average distribution density of the neighborhood data points on the th item data. In the ideal state, the th item data of the th data point should be at the middle position of the th item data of other data points in its neighborhood, to indicate that there are distributions of other data in all directions of the th data point. Therefore, Compare with the average value of all the data in its neighborhood for the nth item. The smaller the gap, the closer it is to the middle position, and it can be considered that the distribution is more uniform. The greater the average distribution density, the sparser the distribution of the neighborhood data points on the nth item; on the contrary, the smaller the average distribution density, the denser the distribution of the neighborhood data points on the nth item; It reflects the difference between the difference and the average difference between two adjacent data in the nth neighborhood sorting sequence of the mth data point. The greater the difference, the more uneven the distribution of the nth neighborhood data of the data point. Then multiply the difference by the reference weight to obtain the weighted difference degree for measuring the distribution uniformity of each item of data of other data points around the data point; It reflects the relative position relationship between the mth data of the mth data point and the nth data of other data points in the neighborhood. In the ideal state, the mth data of the nth item should be at the middle position of the nth data of other data points in its neighborhood, to indicate that there are distributions of other data in all directions of the mth data point. Therefore, compare it with the average value of all the nth data in its neighborhood. The smaller the gap, the closer it is to the middle position, and it can be considered that the distribution is more uniform.

[0038] Specifically, the density uniformity degree of the marked data point satisfies the following relational expression: ; In the formula, represents the density uniformity degree of the mth data point, represents the number of data items of the mth data point.

[0039] In addition, in another embodiment, it further includes: Take any data point as the marked data point, sort all the neighborhood data points of the marked data point to obtain a neighborhood sorting sequence, and calculate the difference between two adjacent data in the neighborhood sorting sequence of the marked data point to obtain a neighborhood difference sequence; Calculate the sum of the squares of the differences between each difference in the neighborhood difference sequence of the marked data and the average value of the neighborhood difference sequence to obtain the local change of the neighborhood data. Divide the local change by the number of neighborhood data points and take the square root to obtain the density uniformity of each item of data of the marked data point.

[0040] Specifically, the density uniformity of each item of data in the neighborhood data of the marked data point satisfies the following relational expression: ; where, represents the density uniformity of the th item of data in the neighborhood data of the th data point, represents the value of the th item of data in the neighborhood difference sequence, represents the average value of the th neighborhood difference sequence of the th item of the

[0041] That is to say, is the difference between two adjacent items of data in the neighborhood sorting sequence of the th data point, reflecting the local change of the neighborhood data; reflects the average local change degree of the neighborhood data, and is the deviation of each difference in the neighborhood difference sequence from the average value, that is, the difference between each local change and the average local change; represents the sum of the squares of all deviations, that is, the sum of the squares of the differences between all local changes and the average local change.

[0042] Obtaining the density uniformity of the marked data point is the same as the method in the first embodiment and will not be described repeatedly.

[0043] Exemplarily, the preset density threshold is 0.47, and the implementer can set the preset density threshold according to the specific implementation situation.

[0044] S3: Use the significant value to perform LOF anomaly detection on each data point to obtain the anomaly degree of each data point, and detect the corresponding abnormal devices in the industrial Internet.

[0045] Input the running data and the significant value into the LOF algorithm. Use the significant value to determine the range of neighborhood data points, calculate the local reachability distance between each data point and the neighborhood data points, calculate the local anomaly factor of each data according to the local reachability distance, and obtain the anomaly degree of the running data.

[0046] Detect device anomalies in the industrial Internet according to the anomaly degree of data points, and conduct safety supervision in a timely manner when anomalous devices appear.

[0047] It should be noted that the local reachability distance and the local outlier factor are well-known technologies to those skilled in the art, and will not be described in detail herein.

[0048] The present invention also provides an industrial Internet security supervision system. As Figure 2 shown, the system includes a processor and a memory. The memory stores computer program instructions, and when the computer program instructions are executed by the processor, it implements an industrial Internet security supervision method according to the first aspect of the present invention.

[0049] The system also includes other components well-known to those skilled in the art such as a communication bus and a communication interface. Their settings and functions are known in the art, and thus will not be elaborated herein.

[0050] In the present invention, the aforementioned memory can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, a computer-readable storage medium can be any suitable magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc., or any other medium that can be used to store the required information and can be accessed by an application program, module, or both. Any such computer storage medium can be part of the device or accessible or connectable to the device. Any application or module described in the present invention can be implemented by computer-readable / executable instructions stored or otherwise held by such a computer-readable medium.

[0051] In the description of this specification, the meanings of "a plurality of" and "several" are at least two, such as two, three, or more, etc., unless otherwise specifically defined.

[0052] Although this specification has shown and described several embodiments of the present invention, it will be apparent to those skilled in the art that such embodiments are provided by way of example only. Many variations, modifications and alternative forms will occur to those skilled in the art without departing from the spirit and scope of the present invention. It should be understood that various alternatives to the embodiments of the invention described herein may be employed in practicing the invention.

Claims

1. An industrial Internet security supervision method, characterized in that: include: Obtain the operating data of equipment in industrial Internet security supervision, including temperature, pressure, operating speed, equipment vibration frequency, and ambient temperature and humidity data; Set the initial value for each data point in the running data. Value, obtain the neighborhood data points of each data point, and calculate the reference weight of the neighborhood data points based on the Euclidean distance and acquisition time sequence of the neighborhood data points; Take any data point as a marked data point, sort all the neighborhood data points of the marked data point to obtain a neighborhood sorting sequence, calculate the difference between any data of the marked data point and the average value of the corresponding data of the neighborhood data point, and divide it by the absolute value of the normalized range of any data in the neighborhood data of the marked data point to obtain the relative position difference; Calculate the difference between the item data of the marked data point corresponding to two adjacent data in the neighborhood sorting sequence of the marked data point, divide it by the average distribution density, and add the absolute value of the difference with 1 to obtain the relative deviation, sum the reference weight of the neighborhood data as the weight of the relative deviation, and multiply it with the product of the relative position difference to obtain the density uniformity of any item of data in the neighborhood data of the marked data point; take the average value of the sum of the density uniformity of each item of the marked data point as the density uniformity of the marked data point; The ratio between the density uniformity of the data points and the preset density threshold is used to calculate the initial The value was corrected and significant value; Significant use The LOF anomaly detection is performed on each data point to obtain the degree of anomaly of each data point, and the corresponding abnormal devices in the industrial Internet are detected.

2. According to claim 1, an industrial Internet security supervision method is characterized in that: The reference weights include: Take any data point as the marked data point and use the Euclidean distance method to calculate the initial The number of neighborhood data points with the same value is obtained, the collection time series of the neighborhood data points is obtained, the Euclidean distance and the exponential decay term of the time series difference between the marked data point and each neighborhood data point are calculated respectively, and the original reference weight of the neighborhood data point corresponding to the marked data point is obtained by multiplying them, the original reference weight of all neighborhood data points is summed up as the normalization factor, and the original reference weight of each neighborhood data point is divided by the normalization factor to obtain the reference weight of each neighborhood data point.

3. The industrial Internet security supervision method according to claim 1 is characterized in that: The reference weights also include: Take any data point as the marked data point, calculate the linear attenuation term of the timing difference between the acquisition index of the marked data point and the acquisition index of the neighboring data points, calculate the Euclidean distance between the marked data point and each neighboring data point, multiply the Euclidean distance by the linear attenuation term to obtain the original reference weight, divide the original reference weight of each neighboring data point by the sum of the original reference weights of all neighboring data points to obtain the normalized reference weight.

4. The industrial Internet security supervision method according to claim 1 is characterized in that: The average distribution density is the ratio between the range of any data item in the neighborhood data of the marked data point and the number of neighborhood data points.

5. The industrial Internet security supervision method according to claim 1 is characterized in that: The abnormality degree of each data point is obtained, including: The running data and significant The value is input into the LOF algorithm, using significant The value determines the range of the neighborhood data points, calculates the local reachable distance between each data point and the neighborhood data points, calculates the local anomaly factor of each data according to the local reachable distance, and obtains the degree of anomaly of the running data.

6. An industrial Internet security supervision system, characterized in that: include: A processor and a memory, wherein the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the industrial Internet security supervision method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Industrial internet security monitoring system and method

    CN119356197A

  • Data processing system suitable for early warning of geological disasters

    CN116304963A

  • Automobile flow data analysis and management system based on artificial intelligence

    CN116644373A

  • Method and system for monitoring running state of battery automatic short circuit antipole detection equipment

    CN119622381A

  • Concentrator operation data management method

    CN119646723A

Cited By

  • Abnormality detection method and system for refrigeration valve

    CN120744779A

  • A method and system for detecting abnormalities in refrigeration valves

    CN120744779B

  • Facility state abnormity diagnosis method and system based on robot inspection data

    CN121500944A

  • A facility state anomaly diagnosis method and system based on robot inspection data

    CN121500944B