Monitoring and early warning method and system based on distributed terminal

By preprocessing and clustering analysis of the monitoring data of distributed terminals, abnormal data and terminals are determined, the problem of low recognition accuracy of abnormal data in the prior art is solved, and efficient abnormal identification and alarm processing is achieved.

CN120145260APending Publication Date: 2025-06-13STATE GRID ZHEJIANG ELECTRIC POWER CO LTD JINHUA POWER SUPPLY CO
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510231855.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The prior art fails to effectively utilize the characteristics of the monitoring data in environmental monitoring, resulting in low recognition accuracy of abnormal data.

Method used

By preprocessing the monitoring data of the distributed terminal, a clustered data set is obtained, and cluster analysis and feature extraction are performed based on the clustered data set, abnormal data and abnormal terminals are determined, alarm information is generated and corresponding alarm actions are performed.

Benefits of technology

It significantly improves the recognition accuracy of abnormal data, can quickly lock the distributed terminal that occurs abnormally, and accurately match the corresponding staff for maintenance when abnormalities are found.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145260A_ABST
    Figure CN120145260A_ABST
Patent Text Reader

Abstract

The invention discloses a monitoring and early warning method and system based on a distributed terminal, and belongs to the technical field of environment monitoring, and the method comprises the steps: collecting the monitoring data of the distributed terminal, and carrying out the preprocessing of the monitoring data, and obtaining a clustering data set; performing clustering analysis on the data in the clustering data set to obtain clustering features, and performing feature extraction based on the time change scale of the data in the clustering data set to obtain data stream features; performing exception identification based on the clustering features and the data flow features to determine exceptional data, and determining an exceptional terminal according to the exceptional data and a corresponding relationship between the clustering features and the distributed terminal; generating alarm information based on the abnormal data and the abnormal terminal, and executing a corresponding alarm action; according to the method, through comprehensive analysis of the data features, the recognition accuracy of the abnormal data is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of environmental monitoring, and specifically provides a monitoring and early warning method and system based on distributed terminals. Background Art

[0002] With the development of the power system, distributed power supply computer rooms have emerged to maintain the stability of the power system. Correspondingly, setting distributed terminals for environmental monitoring in distributed power supply computer rooms is a traditional environmental monitoring method. However, such a method usually simply judges whether the detected data is normal based on manually set thresholds, and it is difficult to detect hidden abnormal data, resulting in low accuracy in identifying abnormal data.

[0003] Chinese Patent, Publication No.: CN117636555A, Publication Date: March 1, 2024, discloses a theft prevention alarm system and method for drainage overhead lines, including: Step 1: Collect real-time data, terminal voltage values, and distributed terminal voltage values, and send the collected data to the server; Step 2: The server analyzes the received signals, compares the phase values corresponding to the terminal voltage values and the distributed terminal voltage values of the data acquisition terminal, and judges the line condition of the drainage overhead line according to the operating state of the transformer to determine whether the drainage overhead line has been stolen; Step 3: Make corresponding anti-theft alarm measures according to whether the drainage overhead line has been stolen and the operating state of the transformer; and this invention still simply judges whether the detected data is normal according to the preset threshold, resulting in low accuracy in identifying abnormal data. Summary of the Invention

[0004] The object of the present invention is to address the problem that the prior art does not consider the characteristics of monitoring data and simply judges whether the detected data is normal based on preset thresholds, resulting in low accuracy in identifying abnormal data; and proposes a monitoring and early warning method and system based on distributed terminals, preprocesses the monitoring data of distributed terminals to obtain a clustering data set, then performs clustering analysis on the clustering data set to obtain clustering features, extracts data flow features based on the corresponding time change scale of the clustering data set, and determines abnormal data and abnormal terminals according to the data flow features, clustering features, and the corresponding relationship between the clustering features and the distributed terminals. Finally, generates an alarm message based on the abnormal data and abnormal terminals and executes corresponding alarm actions; this application significantly improves the accuracy of identifying abnormal data through comprehensive analysis of data characteristics.

[0005] In a first aspect, a technical solution provided in an embodiment of the present invention is a monitoring and early warning method based on distributed terminals, including the following steps: Collect the monitoring data of distributed terminals, and preprocess the monitoring data to obtain a clustering data set; Cluster analysis is performed on the data in the clustering dataset to obtain clustering features, and feature extraction is performed based on the time change scale of the data in the clustering dataset to obtain data stream features; Based on the clustering features and the data stream features, anomaly recognition is performed to determine the abnormal data, and based on the correspondence between the abnormal data, the clustering features and the distributed terminals, the abnormal terminals are determined; Alarm information is generated based on the abnormal data and the abnormal terminals, and corresponding alarm actions are executed.

[0006] In this solution, corresponding distributed terminals are set for the distributed power supply machine rooms that maintain the stability of the power system to monitor the environmental status. The monitoring of the environmental status at least includes the physical working conditions in the distributed power supply machine rooms, such as temperature, humidity, ventilation conditions, etc., the physical feedback information of the staff, the network operation information of the distributed terminals, etc.; The monitoring data of the distributed terminals are collected and preprocessed operations such as missing value, outlier replacement, filtering, and establishing time tags are performed, which can eliminate the interference data generated by interference factors in the monitoring data, including missing values, outliers, irrelevant values, etc., effectively improving the accuracy and integrity of the monitoring data. The correspondence between different types of monitoring data can also be constructed through the established time tags, effectively improving the consistency of different types of monitoring data; At this time, the preprocessed monitoring data is correspondingly set as data points, and clustering analysis can be performed on the data points to analyze the potential characteristics of the data to obtain clustering features. Moreover, since different types of data in the monitoring data affect each other, when one type of data is abnormal, other types of data will undergo implicit changes. In order to analyze the implicit changes, feature extraction is performed based on the time change scale of the data in the clustering dataset to obtain data stream features, and anomaly recognition is performed based on the clustering features and the data stream features to determine the abnormal data, which can comprehensively analyze the monitoring data from one-dimensional and multi-dimensional perspectives, significantly improving the recognition accuracy of the abnormal data; Based on the correspondence between the abnormal data, the clustering features and the distributed terminals, the abnormal terminals are determined, which can quickly and accurately lock the abnormal distributed terminals and perform anomaly location with the help of the distributed terminals; Finally, alarm information is generated based on the abnormal data and the abnormal terminals, and corresponding alarm actions are executed, which can accurately match the corresponding staff when an anomaly is detected and notify the staff to perform maintenance, effectively improving the effectiveness of a monitoring and warning system based on distributed terminals.

[0007] Preferably, the specific process of collecting the monitoring data of the distributed terminals and preprocessing the monitoring data to obtain the clustering dataset is as follows: Collect the monitoring data of the distributed terminals, and perform a filtering operation on the monitoring data to obtain accurate monitoring data; Based on the statistical method, the missing values and outliers of the accurate monitoring data are statistically analyzed, and the monitoring average value is calculated based on the preset monitoring period, the accurate monitoring data, and the types of monitoring data; Replacing the missing values and outliers of accurate monitoring data based on the monitoring average value to obtain complete data; Establishing a consistent timestamp based on the time change scale of the complete data; and constructing a clustering data set based on the consistent timestamp and the complete data; The monitoring data at least includes environmental monitoring data, human feedback data, and terminal network operation data.

[0008] In this solution, filtering operations can be performed according to the frequency of the monitoring data, removing the data with abnormal frequencies. After removing the abnormal data, the monitoring data is divided into multiple data sets with time scale changes based on a preset monitoring period, and the data sets are classified according to the types of the monitoring data. At this time, the monitoring average value is calculated based on the classified data sets and the time change scale, and then the monitoring average value can be used to replace the missing values and outliers in the monitoring data. Secondly, since the data sets have time change scales, a consistent timestamp of the monitoring data can be established based on the time change scale, that is, the monitoring data collected within the same time period, regardless of whether the types are the same, can be unified into a whole according to the consistent timestamp.

[0009] Preferably, the clustering data set is stored by using a heterogeneous storage method, specifically: Extracting data features based on the data structures of the data in the clustering data set, and performing corresponding heterogeneous storage operations based on the data features to store the data in the clustering data set.

[0010] In this solution, since the types of the monitoring data are not unique, the corresponding clustering data also has multiple types. Since different types of data need to consider different conditions when being stored, such as the reading rate, transmission location, etc., data features are extracted based on the data structures corresponding to the clustering data, the storage requirement conditions for each type of data are clarified, and the storage locations for the corresponding data are selected based on the data features. After the data is transmitted to the storage locations, it is stored.

[0011] Preferably, the specific process of performing clustering analysis on the data in the clustering data set to obtain clustering features is as follows: A1. Calculating the mutual distances of the data in the clustering data set based on the Euclidean distance formula to obtain a distance vector, and sorting the distance vector; A2. Counting the number of times of the same distance vector in the sorted distance vector, and marking the data corresponding to the distance vector with the number of times greater than the preset number threshold as the initial clustering points; A3. Counting the number of data in the neighborhood of the initial clustering points, and determining the clustering parameters based on the number of data; A4. Generating a feature set based on the initial clustering points and the clustering parameters, and deleting the data in the clustering data set corresponding to the feature set to obtain a new clustering data set; A5. Determine whether to end the clustering analysis based on the new clustering dataset and the data quantity threshold. If the number of data in the new clustering dataset is greater than or equal to the data quantity threshold, update the clustering dataset based on the new clustering dataset and execute A1. If the number of data in the new clustering dataset is less than the data quantity threshold, establish clustering features based on the feature set and the generation order of the feature set, and end the clustering analysis.

[0012] Preferably, in A5, the specific process of establishing clustering features based on the feature set and the generation order of the feature set is as follows: Sort the feature set according to the generation order of the feature set, and establish an order label for the feature set based on the sorting result; integrate the feature set based on the order label to obtain clustering features.

[0013] In this solution, during the clustering analysis process, the data that has completed the clustering analysis in the clustering dataset is continuously deleted, and the clustering analysis is cycled based on the remaining data. Therefore, the feature set generated in each cycle is essentially a set of multiple data with close distances. And based on the distance of the data, the feature set also has a distance attribute. The closer the generation order of the feature sets is, the closer the distance between them. Correspondingly, the closer the distance of the data within the feature set is. An order label can be established according to the generation order of the feature set, that is, mark the first feature set, the second feature set, etc. Secondly, since the distance of the data is obtained based on the initial clustering points, that is, the data corresponding to the distance vector with the most occurrences of the same distance vector is marked as the initial clustering point. The larger the order label of the feature set, the farther the distance from the relative initial clustering point. The feature set with a smaller order label can be placed within the feature set with a larger order label for merging, that is, place the first feature set within the second feature set for merging.

[0014] Preferably, the specific process of extracting data stream features based on the time change scale of the data in the clustering dataset is as follows: Divide the clustering dataset based on a preset time window and the time change scale of the data in the clustering dataset to obtain a segment dataset; organize the segment dataset based on the types of data in the segment dataset to obtain a classified segment dataset; Conduct a correlation analysis on the data in the classified segment dataset to obtain correlation features, and organize the correlation features to obtain data stream features.

[0015] In this solution, the time window can be set according to the consistency timestamp corresponding to the data to ensure that the divided data is still within the same monitoring period. Secondly, the Pearson correlation coefficient method can be used to conduct a correlation analysis on the divided data to obtain the mutual influence relationship between different types of monitoring data within the same monitoring period.

[0016] Preferably, the specific process of determining abnormal data based on clustering features and data stream features is as follows: Calculate the mutual distances of the data in the clustering dataset based on the clustering features and the mutual distance calculation formula; Perform abnormal identification based on the mutual distance and a preset distance threshold. If the mutual distance is greater than or equal to the distance threshold, mark the corresponding data as direct abnormal data. If the mutual distance is less than the distance threshold, mark the corresponding data as normal data; determine indirect abnormal data based on the data stream features, direct abnormal data, and normal data; Sort out the direct abnormal data and indirect abnormal data to obtain abnormal data.

[0017] In this solution, since the data with overly large mutual distances have been separated during the clustering analysis process, that is, multiple feature sets established during the loop process cannot specifically determine which data is abnormal data. At this time, the mutual distances of different data in the same feature set are calculated in combination with the mutual distance calculation formula. Based on the mutual distance and the preset distance threshold, abnormal data is accurately identified. However, the abnormal data identified in this way are obvious direct abnormal data, and the indirect abnormal data that undergo hidden changes due to the direct abnormal data cannot be identified. Indirect abnormal data can be determined based on the data stream features, direct abnormal data, and normal data to find all the abnormal data in the monitoring data; The specific mutual distance calculation formula is as follows: In the formula, dist(x,y) is the mutual distance between data x and data y, d is the number of data, and i represents the ordinal number of the data.

[0018] Preferably, the specific process of determining abnormal terminals based on the corresponding relationship between abnormal data, clustering features, and distributed terminals is as follows: Perform cross-correlation analysis based on the clustering features and distributed terminals to obtain cross-correlation features, and extract the corresponding relationship between the clustering features and abnormal data; Determine abnormal terminals based on the corresponding relationship between the clustering features and abnormal data and the cross-correlation features.

[0019] In this solution, the specific cross-correlation analysis formula corresponding to the cross-correlation analysis is as follows: C τ =P i a ·P i a-τ ; In the formula, C τ is the correlation coefficient at time τ, P i ais the data sequence of the i-th terminal within the time window a, P i a-τ is the data sequence of the adjacent terminal of the i-th terminal within the time window a - τ, r X,Y is the cross-correlation coefficient between the clustering feature X and the clustering feature Y. Since the calculation of the cross-correlation coefficient is directly related to the correlation coefficient of the terminal, the cross-correlation coefficient also includes the association relationship between the clustering feature and the terminal. n is the number of clustering features, x i is the i-th clustering feature X, is the average value of the clustering feature X, y i is the i-th clustering feature Y, is the average value of the clustering feature Y, where the clustering feature X and the clustering feature Y can be the clustering features corresponding to different data in the same feature set, or the clustering features corresponding to different data in different feature sets.

[0020] Preferably, the specific process of generating an alarm message based on the abnormal data and the abnormal terminal and performing the corresponding alarm action is as follows: Generate an abnormal data table based on the abnormal data and the abnormal terminal, and determine the operation and maintenance information based on the abnormal terminal and the preset operation and maintenance information database; Generate an alarm message based on the abnormal data table and the operation and maintenance information, and perform the corresponding alarm action based on the alarm message.

[0021] In this solution, generating an abnormal data table based on the abnormal data and the abnormal terminal can match the abnormal data with the abnormal terminal in the form of a table. At the same time, different terminals correspond to different operation and maintenance personnel, and the operation and maintenance information in the operation and maintenance information database can be matched based on the abnormal terminal. In order to enable on-site staff and the corresponding operation and maintenance personnel to know the abnormal situation in a timely manner, on-site alarms can be made based on devices such as alarms corresponding to distributed terminals, and the alarm message can be sent to the mobile phones of the corresponding operation and maintenance personnel.

[0022] On the other hand, another technical solution provided in the embodiments of the present invention is a monitoring and warning system based on distributed terminals, including: a terminal acquisition device, a data processing device, and a display and management device; The terminal acquisition device is used to collect and preprocess the monitoring data and upload the monitoring data to the data processing device; The data processing device performs clustering analysis on the monitoring data uploaded by the terminal acquisition device, determines the abnormal data and the abnormal terminal according to the results of the clustering analysis, and uploads the abnormal data and the abnormal terminal to the display and management device; The display and management device generates an alarm message based on the abnormal data and the abnormal terminal uploaded by the data processing device and performs the corresponding alarm action.

[0023] Advantages of the present invention: (1) This application collects the monitoring data of distributed terminals and performs preprocessing operations such as missing value, outlier replacement, filtering, and establishing time tags. It can eliminate the interference data generated by interference factors in the monitoring data, including missing values, outliers, irrelevant values, etc., effectively improving the accuracy and integrity of the monitoring data. It can also establish the corresponding relationship between different types of monitoring data through the established time tags, effectively improving the consistency of different types of monitoring data. (2) This application performs clustering analysis on the preprocessed monitoring data to analyze the potential characteristics of the data and obtain clustering features. Since different types of data in the monitoring data affect each other, when one type of data appears abnormal, other types of data will undergo implicit changes. In order to analyze the implicit changes, feature extraction is performed based on the time change scale of the data in the clustering dataset to obtain data stream features, and anomaly recognition is performed based on the clustering features and data stream features to determine abnormal data. It can comprehensively analyze the monitoring data from one-dimensional and multi-dimensional perspectives, significantly improving the recognition accuracy of abnormal data. (3) This application determines the abnormal terminal according to the corresponding relationship between the abnormal data, clustering features and the distributed terminal, can quickly and accurately lock the distributed terminal with abnormal conditions, and perform abnormal positioning with the help of the distributed terminal. And based on the abnormal data and abnormal terminal, an alarm message is generated and the corresponding alarm action is executed, which can accurately match the corresponding staff when an abnormality is found and notify the staff to perform maintenance, effectively improving the effectiveness of a monitoring and warning system based on distributed terminals. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives and advantages of the present invention will become more obvious. The drawings are only for the purpose of showing the preferred embodiments and are not considered as limiting the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components.

[0025] Figure 1 It is a flow schematic diagram of a monitoring and warning method based on distributed terminals; Figure 2 It is a structural schematic diagram of a monitoring and warning system based on distributed terminals. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only the best embodiments of the present invention, only used to explain the present invention, and do not limit the protection scope of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present invention.

[0027] Before discussing the exemplary embodiments in more detail, it should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts depict the operations (or steps) as sequential processes, many of the operations (or steps) can be implemented in parallel, concurrently, or simultaneously. In addition, the order of the operations can be rearranged. The process can be terminated when its operations are completed, but it can also have additional steps not included in the figures; the process can correspond to a method, function, procedure, subroutine, subprogram, and so on.

[0028] Embodiment 1: As Figure 1 shown, this embodiment provides a monitoring and early warning method based on distributed terminals, including the following steps: Collect the monitoring data of the distributed terminals, and preprocess the monitoring data to obtain a clustering data set; Specifically, collect the monitoring data of the distributed terminals, and perform a filtering operation on the monitoring data to obtain accurate monitoring data; statistically calculate the missing values and outliers of the accurate monitoring data based on the statistical method, and calculate the monitoring average value based on the preset monitoring period, accurate monitoring data, and types of monitoring data; Replace the missing values and outliers of the accurate monitoring data with the monitoring average value to obtain complete data; Establish a consistent timestamp based on the time change scale of the complete data; and construct a clustering data set based on the consistent timestamp and the complete data; The monitoring data at least includes environmental monitoring data, human body feedback data, and terminal network operation data.

[0029] In this embodiment, the distributed terminal is installed in the corresponding distributed power supply machine room. When the staff enters the distributed power supply machine room, electromagnetic radiation generated by power equipment will affect the staff's body. To analyze this impact, the echo signal reflected by the human body can be collected as human feedback data. The echo signal is formed by the reflection of the high-frequency radiation wave emitted by the voltage-controlled oscillator set in the distributed power supply machine room. The working environment of the distributed power supply machine room, such as temperature, humidity, etc., is also a key factor to be considered. Environmental data can be collected based on various sensor terminals as environmental monitoring data. The network security operation information of the distributed terminal is also one of the key data to be focused on. The terminal network security monitoring information, including vulnerability scanning, traffic analysis, behavior monitoring, etc., can be used as terminal network operation data. Secondly, filtering operations can be performed according to the frequency of the monitoring data to remove data with abnormal frequencies. After removing the abnormal data, the monitoring data can be divided into multiple data sets with time scale changes based on a preset monitoring period. And the data sets are classified according to the types of the monitoring data. At this time, the monitoring average value is calculated based on the classified data sets and the time change scale, and then the missing values and abnormal values in the monitoring data can be replaced by the monitoring average value. Secondly, since the data sets have time change scales, a consistent time stamp for the monitoring data can be established based on the time change scales, that is, the monitoring data collected within the same time period, regardless of whether the types are the same, can be unified into a whole according to the consistent time stamp. The specific calculation formula of the monitoring average value is: In the formula, is the monitoring average value, T is the time scale corresponding to the monitoring period, p i is the i-th accurate monitoring data, and n is the number of monitoring data.

[0030] In one embodiment, the clustering data set is stored by using the heterogeneous storage method, specifically: Extract data features based on the data structure of the data in the clustering data set, and perform corresponding heterogeneous storage operations based on the data features to store the data in the clustering data set.

[0031] In this embodiment, the clustering data set, like the monitoring data, includes environmental monitoring data, human feedback data, terminal network operation data, etc. Among them, the environmental monitoring data is usually numerical data with a large data volume. When storing it, the efficiency of querying and storing new data needs to be considered. While summarizing, the latest data also needs to be cached at the terminal to ensure data accuracy. The human feedback data usually includes two types: numerical data and waveform data. Therefore, when considering the data storage efficiency and query efficiency, the query and storage functions of waveform data also need to be considered. The terminal network operation data usually includes numerical data and text data. Therefore, the query and storage functions of text data need to be considered. Based on this, different types of monitoring data need to be stored in different devices, and these devices are correspondingly located at different positions in the environmental monitoring system based on distributed terminals.

[0032] Perform clustering analysis on the data in the clustering data set to obtain clustering features; Specifically, A1. Calculate the mutual distances of the data in the clustering data set based on the Euclidean distance formula to obtain a distance vector, and sort the distance vector; A2. Count the number of times of the same distance vector in the sorted distance vector, and mark the data corresponding to the distance vector with the number of times greater than the preset number threshold as the initial clustering point; A3. Count the number of data in the neighborhood of the initial clustering point, and determine the clustering parameter based on the number of data; A4. Generate a feature set based on the initial clustering point and the clustering parameter, and delete the data in the clustering data set corresponding to the feature set to obtain a new clustering data set; A5. Determine whether to end the clustering analysis based on the new clustering data set and the data quantity threshold. If the number of data in the new clustering data set is greater than or equal to the data quantity threshold, update the clustering data set based on the new clustering data set and execute A1. If the number of data in the new clustering data set is less than the data quantity threshold, establish clustering features based on the feature set and the generation order of the feature set and end the clustering analysis; In A5, the specific process of establishing clustering features based on the feature set and the generation order of the feature set is as follows: Sort the feature set based on the generation order of the feature set, and establish an order label for the feature set based on the sorting result; Integrate the feature set based on the order label to obtain clustering features.

[0033] In this embodiment, during the clustering analysis process, the data that has completed the clustering analysis in the clustering dataset is continuously deleted, and the clustering analysis is cyclically performed based on the remaining data. Therefore, the feature set generated in each cycle is essentially a set of data with similar distances. Based on the distances of the data, the feature set also has a distance attribute. The closer the generation order of the feature sets, the closer the distances between them. Correspondingly, the closer the distances within the feature set. An order label can be established according to the generation order of the feature sets, that is, the first feature set, the second feature set, etc. are marked. Secondly, since the distance of the data is obtained based on the initial clustering points, that is, the data corresponding to the distance vector with the most occurrences of the same distance vector is marked as the initial clustering point. The feature set with a larger order label is relatively farther from the initial clustering point. The feature set with a smaller order label can be placed within the feature set with a larger order label for merging, that is, the first feature set is placed within the second feature set for merging.

[0034] Feature extraction is performed based on the time change scale of the data in the clustering dataset to obtain data stream features; Specifically, the clustering dataset is divided into segment datasets based on a preset time window and the time change scale of the data in the clustering dataset; The segment datasets are sorted based on the types of data in the segment datasets to obtain classified segment datasets; Correlation analysis is performed on the data in the classified segment datasets to obtain correlation features, and the correlation features are sorted to obtain data stream features.

[0035] In this embodiment, the time window can be set according to the consistent timestamps corresponding to the data to ensure that the divided data is still within the same monitoring period. Secondly, the Pearson correlation coefficient method can be used to perform correlation analysis on the divided data to obtain the mutual influence relationship between different types of monitoring data within the same monitoring period.

[0036] Anomaly identification is performed based on the clustering features and the data stream features to determine the abnormal data; Specifically, the mutual distances of the data in the clustering dataset are calculated based on the clustering features and the mutual distance calculation formula; Anomaly identification is performed based on the mutual distance and a preset distance threshold. If the mutual distance is greater than or equal to the distance threshold, the corresponding data is marked as directly abnormal data. If the mutual distance is less than the distance threshold, the corresponding data is marked as normal data; Indirect abnormal data is determined based on the data stream features, the directly abnormal data, and the normal data; The directly abnormal data and the indirect abnormal data are sorted to obtain the abnormal data.

[0037] In this embodiment, since the data with too large mutual distances have been separated during the clustering analysis process, that is, for the multiple feature sets established during the loop process, it is impossible to specifically determine which data is abnormal data. At this time, the mutual distances between different data in the same feature set are calculated in combination with the mutual distance calculation formula, and the abnormal data is accurately identified based on the mutual distance and the preset distance threshold. However, the abnormal data is relatively obvious direct abnormal data, and the indirect abnormal data that undergoes implicit changes due to the direct abnormal data cannot be identified. The indirect abnormal data can be determined based on the data stream characteristics, direct abnormal data, and normal data to find all the abnormal data in the monitoring data; The specific mutual distance calculation formula is as follows: In the formula, dist(x,y) is the mutual distance between data x and data y, d is the number of data, and i represents the ordinal number of the data.

[0038] Determine the abnormal terminal according to the correspondence between the abnormal data and the clustering characteristics and the distributed terminal; Specifically, perform cross-correlation analysis based on the clustering characteristics and the distributed terminal to obtain cross-correlation characteristics, and extract the correspondence between the clustering characteristics and the abnormal data; Determine the abnormal terminal based on the correspondence between the clustering characteristics and the abnormal data and the cross-correlation characteristics.

[0039] In this embodiment, the specific cross-correlation analysis formula corresponding to the cross-correlation analysis is as follows: C τ =P i a ·P i a-τ ; In the formula, C τ is the correlation coefficient at time τ, P i a is the data sequence of the i-th terminal in the time window of a, P i a-τ is the data sequence of the adjacent terminal of the i-th terminal in the time window of a - τ, r X,Y is the cross-correlation coefficient between the clustering feature X and the clustering feature Y. Since the calculation of the cross-correlation coefficient is directly related to the correlation coefficient of the terminal, the cross-correlation coefficient also includes the association relationship between the clustering feature and the terminal. n is the number of clustering features, x i is the i-th clustering feature X, is the average value of the clustering feature X, y i is the i-th clustering feature Y, is the average value of the clustering feature Y, where the clustering feature X and the clustering feature Y can be the clustering features corresponding to different data in the same feature set, or the clustering features corresponding to different data in different feature sets.

[0040] Generate alarm information based on the abnormal data and abnormal terminal and perform corresponding alarm actions; Specifically, generate an abnormal data table based on the abnormal data and abnormal terminal, and determine operation and maintenance information based on the abnormal terminal and a preset operation and maintenance information database; Generate alarm information based on the abnormal data table and operation and maintenance information, and perform corresponding alarm actions based on the alarm information.

[0041] In this embodiment, generating an abnormal data table based on the abnormal data and abnormal terminal can match the abnormal data with the abnormal terminal in the form of a table. At the same time, different terminals correspond to different operation and maintenance personnel, and the operation and maintenance information in the operation and maintenance information database can be matched based on the abnormal terminal. In order to enable on-site staff and corresponding operation and maintenance personnel to know the abnormal situation in a timely manner, on-site alarms can be made based on devices such as alarms corresponding to distributed terminals, and the alarm information can be sent to the mobile phones of corresponding operation and maintenance personnel.

[0042] On the other hand, as Figure 2 shown, another technical solution provided in the embodiment of the present invention is a monitoring and early warning system based on distributed terminals, including: a terminal acquisition device, a data processing device, and a display and management device; The terminal acquisition device is used to collect and preprocess monitoring data and upload the monitoring data to the data processing device; The data processing device performs clustering analysis on the monitoring data uploaded by the terminal acquisition device, determines abnormal data and abnormal terminals according to the results of the clustering analysis, and uploads the abnormal data and abnormal terminals to the display and management device; The display and management device generates alarm information based on the abnormal data and abnormal terminals uploaded by the data processing device and performs corresponding alarm actions.

[0043] This embodiment has at least the following substantial effects: (1) In this embodiment, the monitoring data of distributed terminals is collected and preprocessing operations such as missing value, outlier replacement, filtering, and establishing time tags are performed, which can eliminate interference data generated by interference factors in the monitoring data, including missing values, outliers, irrelevant values, etc., effectively improving the accuracy and integrity of the monitoring data. It can also construct the corresponding relationship between different types of monitoring data through the established time tags, effectively improving the consistency of different types of monitoring data; (2) In this embodiment, clustering analysis is performed on the monitored data that has completed preprocessing to analyze the potential characteristics of the data and obtain clustering features. Moreover, since different types of data in the monitored data influence each other, when one type of data shows an anomaly, hidden changes will occur in other types of data. To analyze such hidden changes, feature extraction is performed based on the time change scale of the data in the clustering dataset to obtain data stream features, and anomaly recognition is performed based on the clustering features and data stream features to determine abnormal data, enabling comprehensive analysis of the monitored data from both single-dimensional and multi-dimensional perspectives and significantly improving the recognition accuracy of abnormal data; (3) In this embodiment, the abnormal terminal is determined according to the correspondence between the abnormal data, clustering features, and the distributed terminal, which can quickly and accurately lock the distributed terminal where the anomaly occurs, and perform anomaly positioning with the aid of the distributed terminal. Moreover, alarm information is generated based on the abnormal data and abnormal terminal, and corresponding alarm actions are executed, which can accurately match the corresponding staff when an anomaly is detected and notify the staff to perform maintenance, effectively enhancing the effectiveness of a monitoring and warning system based on distributed terminals.

[0044] The above specific implementation manners are the preferred implementation manners of the present invention, which do not limit the specific implementation scope of the present invention. The scope of the present invention includes but is not limited to this specific implementation manner. All equivalent changes made according to the shape, structure, and method of the present invention are within the protection scope of the present invention.

Claims

1. A monitoring and early warning method based on distributed terminals, characterized in that: The method comprises the following steps: Collect monitoring data from distributed terminals and pre-process the monitoring data to obtain a clustering data set; Perform cluster analysis on the data in the clustering data set to obtain clustering features, and extract features based on the time change scale of the data in the clustering data set to obtain data flow features; Based on clustering features and data flow features, abnormal data is identified and abnormal terminals are determined according to the corresponding relationship between abnormal data and clustering features and distributed terminals; Generate alarm information based on abnormal data and abnormal terminals and execute corresponding alarm actions.

2. A distributed terminal-based monitoring and early warning method according to claim 1, characterized in that: The specific process of collecting the monitoring data of the distributed terminals and preprocessing the monitoring data to obtain the clustering data set is as follows: Collecting monitoring data from distributed terminals and filtering the monitoring data to obtain accurate monitoring data; Counting missing values ​​and abnormal values ​​of the accurate monitoring data based on statistical methods, and calculating the monitoring average value based on the preset monitoring period, accurate monitoring data and monitoring data types; Complete data is obtained by replacing missing values ​​and abnormal values ​​of accurate monitoring data based on the monitoring average value; Establish consistent timestamps based on the time change scale of complete data; And build a clustering data set based on consistent timestamps and complete data; The monitoring data at least includes environmental monitoring data, human body feedback data, and terminal network operation data.

3. A distributed terminal-based monitoring and early warning method according to claim 2, characterized in that: The clustering data set is stored using a heterogeneous storage method, specifically: Data features are extracted based on the data structure of the data in the clustering data set, and corresponding heterogeneous storage operations are performed based on the data features to store the data in the clustering data set.

4. A distributed terminal-based monitoring and early warning method according to claim 1, characterized in that: The specific process of performing cluster analysis on the data in the clustering data set to obtain clustering features is as follows: A1. Calculate the mutual distance of data in the clustering data set based on the Euclidean distance formula to obtain a distance vector, and sort the distance vector; A2. Count the number of identical distance vectors in the sorted distance vectors, and mark the data corresponding to the distance vectors whose number is greater than a preset number threshold as initial clustering points; A3, counting the number of data in the initial clustering point field, and determining clustering parameters based on the number of data; A4. Generate a feature set based on the initial clustering points and clustering parameters, and delete the data corresponding to the feature set in the clustering data set to obtain a new clustering data set; A5. Determine whether to end the clustering analysis based on the new clustering data set and the data quantity threshold. If the data quantity in the new clustering data set is greater than or equal to the data quantity threshold, update the clustering data set based on the new clustering data set and execute A1. If the data quantity in the new clustering data set is less than the data quantity threshold, establish clustering features based on the feature set and the generation order of the feature set and end the clustering analysis.

5. A distributed terminal-based monitoring and early warning method according to claim 4, characterized in that: In A5, the specific process of establishing clustering features based on the feature set and the generation order of the feature set is: Sorting the feature sets based on the order in which the feature sets are generated, and establishing a sequence label of the feature sets based on the sorting result; The feature set is integrated based on the sequential labels to obtain clustering features.

6. A distributed terminal-based monitoring and early warning method according to claim 1, characterized in that: The specific process of extracting features based on the time change scale of data in the clustering data set to obtain data stream features is as follows: The clustering data set is divided based on a preset time window and a time variation scale of the data in the clustering data set to obtain a segmented data set; Arrange the fragment data sets based on the types of data in the fragment data sets to obtain a classified fragment data set; Correlation analysis is performed on the data in the classified fragment data set to obtain relevant features, and the relevant features are sorted to obtain data flow features.

7. A distributed terminal-based monitoring and early warning method according to claim 1, characterized in that: The specific process of performing anomaly identification and determining abnormal data based on clustering features and data stream features is as follows: Calculate the mutual distance of data in the clustering data set based on clustering characteristics and mutual distance calculation formula; Anomaly identification is performed based on the mutual distance and a preset distance threshold. If the mutual distance is greater than or equal to the distance threshold, the corresponding data is marked as direct abnormal data; if the mutual distance is less than the distance threshold, the corresponding data is marked as normal data; indirect abnormal data is determined based on data flow characteristics, direct abnormal data and normal data; The direct abnormal data and the indirect abnormal data are sorted to obtain abnormal data.

8. A distributed terminal-based monitoring and early warning method according to claim 7, characterized in that: The specific process of determining abnormal terminals according to the correspondence between abnormal data and clustering features and distributed terminals is as follows: Based on the clustering features and the distributed terminals, a cross-correlation analysis is performed to obtain cross-correlation features, and a corresponding relationship between the clustering features and the abnormal data is extracted; The abnormal terminal is determined based on the corresponding relationship between the clustering features and the abnormal data and the mutual correlation features.

9. The distributed terminal-based monitoring and early warning method according to claim 1, characterized in that: The specific process of generating alarm information based on abnormal data and abnormal terminals and executing corresponding alarm actions is as follows: Generate an abnormal data table based on abnormal data and abnormal terminals, and determine operation and maintenance information based on abnormal terminals and a preset operation and maintenance information library; Alarm information is generated based on the abnormal data table and the operation and maintenance information, and corresponding alarm actions are performed based on the alarm information.

10. A monitoring and early warning system based on distributed terminals, applicable to a monitoring and early warning method based on distributed terminals as claimed in any one of claims 1 to 9, characterized in that: It includes: terminal collection device, data processing device, display management device; The terminal acquisition device is used to collect and pre-process monitoring data and upload the monitoring data to the data processing device; The data processing device performs cluster analysis on the monitoring data uploaded by the terminal acquisition device, determines abnormal data and abnormal terminals according to the results of the cluster analysis, and uploads the abnormal data and abnormal terminals to the display management device; The display management device generates alarm information based on the abnormal data and abnormal terminals uploaded by the data processing device and executes corresponding alarm actions.

Citation Information

Patent Citations

  • Anti-theft alarm system and method for irrigation and drainage overhead line

    CN117636555A