Learning Fusion and Anomaly Detection Method for Industrial Time-Series Data

By constructing IP-PLC mapping relationship tables and multimodal features fusion, combined with spatial topology maps and dynamic tolerance mechanisms, the multi-dimensional detection bottleneck of industrial timing data is solved, and the intelligence and interpretability of equipment health management is realized.

CN120179654BActive Publication Date: 2025-07-25南京迅集科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510626277.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-25
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

The existing industrial timing data anomaly detection technology has shortcomings in multiple dimensions, including weak multi-source data fusion capabilities, lack of spatial context modeling and lack of closed-loop optimization mechanisms, resulting in limited robustness and intelligence levels of the system in complex dynamic environments.

Method used

By analyzing the industrial communication protocol, building an IP-PLC mapping relationship table, collecting multimodal data and embeding physical constraint parameters, extracting time domain, frequency domain and spatial features, building a constraint rule library, generating a global benchmark system, and optimizing through hierarchical modeling to form an alarm response mechanism for closed-loop iteration.

Benefits of technology

It realizes accurate detection and root cause traceability of equipment-level and operating condition-level abnormalities, improves the system's robustness and self-evolution ability under dynamic operating conditions, reduces the false alarm rate, and supports differentiated management of high and low risk equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120179654B_ABST
    Figure CN120179654B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of equipment health monitoring and anomaly detection. The present invention discloses a learning fusion and anomaly detection method for industrial time-series data, including: constructing an IP-PLC mapping relationship table, collecting multi-modal data, constructing a physical constraint parameter list, generating structured data and storage indexes; extracting time-domain features and frequency-domain features, constructing a spatial topology graph, extracting node spatial feature vectors and edge association strengths, generating spatial association feature vectors, constructing a constraint rule library, and forming an enhanced feature set; aggregating the enhanced feature set and the constraint rule library, generating a multi-dimensional feature matrix and a global reference parameter table, further constructing a global reference system, obtaining an equipment-level anomaly probability matrix and generating a working condition-level anomaly probability matrix; performing hierarchical optimization through hierarchical modeling to generate an optimized parameter set; constructing an alarm response mechanism and performing reverse update to form a closed-loop iteration; providing an interpretable and extensible solution for equipment health management in complex industrial scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of equipment health monitoring and anomaly detection, and more specifically, to a method for learning fusion and anomaly detection of industrial time-series data. Background Art

[0002] With the rapid development of industrial automation and intelligent operation and maintenance technologies, equipment health monitoring in complex production lines has put forward higher requirements for anomaly detection. Enterprises urgently need to integrate multi-source heterogeneous data (such as vibration, temperature, image signals, process parameters, etc.), combine physical constraint rules and spatial topological relationships, and build an intelligent diagnosis system with strong dynamic adaptability to cope with the impact of non-steady-state noise, collaborative failure risks, and process fluctuations during equipment operation on production safety and efficiency. However, existing systems mostly rely on single data sources or static threshold strategies, lacking the ability to deeply mine the fusion of spatio-temporal features, the modeling of the correlation between devices, and dynamic tolerance adjustment, and it is difficult to achieve global collaborative optimization of anomaly detection and root cause tracing.

[0003] Current industrial time-series data anomaly detection technologies have multi-dimensional technical bottlenecks, resulting in limited robustness and intelligence level of the system under dynamic working conditions. First, the multi-source data fusion ability is weak. The system can only process single-type sensor data in isolation (such as only focusing on vibration spectra or temperature trends), and does not effectively integrate time domain, frequency domain, spatial features, and physical constraint rule bases, resulting in the omission of key patterns (such as the chain temperature rise caused by the failure of the cooling system); second, the spatial context modeling is missing. Existing methods ignore the influence propagation paths of equipment layout and adjacent nodes (such as heat conduction chain reactions) and cannot identify the risk of cross-device collaborative failures; finally, the closed-loop optimization mechanism is lacking. Most solutions are "open-loop detection" and lack a feedback loop based on execution records (such as shutdown instructions, maintenance logs), resulting in a high false alarm rate. The above defects jointly restrict the accurate detection ability and self-evolution level of the system in complex dynamic environments. Summary of the Invention

[0004] To overcome the above defects of the prior art and to achieve the above object, the present invention provides the following technical solution: A method for learning fusion and anomaly detection of industrial time-series data, including:

[0005] S1: Analyze the industrial communication protocol, extract the PLC device ID and IP address, and establish an initial device list; combine the IP address and device ID to construct an IP-PLC mapping relationship table; collect multi-modal data, align it according to the time stamp, and then construct a physical constraint parameter list according to the physical characteristics of the sensor; manage the data through a hierarchical storage strategy to generate structured data and storage indexes;

[0006] S2: Based on the structured data, extract the time-domain feature vectors and frequency-domain feature vectors; construct a spatial topology graph based on the IP-PLC mapping relation table, extract the node spatial feature vectors and edge association strengths, and generate spatial association feature vectors; combine the physical constraint parameter list, encode the physical rules and topology rules, construct a constraint rule library, and form an enhanced feature set;

[0007] S3: Aggregate the enhanced feature set and constraint rule library of the industrial equipment in the factory to generate a multi-dimensional feature matrix, optimize the detection threshold through spatio-temporal feature fusion and physical constraint parameters, generate a global benchmark parameter table, and then construct a global benchmark system; generate an equipment-level anomaly probability matrix and a working condition-level anomaly probability matrix based on the global benchmark system;

[0008] S4: Based on the equipment-level anomaly probability matrix and the generated working condition-level anomaly probability matrix, generate an equipment-level feature model and a working condition-level feature model through hierarchical modeling, and perform hierarchical optimization to generate an optimized parameter set;

[0009] S5: Based on the output results of the equipment-level feature model and the working condition-level feature model and the optimized parameter set, construct an alarm response mechanism, and reversely update the physical constraint parameters associated with the sensors to form a closed-loop iteration.

[0010] Further, the ways of the structured data and its storage index include:

[0011] Parse the communication protocol data of the PLC device through the industrial protocol parsing mechanism, and extract the device identifiers, including the IP address and device ID;

[0012] Integrate the IP addresses and device IDs of all PLC devices to establish an initial device list;

[0013] Based on the initial device list, identify the PLC devices with the same IP address, combine the physical interface information, assign a unique physical interface to each PLC device, assign the PLC devices with the same IP address to different physical interfaces, and set the interface binding through the network configuration tool;

[0014] Integrate the device ID, IP address, and physical interface information into a structured table to obtain the IP-PLC mapping relation table;

[0015] Real-time collect various types of data of the device through various types of sensor interfaces, use it as the multi-modal data of the device, align it according to the time stamp to form an original data stream, and then perform data cleaning and standardization processing to integrate it into a preprocessed data stream;

[0016] According to the physical characteristics of the device, define the physical constraint parameters of various types of sensors, and integrate and construct them to obtain a physical constraint parameter list;

[0017] Embed physical constraint parameters through the hardware layer, algorithm layer, and data layer based on the physical constraint parameter list;

[0018] The hardware layer embedding is to define the sampling parameters of the sensor according to the physical constraint parameters; the algorithm layer embedding is to embed different physical equations for different data types;

[0019] The data layer embedding is to define real-time constraints and security constraints. The real-time constraints are timestamp synchronization and data range check, and the security constraints are to add hardware-level threshold triggers;

[0020] Divide all types of data into high-timeliness data and low-timeliness data according to the expert experience method, divide the high-timeliness data into hot data, and divide the low-timeliness data into cold data, and then divide the data storage levels according to the hot data / cold data strategy;

[0021] Standardize the data into a structured format through data standardization technology to obtain structured data; synchronously generate a storage list to record the physical location and access priority of data blocks to obtain a storage index.

[0022] Furthermore, the method of constructing the constraint rule library and forming the enhanced feature set includes:

[0023] Extract the time-domain features of each type of data from the structured data, and then horizontally splice the time-domain features of each type of data into a multi-modal time-domain feature vector;

[0024] Decompose each type of data through frequency-domain analysis, and then extract the frequency-domain features of each type of data;

[0025] Set a fixed time window, and horizontally splice the frequency-domain feature vectors of each type of data within each time window in chronological order to form a single time-series feature item;

[0026] Arrange the single time-series feature items of all time windows in chronological order to generate a multi-modal frequency-domain feature sequence;

[0027] Based on the IP-PLC mapping relationship table, construct the spatial topology map of the sensor, extract the node spatial feature vector and edge association strength in the spatial topology map, obtain the spatial association feature vector of each node as the spatial feature of the sensor, and encode the physical constraint parameter list into the physical constraint rule library in combination with the spatial topology map;

[0028] Horizontally splice the time-domain features, frequency-domain features, and spatial features, and convert the rule thresholds in the physical constraint rule library into numerical features, and merge all features to form a multi-modal enhanced feature set;

[0029] At the same time, combine the spatial features to add topological constraints to the physical constraint rule library to form a constraint rule library.

[0030] Furthermore, the obtaining methods of the node spatial feature vector and the edge association strength include:

[0031] Regarding each sensor as a node, assign attributes to each node, including sensor type, range, and installation coordinates;

[0032] Based on the IP-PLC mapping relation table, establish edges for the nodes and assign attributes to each edge, including the physical distance, directionality, and communication protocol between sensors as edge attributes, and construct a spatial topology graph;

[0033] Based on the edges between all nodes in the spatial topology graph, define the nodes with edges as connected by a connection relationship, and define the nodes without edges as not connected by a connection relationship, extract all the connection relationships between nodes, and construct an adjacency matrix;

[0034] Encode the node attributes into numerical feature vectors as node features, and extract all node features to construct a node feature matrix;

[0035] Perform normalization processing on the adjacency matrix. Based on the node attribute matrix and the normalized adjacency matrix, for each node, aggregate the node features of all adjacent nodes to generate the node spatial feature vector of each node, including type correlation, spatial proximity, and range consistency;

[0036] Meanwhile, based on any pair of nodes with edges, extract the physical distance, communication protocol, and sensor type between the two nodes;

[0037] Set the attenuation coefficient of the physical distance, multiply the physical distance by the attenuation coefficient, add 1, and then take the reciprocal to obtain the physical distance strength value;

[0038] For the communication protocol between two nodes, if the communication protocols are exactly the same, assign a communication protocol consistency strength value of 1, and if the communication protocols are different, the communication protocol consistency strength value is 0;

[0039] According to the predefined type complementary rule table, determine the adjustment coefficient of the sensor type combination, and multiply the adjustment coefficient by the default basic sensor type complementary strength value to obtain the final sensor type complementary strength value;

[0040] Perform weighted summation on the physical distance strength value, communication protocol consistency strength value, and sensor type complementary strength value between nodes to calculate the edge association strength.

[0041] Furthermore, the obtaining method of the physical constraint rule library includes:

[0042] The node spatial feature vector of the node is horizontally concatenated with the edge association strength to obtain the spatial association feature vector of each node;

[0043] Based on the physical constraint parameter list and combined with the spatial topology graph, the physical constraint parameter list is transformed into structured rules, including physical rules and topological rules, and the physical rules and topological rules are merged into a structured physical constraint rule library.

[0044] Furthermore, the multi-dimensional feature matrix is generated by:

[0045] Extracting time domain feature vectors, frequency domain feature vectors, and spatial correlation feature vectors across devices from the enhanced feature set as heterogeneous data;

[0046] Based on the device ID and physical interface information, all heterogeneous data with timestamps across devices are timestamped and aligned;

[0047] And according to the range in the physical constraint parameter list, the processed heterogeneous data are normalized and integrated to obtain a standardized data set;

[0048] Extract the physical constraints of each device from the physical constraint rule library as a single-device benchmark; then derive the joint constraints of each device under collaborative working conditions based on the edge association strength in the spatial topology graph as a cross-device benchmark;

[0049] By using the expert experience method to assign weights to each device according to its criticality in the factory production chain, the single-device benchmarks are weighted averaged to generate a single-type benchmark range that is common to the entire factory;

[0050] Integrate all types of single-type benchmark ranges to generate a global benchmark parameter table;

[0051] Then, in the global parameter table, a static allowable deviation range is preset for each type of equipment based on physical constraints combined with expert experience as the original tolerance of each equipment;

[0052] And define the ratio of the actual value of the device collected by the sensor and the corresponding global benchmark parameter as the benchmark verification function;

[0053] The standardized data set is segmented into fixed time windows to extract time series statistical features, and the filtering algorithm is used to separate long-term trends from short-term fluctuations;

[0054] Based on the adjacency matrix of the spatial topology graph, the spatial context features of the nodes are aggregated to generate a spatial context vector;

[0055] Convert the physical constraints in the physical constraint rule library into feature screening conditions to eliminate data that does not meet the physical constraints;

[0056] Then, the time domain feature vector, frequency domain feature vector and spatial context vector are horizontally spliced in sequence into a feature sequence of uniform length, and the redundant dimensions of the feature sequence are compressed through principal component analysis to generate a multi-dimensional feature matrix in a unified format.

[0057] Furthermore, the global benchmark system is constructed in the following manner:

[0058] Define high-risk devices and low-risk devices based on industry standards, bind detection parameters and assign detection priorities to high-risk devices and low-risk devices;

[0059] The detection parameter binding is: assigning initial sensitivity coefficients to high-risk devices and low-risk devices, and assigning initial fault tolerance coefficients to low-risk devices; and defining the sensitivity assignment rule as that the sensitivity coefficient of the high-risk device is greater than the sensitivity coefficient of the low-risk device;

[0060] The detection priority is allocated as follows: according to the expert experience method, the various types of data collected from the equipment are divided into two types: safety and efficiency, and the contribution coefficient of the benchmark verification function of each type of data is allocated with the safety type being higher than the efficiency type;

[0061] The benchmark calibration function is modified by the sensitivity coefficient to obtain a modified benchmark calibration function;

[0062] The original tolerance is corrected by the fault tolerance coefficient to obtain the corrected dynamic tolerance; the sum of the actual value of the device collected by each type of sensor and the dynamic tolerance is taken to obtain the dynamic tolerance range;

[0063] If the actual value of any type of equipment is greater than the maximum value of the corresponding dynamic tolerance range, the equipment is judged to be abnormal and an alarm is issued;

[0064] If the actual values of all types of equipment are less than or equal to the maximum value of the corresponding dynamic tolerance range, then the corrected benchmark calibration function is calculated separately for the actual value of each type of equipment to obtain the sensitivity of the actual value of each type of equipment;

[0065] According to the security and efficiency classification of each type of data, the contribution coefficient is used as the sensitivity weight of the actual value of the equipment, and then the sensitivity of the actual value of all types of equipment is weighted and integrated to generate a comprehensive verification value;

[0066] If the comprehensive check value is greater than the preset check value threshold, it is determined that the device is abnormal and an alarm is issued; if the comprehensive check value is less than or equal to the check value threshold, it is determined that the device is not abnormal;

[0067] Combine the standardized data set with the global benchmark parameter table to define the dynamic correction strategy, including the real-time synchronization mechanism of dynamic tolerance and the feedback loop optimization of sensitivity coefficients;

[0068] The real-time synchronization mechanism for dynamic tolerance calculates the standard deviation of the dynamic tolerance within a fixed time window. If the standard deviation of the dynamic tolerance is greater than the preset standard deviation threshold, the dynamic tolerance is updated.

[0069] The feedback loop of the sensitivity coefficient is optimized to calculate the ratio of the number of false alarms to the total number of alarms as the false alarm rate, and automatically adjusts the sensitivity coefficient according to the false alarm rate.

[0070] Integrate the multi-dimensional feature matrix, the benchmark verification function, and the global benchmark parameter table to form a global benchmark system; and it includes static thresholds, dynamic tolerances, and feedback optimization logic.

[0071] Further, the generation methods of the device-level anomaly probability matrix and the generation of the working condition-level anomaly probability matrix include:

[0072] Based on the global benchmark system, calculate the ratio of the difference between the actual value of the device and the maximum value of the dynamic tolerance range to the dynamic tolerance to obtain the standardized deviation.

[0073] If the standardized deviation is negative, assign it a value of 0.

[0074] Furthermore, map the standardized deviation to a probability value as the preliminary anomaly probability.

[0075] The mapping method can normalize the standardized deviation to the interval [0,1] through linear normalization.

[0076] Combine the multi-dimensional feature matrix and the physical constraint rule base, and perform reconstruction error processing on the multi-dimensional feature matrix through the principal component analysis method to obtain the PCA reconstruction error probability.

[0077] Perform probability density estimation on the multi-dimensional feature matrix through the Gaussian mixture model to obtain the GMM probability.

[0078] Weightedly fuse the preliminary anomaly probability, the PCA reconstruction error probability, and the GMM probability to obtain the comprehensive anomaly probability.

[0079] Use the edge association strength in the spatial topology graph to correct the comprehensive anomaly probability to obtain the corrected comprehensive anomaly probability.

[0080] Organize the comprehensive anomaly probabilities of all devices into a matrix structure according to the time series by device ID and timestamp to obtain the device-level anomaly probability matrix; including the number of devices, the number of time windows, and the comprehensive anomaly probability of each device in each time window.

[0081] Aggregate the comprehensive anomaly probabilities of associated devices based on the spatial topology graph according to the process stage and production line module.

[0082] Combine the joint constraints in the physical constraint rule library and introduce the working condition characteristics to obtain the working condition level abnormal probability matrix.

[0083] Furthermore, the generation method of the optimization parameter set includes:

[0084] Extract the time series characteristics from the device-level abnormal probability matrix, perform PCA dimensionality reduction on the extracted time series characteristics to obtain the low-dimensional feature vector of the time series characteristics; and perform physical constraint verification through the physical constraint rule library to filter out the data values that do not conform to the physical rules to obtain the device-level feature model.

[0085] Based on the spatial topology graph, aggregate the comprehensive abnormal probabilities of associated devices to generate the preliminary working condition level probability, and establish a causal relationship model in combination with the joint rules in the physical constraint rule library.

[0086] Integrate the working condition level characteristics as supplementary inputs, use the spatial topology graph as the graph structure, and train the GNN model to capture the dependency relationship between devices to obtain the working condition level feature model.

[0087] According to the division of high-risk and low-risk types of devices, perform device-level optimization, quantify the influence intensity of adjacent nodes, jointly optimize the false alarm rate, perform working condition level optimization, and generate the optimization parameter set.

[0088] Furthermore, the construction method of the alarm response mechanism includes:

[0089] Set the comprehensive risk level according to the values in the device-level abnormal probability matrix and the working condition level abnormal probability matrix.

[0090] Divide the alarm levels based on the comprehensive risk level.

[0091] Automatically generate an operation and maintenance work order after the alarm is triggered; automatically allocate the operation and maintenance work order according to the matching of the alarm level and the skills of the maintenance personnel, and optimize the response path in combination with traffic information.

[0092] Locate the root cause of the anomaly by combining the multi-dimensional feature matrix, the physical constraint rule library and the historical maintenance records.

[0093] Dynamically adjust the sensitivity coefficient and the tolerance range according to the false alarm rate; store each maintenance process in the preset operation and maintenance database, and then regularly update the physical constraint rule library.

[0094] The technical effects and advantages of the industrial time series data learning fusion and anomaly detection method of the present invention:

[0095] The present invention takes the time-series data of industrial equipment (such as vibration, temperature, images, etc.) as input, and through IP-PLC mapping, multi-modal feature fusion, dynamic tolerance mechanism and closed-loop optimization, realizes the accurate detection and root cause tracing of equipment-level and working condition-level abnormalities; the core goal is to improve the safety, reliability and operation and maintenance efficiency of equipment operation in industrial scenarios, and directly serve the equipment health management needs in intelligent manufacturing.

[0096] First, based on communication protocol parsing and physical interface binding, an IP-PLC mapping relationship table is generated. Combining the standardized processing of multi-source sensor (such as vibration, temperature, image) data and the embedding of physical constraint parameters (sampling rules, hardware thresholds), it breaks through the dependence of traditional systems on single data sources or static thresholds, solves the problems of difficult multi-source heterogeneous data fusion and lack of physical correlation, and makes the equipment feature representation more comprehensive and in line with engineering logic;

[0097] Secondly, by quantifying the edge association strength between adjacent nodes in the spatial topology graph (physical distance attenuation coefficient, communication protocol consistency strength), and introducing algorithms such as principal component analysis (PCA) and Gaussian mixture model (GMM) to generate a comprehensive anomaly probability. Compared with the prior art that only focuses on single-point features or ignores the spatial context, the present invention significantly improves the collaborative fault identification ability. For example, the chain temperature rise risk caused by the failure of the cooling system can be accurately located;

[0098] Then, a dual-regulation mechanism of dynamic tolerance and sensitivity coefficient is constructed. The threshold is updated in real time according to the content difference standard deviation within the time window, and the sensitivity coefficient is automatically optimized through the false alarm rate feedback loop, enabling the system to adapt to dynamic factors such as production line capacity fluctuations and seasonal changes. At the same time, it supports differential management of high / low-risk equipment (such as sensitivity coefficient of high-risk equipment > sensitivity coefficient of low-risk equipment), taking into account both safety and operation efficiency;

[0099] Finally, by reverse-updating the physical constraint rule base and historical compensation template through execution records, a closed-loop iterative link of virtual-real interaction is formed. Compared with the existing "open-loop detection" scheme that relies on manual experience to adjust strategies, the present invention realizes the automatic optimization of anomaly detection weights and the continuous evolution of the rule base;

[0100] The present invention solves the data correlation problem through IP-PLC mapping and physical constraint embedding, improves the collaborative detection ability through spatial topology modeling and dynamic tolerance mechanism, and enhances the system self-adaptability through the closed-loop optimization link. Finally, it realizes the full-process intelligence from data acquisition to root cause tracing, and has significant advantages over traditional methods in terms of false alarm rate control, collaborative fault identification accuracy and strategy iteration efficiency, providing an interpretable and extensible solution for equipment health management in complex industrial scenarios. Description of the Drawings

[0101] Figure 1Schematic diagram of the learning fusion and anomaly detection method for industrial time-series data of the present invention;

[0102] Figure 2 Schematic diagram of the construction of the enhanced feature set and the constraint rule library in the learning fusion and anomaly detection method for industrial time-series data of the present invention;

[0103] Figure 3 Flow chart of the learning fusion and anomaly detection method for industrial time-series data of the present invention;

[0104] Figure 4 Schematic diagram of the learning fusion and anomaly detection system for industrial time-series data of the present invention. Detailed implementation manners

[0105] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0106] Embodiment 1

[0107] Please refer to Figures 1 to 3 As shown, the learning fusion and anomaly detection method for industrial time-series data in this embodiment includes:

[0108] S1: Analyze the industrial communication protocol, extract the PLC device ID and IP address, and establish an initial device list; combine the IP address and device ID to construct an IP-PLC mapping relationship table; collect multi-modal data, align it according to the time stamp, and then construct a physical constraint parameter list according to the physical characteristics of the sensor; manage the data through a hierarchical storage strategy to generate structured data and storage indexes;

[0109] S2: Based on the structured data, extract the time-domain feature vector and frequency-domain feature vector; construct a spatial topology graph based on the IP-PLC mapping relationship table, extract the node spatial feature vector and edge association strength, and generate a spatial association feature vector; combine the physical constraint parameter list, encode the physical rules and topological rules, construct a constraint rule library, and form an enhanced feature set;

[0110] S3: Aggregate the enhanced feature set and the constraint rule library of industrial devices in the factory to generate a multi-dimensional feature matrix, optimize the detection threshold through spatio-temporal feature fusion and physical constraint parameters, generate a global benchmark parameter table, and then construct a global benchmark system; generate a device-level anomaly probability matrix and a working condition-level anomaly probability matrix based on the global benchmark system;

[0111] S4: Based on the device-level anomaly probability matrix and generate the working condition-level anomaly probability matrix, generate the device-level feature model and the working condition-level feature model through hierarchical modeling, and perform hierarchical optimization to form an optimized parameter set;

[0112] S5: Based on the output results of the device-level feature model and the working condition-level feature model and the optimized parameter set, construct an alarm response mechanism, and reversely update the physical constraint parameters associated with the sensors to form a closed-loop iteration;

[0113] Parse the communication protocol data of the PLC device through an industrial protocol parsing mechanism (such as Modbus, OPC UA parser), and extract the device identifier, including the IP address and the device ID;

[0114] Integrate the IP addresses and device IDs of all PLC devices to establish an initial device list;

[0115] Based on the initial device list, identify PLC devices with the same IP address, combine the physical interface information (such as eth0, eth1), assign a unique physical interface to each PLC device, and assign PLC devices with the same IP address to different physical interfaces, and set the interface binding through a network configuration tool (such as iproute2);

[0116] For example, if it is found that two PLC devices (PLC_A and PLC_B) have the same IP address 192.168.1.1, they need to be bound to different physical interfaces;

[0117] Example: Configure IP binding in the Linux system;

[0118] 192.168.1.1 PLC_A_eth0 is bound to the eth0 interface;

[0119] 192.168.1.1 PLC_B_eth1 is bound to the eth1 interface;

[0120] Integrate the device ID, IP address, and physical interface information into a structured table to obtain the IP-PLC mapping relationship table; used to record the corresponding relationship between the IP address, physical interface, and device ID of each PLC device;

[0121] It should be noted that the PLC device, as the core of data acquisition and control, is responsible for protocol parsing, data integration, and transmission. It is the intermediate hub of data acquisition, used to read data from devices such as sensor controllers and parse it through industrial protocols;

[0122] Collect various types of data of the device in real time through various types of sensor interfaces as the multi-modal data of the device (including but not limited to vibration data (collected by an accelerometer sensor), temperature data (collected by a thermocouple sensor), and image data (collected by a camera)), align them by timestamp (such as synchronizing all sensor clocks through NTP and uniformly accessing vibration, temperature, and image data through the ECC800-Pro device) to form an original data stream, and then perform data cleaning and standardization processing to integrate it into a preprocessed data stream;

[0123] According to the physical characteristics of the device, define the physical constraint parameters (such as range, accuracy, response time) of various types of sensors, and integrate and construct them to obtain a physical constraint parameter list;

[0124] Examples of physical constraint parameters:

[0125] Vibration type: sampling frequency (such as 0~10kHz), acceleration limit (such as ±20g), noise threshold (such as ISO 10816 standard);

[0126] Temperature type: range (maximum and minimum temperature, such as -40°C~150°C), safety threshold (such as the melting point of the material 1500°C), response time (such as ≤1 second);

[0127] Image type: resolution (such as 4096×2160), minimum defect size (such as 0.1mm), lighting condition (such as Lux≥500);

[0128] Based on the physical constraint parameter list, embed the physical constraint parameters through the hardware layer, algorithm layer, and data layer;

[0129] The hardware layer embedding is to define the sampling parameters of the sensor according to the physical constraint parameters,

[0130] Exemplarily, define the sampling frequency, range, and filtering parameters of the vibration sensor, and configure the FPGA pins (such as Package Pin U18) and I / O standard (LVCMOS33); define the range, accuracy (±0.5°C), and communication protocol (1-Wire / Modbus) of the temperature sensor, and define the resolution, frame rate, exposure time, and trigger mode (hardware synchronization) of the image sensor;

[0131] The algorithm layer embedding is to embed different physical equations for different data types. For example, the Fourier transform and Newton's law of vibration data, the constrained heat conduction equation (Q = KAΔT) of temperature data, and the geometric constraints (constrained size range) of image data;

[0132] The data layer is embedded to define real-time constraints and safety constraints. The real-time constraints are timestamp synchronization (NTP / GPIO) and data range check (removing outliers), and the safety constraints are adding hardware-level threshold triggers (such as when the vibration intensity > 4mm / s, the relay stops).

[0133] It should be noted that the physical constraint parameters are usually defined by the equipment manufacturer or physical model (such as the upper limit of motor speed), including mechanical and dynamic constraints (such as the upper limit of motor speed (such as motor speed ≤ 1500rpm), vibration threshold (such as vibration amplitude ≤ 4mm / s), structural stiffness and strength limits (such as the maximum allowable deformation of the robotic arm), inertia and damping parameters (such as the moment of inertia and damping coefficient of the robotic arm)), thermodynamic constraints (such as the temperature safety range (such as the surface temperature of the equipment ≤ 80°C), heat conduction equation (such as Q = KAΔT (the relationship between heat flux density and temperature gradient)), cooling rate limit (such as the temperature drop rate ≤ 5°C / minute)), energy and fluid dynamics constraints (such as the energy conservation equation (such as the energy conservation equation of the wellbore flow system of an electric pump well), liquid pressure constraint (such as the pressure range of the hydraulic system 20 - 40MPa), flow and pressure relationship (such as the coupling relationship between flow and pumping pressure)), material and structural constraints (such as the fatigue limit of the material (such as the stress-life curve of steel), the natural frequency of the structure (such as the first natural frequency of the robotic arm 1.2Hz), deformation threshold (such as the maximum allowable bending deformation of the processing robotic arm)) and control and safety constraints (such as control instruction constraints (such as the speed adjustment range 80% - 100% of the rated value), safety interlock conditions (such as automatic shutdown when the temperature exceeds the threshold));

[0134] All types of data are divided into high-timeliness data and low-timeliness data according to the expert experience method. The high-timeliness data is divided into hot data, and the low-timeliness data is divided into cold data. Then, the data storage levels are divided according to the hot data / cold data strategy (such as storing frequently accessed vibration and temperature data in SSD and historical image data in HDD);

[0135] The data is standardized into a structured format (such as TSDB time series database) through data standardization technology (such as ETL) to obtain structured data; a storage list is synchronously generated to record the physical location and access priority of the data block to obtain a storage index;

[0136] It should be noted that the implementation of dynamic IP binding can be achieved through IP configuration methods (such as etc / hosts), combined with Linux network namespace technology, to ensure that PLC devices with the same IP communicate through different physical interfaces; then, the iptables or iproute2 tool is used to achieve route table separation to avoid IP conflicts;

[0137] In the embedding of physical constraint parameters, physical constraints (such as the heat conduction equation) need to be attached to the data metadata in a standardized format (such as JSON) for subsequent anomaly detection;

[0138] For the hierarchical storage strategy, according to the hot data strategy, the LSM-Tree structure can be adopted to manage the write and merge operations to optimize the storage efficiency;

[0139] The design of the storage index table refers to the database index principle, and the data block can be quickly located through the ROWID;

[0140] Through the above steps, a complete process from device network configuration to data acquisition, constraint embedding, and storage management is achieved, providing reliable input for the subsequent steps;

[0141] Extract the time-domain features of each type of data from the structured data, and then horizontally splice the time-domain features of each type of data into a multi-modal time-domain feature vector;

[0142] Decompose each type of data through frequency-domain analysis methods (such as wavelet transform, Fourier transform), and then extract the frequency-domain features of each type of data (such as the proportion of fundamental frequency energy, high-frequency impact energy);

[0143] Set a fixed time window (such as every 10 minutes, every 1 hour, every 1 day), and horizontally splice the frequency-domain feature vectors of each type of data within each time window in chronological order to form a single time-series feature item;

[0144] Arrange the single time-series feature items of all time windows in chronological order to generate a multi-modal frequency-domain feature sequence;

[0145] Exemplarily, based on the structured data, extract the vibration amplitude in the vibration data (such as peak vibration intensity, root mean square RMS) and the temperature fluctuation rate in the temperature data (the temperature change rate per unit time, that is, the ratio of temperature to time), and then horizontally splice them into a time-domain feature vector;

[0146] Perform multi-scale decomposition on the vibration data through wavelet transform (such as Daubechies wavelet) to obtain wavelet coefficients in different frequency bands;

[0147] Extract the proportion of fundamental frequency energy in the wavelet coefficients of different frequency bands (such as the energy of the wavelet coefficients of the first 3 scales, used to reflect the fundamental frequency vibration of the device) as the low-frequency trend item, and extract the energy of the wavelet coefficients of the high-frequency scale (such as the last 2 scales, reflecting the local fault impact energy) as the high-frequency impact energy;

[0148] Horizontally splice the low-frequency trend item and the high-frequency impact energy to form a vibration frequency-domain feature vector (such as {proportion of low-frequency energy, proportion of high-frequency energy});

[0149] The temperature data is decomposed into a combination of sine waves in different frequency bands through Fourier transform, and the low-frequency component with the largest amplitude in the sine wave combination (such as the periodic fluctuation frequency of the device, for example, a 24-hour period corresponds to 0.04 Hz) is extracted as the main frequency energy (the frequency component with the largest amplitude in the temperature data, the energy is concentrated and the low-frequency frequency component with physical significance, usually reflecting the periodic temperature change of the device, corresponding to the dominant period of the temperature change, such as the temperature rise process after the device motor starts (slow change, dominated by low-frequency components)).

[0150] The total energy of the frequency bands higher than the preset frequency threshold (such as 1 Hz, 10 Hz) in the sine wave combination is extracted (such as the total energy > 10 Hz, corresponding to short-period fluctuations, such as the high-frequency impact energy caused by faults) as the high-frequency noise energy (the frequency components in the high-frequency band, whose amplitude is usually small and has no actual physical significance, such as sensor noise (such as Johnson noise of thermistor), environmental interference (such as instantaneous airflow, electromagnetic interference) or sampling error (ADC quantization error or noise in signal transmission)). The main frequency energy and the high-frequency noise energy levels are spliced to form a temperature frequency domain feature vector (such as {main frequency energy ratio, high-frequency noise energy ratio});

[0151] A fixed time window is set (such as every 10 minutes, every 1 hour, every 1 day). In chronological order, the vibration frequency domain feature vector and the temperature frequency domain feature vector within each time window are horizontally spliced to form a single time series feature item;

[0152] All the single time series feature items of all time windows are arranged in chronological order to generate a multi-modal frequency domain feature sequence;

[0153] Exemplarily, the method of converting temperature data into the frequency domain is as follows: Assume that there is a temperature value at each timestamp, and the temperature values of all timestamps are combined into a set of temperature data;

[0154] According to this set of temperature data, a set of frequency components are obtained through the Fourier transform formula, and each frequency component corresponds to an amplitude and a phase;

[0155] The Fourier transform formula is: ;

[0156] Among them, represents the nth temperature value, is the frequency component, and the value range is 0 ≤ f ≤ N / 2 (due to symmetry), = 1 corresponds to the frequency with a period of N / f = 10 sampling points (such as the temperature data is sampled hourly, and the period is 10 hours), = 0.1 corresponds to the low-frequency component with a period of 10 / 0.1 = 100 sampling points, represents the natural constant, represents the imaginary unit, represents pi, is the total number of data points, represents the frequency-domain result after Fourier transform, indicating the complex amplitude (including amplitude and phase information) of the temperature data at frequency , the amplitude represents the energy magnitude of the signal at frequency , and the phase represents the phase shift of this frequency component relative to the time origin. For example, CX(0.1) represents the energy of the low-frequency component in a set of temperature data;

[0157] This formula decomposes the temperature data into the superposition of different frequency components by accumulating the product of the time-domain data and the sub-exponential function ;

[0158] Based on the IP-PLC mapping relationship table, construct the spatial topology map of the sensor, extract the node spatial feature vectors and edge association strengths in the spatial topology map, obtain the spatial association feature vectors of each node as the spatial features of the sensor, and encode the physical constraint parameter list into the physical constraint rule library in combination with the spatial topology map;

[0159] Horizontally splice the time-domain features, frequency-domain features and spatial features, and convert the rule thresholds in the physical constraint rule library (such as temperature value > 125°C, temperature difference between sensor 1 and 2 > 5°C) into numerical features, and merge all features to form a multi-modal enhanced feature set;

[0160] At the same time, in combination with the spatial features, add topological constraints (such as triggering a linkage alarm when the temperature difference between adjacent sensors exceeds the threshold) to the physical constraint rule library to form a constraint rule library; The constraint rule library includes the rule name (the unique identifier of the rule (such as vibration shock energy exceeding the standard)), the trigger condition (feature threshold or logical expression (such as high-frequency energy ratio > 0.3)) and the execution action (predefined operation (such as generating a warning, triggering a shutdown));

[0161] Take each sensor (vibration, temperature, image sensor) as a node, and assign attributes to each node, including sensor type, range and installation coordinates (three-dimensional space coordinates);

[0162] Based on the IP-PLC mapping relationship table, establish edges for the nodes, and assign attributes to each edge, including the physical distance between sensors (such as distance ≤ 1m), directionality (such as sensor 1 is on the left of 2, and sensor 1 and 2 are connected through a directed PLC port) and communication protocol (such as Modbus TCP or Profibus) as edge attributes, and construct the spatial topology map;

[0163] Exemplary spatial topology diagram: Sensor A (vibration) —— physical distance ≤ 1m → Sensor B (temperature); Sensor C (image) —— PLC port X2 → Controller;

[0164] Exemplary edge attributes: Sensor 1 and Sensor 2 are located on both sides of the same equipment bearing, with a physical distance ≤ 1m, connecting port 0 and port 1 of the PLC port;

[0165] Based on the edges between all nodes in the spatial topology diagram, define the nodes with edges as connected by a connection relationship, and the nodes without edges as not connected by a connection relationship. Extract the connection relationships between all nodes and construct an adjacency matrix (each element in the adjacency matrix is 1 or 0, 1 indicates that there is an edge between the corresponding two nodes, which is connected, and 0 indicates that there is no edge between the corresponding two nodes, which is not connected);

[0166] Encode the node attributes into numerical feature vectors as node features, and extract all node features to construct a node feature matrix;

[0167] Exemplary node attribute encoding method:

[0168] Sensor type: One - Hot encoding (e.g., vibration sensor = [1, 0], temperature sensor = [0, 1], image sensor = [0, 0]);

[0169] Range: Normalized value (e.g., 0 - 150°C → 0.8 represents 120°C);

[0170] Installation coordinates: Directly use three - dimensional coordinate values;

[0171] Perform standardization processing on the adjacency matrix. Based on the node attribute matrix and the standardized adjacency matrix, for each node, aggregate the node features of all adjacent nodes to generate the node spatial feature vector of each node, including type correlation (similarity with the sensor types of adjacent nodes), spatial proximity (average distance weight with adjacent sensors), and range consistency (similarity of the range of adjacent sensors);

[0172] At the same time, based on any pair of nodes with edges, extract the physical distance, communication protocol, and sensor type between the two nodes;

[0173] Set the attenuation coefficient of the physical distance (e.g., 0.5, set by expert experience). Multiply the physical distance by the attenuation coefficient, add 1, and then take the reciprocal to obtain the physical distance intensity value; that is, physical distance intensity value = 1 / (1 + physical distance × attenuation coefficient). The attenuation coefficient is used to control the influence degree of the physical distance on the physical distance intensity;

[0174] For the communication protocol between two nodes, if the communication protocols are exactly the same, the communication protocol consistency strength value is given as 1; if the communication protocols are different, the communication protocol consistency strength value is 0. That is, when sensors use the same communication protocol, the association strength increases; when the protocols are different, the strength decreases.

[0175] According to the predefined type complementarity rule table, determine the adjustment coefficient for the sensor type combination, and multiply the adjustment coefficient by the default base sensor type complementarity strength value (usually 1) to obtain the final sensor type complementarity strength value. That is, when sensor types are complementary (such as vibration and temperature), the association strength needs to be adjusted to reflect their synergistic effect.

[0176] Exemplary type complementarity rule table:

[0177] [Sensor type combination: vibration and temperature], [Adjustment coefficient: 1.5], [Description: high coupling relationship (such as bearing failure)]; [Sensor type combination: same type sensors], [Adjustment coefficient: 0.8], [Description: redundant backup or redundant monitoring];

[0178] Perform a weighted sum of the physical distance strength value, communication protocol consistency strength value, and sensor type complementarity strength value between nodes to calculate the edge association strength.

[0179] Exemplary weighted sum:

[0180] Assign different importance weights to the three parts of strength values (such as α = 0.4, β = 0.3, γ = 0.3). Assume that the physical distance strength between sensors 1 and 2 is 0.5, the communication protocol consistency strength is 1.0, and the type complementarity strength is 1.5. Then the edge association strength = (0.4 × 0.5) + (0.3 × 1.0) + (0.3 × 1.5) = 0.2 + 0.3 + 0.45 = 0.95;

[0181] Horizontally concatenate the node spatial feature vector of the node and the edge association strength level to obtain the spatial association feature vector of each node.

[0182] The specific processing flow for generating the node spatial feature vector is as follows:

[0183] Step 1: Add self - connections to the adjacency matrix and perform normalization processing to eliminate the influence of node degree differences, obtaining a normalized adjacency matrix;

[0184] Step 2: For each node, aggregate the node features of all its adjacent nodes,

[0185] The relational expression is: ;

[0186] Where, Denotes the node space feature vector of node v after the (l + 1)-th processing. Denotes the activation function, such as ReLU, Sigmoid, which is used to introduce non-linearity and help identify more complex patterns. u represents an adjacent node, and U represents the set of all adjacent nodes. Denotes the normalization term, which is used to balance the contributions between nodes with different degrees, where is the degree matrix based on the adjacency matrix plus self-connections (i.e., the normalized adjacency matrix). and are the degrees of nodes v and u respectively (i.e., the number of edges connected to them plus self-connections). Denotes the feature vector of node u at the l-th time, which is the data input to the current layer. Denotes the current weight matrix, which is a learnable parameter that determines how to transform node features into node space feature vectors.

[0187] After aggregating the node features of all adjacent nodes, each node will obtain a feature vector, which is the node space feature vector and contains the aggregated spatial association information, namely type correlation, spatial proximity, and range consistency.

[0188] Based on the physical constraint parameter list, combined with the spatial topology graph, the physical constraint parameter list is transformed into structured rules, including physical rules and topological rules, and the physical rules and topological rules are merged into a structured physical constraint rule library (such as JSON format).

[0189] Exemplarily transforming the parameter list into structured rules:

[0190] Physical rules:

[0191] Rule name: Temperature upper limit constraint; Trigger condition: Temperature value > 125°C; Execution action: Trigger an alarm and record.

[0192] Topological rules:

[0193] Rule name: Adjacent sensor temperature difference constraint; Trigger condition: Temperature difference between sensor 1 and 2 > 5°C; Execution action: Mark the abnormal area.

[0194] Extract cross-device time-domain feature vectors, frequency-domain feature vectors, and spatial association feature vectors from the enhanced feature sets of all devices in the factory as heterogeneous data. Combine the physical location and access priority in the storage index, and preferentially load data blocks with high access priority (such as real-time vibration data).

[0195] Based on the device ID and physical interface information, perform timestamp alignment processing (such as interpolation and downsampling) on all heterogeneous data with timestamps across devices (referring to data with timestamps), and eliminate the time offset caused by network latency;

[0196] And according to the range in the physical constraint parameter list, perform normalization processing on the processed heterogeneous data, integrate to obtain a standardized dataset, and synchronously record the corresponding relationship between the device ID and the physical constraint parameters to construct a metadata mapping table;

[0197] To ensure data comparability between different devices and eliminate biases caused by differences in sensor types or sampling frequencies;

[0198] Extract the physical constraints of each device from the physical constraint rule library as a single-device benchmark, such as the upper limit of vibration amplitude and the temperature rate threshold; furthermore, based on the edge association strength in the spatial topology graph, derive the joint constraints of each device under the collaborative working conditions as a cross-device benchmark;

[0199] Assign weights to each device according to the criticality of the device in the factory production chain through the expert experience method, and then perform weighted averaging on the single-device benchmark to generate a single-type benchmark range that is common to the whole factory;

[0200] Integrate the single-type benchmark ranges of all types to generate a global benchmark parameter table;

[0201] Furthermore, based on physical constraints (such as safety specification requirements) in the global parameter table and combined with the expert experience method, preset a static allowable deviation range for each type of device (such as temperature ±3%, vibration value ±0.5mm / s 2 ) as the original tolerance for each device;

[0202] And define the ratio of the actual value of the device collected by the sensor to the corresponding global benchmark parameter as a benchmark verification function (for example, the temperature value collected by the temperature sensor is compared with the temperature benchmark in the global benchmark parameter to obtain the result of the benchmark verification function of the device regarding temperature);

[0203] Exemplary original tolerance settings:

[0204] For example, if the physical constraint rule library stipulates that the upper temperature limit of a high-temperature device is 80°C, it can be directly mapped to the original tolerance range of 80°C ± 3%; at the same time, combined with the association strength of the spatial topology graph (such as the temperature-vibration complementarity of adjacent devices), derive the tolerance correction coefficient under the joint constraint;

[0205] Extract time-series statistical features (such as the mean change rate) by splitting the standardized dataset with a fixed time window, and use a filtering algorithm to separate the long-term trend and short-term fluctuations;

[0206] Based on the adjacency matrix of the spatial topology graph, aggregate the spatial context features of nodes (such as the reciprocal of the installation distance, the intensity of type complementarity) to generate a spatial context vector;

[0207] Convert the physical constraints in the physical constraint rule library into feature screening conditions to eliminate data that does not meet the physical constraints;

[0208] Furthermore, horizontally concatenate the time-domain feature vector, the frequency-domain feature vector, and the spatial context vector in sequence into a feature sequence of unified length, and compress the redundant dimensions of the feature sequence through the principal component analysis method (such as retaining the core features with 90% variance) to generate a multi-dimensional feature matrix in a unified format, and label the physical attributes strongly related to the fault mode (such as high-frequency impact energy) to generate a list of retained key physical attributes;

[0209] Define high-risk devices and low-risk devices based on industry standards, and perform detection parameter binding and detection priority allocation for high-risk devices and low-risk devices;

[0210] The detection parameter binding is as follows: Assign initial sensitivity coefficients to high-risk devices and low-risk devices, and assign initial fault tolerance coefficients to low-risk devices (such as ≤ 2 false alarms per thousand detections);

[0211] And define the sensitivity allocation rule as the sensitivity coefficient of high-risk devices being greater than that of low-risk devices (such as high-temperature equipment = 1.5);

[0212] It should be noted that the definition of high-risk devices and low-risk devices is only exemplary, and more refined settings can be made according to the actual situation, such as introducing a three-level risk classification:

[0213] Level P0 (severe risk): Key devices that directly affect production safety or product quality (such as high-temperature and high-pressure vessels);

[0214] Level P1 (medium risk): Core devices that affect efficiency or cost (such as the main motor of the production line);

[0215] Level P2 (low risk): Auxiliary devices (such as lighting systems);

[0216] Refine the parameter binding:

[0217] Such as the sensitivity coefficient: decreasing according to the risk level (P0 > P1 > P2);

[0218] The fault tolerance coefficient: increasing according to the risk level (P0 < P1 < P2), allowing a higher tolerance for low-risk devices;

[0219] The detection priority is assigned as follows: According to the expert experience method, various types of data collected from the device are divided into two types: safety type and efficiency type, and the contribution degree coefficient of the benchmark verification function for each type of data is assigned according to the priority that the safety type is greater than the efficiency type (for example, safety type = 0.7, efficiency type = 0.3);

[0220] The benchmark verification function is corrected according to the sensitivity coefficient to obtain the corrected benchmark verification function;

[0221] Multiply the value of the benchmark verification function by the sensitivity coefficient as the corrected benchmark verification function; (Example, the sensitivity of the high-temperature device = 1.5 × the benchmark value, that is, the actual value only needs to reach 67% of the benchmark value to trigger an alarm);

[0222] Multiply the sum of the fault tolerance coefficient and 1 by the original tolerance as the corrected dynamic tolerance; (Example, the fault tolerance coefficient = 2 times per thousand times, then the original tolerance is extended from ±3% to ±3.3%);

[0223] Take the sum of the actual value of the device collected by each type of sensor and the dynamic tolerance to obtain the dynamic tolerance range (for example, the actual temperature collected from a certain high-temperature fan is 80°C, and the dynamic tolerance is ±3.3%, then the threshold judgment interval of the benchmark verification function is 80°C ± 3.3%, that is, 76°C to 84°C);

[0224] If the actual value of any type of device is greater than the maximum value of the corresponding dynamic tolerance range, it is determined that the device is abnormal and an alarm is issued;

[0225] If the actual values of all types of devices are less than or equal to the maximum value of the corresponding dynamic tolerance range, the corrected benchmark verification function is calculated separately for the actual value of each type of device to obtain the sensitivity of the actual value of each type of device;

[0226] According to the division of the safety type and efficiency type of each type of data, the contribution degree coefficient is used as the weight of the sensitivity of the actual value of the device, and then the sensitivities of the actual values of all types of devices are weighted and fused to generate a comprehensive verification value;

[0227] If the comprehensive verification value is greater than the preset verification value threshold, it is determined that the device is abnormal and an alarm is issued;

[0228] If the comprehensive verification value is less than or equal to the verification value threshold, it is determined that the device is not abnormal;

[0229] Combined with the standardized data set and the global benchmark parameter table, a dynamic correction strategy is defined, including the real-time synchronization mechanism of the dynamic tolerance and the feedback loop optimization of the sensitivity coefficient;

[0230] The real-time synchronization mechanism for dynamic tolerance calculates the standard deviation of the dynamic tolerance within a fixed time window. If the standard deviation of the dynamic tolerance is greater than the preset standard deviation threshold, the dynamic tolerance is updated.

[0231] Calculate the difference between 1 and the standard deviation threshold, and then multiply it by the dynamic tolerance to obtain the updated dynamic tolerance; that is, dynamic tolerance × (1 - standard deviation threshold) = new dynamic tolerance;

[0232] The feedback loop of the sensitivity coefficient is optimized to calculate the ratio of the number of false alarms to the total number of alarms as the false alarm rate, and automatically adjust the sensitivity coefficient according to the false alarm rate;

[0233] That is, the original sensitivity coefficient × (1 - false alarm rate) = new sensitivity coefficient;

[0234] Integrate the multi-dimensional feature matrix, the benchmark verification function, and the global benchmark parameter table to form a global benchmark system; and it includes static thresholds, dynamic tolerances, and feedback optimization logic;

[0235] Decouple the physical constraint rule library, statistical model library, and spatial topology rule library of the global benchmark system to support independent updates and hot pluggability (such as replacing a new vibration spectrum analysis algorithm does not affect temperature detection);

[0236] Define a standardized defect scoring interface for image data (such as CNN extracts defect features and maps them to numerical defect intensities), and unify the format with other sensor data;

[0237] For two high-temperature fans (equipment A / B):

[0238] Global benchmark system:

[0239] Single-device benchmark: The upper temperature limit of equipment A = 80°C ± 3%, and the vibration amplitude of equipment B ≤ 5mm / s²;

[0240] Joint constraint: If the temperature-vibration gradient ΔT + ΔV of A + B > 0.5MPa / km, then upgrade the detection priority;

[0241] Detection parameter binding:

[0242] The sensitivity of equipment A = 1.5, and the tolerance = 80°C ± 2%;

[0243] The contribution degree of the safety category = 0.7, and the efficiency category = 0.3;

[0244] Dynamic correction: When the standard deviation of equipment A in 3 consecutive windows > 0.1, automatically shrink its temperature tolerance to 80°C ± 2%.

[0245] It should be noted that through the construction of the global benchmark, a complete chain from data standardization to rule mapping and then to multi-dimensional modeling is realized, ensuring the accuracy and interpretability of subsequent anomaly detection;

[0246] Based on the global benchmark system, calculate the ratio of the difference between the actual value of the device and the maximum value of the dynamic tolerance range to the dynamic tolerance to obtain the standardized deviation;

[0247] If the standardized deviation is negative, assign it as 0. If it is positive, it indicates that the tolerance range is exceeded;

[0248] Furthermore, map the standardized deviation to a probability value as the preliminary anomaly probability;

[0249] The mapping method can normalize the standardized deviation to the interval [0,1] through linear normalization;

[0250] Example: A certain temperature value is 85°C, the reference value is 80°C, the dynamic tolerance is ±3.3% → the upper tolerance limit = 84.24°C, the standardized deviation = (85 - 84.24) / 3.3 ≈ 0.23 → the preliminary anomaly probability ≈ 23%;

[0251] Combined with the multi-dimensional feature matrix and the physical constraint rule base, perform reconstruction error processing on the multi-dimensional feature matrix through the principal component analysis method (PCA) to obtain the PCA reconstruction error probability;

[0252] Specifically, combined with the multi-dimensional feature matrix and the physical constraint rule base, perform PCA dimensionality reduction on the multi-dimensional feature matrix through the principal component analysis method, calculate the reconstruction error (Euclidean norm) of each sample in the low-dimensional space as the structured anomaly score, and standardize the reconstruction error to an anomaly probability in the range of [0,1];

[0253] Perform probability density estimation on the multi-dimensional feature matrix through the Gaussian mixture model (GMM) to obtain the GMM probability;

[0254] Specifically, assume that the normal data follows a multi-dimensional Gaussian distribution and use GMM to fit the feature distribution;

[0255] Calculate the probability density value of each sample, convert it to the statistical anomaly probability; and combine the physical constraint rule base to filter out data points that do not conform to the rules (such as noise interference);

[0256] Perform weighted fusion on the preliminary anomaly probability, PCA reconstruction error probability, and GMM probability to obtain the comprehensive anomaly probability;

[0257] Use the edge association strength in the spatial topology graph to correct the comprehensive anomaly probability to obtain the corrected comprehensive anomaly probability;

[0258] Specifically, if multiple adjacent nodes of a certain node (with consistent communication protocols and short physical distances) simultaneously exhibit a high abnormal probability, it is determined that the abnormal probability of this node needs to be multiplied by an association amplification factor to reflect the likelihood of collaborative failures;

[0259] ; is the association weight decay factor (usually set to 0.1) to prevent excessive amplification of isolated events;

[0260] Organize the comprehensive abnormal probabilities of all devices into a matrix structure according to the time series by device ID and timestamp to obtain the device-level abnormal probability matrix; it includes the number of devices, the number of time windows, and the comprehensive abnormal probability of each device in each time window (range [0,1]);

[0261] Example matrix: {device ID, timestamp 1, timestamp 2,..., threshold trigger}; {ID1, 0.12, 0.35,..., 0.3}; {ID2, 0.05, 0.28,..., 0.3};

[0262] Dynamically set the threshold (such as 0.3) according to business requirements (e.g., security devices have higher priorities), and cells exceeding the threshold are marked as potentially abnormal;

[0263] Aggregate the comprehensive abnormal probabilities of associated devices based on the spatial topology graph according to process stages and production line modules (such as injection molding, assembly, testing) (e.g., aggregate by weighted average or max pooling methods);

[0264] Combine the joint constraints in the physical constraint rule base and introduce operating condition characteristics to obtain the operating condition-level abnormal probability matrix;

[0265] The generation relationship formula for the operating condition-level probability is:

[0266] ;

[0267] Among them, represents the set of devices in the m-th operating condition group, represents the weight of device c in this operating condition group, represents the comprehensive abnormal probability of device c at time t, represents the operating condition-level characteristic at time t (such as energy consumption deviation), represents the fusion coefficient of the preset operating condition characteristics;

[0268] The operating condition-level abnormal probability matrix Each cell P(m,t) in it represents the joint abnormal probability of the m-th process stage or production line module in the time window t;

[0269] It should be noted that the device-level anomaly probability matrix shows the independent anomaly probabilities of individual devices for locating specific fault sources (such as abnormal vibration of a certain motor), and typical application scenarios include equipment inspection and single-machine maintenance. The working-condition-level anomaly probability matrix shows the joint anomaly probabilities under the collaborative state of multiple devices for discovering systemic risks (such as abnormal overall energy consumption of a production line), and typical application scenarios are process optimization and energy efficiency management;

[0270] Extract time-series features (such as amplitude volatility and fundamental frequency energy ratio) from the device-level anomaly probability matrix;

[0271] Example: According to the device-level anomaly probability matrix, convert the anomaly probability of the device into a curve form, analyze the anomaly probability curve, identify periodic fluctuations, and extract the fluctuation frequency as a time-series feature;

[0272] Perform PCA dimensionality reduction on the extracted time-series features to obtain low-dimensional feature vectors of the time-series features; and perform physical constraint verification through a physical constraint rule library to filter out data values that do not conform to physical rules (such as local anomalies caused by sensor noise), resulting in a device-level feature model that includes the reduced feature set and the physical constraint verification results;

[0273] Example: If the abnormal vibration probability of a certain device suddenly increases but the temperature is normal, it is marked as a suspected false alarm;

[0274] Based on the spatial topology graph, aggregate the comprehensive anomaly probabilities of associated devices (weighted average or max pooling processing) to generate a preliminary working-condition-level probability;

[0275] Example: Slight anomalies occur in all 3 motors in the injection molding section → Generate a working-condition-level probability after aggregation;

[0276] Establish a causal relationship model by combining the joint rules (such as heat conduction chain reaction and energy consumption coupling) in the physical constraint rule library;

[0277] Example: Failure of the cooling system may cause temperature offsets in multiple devices → Establish a causal relationship model;

[0278] Integrate working-condition-level features (such as production capacity volatility and energy consumption trend) as supplementary inputs;

[0279] Example: The overall energy consumption of the production line drops by 10% → Integrate it as a working-condition-level feature;

[0280] Using the spatial topology graph as the graph structure, train a GNN model to capture the dependencies between devices (such as heat conduction chain reaction and energy consumption coupling), resulting in a working-condition-level feature model that covers cross-device association features, joint constraints, and GNN modeling results;

[0281] Example: The anomaly probability propagation path of adjacent nodes → Quantify the collaborative fault risk;

[0282] It should be noted that the purpose of the device-level feature model is to locate the root cause of single-device faults and output the results of feature dimensionality reduction and physical rule filtering;

[0283] The purpose of the working condition-level feature model is to identify systematic risks and output cross-device correlation features and the output of the GNN model;

[0284] Example: Device level: The abnormal probability matrix of D1 device shows that the high temperature continues to rise → Feature modeling finds abnormal temperature gradient → Trigger bearing wear warning;

[0285] Working condition level: The working condition-level matrix of the injection molding section shows energy consumption deviation → GNN detects collaborative faults in the cooling system → Recommend checking the pump status;

[0286] According to the classification of high-risk and low-risk types of devices, perform device-level optimization, quantify the influence intensity of adjacent nodes, jointly optimize the false alarm rate, perform working condition-level optimization, and form an optimization parameter set;

[0287] Specifically, device-level optimization is to automatically adjust the feature weights according to the classification of high-risk and low-risk types of devices,

[0288] Example: The weight of the safety class index of P0-level devices is set to 80%, and the efficiency class is set to 20%;

[0289] And update the device-level feature model through the incremental learning mechanism to adapt to process changes;

[0290] Working condition-level optimization is to calculate the influence weight of adjacent nodes (such as the closer the distance, the higher the weight) based on the spatial topology graph to quantify the correlation strength; and jointly optimize the false alarm rate and the missed alarm rate, and set a lower threshold for key working conditions;

[0291] According to the values in the device-level abnormal probability matrix and the working condition-level abnormal probability matrix, set the comprehensive risk level (such as P0 level, P1 level, P2 level, device-level abnormal probability matrix, P0 level: P>0.5, P1 level: 0.3<P≤0.5, P2 level: P≤0.3, working condition-level abnormal probability matrix, P0 level: P>0.4, P1 level: 0.2<P≤0.4, P2 level: P≤0.2);

[0292] Based on the comprehensive risk level, divide the alarm levels; for example, P0 level triggers a red alarm + automatic shutdown (such as power off of key devices), P1 level pushes a yellow warning (such as power off of key devices), P2 level records a green prompt (such as slight fluctuations of auxiliary devices);

[0293] After the alarm is triggered, an operation and maintenance work order (including device ID, timestamp, priority) is automatically generated, and manual remarks can be supplemented (such as the need to carry an infrared thermal imager for troubleshooting);

[0294] Automatically allocate work orders according to the matching of alarm levels and maintenance personnel skills, and optimize the response path in combination with traffic information;

[0295] Locate the root cause of anomalies by combining a multi-dimensional feature matrix, a physical constraint rule base, and historical maintenance records. For example: abnormal motor temperature → frequency domain analysis reveals bearing wear → recommend replacement model;

[0296] Dynamically adjust the sensitivity coefficient and tolerance range according to the false alarm rate, and use Bayesian optimization to balance sensitivity and specificity; store each maintenance process in a preset operation and maintenance database, and then regularly update the physical constraint rule base.

[0297] Embodiment 2

[0298] Please refer to Figure 4 As shown, the parts not described in detail in this embodiment can be seen in the description of Embodiment 1. Provide a learning fusion and anomaly detection system for industrial time series data, including:

[0299] Data acquisition and preprocessing module: Parse industrial communication protocols, extract PLC device IDs and IP addresses, and establish an initial device list; combine the IP address and device ID to construct an IP-PLC mapping relationship table; collect multi-modal data, align it according to the time stamp, and then construct a physical constraint parameter list according to the physical characteristics of the sensors; manage data through a hierarchical storage strategy to generate structured data and storage indexes;

[0300] Feature extraction and enhancement module: Based on the structured data, extract time domain feature vectors and frequency domain feature vectors; construct a spatial topology graph based on the IP-PLC mapping relationship table, extract node spatial feature vectors and edge association strengths, and generate spatial association feature vectors; combine the physical constraint parameter list, encode physical rules and topological rules, construct a constraint rule base, and form an enhanced feature set;

[0301] Global benchmark system construction module: Aggregate the enhanced feature sets and constraint rule bases of industrial equipment in the factory to generate a multi-dimensional feature matrix, optimize the detection threshold through spatio-temporal feature fusion and physical constraint parameters, generate a global benchmark parameter table, and then construct a global benchmark system; generate a device-level anomaly probability matrix and a working condition-level anomaly probability matrix based on the global benchmark system;

[0302] Anomaly detection and hierarchical modeling module: Based on the device-level anomaly probability matrix and the generated working condition-level anomaly probability matrix, generate a device-level feature model and a working condition-level feature model through hierarchical modeling, and perform hierarchical optimization to generate an optimized parameter set;

[0303] Closed-loop optimization and alarm response module: Based on the output results of the device-level feature model and the working condition-level feature model and the optimized parameter set, construct an alarm response mechanism, and reversely update the physical constraint parameters associated with the sensors to form a closed-loop iteration.

[0304] Embodiment III

[0305] This embodiment discloses an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the operation mode of the above-provided learning fusion and anomaly detection method for industrial time-series data.

[0306] Since the electronic device introduced in this embodiment is the electronic device adopted for implementing the learning fusion and anomaly detection method for industrial time-series data in the embodiments of the present application, based on the learning fusion and anomaly detection method for industrial time-series data introduced in the embodiments of the present application, those skilled in the art can understand the specific implementation manners and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device implements the method in the embodiments of the present application will not be described in detail here. As long as those skilled in the art implement the electronic device adopted for the learning fusion and anomaly detection method for industrial time-series data in the embodiments of the present application, it falls within the scope of protection of the present application.

[0307] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.

[0308] The above is only the preferred embodiment of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for ordinary technical users in this technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.

Claims

1. A method for learning fusion and anomaly detection of industrial time-series data, characterized in that, Including: S1: Analyze the industrial communication protocol, extract the PLC device ID and IP address, and establish an initial device list; Combine the IP address and device ID to construct an IP-PLC mapping relationship table; Collect multi-modal data, align it according to the timestamp, and then construct a physical constraint parameter list according to the physical characteristics of the sensor; Manage the data through a hierarchical storage strategy to generate structured data and storage indexes; S2: Based on the structured data, extract time-domain feature vectors and frequency-domain feature vectors; Construct a spatial topology graph based on the IP-PLC mapping relationship table, extract node spatial feature vectors and edge association strengths, and generate spatial association feature vectors; Combine the physical constraint parameter list, encode the physical rules and topological rules, construct a constraint rule library, and form an enhanced feature set; S3: Aggregate the enhanced feature set and constraint rule library of industrial devices in the factory to generate a multi-dimensional feature matrix, optimize the detection threshold through spatio-temporal feature fusion and physical constraint parameters, generate a global reference parameter table, and then construct a global reference system; Generate a device-level anomaly probability matrix and a working condition-level anomaly probability matrix based on the global reference system; S4: Based on the device-level anomaly probability matrix and the generated working condition-level anomaly probability matrix, generate a device-level feature model and a working condition-level feature model through hierarchical modeling, and perform hierarchical optimization to generate an optimization parameter set; S5: Based on the output results of the device-level feature model and the working condition-level feature model and the optimization parameter set, construct an alarm response mechanism, and reverse-update the physical constraint parameters associated with the sensor to form a closed-loop iteration.

2. The learning fusion and anomaly detection method for industrial time-series data according to claim 1, characterized in that The methods for the structured data and storage indexes include: Parse the communication protocol data of the PLC device through an industrial protocol parsing mechanism, and extract device identifiers, including the IP address and device ID; Integrate the IP addresses and device IDs of all PLC devices to establish an initial device list; Based on the initial device list, identify PLC devices with the same IP address, combine the physical interface information, assign a unique physical interface to each PLC device, assign PLC devices with the same IP address to different physical interfaces, and set interface bindings through a network configuration tool; Integrate the device ID, IP address, and physical interface information into a structured table to obtain an IP-PLC mapping relationship table; Real-time collect various types of data of the device through various types of sensor interfaces as the multi-modal data of the device, align it according to the timestamp to form an original data stream, and then perform data cleaning and standardization processing to integrate it into a preprocessed data stream; According to the physical characteristics of the device, define the physical constraint parameters of various types of sensors, and integrate and construct them to obtain a physical constraint parameter list; Based on the physical constraint parameter list, embed the physical constraint parameters through the hardware layer, algorithm layer, and data layer; The hardware layer embedding is to define the sampling parameters of the sensor according to the physical constraint parameters; The algorithm layer embedding is to embed different physical equations for different data types; The data layer embedding is to define real-time constraints and security constraints. The real-time constraints are timestamp synchronization and data range checking, and the security constraints are to add hardware-level threshold triggers; All types of data are divided into high-timeliness data and low-timeliness data according to the expert experience method. The high-timeliness data is divided into hot data, and the low-timeliness data is divided into cold data. Then, the data storage levels are divided according to the hot data / cold data strategy; The data is standardized into a structured format through data standardization technology to obtain structured data; a storage list is synchronously generated to record the physical location and access priority of data blocks, and a storage index is obtained.

3. The learning fusion and anomaly detection method for industrial time-series data according to claim 2, characterized in that The ways of constructing the constraint rule library and forming the enhanced feature set include: Extract the time-domain features of each type of data from the structured data, and then horizontally concatenate the time-domain features of each type of data into a multi-modal time-domain feature vector; Decompose each type of data through frequency-domain analysis, and then extract the frequency-domain features of each type of data; Set a fixed time window, and horizontally concatenate the frequency-domain feature vectors of each type of data within each time window in chronological order to form a single time-series feature item; Arrange the single time-series feature items of all time windows in chronological order to generate a multi-modal frequency-domain feature sequence; Based on the IP-PLC mapping relationship table, construct the spatial topology map of the sensor, extract the node spatial feature vector and edge association strength in the spatial topology map, obtain the spatial association feature vector of each node as the spatial feature of the sensor, and encode the physical constraint parameter list into the physical constraint rule library in combination with the spatial topology map; Horizontally concatenate the time-domain features, frequency-domain features and spatial features, and convert the rule thresholds in the physical constraint rule library into numerical features, and merge all features to form a multi-modal enhanced feature set; At the same time, in combination with the spatial features, add topological constraints to the physical constraint rule library to form a constraint rule library.

4. The learning fusion and anomaly detection method for industrial time series data according to claim 3, wherein The ways of obtaining the node spatial feature vector and edge association strength include: Take each sensor as a node, and assign attributes to each node, including sensor type, range and installation coordinates; Based on the IP-PLC mapping relationship table, establish edges for the nodes, and assign attributes to each edge, including the physical distance, directionality and communication protocol between sensors as edge attributes, and construct a spatial topology map; Based on the edges between all nodes in the spatial topology map, define the nodes with edges as connected by the connection relationship, and define the nodes without edges as not connected by the connection relationship, extract all the connection relationships between nodes, and construct an adjacency matrix; Encode the node attributes into a numerical feature vector as the node feature, and extract all node features to construct a node feature matrix; Perform standardization processing on the adjacency matrix. Based on the node attribute matrix and the standardized adjacency matrix, for each node, aggregate the node features of all adjacent nodes to generate the node spatial feature vector of each node, including type correlation, spatial proximity and range consistency; At the same time, based on any pair of nodes with edges, extract the physical distance, communication protocol and sensor type between the two nodes; Set the attenuation coefficient of the physical distance, multiply the physical distance by the attenuation coefficient, add 1, and then take the reciprocal to obtain the physical distance intensity value; For the communication protocol between two nodes, if the communication protocols are exactly the same, the consistency strength value of the communication protocol is assigned as 1; if the communication protocols are different, the consistency strength value of the communication protocol is 0. According to the predefined type complementarity rule table, determine the adjustment coefficient of the sensor type combination, and multiply the adjustment coefficient by the default basic sensor type complementarity strength value to obtain the final sensor type complementarity strength value. Perform a weighted sum of the physical distance strength value, communication protocol consistency strength value, and sensor type complementarity strength value between nodes to calculate the edge association strength.

5. The learning fusion and anomaly detection method for industrial time-series data according to claim 4, wherein The method for obtaining the physical constraint rule library includes: Horizontally splice the node space feature vector of the node and the edge association strength level to obtain the spatial association feature vector of each node. Based on the physical constraint parameter list, combined with the spatial topology graph, convert the physical constraint parameter list into structured rules, including physical rules and topological rules, and merge the physical rules and topological rules into a structured physical constraint rule library.

6. The learning fusion and anomaly detection method for industrial time-series data according to claim 5, characterized in that, The method for generating the multi-dimensional feature matrix includes: Extract the cross-device time-domain feature vector, frequency-domain feature vector, and spatial association feature vector from the enhanced feature set as heterogeneous data. Based on the device ID and physical interface information, perform timestamp alignment processing on all timestamped heterogeneous data across devices. And according to the range in the physical constraint parameter list, perform normalization processing on the processed heterogeneous data, and integrate to obtain a standardized data set. Extract the physical constraints of each device from the physical constraint rule library as a single-device benchmark; furthermore, based on the edge association strength in the spatial topology graph, deduce the joint constraints of each device under the collaborative working condition as a cross-device benchmark. Assign weights to each device according to the criticality of the device in the factory production chain through the expert experience method, and then perform a weighted average on the single-device benchmark to generate a single-type benchmark range common to the whole factory. Integrate the single-type benchmark ranges of all types to generate a global benchmark parameter table. Furthermore, based on the physical constraints in the global parameter table and the expert experience method, preset a static tolerance range for each type of device as the original tolerance of each device. And define the ratio of the actual value of the device collected by the sensor to the corresponding global benchmark parameter as the benchmark verification function. Extract the time series statistical features by splitting the standardized data set with a fixed time window, and use the filtering algorithm to separate the long-term trend and short-term fluctuations. Based on the adjacency matrix of the spatial topology graph, aggregate the spatial context features of the nodes to generate a spatial context vector. Convert the physical constraints in the physical constraint rule library into feature screening conditions, and eliminate the data that does not meet the physical constraints. Furthermore, horizontally splice the time-domain feature vector, frequency-domain feature vector, and spatial context vector in sequence into a feature sequence of a unified length, and compress the redundant dimensions of the feature sequence through the principal component analysis method to generate a multi-dimensional feature matrix in a unified format.

7. The learning fusion and anomaly detection method for industrial time series data according to claim 6, characterized in that The method for constructing the global benchmark system includes: Define high-risk devices and low-risk devices based on industry standards, and perform detection parameter binding and detection priority allocation for high-risk devices and low-risk devices. The detection parameters are bound as follows: initial sensitivity coefficients are assigned to high-risk devices and low-risk devices, and an initial fault tolerance coefficient is assigned to low-risk devices; and the sensitivity assignment rule is defined such that the sensitivity coefficient of high-risk devices is greater than that of low-risk devices. The detection priorities are assigned as follows: according to the expert experience method, various types of data collected from the device are divided into two types, namely, safety type and efficiency type, and contribution degree coefficients of the benchmark verification functions for each type of data are assigned according to the priority that the safety type is greater than the efficiency type. The benchmark verification function is corrected by the sensitivity coefficient to obtain a corrected benchmark verification function. The original tolerance is corrected by the fault tolerance coefficient to obtain a corrected dynamic tolerance; the sum of the actual device values collected by each type of sensor and the dynamic tolerance is taken to obtain a dynamic tolerance range. If the actual value of any type of the device is greater than the maximum value of the corresponding dynamic tolerance range, the device is determined to be abnormal and an alarm is issued. If the actual values of all types of the device are less than or equal to the maximum value of the corresponding dynamic tolerance range, the corrected benchmark verification function is calculated separately for the actual value of each type of the device to obtain the sensitivity of the actual value of each type of the device. According to the division of the safety type and efficiency type of each type of data, the contribution degree coefficient is used as the weight of the sensitivity of the actual value of the device, and then the sensitivities of the actual values of all types of the device are weighted and fused to generate a comprehensive verification value. If the comprehensive verification value is greater than the preset verification value threshold, it is determined that the device is abnormal and an alarm is issued; if the comprehensive verification value is less than or equal to the verification value threshold, it is determined that the device is not abnormal. Combined with the standardized data set and the global benchmark parameter table, a dynamic correction strategy is defined, including a real-time synchronization mechanism for the dynamic tolerance and a feedback loop optimization for the sensitivity coefficient. The real-time synchronization mechanism for the dynamic tolerance is to calculate the standard deviation of the dynamic tolerance within a fixed time window. If the standard deviation of the dynamic tolerance is greater than the preset standard deviation threshold, the dynamic tolerance is updated. The feedback loop optimization for the sensitivity coefficient is to calculate the ratio of the number of false alarms to the total number of alarms as the false alarm rate, and automatically adjust the sensitivity coefficient according to the false alarm rate. The multi-dimensional feature matrix, the benchmark verification function, and the global benchmark parameter table are integrated to form a global benchmark system; and it includes static thresholds, dynamic tolerances, and feedback optimization logics.

8. The learning fusion and anomaly detection method for industrial time-series data according to claim 7, wherein The generation methods of the device-level abnormal probability matrix and the generation of the working condition-level abnormal probability matrix include: Based on the global benchmark system, the ratio of the difference between the actual value of the device and the maximum value of the dynamic tolerance range to the dynamic tolerance is calculated to obtain a standardized deviation. If the standardized deviation is negative, it is assigned a value of 0. Furthermore, the standardized deviation is mapped to a probability value as a preliminary abnormal probability. The mapping method can normalize the standardized deviation to the interval [0, 1] through linear normalization. Combined with the multi-dimensional feature matrix and the physical constraint rule base, the multi-dimensional feature matrix is processed for reconstruction error through the principal component analysis method to obtain the PCA reconstruction error probability. The probability density of the multi-dimensional feature matrix is estimated through the Gaussian mixture model to obtain the GMM probability. The preliminary abnormal probability, the PCA reconstruction error probability, and the GMM probability are weighted and fused to obtain a comprehensive abnormal probability. The comprehensive anomaly probability is corrected using the edge association strength in the spatial topology graph to obtain the corrected comprehensive anomaly probability; All devices' comprehensive anomaly probabilities are organized into a matrix structure according to the time series by device ID and timestamp to obtain the device-level anomaly probability matrix; including the number of devices, the number of time windows, and the comprehensive anomaly probability of each device in each time window; Based on the spatial topology graph, the comprehensive anomaly probabilities of associated devices are aggregated according to the process stage and production line module; Combined with the joint constraints in the physical constraint rule base and introducing the working condition characteristics to obtain the working condition-level anomaly probability matrix.

9. The learning fusion and anomaly detection method for industrial time-series data according to claim 8, wherein, The generation method of the optimization parameter set includes: The time series features are extracted from the device-level anomaly probability matrix, and the extracted time series features are dimensionally reduced by PCA to obtain the low-dimensional feature vector of the time series features; and the physical constraint verification is carried out through the physical constraint rule base to filter out the data values that do not conform to the physical rules to obtain the device-level feature model; Based on the spatial topology graph, the comprehensive anomaly probabilities of associated devices are aggregated to generate the preliminary working condition-level probability, and a causal relationship model is established by combining the joint rules in the physical constraint rule base; Integrate the working condition-level features as supplementary inputs, use the spatial topology graph as the graph structure, and train the GNN model to capture the dependence relationship between devices to obtain the working condition-level feature model; According to the division of high-risk and low-risk types of devices, device-level optimization is carried out, the influence intensity of adjacent nodes is quantified, the false alarm rate is jointly optimized, and working condition-level optimization is carried out to generate the optimization parameter set.

10. The learning fusion and anomaly detection method for industrial time-series data according to claim 9, characterized in that The construction method of the alarm response mechanism includes: Set the comprehensive risk level according to the values in the device-level anomaly probability matrix and the working condition-level anomaly probability matrix; Divide the alarm levels based on the comprehensive risk level; Automatically generate an operation and maintenance work order after the alarm is triggered; automatically allocate the operation and maintenance work order according to the matching of the alarm level and the skills of the maintenance personnel, and optimize the response path in combination with traffic information; Locate the root cause of the anomaly by combining the multi-dimensional feature matrix, the physical constraint rule base and the historical maintenance records; Dynamically adjust the sensitivity coefficient and the tolerance range according to the false alarm rate; store each maintenance process in the preset operation and maintenance database, and then regularly update the physical constraint rule base.

Citation Information

Patent Citations

  • Industrial control system anomaly detection method based on dual-contour model

    CN106502234A

  • Water conservancy safety detection method based on AI edge calculation

    CN119652942A