Unmanned aerial vehicle unsupervised anomaly detection method
Through the unsupervised anomaly detection method and the PA-LSTM-AE model, the complex problem of relying on expert experience and physical model construction in the abnormality detection of unmanned aerial vehicle flight data is solved, efficient feature screening and accurate anomaly detection are realized, and the robustness and generalization ability of detection are improved.
Patent Information
- Application Number
- CN202510335325.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-24
AI Technical Summary
The existing drone flight data anomaly detection technology relies on expert experience, complex physical model construction, insufficient generalization ability to unknown anomaly types, and high computing costs.
Unsupervised anomaly detection method was used to filter key feature data through Spearman correlation coefficient method, and abnormality detection was performed using the PA-LSTM-AE model. The model includes parallel LSTM structure, attention mechanism and random discard layer, which can automatically filter features, reduce model complexity, and improve generalization capabilities.
It realizes efficient feature screening, accurate anomaly detection, strong robustness and generalization capabilities, reduces calculation costs, improves detection efficiency and accuracy, and adapts to different flight environments and mission needs.
Smart Images

Figure CN120197103A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of unmanned aerial vehicle (UAV) anomaly detection, and particularly to an unsupervised UAV anomaly detection method. Background Art
[0002] In the field of UAVs, anomaly detection can detect anomalies in flight data in advance, so as to perform preventive maintenance or mission replanning, improving the safety and reliability of UAVs. UAV flight data anomaly detection technologies are mainly divided into three categories: knowledge-based methods, model-based methods, and data-driven methods: 1. Knowledge-based methods rely on expert experience and prior knowledge to identify anomalies by defining normal behavior patterns in UAV flight data. This method is simple to implement, but highly dependent on expert knowledge and difficult to adapt to new or unknown types of anomalies; 2. Model-based methods describe the normal flight behavior of UAVs by establishing mathematical models, and any data deviating from this model is considered abnormal. This method has high precision, but requires accurate physical models, and the model construction is complex and difficult; 3. Data-driven methods directly learn the normal behavior patterns of UAVs from data and identify data points deviating from these patterns. This method reduces the dependence on expert knowledge and does not require the construction of accurate physical models, and is currently a research hotspot.
[0003] The method proposed in Patent 201810639367.6 demonstrates the effectiveness of the combination of LSTM, CNN, and autoencoder (AE) in UAV flight data anomaly detection. However, these methods face a common challenge in practical applications: when UAV flight data contains a large number of parameters, how to effectively screen key parameters to avoid the reduction of model performance due to redundant information. Specifically, although the existing technologies can handle high-dimensional data, the inclusion of too many irrelevant or weakly relevant parameters not only increases the computational complexity, but may also dilute the sensitivity of the model to true anomaly patterns, resulting in a decrease in detection efficiency and accuracy. Summary of the Invention
[0004] The present invention provides an unsupervised UAV anomaly detection method to solve the problems in the existing UAV flight data anomaly detection technologies, such as dependence on expert experience, complex physical model construction, insufficient generalization ability for unknown anomaly types, and high computational costs.
[0005] The solution of the present invention is as follows: an unsupervised UAV anomaly detection method sequentially includes the following steps:
[0006] (1) Collect an initial data set; collect characteristic data of UAV flight in multiple dimensions;
[0007] (2) Association analysis: The Spearman correlation coefficient method is used to perform association analysis on the feature data, and the feature data with the absolute value of the Spearman correlation coefficient greater than 0.4 is selected for output;
[0008] (3) Preprocess the data set: Normalize and reconstruct the selected feature data;
[0009] (4) Model training: Use the selected feature data to train the PA-LSTM-AE model. For each dimension of feature data, a corresponding model is trained. The output loss function of the model is used as the reconstruction error, and the anomaly threshold T for the feature data of this dimension is obtained after calculation;
[0010] (5) Model application: Import the trained model and its parameters into the airborne system of the UAV to be tested. During navigation, each dimension of feature data is input into its corresponding model, and the anomaly detection of this dimension is carried out by comparing the reconstruction error output by the model with the anomaly threshold T.
[0011] The beneficial effects are as follows: (1) Efficient feature screening: Through association analysis using the Spearman correlation coefficient method, feature data highly correlated with the UAV flight state (the absolute value of the correlation coefficient is greater than 0.4) can be automatically screened out, effectively reducing redundant information, lowering the model complexity, and getting rid of the excessive dependence on expert experience, thus enhancing the universality and self-adaptability of the method; (2) Precise anomaly detection: The data-driven PA-LSTM-AE model is adopted. The parallel LSTM structure is used to capture complex dynamic patterns in the time series, and the attention mechanism is combined to enhance the attention to key time steps, significantly improving the accuracy and sensitivity of anomaly detection. This method can identify subtle anomalies in UAV flight data in real time, providing timely basis for preventive maintenance and mission adjustment; (3) Strong robustness and generalization ability: A random dropout layer is introduced during the model training process, effectively preventing overfitting and enhancing the model's generalization ability to unknown anomaly types. At the same time, the dynamic anomaly threshold T set by quantiles can adapt to different flight environments and mission requirements, ensuring the robustness of anomaly detection. (4) Low computational cost and high efficiency: Data normalization and reconstruction processing not only meet the input requirements of the LSTM model but also reduce the computational amount through the sliding window technique, improving the processing efficiency. In addition, the division of the model training and test sets ensures the reliable evaluation of the model performance, further verifying the feasibility of the method in practical applications. In summary, this solution realizes the real-time identification and robust detection of subtle anomalies in UAV flight data, enhancing the universality, self-adaptability, and practical application feasibility of the method.
[0012] Furthermore, the PA-LSTM-AE model is based on the LSTM structure. The input of the previous time period will enter the parallel LSTM units simultaneously. After passing through the forget gate, the input gate and the output gate will be passed into the next parallel LSTM unit respectively, and the outputs of each parallel unit will be fused together. It specifically includes the following levels:
[0013] 1 input layer: As the entrance of the model, it passes the feature data to the subsequent layers;
[0014] 1 parallel LSTM layer: In which, the upper layer is two LSTMs in series, and the lower layer has only one LSTM, which is used to process the input data and extract time series features;
[0015] input data and extract time series features;
[0016] 1 parallel dropout layer: Randomly drops the outputs of the upper and lower layer LSTMs respectively to prevent overfitting;
[0017] 1 multiplication layer: Multiplies and fuses the outputs of the two dropout layers to enhance feature interaction;
[0018] 1 attention layer: Calculates the attention weights for each time step to enhance the attention to important time steps;
[0019] 1 repeat vector layer: Repeats the output of the attention layer twice to generate time series data;
[0020] 1 LSTM layer; Processes the data of the attention layer;
[0021] 1 output layer: Used to output the mean squared error (MSE) of the loss function.
[0022] In this solution, the PA-LSTM-AE model significantly improves the performance in UAV anomaly detection by virtue of its unique parallel LSTM structure and attention mechanism: Its parallel LSTM layer effectively captures the short-term and long-term dependencies of flight data, combines with the multiplication layer to enhance feature interaction, and significantly improves the ability to extract complex dynamic features; The attention mechanism dynamically focuses on key time steps, optimizing the accuracy and efficiency of anomaly detection; The dynamic threshold setting adapts to the requirements of multiple scenarios, balances false positives and false negatives, and enhances the reliability of detection; The parallel dropout layer prevents overfitting, ensuring the generalization and stability of the model. Through innovative design and algorithm optimization, this model provides an efficient and accurate technical guarantee for the safe flight of UAVs.
[0023] Furthermore, in the correlation analysis, the calculation formula of the Spearman correlation coefficient is as follows:
[0024]
[0025] In the formula, ρ is the Spearman correlation coefficient, d irepresents the rank difference of the corresponding observed values of two variables, and n is the number of features in the data set. is the sum of the squares of all pairwise rank differences. In this solution, Spearman correlation coefficient (ρ) is used for correlation analysis. By calculating the rank difference (di) of the corresponding observed values of two variables and its sum of squares, the correlation between feature data can be accurately quantified, ensuring that features highly correlated with the UAV flight state are selected (absolute value of ρ greater than 0.4), providing a high-quality data basis for subsequent model training and effectively improving the accuracy and efficiency of feature selection.
[0026] Furthermore, the calculation formula for the normalization process is as follows:
[0027]
[0028] In the formula, the initial data is represented by x o and the normalized data is represented by x new . The maximum and minimum values of x o are represented by x omax and x omin respectively. In this solution, through normalization, the initial data is mapped to the [-1, 1] interval through linear transformation, which not only eliminates the dimensional difference between different features but also enhances the comparability of data, making the model training more stable and efficient. This standardization process significantly improves the convergence speed and generalization ability of the model.
[0029] Furthermore, the process of data reconstruction includes using a sliding window of length E to capture local data in the time series of feature data, and the reconstructed data is an input matrix X(T) that meets the requirements of LSTM training, specifically as follows:
[0030]
[0031] In the formula, x n is the original data in the time series of feature data, and n is the length of the selected feature data sequence. This solution not only retains the time series characteristics of the data but also optimizes the data structure through reconstruction, enabling the model to better capture the dynamic patterns in the data and improving the sensitivity of anomaly detection.
[0032] Furthermore, in the model training step, the calculation formula for the loss function MSE is as follows:
[0033]
[0034] In the formula, where y i is the i-th data point without anomaly in the original feature data sequence. The \(i\)-th data point of the model estimated value, and \(n\) is the length of the selected feature data sequence. This solution provides a clear optimization goal for model training by quantifying the difference between the model estimated value and the original anomaly-free data point. The calculation formula of MSE directly reflects the accuracy of model prediction, which helps to adjust model parameters in a timely manner during training and improve model performance.
[0035] Furthermore, in the model training step, a quantile \(p\leq1\) is set, and the product of this quantile and the reconstruction error is used as the anomaly threshold \(T\). This solution enables the anomaly detection threshold to be dynamically adjusted according to different flight environments and mission requirements. This flexible threshold setting mechanism effectively balances the false alarm rate and the miss rate, improving the reliability and practicality of anomaly detection.
[0036] Furthermore, in the model training step, 85% of the data set is used as the training set and 15% as the test set, and the training set is input into the PA-LSTM-AE model for training. This solution not only ensures the sufficiency of model training but also provides an independent test set to verify model performance. By comparing the reconstruction error of the test set with the anomaly threshold \(T\), the normal or abnormal state of the data can be accurately judged, further verifying the effectiveness and stability of the model in practical applications.
[0037] Furthermore, in the model training step, after the PA-LSTM-AE model is trained, the data of the test set is used to test the PA-LSTM-AE model to obtain the reconstruction error of the test set. When the reconstruction error of the test set is less than the anomaly threshold \(T\), it proves that the data at this time is normal data; when the reconstruction error of the test set is greater than the anomaly threshold \(T\), it indicates that the data at this time is abnormal data. This solution through the test set verification mechanism can intuitively show the performance of the model on unknown data, providing strong evidence for the credibility and practicality of the model. This is particularly important for the safe application of critical systems such as unmanned aerial vehicles, helping to enhance users' trust and dependence on model performance. Description of the Drawings
[0038] Figure 1 It is a schematic diagram of a sliding window;
[0039] Figure 2 It is a diagram of the PLSTM model;
[0040] Figure 3 It is a diagram of the PA-LSTM-AE model;
[0041] Figure 4 It is a diagram of the normal and injected deviation data of Flight 69 of Thor;
[0042] Figure 5Abnormal detection result graphs of PA-LSTM-AE, LSTM-AE, PLSTM-AE, and ALSTM-AE models after injecting bias = 10;
[0043] Figure 6 Visualization result graphs of abnormal detection of PA-LSTM-AE, LSTM-AE, PLSTM-AE, and ALSTM-AE models (δ = 10);
[0044] Figure 7 Abnormal detection result graphs of PA-LSTM-AE, LSTM-AE, PLSTM-AE, and ALSTM-AE models after injecting bias = 5;
[0045] Figure 8 Flow schematic diagram of an unsupervised abnormal detection method for an unmanned aerial vehicle in the present invention. Detailed implementation manners
[0046] Embodiment
[0047] An unsupervised abnormal detection method for an unmanned aerial vehicle in this embodiment is as Figure 8 shown and includes the following steps:
[0048] (1) Data collection
[0049] This embodiment uses a publicly available dataset of the Thor 69 UAV (i.e., unmanned aerial vehicle) collected by the University of Minnesota, which consists of 75 feature data sequences recorded during the 69th normal flight of the Thor UAV. The sampling frequency is 50 Hz, with a total of 42,711 data sampling points.
[0050] (2) Correlation analysis
[0051] The Spearman correlation coefficient method is used to perform correlation analysis on the collected feature data, and the feature data sequences with the absolute value of the Spearman correlation coefficient greater than 0.4 are selected for output. The calculation formula is as shown in Equation (1):
[0052]
[0053] In the formula, ρ is the Spearman correlation coefficient, d i represents the rank difference of the corresponding observed values of the two variables, n is the number of features in the dataset, is the sum of the squares of all rank differences.
[0054] (3) Data preprocessing
[0055] Normalization and data reconstruction processing are performed on each selected feature data sequence. The normalization formula is as shown in Equation (2), and the initial data is represented by x o and the normalized data is represented by xnew Indicates that x o The maximum and minimum values of omax and x omin express:
[0056]
[0057] The normalized data is reconstructed. Specifically, a sliding window with a length of E is used to capture local data in the time series data. The sliding mechanism using E=2 as an example is as follows: Figure 1 As shown, Figure 1 Where n is the length of the selected feature data sequence. The equation for defining the reconstruction is shown in equation (3). The reconstructed data is the input matrix X(T) that can meet the LSTM training requirements:
[0058]
[0059] In formula (3), x n is the original data in the feature data time series, and n is the length of the selected feature data sequence.
[0060] (4) Dataset Division
[0061] The preprocessed feature data is randomly divided into training set and test set. The training set consists of [0:12.750], accounting for 85% of the data set, and the test set consists of [12.750:15.000], accounting for 15% of the data set.
[0062] Since abnormal data is difficult to obtain, this embodiment uses an abnormal injection method to generate abnormal data. Drift anomaly occurs when the UAV cannot maintain the expected trajectory, position or attitude due to factors such as sensor errors, environmental interference or power problems, causing the UAV flight data to deviate from the expected v value. Drift anomaly involves the gradual deviation of UAV flight data from the predetermined trajectory or position, which is usually caused by dynamic factors. The formula for injecting offset anomaly is shown in formula (4).
[0063] x bias =x t +δ (4)
[0064] where x t is the original flight data, δ is a constant, and t is time. Abnormal data is injected into the test set before model training, or injected into the test set after model training is completed to test the model's anomaly detection ability.
[0065] (5) Model training
[0066] A. Model Construction
[0067] Introduction to PLSTM: LSTM is a variant of the Recurrent Neural Network (RNN) proposed by Hochreiter and Schmidhuber in 1997. It aims to solve the problem of vanishing gradients or exploding gradients encountered by traditional RNNs when dealing with long sequence data. The structure of LSTM usually consists of a forget gate, an input gate, an output gate, and a memory cell. The forget gate will decide which information should be retained in the cell state and which information should be forgotten based on the current input and the output of the previous time step. At the same time, the input gate will decide whether to add new information to the cell state. The cell state will be updated according to the decisions of the forget gate and the input gate. Finally, the output gate determines the output value, and it also saves the current data to the next hidden layer cell, and the storage cell determines and sends the data to the next layer. As Figure 2 shown, on the basis of the original LSTM structure, the PLSTM model structure proposes a parallel LSTM structure. The input of the previous time period will enter the parallel LSTM units simultaneously. After passing through the forget gate, the input gate and the output gate will be passed into the next parallel LSTM unit respectively, and the outputs of each parallel unit will be fused together.
[0068] As Figure 3 shown, in this embodiment, the training set is used to train the PA-LSTM-AE model, and the output is the loss function MSE. PA-LSTM-AE is a neural network that combines the LSTM network with AE. It combines the feature extraction ability of the autoencoder with the time data processing ability of LSTM to retain the time data information in the extracted features. And the introduced parallel mechanism can improve the accuracy of model anomaly detection. In the PA-LSTM-AE model, on the basis of the LSTM structure, the input of the previous time period will enter the parallel LSTM units simultaneously. After passing through the forget gate, the input gate and the output gate will be passed into the next parallel LSTM unit respectively, and the outputs of each parallel unit will be fused together.
[0069] Figure 3 The dotted line in represents the path for the parameters output by LSTM to be passed to the next LSTN unit. The hierarchy of the PA-LSTM-AE model is shown in Table 1:
[0070]
[0071] According to Table 1 and Figure 3 shown, the structure of the PA-LSTM-AE model is as follows:
[0072] 1 input layer (i.e., Input layer): As the entrance of the model, it passes the feature data to the subsequent layers;
[0073] 1 parallel LSTM layer (i.e., PLSTM Layer), where the upper layer is two LSTMs in series and the lower layer has only one LSTM; processes the input data to extract time series features;
[0074] 1 parallel dropout layer (i.e., dropout layer): randomly drops the outputs of the upper and lower LSTMs respectively to prevent overfitting;
[0075] 1 multiplication layer (i.e., Multiply layer): multiplies and fuses the outputs of the upper and lower dropouts to enhance feature interaction;
[0076] 1 attention layer (i.e., Attention Mech layer): calculates the attention weights for each time step to enhance the attention to important time steps;
[0077] 1 repeat vector layer (i.e., Repeat vector layer): converts the output of the attention layer into data suitable for the LSTM layer;
[0078] 1 LSTM layer; processes the data of the attention layer;
[0079] 1 output layer (i.e., Output layer layer): outputs the mean squared error (MSE) of the loss function.
[0080] B. Model Training
[0081] In this embodiment, the training set is used to train the PA-LSTM-AE model. The loss function MSE used by the model is as shown in Equation (5):
[0082]
[0083] where \(y\) i is the \(i\)-th data point of the original feature data sequence without anomalies, is the \(i\)-th data point of the model estimate, and \(n\) is the length of the selected feature data sequence. In this embodiment, the loss function MSE is used as the reconstruction error.
[0084] Since too many LSTM parameters will cause overfitting in model training and affect the training of forward propagation, some LSTM units need to be discarded during training to prevent overfitting. In this embodiment, the PA-LSTM-AE model introduces a dropout layer with dropout = 0.1. The activation function of the PA-LSTM-AE model is the ReLU function, and the Adam optimizer is used to update the network weights.
[0085] After training is completed, a quantile \(p\leq1\) is set, and the quantile is multiplied by the reconstruction error as the anomaly threshold \(T\) for subsequent anomaly detection.
[0086] After the model training is completed, the data in the test set is used to test the model, and the reconstruction error of the test set can be obtained by Equation (5). When the reconstruction error of the test set is less than the anomaly threshold T, it proves that the data at this time is normal data; when the reconstruction error of the test set is greater than the anomaly threshold T, it indicates that the data at this time is abnormal data, and the relevant representation is shown in Equation (6):
[0087]
[0088] (6) Model verification
[0089] In this embodiment, navalt is selected as the detection parameter to verify the performance of the PA-LSTM-AE model. For the embodiment, two pairs of deviations of 5 and 10 are respectively used to inject into the model for verification.
[0090] Figure 4 Shows the flight data set with injected bias anomalies and the data division. The injection anomaly range is [14200:15000], and the injected bias anomaly δ value is 5.
[0091] In the anomaly detection task, the key to diagnosing the quality of a model lies in the model's ability to detect anomalies. In this embodiment, the accuracy (ACC), true positive rate (TPR), and false positive rate (FPR) are used as the performance evaluation criteria for the experimental model, and the calculation formulas are shown in Equations (7), (8), and (9):
[0092]
[0093]
[0094]
[0095] In Equations (7), (8), and (9), TP represents the number of normal samples correctly identified, TN represents the number of abnormal samples correctly identified, FP represents the number of normal samples misidentified as abnormal, and FN represents the number of abnormal samples misidentified as normal. The higher the ACC and TPR values, and the smaller the FPR value, the better the training effect of the model.
[0096] When the model is applied, for a certain type of unmanned aerial vehicle, the applicable features are first selected using historical data according to the above process, and then the model is trained using these selected feature data. The trained parameters and the model can be imported into the on-board system of the unmanned aerial vehicle of this type to be tested for direct anomaly detection.
[0097] A. Ablation experiment
[0098] To verify the effectiveness of the proposed solution in this embodiment, it is compared with LSTM-AE, PLSTM-AE, and ALSTM-AE, and the model is trained and then tested using the real drone dataset of Thor 69. The measured Threshold is used to divide the abnormal data and normal data, and the results are as Figure 5 shown.
[0099] Figure 5 In the figure, it is the comparison of the anomaly detection capabilities between PA-LSTM-AE and the model after removing the relevant strategy when δ is 10. It can be seen that when the strategy is not added, the ACC of LSTM-AE is only 77.42%, the TPR is only 70.29%, and the FPR is 18.63%. This indicates that LSTM-AE cannot accurately judge abnormal data, that is, LSTM-AE cannot accurately judge abnormal data and will also misidentify some normal data as abnormal data. After adding the Attention mechanism to ALSTM-AE, that is, LSTM-AE, its ACC is 94.13%, the TPR is 83.90%, and the FPR is 0.21%. Thus, it can be seen that after adding the Attention mechanism, the correctness of the anomaly data recognition model has been improved, and it can more accurately distinguish correct data and incorrect data. The number of misrecognized normal data has also decreased, and its accuracy can reach a very high standard. In order to make the model reach a relatively high TPR value as much as possible, this paper proposes an improved PLSTM-AE model. The parallel mechanism of this model does not mean that the two LSTMs are independently iteratively trained, but that the two parallel LSTMs are trained at the same sample point and the same time point. And the results of each training need to be combined with the multiplication layer at the same time. The output and the backpropagation process are completed at a certain time point simultaneously, which means that although the LSTMs in the encoder are in a parallel structure, the previous states of the LSTMs in each recursion are consistent. Therefore, the structure proposed in this paper avoids the problem that parallel LSTMs cannot be combined due to simultaneous recursive training, greatly improving the feature extraction ability of the model. After experiments, the ACC value of PLSTM-AE is 95.33%, the TPR value is 99.63%, and the FPR value is 7.04%. These data indicate that the accuracy of this model in detecting abnormal data has been greatly improved, but the probability of misidentifying some abnormal data has increased.
[0100] Compared with the LSTM-AE with an attention mechanism, the normal data has also increased as abnormal data. In addition, the PLSTM-AE model is prone to overfitting during training. Combining the above information, this paper combines the improved PLSTM-AE model with the attention mechanism to form the PA-LSTM-AE model. After training on real data, an ACC value of 98.31%, a TPR value of 99.63%, and an FPR value of 2.42% are obtained. The results show that the proposed model can distinguish almost all abnormal data, greatly reducing the abnormal discrimination of normal data, and also proving the abnormal detection ability of the proposed model.
[0101] Figure 6 The visualization of anomaly detection for each model after the ablation experiment (delta = 10) is shown. In the anomaly detection module, that is, the top graph of each model, where blue represents normal data and red represents abnormal data. It corresponds to the visual comparison of the initial data and the reconstructed data, where the red solid line represents the reconstructed data after the model experiment, and the blue solid line represents the initial data. The wireframe indicates the situation of misdetection and is magnified in the figure. Since abnormal data will generate a large error during the decoding and reconstruction process, it can be detected through anomaly detection. It can be seen from the figure that compared with other models, PA-LSTM-AE amplifies the reconstruction difference between normal data and abnormal data by optimizing the feature extraction and fusion strategy, thus setting the detection threshold more accurately for anomaly detection.
[0102] Table 2 gives the change amounts of TPR, FPR, and ACC of PA-LSTM-AE, PLSTM-AE, and ALSTM-AE relative to LSTM-AE. The more TPR and ACC increase, and the more FPR decreases, the better the model improvement. It can be seen from the data in Table 3 that compared with LSTM-AE, the ACC of ALSTM-AE has increased by 16.71%, the FPR has decreased by 18.42%, and the TPR has increased by 13.61%. Thus, it can be seen that the addition of the attention mechanism has indeed greatly improved the anomaly detection rate, and the false detection rate of the model has also been greatly reduced. Compared with LSTM-AE, the ACC of PLSTM-AE has increased by 17.91%, the FPR has decreased by 11.59%, and the TPR has increased by 29.34%. The accuracy effect of PLSTM-AE is better, and the false detection rate has also been greatly reduced. In contrast, PA-LSTM-AE increases ACC by 20.89%, decreases FPR by 16.21%, and increases TPR by 29.34%. Combining the advantages of the above two makes the proposed PA-LSTM-AE not only greatly improve the anomaly detection effect, but also further reduce the false detection rate. This shows that PA-LSTM-AE can more effectively mine the dependencies between spatio-temporal related features, thereby detecting more anomalies.
[0103] Table 2 Comparison of the Anomaly Detection Capabilities between PA-LSTM-AE and the Model after Removing Relevant Strategies (δ = 10)
[0104]
[0105] As Figure 7 shown, when the δ value is 5, the ACC of LSTM-AE is only 66.04%, the FPR is 24.36%, and the TPR is 48.69%. While the ACC value of ALSTM-AE is 80.80%, the FPR value is 10.56%, and the TPR value is 65.17%. This can also prove that the introduced attention mechanism improves the performance of its model for anomaly detection to a certain extent. The ACC of PLSTM-AE is 93.02%, the FPR is 8.83%, and the TPR is 96.37%. Although its TPR is the best, it can be seen that the data predicted by PLSTM-AE deviates greatly from the real data and is prone to overfitting during the training process. Therefore, the actual effect is not ideal. The accuracy of PA-LSTM-AE proposed in this paper is 93.24%, the FPE is 6.34%, and the TPR is 92.51%. Although the TPR value is not as high as that of the initial PLSTM-AE, it avoids the problem of the predicted data deviating from the real data and also greatly reduces the overfitting of the model. This indicates that the proposed PLSTM-AE has a large deviation from the actual data.
[0106] B. Benchmark Experiment
[0107] To further verify the effectiveness of the proposed model, we compared KPCA, KNN, SVM, CAE with PA-LSTM-AE. The principle of anomaly detection in KPCA is a non-linear data processing method. By mapping the data into a high-dimensional feature space, principal component analysis is performed in the high-dimensional feature space to extract the main features, and then the T2 and Q statistics are used for anomaly detection. KNN is a time-dependent anomaly detection method. It realizes anomaly detection by calculating the distance between the predicted data point and the nearest K sample points and distinguishing the anomaly samples according to the threshold. The similarity between SVM and KPCA is that it also maps the data into a high-dimensional feature space through the kernel function and maximizes the distance between all data points and the origin through the decision function, so that the points far from most data points are regarded as anomalies. CAE is a variant of AE and is an unsupervised anomaly detection method. It uses a convolutional neural network to extract the features of the input data and then uses the reconstruction error to judge whether the new data is abnormal.
[0108] Table 3 Comparison of the Anomaly Detection Capabilities between PA-LSTM-AE and Benchmark Methods
[0109]
[0110]
[0111] Table 3 shows the results of the above anomaly detection methods. When the bias is 5, the TPR of SVM is the highest, which is 99.88%, but the FPR value is not very good, which is 27.67%. Most of the normal data detected by this method are outliers, but this is usually not allowed in practical applications. The ACC value of KPCA is 85.24%, the TPR value is 67.29%, and the FPR value is 4.83%. This is not a very good result. The reason may be that the principal elements with smaller eigenvalues may capture the main fault information, while the principal elements with larger eigenvalues may not capture the main fault information, resulting in the TPR value and ACC value of KNN being 19.66% and 78% respectively. The reason for this phenomenon may be that KNN has a lower tolerance for training data and is more sensitive to noise data and outliers. The ACC, TPR, and FPR of CAE are 86.49%, 66.79%, and 2.62% respectively. The reason for this phenomenon may be the high volatility of the data, resulting in large fluctuations in CAE during the training process. CAE may not converge or be unstable during the training process, resulting in lower TPR and ACC values.
[0112] Table 4 Comparison of the rate of change of the results based on the PA-LSTM-AE benchmark method
[0113]
[0114] Table 4 shows the performance differences between the PA-LSTM-AE model and CAE, KNN, KPCA, and SVM. When the bias is 5, compared with CAE, KNN, KPCA, and SVM, the ACC of PA-LSTM-AE increases by 6.75%, 15.24%, 8.00%, and 11.11% respectively. The TPR of PA-LSTM-AE is 7.37% lower than that of SVM, but 25.72%, 72.85%, and 25.22% higher than that of CAE, KNN, and KPCA respectively. The FPR value of PA-LSTM-AE is 6.34%, which is 3.72% and 1.51% higher than that of CAE and KPCA respectively, but 12.6% and 21.33% lower than that of KNN and SVM respectively. The above results show that PA-LSTM-AE has a very good anomaly detection effect.
[0115] When the deviation is 10, the TPR of SVM is the highest, at 99.88%. The TPR of PA-LSTM-AE also increases with the increase of error, at 99.63%. The TPR values of KNN and CAE are 23.93% and 70.03% respectively, both showing a slight increase. However, in the FPR comparison, the FPR value of PA-LSTM-AE is the smallest, at 2.42%, which is reduced by 0.58%, 15.49%, 9.80% and 0.25% compared with CAE, KNN, KPCA and SVM respectively. This reduction is due to the attention mechanism greatly improving the ability of PA-LSTM-AE to capture abnormal data under high bias, resulting in the reduction of FPR. Compared with CAE, KNN, KPCA and SVM, the ACC values of PA-LSTM-AE are increased by 10.93%, 19.31%, 10.84% and 12.27% respectively.
[0116] Conclusion: A new LSTM-AE framework for UAV anomaly detection, namely the PA-LSTM-AE model. First, the Spearman correlation coefficient is used to achieve the correlation selection of flight features, effectively reducing the dependence on expert knowledge. Then, the maximum-minimum normalization is used to normalize the data range to between -1 and 1, and the data is reconstructed to meet the requirements of LSTM. Secondly, the attention mechanism is introduced to improve the feature extraction ability of PLSTM in the decoder. Finally, the data is divided into a training set and a test set, imported into the model for training, and the anomaly detection ability of the model is verified through a real dataset.
Claims
1. A method for unsupervised anomaly detection of drones, characterized in that The steps are as follows: (1) Collect the initial data set; collect characteristic data of drone flight in multiple dimensions; (2) Correlation analysis: The Spearman correlation coefficient method was used to perform correlation analysis on the feature data, and the feature data with an absolute value of the Spearman correlation coefficient greater than 0.4 were selected for output; (3) Preprocessing the data set: normalizing and reconstructing the selected feature data; (4) Model training: The PA-LSTM-AE model is trained using the selected feature data. A set of corresponding models is trained for each dimension of feature data. The model outputs a loss function as the reconstruction error. After calculation, the abnormal threshold T of the feature data of that dimension is obtained. (5) Model application: The trained model and its parameters are imported into the onboard system of the UAV to be tested. During the flight, the feature data of each dimension is input into its corresponding model, and the reconstruction error output by the model is compared with the anomaly threshold T to perform anomaly detection in that dimension.
2. The unsupervised anomaly detection method for drones according to claim 1 is characterized in that The PA-LSTM-AE model is based on the LSTM structure. The input of the previous time period will enter the parallel LSTM unit at the same time. After passing through the forget gate, the input gate and the output gate will be respectively passed to the next parallel LSTM unit. The output of each parallel unit will be fused together. Specifically, it includes the following layers: 1 input layer: as the entry of the model, passing feature data to subsequent layers; 1 parallel LSTM layer: the upper layer consists of two LSTMs connected in series, and the lower layer has only one LSTM, which is used to process input data and extract time series features; 1 parallel dropout layer: randomly drop the outputs of the upper and lower LSTM layers to prevent overfitting; 1 multiplication layer: multiply and fuse the outputs of the two discard layers to enhance feature interaction; 1 attention layer: calculates the attention weight of each time step to enhance the attention to important time steps; 1 Repeat Vector Layer: Repeat the output of the attention layer twice to generate time series data; 1 LSTM layer; processes the data of the attention layer; 1 output layer: used to output the loss function MSE.
3. The unsupervised anomaly detection method for drones according to claim 2, characterized in that: In the association analysis, the calculation formula of Spearman correlation coefficient is as follows: Where ρ is the Spearman correlation coefficient, d i represents the rank difference of the corresponding observations of two variables, n is the number of features of the data set, is the sum of squares of all pairs of rank differences.
4. The unsupervised anomaly detection method for drones according to claim 3 is characterized in that: The calculation formula for the normalization process is as follows: In the formula, the initial data is x o Indicates that the normalized data is represented by x new Indicates that x o The maximum and minimum values of omax and x omin express.
5. The unsupervised anomaly detection method for drones according to claim 4, characterized in that: The data reconstruction process includes using a sliding window of length E to capture local data in the feature data time series. The reconstructed data is an input matrix X(T) that can meet the LSTM training requirements, as follows: In the formula, x n is the original data in the feature data time series, and n is the length of the selected feature data sequence.
6. The unsupervised anomaly detection method for drones according to claim 5, characterized in that: In the model training step, the calculation formula of the loss function MSE is as follows: In the formula, y i is the i-th data point without abnormality in the original feature data sequence, is the i-th data point of the model estimate, and n is the length of the selected feature data sequence.
7. The unsupervised anomaly detection method for drones according to claim 6, characterized in that: In the model training step, a quantile p≤1 is set, and the quantile multiplied by the reconstruction error is used as the abnormal threshold T.
8. The unsupervised anomaly detection method for drones according to claim 7, characterized in that: In the model training step, 85% of the data set is used as a training set and 15% is used as a test set, and the training set is input into the PA-LSTM-AE model for training.
9. The unsupervised anomaly detection method for drones according to claim 8, characterized in that: In the model training step, after the PA-LSTM-AE model training is completed, the PA-LSTM-AE model is tested using the data of the test set to obtain the reconstruction error of the test set. When the reconstruction error of the test set is less than the abnormal threshold T, it proves that the data at this time is normal data; when the reconstruction error of the test set is greater than the abnormal threshold T, it indicates that the data at this time is abnormal data.
Citation Information
Patent Citations
An LSTM-based method for detecting anomalies in UAV flight data
CN108960303B
Cited By
Unmanned cluster abnormal behavior detection method and device based on lightweight block chain consensus, storage medium and electronic equipment
CN122394978A