High parallel computing method for multi-strategy anomaly detection

By adopting a high-parallel computing method in the field of multi-strategy exception detection, using base-class templates to standardize scheduling, multi-task parallel computing across process common data pools, and weak branch-delimited signal-level exception attribution, the problems of scheduling difficulties, low computing efficiency and result conflicts in the existing technology are solved, and efficient and robust operation of complex equipment and completeness of exception monitoring information are achieved.

CN120217219APending Publication Date: 2025-06-27CHENGDU AIRCRAFT INDUSTRY GROUP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510186926.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing multi-strategy anomaly detection method has defects in scheduling difficulties, low computing efficiency and result conflicts, and it is difficult to meet the robust operation needs of complex equipment.

Method used

The high-parallel calculation method for multi-strategy exception detection is adopted to improve the scalability and efficiency of the anomaly detection algorithm through standardized scheduling of base class templates, multi-task parallel computing across process common data pools, and weak branch-delimited signal-level anomaly attribution.

Benefits of technology

It realizes efficient scheduling and computing in the field of multi-strategy exception detection, reduces result conflicts, improves the robustness of complex devices and the completeness of exception monitoring information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217219A_ABST
    Figure CN120217219A_ABST
Patent Text Reader

Abstract

The invention discloses a high parallel computing method for multi-strategy anomaly detection, which relates to the technical field of fault diagnosis and comprises the following steps: S1, multi-strategy task standardized scheduling based on a base class template; s2, multi-task parallel computing based on a cross-process common data pool; and S3, determining a fault occurrence position based on signal level anomaly attribution of weak branch delimitation, and improving application defect problems of difficult scheduling of a multi-strategy algorithm, low efficiency of multi-model calculation, conflict of multi-view results and the like in the field of multi-strategy anomaly detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of fault diagnosis, and particularly relates to a high parallel computing method for multi-strategy anomaly detection. Background Art

[0002] Complex devices represented by aircraft have harsh working environments and diverse fault mechanisms, resulting in perception blind spots in existing knowledge-based fault interpretation methods, bringing certain risks to the normal operation of complex devices. Although data-driven anomaly detection algorithms can effectively make up for the fault perception blind spots brought by the knowledge-driven mode, the existing anomaly detection algorithms are only robust to the data sensitive to the algorithm, and it is difficult for a single-strategy anomaly detection algorithm to fully cover the anomaly detection requirements of different types of signal time series. Therefore, a multi-strategy anomaly detection mechanism formed by integrating multiple anomaly detection algorithms has become an important way to ensure the completeness of device-level anomaly detection.

[0003] However, on the one hand, the current detection algorithms have different implementation principles, which makes there are obvious bottlenecks in the scalability of each algorithm required for the integration of anomaly detection algorithms. To meet the requirement of improving the scalability of anomaly detection algorithms, a standardized encapsulation mechanism needs to be provided for the anomaly detection algorithms. On the other hand, to meet the real-time requirements of complex device anomaly detection, it is necessary to improve the efficiency of large-scale complex calculations in anomaly detection tasks through a parallelized scheduling mechanism.

[0004] In view of the above two objective problems of feasibility and usability, there is an urgent need for a better computing method to provide more complete anomaly monitoring information for the robust operation of complex devices. Summary of the Invention

[0005] The purpose of the present invention is to provide a high parallel computing method for multi-strategy anomaly detection, which solves the application defect problems such as difficult scheduling of multi-strategy algorithms, low efficiency of multi-model calculations, and result conflicts of multi-perspectives in the field of multi-strategy anomaly detection.

[0006] The present invention is realized through the following technical solutions: A high parallel computing method for multi-strategy anomaly detection includes the following steps: S1. Normalized scheduling of multi-strategy tasks based on a base class template; S2. Multi-task parallel computing based on a cross-process common data pool; S3. Signal-level anomaly attribution based on weak branch and bound to determine the location where the fault occurs.

[0007] Further, in step S1: The base class template covers the information required by the algorithm. The information required by the algorithm includes the ID for recording the model configuration location, the maximum and minimum values on which normalization depends, the flag bit for marking training or not to distinguish model initialization and enhancement, the basic model parameters, and the data cache space for model timing discrimination requirements. The base class template provides common methods for algorithms within the architecture during the model initialization phase, including normalization configuration, re - normalization configuration during the model enhancement phase, normalization, import and storage for the model configuration database, model training and retraining during initialization and enhancement phases, timing parameter cache relationship, and fault quantitative interpretation. The base class template requires algorithm designers to supplement the generation and parsing methods of binary configuration information in the model configuration database and the training and detection logic of the algorithm itself in the algorithm instance.

[0008] Further, the normalization is responsible for converting the data into data between - 0.5 and 0.5. The normalized input data satisfies the following relational expression (1): (1); In the formula: represents the i th frame value of the t th flight parameter in the output data; x min,i and x max,i respectively represent the theoretical minimum and maximum values of the th flight parameter, corresponding to the minimum and maximum values of the

[0009] th flight parameter in the training dataset; sgn represents the sign function. (2); In the formula: represents the i th frame value of the t th flight parameter in the output data; x min,i and x max,i respectively represent the theoretical minimum and maximum values of the

[0010] Furthermore, for the storage of model parameters, the binary configuration information of the model is obtained by calling the parameter acquisition interfaces in the specific algorithm classes, and the binary information is stored in the position corresponding to the model identifier in the database, realizing the permanent storage of model parameters. The reading of model parameters is responsible for reading the model binary information in the database according to the identifier of the model, and then calling the model parameter configuration interface of the specific algorithm class with the binary information as the input to realize the configuration of model parameters.

[0011] Furthermore, it also includes the training and detection of flight parameters, and the processing method is as follows: Firstly, the data is improved to the ideal data quality through steps such as resampling, missing value supplementation, and normalization. Then, the specific algorithm is called to implement the specific interpretation through the internal training and detection logic with the array as the input, thus decoupling the preprocessing of flight parameters from the actual training / detection tasks.

[0012] Furthermore, under the encapsulation of the base class template, the specific algorithm classes are uniformly scheduled by the detection architecture, and the detection architecture includes two modes: offline training and online detection: During the offline training process, the architecture sequentially calls the model training and storage mechanisms encapsulated by the parent class to process and learn the input flight parameter training data. During the online detection process, the architecture sequentially calls the model loading and model detection mechanisms encapsulated by the parent class to detect the input flight parameter training data.

[0013] Furthermore, in step S2, the multi-process interaction architecture based on the cross-process common data pool includes three core parts: the scheduling process, the anomaly detection subprocess, and the anomaly result cache pool. Before each anomaly detection task is executed, each anomaly detection subprocess loads three key pieces of information: the corresponding algorithm name, model identifier, and signal to be measured according to the configuration domain of the scheduling process. When the anomaly detection subprocess goes online, the scheduling process assigns tasks inside the anomaly detection subprocess according to the configuration information. The anomaly detection subprocess loads its own anomaly detection model and measured signal data by sending a query request to the cross-process common data pool. When the anomaly detection subprocess ends, the anomaly detection subprocess pushes the anomaly judgment result composed of the model identifier and the anomaly judgment result to the anomaly result cache pool. During the process of the anomaly detection subprocess, the scheduling process will regularly pull the anomaly detection results from the anomaly result cache pool and store them in the total anomaly detection results for signal-level anomaly attribution.

[0014] Further, in step S2, the multi-task parallel computing of the cross-process common data pool is a dynamic task allocation and inter-process communication method under the constraint of the process scale. The dynamic task allocation scheme under the constraint of the process scale is carried out according to the expected memory of the task and the remaining allocated memory of the process. The more significant the memory requirements among tasks are, the more the impact of this allocation on subsequent task allocations needs to be considered during task allocation; the less significant they are, the more it is necessary to ensure sufficient computing space for the task within the process. For the dynamic task allocation under the constraint of the process scale, whenever a new anomaly detection task is generated, the benefits of each process will be evaluated, and the process with the highest benefit will be selected to create an instance of the corresponding task.

[0015] Further, the expected memory of the task determines the constraint coefficient corresponding to the algorithm complexity through multiple experiments and evaluations of the algorithm. The remaining allocated memory of the process is determined based on the server configuration, reflecting the memory constraint for immediate processing that can be achieved under the ideal full-load operation state of the server. Based on the expected memory of the task and the remaining allocated memory of the process, the benefit definition of the task in the process allocation satisfies the following relational expression (3). (3) Where task i represents the task i estimated memory requirement, which is measured by the memory occupancy of the model performing the detection task on the training set in the later stage of the model training phase. rest j represents the process j remaining memory; memory represents the available memory scale of the empty process; Q ij represents the task i in the process j allocation benefit; task min and task max represent the minimum and maximum memory requirements in the task; task i / rest j and max( rest j - task i , 0) / memory respectively represent the abundance benefit brought by the task to other processes and the availability benefit of the task within the process. task min / task max Represents the difference coefficient of task memory occupancy.

[0016] Furthermore, in step S3, first establish an anomaly detection model - signal association matrix, which is composed of 0 and 1. 0 indicates that the detection range of the corresponding anomaly detection model does not include the corresponding signal; 1 indicates that the detection range of the corresponding anomaly detection model includes the corresponding signal; The abnormal states of each signal parameter can be divided into four states: normal, abnormal, suspicious, and unknown. Among them: normal means that the signal parameter indicates that the part of the interpretation result is normal, and the anomaly detection model can confirm that the signal is normal; Abnormal means that the signal parameter is within the detection range of an anomaly detection model, and there is no other signal in this anomaly detection model that can be used as the source of the anomaly; Suspicious means that the signal parameter is within the detection range of some anomaly detection models, but there is other signal in each anomaly detection model that can be used as the source of the anomaly, and it cannot be fully attributed; Unknown means that the signal is not within the detection range of any anomaly detection model.

[0017] Furthermore, in step S3, the signal-level anomaly attribution method based on weak branch and bound is as follows: S3.1. First, create empty sets for the four states, add all signal patterns to the unknown set, and input the anomaly detection model - signal association matrix and the anomaly detection model interpretation results; S3.2. Traverse the anomaly detection model interpretation results, move the signal parameters related to all anomaly detection models with normal interpretation results from the unknown set to the normal set, and confirm the fault modes with normal states; S3.3. Traverse the anomaly detection model interpretation results of all abnormal interpretation results. If there are no signal parameters in abnormal states related to it, but there are signal parameters in normal states related to this model, then move this signal parameter from the normal set to the suspicious set; S3.4. Traverse the anomaly detection model interpretation results of all abnormal interpretation results again. If there is only one signal parameter in abnormal state related to it, then move this signal parameter from the unknown set to the abnormal set; if the number of related signals ≥ 2, move the related signal parameters from the unknown set to the suspicious set.

[0018] Compared with the prior art, the present invention has the following advantages and beneficial effects: 1. In the present invention, a high-parallel computing method for multi-strategy anomaly detection is proposed. This method improves its scalability by normalizing the anomaly detection algorithm through a base class template, performs multi-strategy anomaly detection through multi-task parallel computing based on a cross-process common data pool to improve the anomaly inference efficiency of anomaly detection, and performs signal-level anomaly attribution through weak branch and bound, thereby supporting the anomaly detection requirements of complex devices.

[0019] 2. In the present invention, this method is a multi-strategy task normalization scheduling method based on a base class template, which reduces the normalization encapsulation threshold of algorithm code and improves the development efficiency of multi-strategy anomaly detection algorithms.

[0020] 3. In the present invention, this method is a multi-task parallel computing method based on a cross-process common data pool, which solves the problem of dynamic allocation of process memory, reasonably allocates memory according to process benefit evaluation, and improves the multi-strategy anomaly detection efficiency.

[0021] 4. In the present invention, this method is a signal-level anomaly attribution method based on weak branch and bound, which establishes an anomaly detection model-signal association matrix, and realizes fast signal-level anomaly attribution and positioning through the immediate update of the state sets of four types of signals to be detected. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 is a relationship diagram of each step in the high-parallel computing method for multi-strategy anomaly detection of the present invention.

[0023] Figure 2 is an inheritance logic diagram in Embodiment 1.

[0024] Figure 3 is a scheduling logic diagram of the detection architecture in the offline training mode in Embodiment 1.

[0025] Figure 4 is a scheduling logic diagram of the detection architecture in the online training mode in Embodiment 1.

[0026] Figure 5 is a multi-process interaction architecture diagram based on a cross-process common data pool. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] To facilitate public understanding of the present invention, the following describes the high-parallel computing method for multi-strategy anomaly detection provided by the present invention in conjunction with the accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0028] Embodiment 1 This embodiment is a high - parallel computing method for multi - strategy anomaly detection. In this method, the high - parallel computing method for multi - strategy anomaly detection improves its scalability by normalizing the anomaly detection algorithm through a base - class template, conducts multi - strategy anomaly detection through multi - task parallel computing based on a cross - process common data pool to improve the anomaly inference efficiency of anomaly detection, and performs signal - level anomaly attribution based on weak branch - and - bound, thereby supporting the anomaly detection requirements of complex devices.

[0029] As Figure 1 shown, the high - parallel computing method for multi - strategy anomaly detection includes the following three key steps: Step S1: Multi - strategy task normalization scheduling based on a base - class template; Step S2: Multi - task parallel computing based on a cross - process common data pool; Step S3: Signal - level anomaly attribution based on weak branch - and - bound to determine the location where the fault occurs.

[0030] The following is a more detailed description of each step.

[0031] Step S1: Multi - strategy task normalization scheduling based on a base - class template.

[0032] It is required that the user re - declare some interfaces on the basis of inheriting this base class. The specific inheritance logic is as shown in the appendix Figure 2 shown.

[0033] The base - class template covers information required by algorithms such as the ID (uuid) for recording the model configuration location, the maximum and minimum values (max, min) on which normalization depends, the flag bit (trained) for marking whether it is trained or not to distinguish model initialization and enhancement, the basic model parameters (config), the data cache space (arrStock) for model - oriented time - series discrimination requirements, etc. It provides common methods within the architecture such as normalization configuration (set_normalization) in the model initialization stage, normalization re - configuration (reset_normalization) in the model enhancement stage, normalization (normalization), import (from_db) and storage (to_db) for the model configuration database, model training and retraining (fit) in the initialization and enhancement stages, time - series parameter cache relationship (refreshStock), and fault quantitative judgment (validata). The base - class template requires algorithm designers to supplement the methods for generating (set_config) and parsing (get_config) binary configuration information in the model configuration database in the algorithm instance, as well as the training (inner_fit) and detection (inner_validate) logics of the algorithm itself.

[0034] 1. Specific application methods of the base class template In object-oriented assembly languages such as Python, the class inheritance mechanism can automatically assign the attributes and methods of the parent class (base class template) to the subclass (specific algorithm class) that has not redefined the corresponding methods. Therefore, the parent class will uniformly define the common functions including normalization for different algorithms, and the subclass will directly obtain these functions through the inheritance mechanism.

[0035] The common functions mainly include normalization, denormalization, model parameter storage and reading, etc., where: Normalization Normalization is mainly responsible for converting the data into the data between -0.5 and 0.5, so as to facilitate the subsequent reasoning of the specific algorithm. Normalization processes the input data according to the following formula: In the formula: represents the value of the i-th flight parameter in the t-th frame of the output data; x min,i and x max,i respectively represent the theoretical minimum and maximum values of the i-th flight parameter, corresponding to the minimum and maximum values of the i-th flight parameter in the training dataset; sgn represents the sign function.

[0036] Denormalization Denormalization is mainly responsible for converting the normalized data between -0.5 and 0.5 back to the original data value range, so as to facilitate the drawing of the auxiliary time series inferred by different algorithms for flight parameter interpretation.

[0037] Denormalization processes the input data according to the following formula: .

[0038] Model parameter storage Model parameter storage obtains the binary configuration information of the model by calling the parameter acquisition interface in each specific algorithm class, so as to realize storing the binary information into the position corresponding to the model identifier in the database and achieve the permanent storage of model parameters. Model parameter storage separates database storage from model parameter export, avoiding algorithm developers from being involved in the database writing function tightly coupled with the system, and reducing the technical threshold and time cost of algorithm development and embedding.

[0039] Model parameter reading The model parameter reading is mainly responsible for reading the model binary information in the database according to the model identifier, so as to call the model parameter configuration interface of the specific algorithm class with the binary information as the input, and realize the configuration of the model parameters. The model parameter storage separates the database reading from the model parameter loading, avoiding the algorithm developers from being involved in the database reading function tightly coupled with the system, and reducing the technical threshold and time cost of algorithm development and embedding.

[0040] Training and Detection of Flight Parameters Flight parameters often have problems such as inconsistent sampling rates and null values. The training and detection of flight parameters first improve the data to ideal data quality through steps such as resampling, missing value supplementation, and normalization, and then call the internal training and detection logic of the specific algorithm with the array as the input to achieve specific interpretation, thus decoupling the flight parameter preprocessing from the actual training / detection tasks. Specifically, resampling samples the data based on the sampling rate configured by the user, and the data that does not exist in the sampling period is recorded as a missing value (NaN); missing value supplementation fills the data backward and then forward through the maximum number of missing value frames configured by the user (that is, first fills the data at the existing value positions forward to the missing moments within the range of the maximum number of missing value frames, and then fills it backward to the missing moments within the range of the maximum number of missing value frames); for the detection call, an initial detection result array filled with all 0s is first generated, and then the moments with missing values after value supplementation are masked and input into the internal detection logic of the specific algorithm, and the masked output result is filled into the corresponding position of the initial detection result array, so as to realize the detection function in the case of serious numerical missing.

[0041] 2. Anomaly Detection Function Based on the Base Class Template Under the encapsulation of the base class template, the specific algorithm class is uniformly scheduled by the detection architecture. The detection architecture mainly has two modes: offline training and online detection.

[0042] During the offline training process, the architecture sequentially calls the model training and storage mechanisms encapsulated by the parent class to process and learn the input flight parameter training data. Refer to Figure 3 , the model training mechanism first improves the data quality through preprocessing operations such as resampling provided by the parent class, and then provides the internal training logic defined by the specific algorithm class to build the detection model; the storage mechanism calls the model parameter acquisition logic defined by the specific algorithm for the trained model to obtain the binary information required for model configuration, and then provides the binary model parameter storage method provided by the parent class to permanently store the model in the database.

[0043] During the online detection process, the architecture sequentially calls the model loading and model detection mechanisms encapsulated by the parent class to detect the input flight parameter training data. Refer to Figure 4, the model detection mechanism first reads the corresponding model information from the database through the binary information reading operation provided by the parent class, and then loads the detection model through the model parameter configuration logic defined by the specific algorithm class; the detection mechanism first improves the data quality through the preprocessing operations such as resampling provided by the parent class, and then obtains the anomaly detection result and the auxiliary line for assisting manual analysis through the internal training detection defined by the specific algorithm class. Finally, it provides the auxiliary line denormalization operation of the parent class to return to the original value range of the flight parameters, forming a complete interpretation result.

[0044] Step S2: Multitask parallel computing of the cross-process common data pool.

[0045] A method for dynamic task allocation and communication between multiple processes under the constraint of process scale. The dynamic task allocation scheme under the constraint of process scale is mainly carried out according to the predicted memory of the task and the remaining allocated memory of the process.

[0046] The predicted memory of the task determines the constraint coefficient corresponding to the algorithm complexity through multiple experiments and evaluations of the algorithm; the remaining allocated memory of the process is determined based on the server configuration, reflecting the memory constraint that can be achieved for instant processing under the ideal full-load running state of the server. Based on the predicted memory of the task and the remaining allocated memory of the process, the benefit definition of the task in the process allocation satisfies the following relational expression: ; In the formula: task i represents the task i estimated memory requirement, which is measured by the memory occupancy of the model when performing detection tasks on the training set in the later stage of the model training phase; rest j represents the process j remaining memory; memory represents the available memory scale of the empty process; Q ij represents the task i in the process j allocation benefit; task min and task max represent the minimum and maximum memory requirements in the task; task i / rest j and max( rest j - task i , 0) / memory respectively represent the abundance benefit brought by the task to other processes and the availability benefit of the task within the process; task min / task max The difference coefficient representing the memory occupancy of tasks.

[0047] The more significant the memory requirements between tasks are, the more necessary it is to consider the impact of this allocation on subsequent task allocations during task allocation; the less significant they are, the more necessary it is to ensure sufficient computing space for tasks within the process.

[0048] For the dynamic task allocation under the constraint of the process scale, whenever a new anomaly detection task is generated, the benefits of each process will be evaluated, and the process with the highest benefit will be selected to create an instance of the corresponding task. Through the above mechanism, the dynamic allocation of large-scale algorithm tasks under a limited process scale can be achieved.

[0049] The multi-process interaction architecture based on the cross-process common data pool is as Figure 5 shown, and includes three core parts: a scheduling process, an anomaly detection subprocess, and an anomaly result cache pool.

[0050] Before each anomaly detection task is executed, each anomaly detection subprocess loads three key pieces of information: the corresponding algorithm name, model identifier, and signal to be measured, according to the configuration domain of the scheduling process; When the anomaly detection subprocess goes online, the scheduling process assigns tasks inside the subprocess according to the configuration information, and the subprocess loads its own anomaly detection model and measured signal data by sending a query request to the cross-process common data pool; When the anomaly detection subprocess ends, the subprocess will push the anomaly judgment result composed of the model identifier and the anomaly judgment result to the anomaly result cache pool; during the process of the subprocess, the scheduling process will regularly pull the anomaly detection results from the anomaly result cache pool and store them in the total anomaly detection results for signal-level anomaly attribution.

[0051] Step S3: Signal-level anomaly attribution based on weak branch and bound.

[0052] The abnormal signals detected by the anomaly detection algorithm are used to infer and attribute the faults to find the fault locations. The signal-level anomaly attribution method based on weak branch and bound first establishes an anomaly detection model-signal association matrix, which consists of 0 and 1. 0 indicates that the detection range of the corresponding anomaly detection model does not include the corresponding signal; 1 indicates that the detection range of the corresponding anomaly detection model includes the corresponding signal. The abnormal states of the signal parameters can be divided into four states: normal, abnormal, suspicious, and unknown. Among them, normal means that the signal parameter refers to that the partial interpretation results of some anomaly detection models are normal and can confirm that the signal is normal; abnormal means that the signal parameter is within the detection range of a certain anomaly detection model, and there is no other signal in this anomaly detection model that can be used as the source of the anomaly; suspicious means that the signal parameter is within the detection ranges of some anomaly detection models, but there is other signal in each anomaly detection model that can be used as the source of the anomaly and cannot be fully attributed; unknown means that the signal is not within the detection range of any anomaly detection model.

[0053] The specific steps of the signal-level anomaly attribution based on weak branch and bound are as follows: (1) First, create empty sets of the four states and add all signal patterns to the unknown set, and input the anomaly detection model-signal association matrix and the anomaly detection model interpretation results; (2) Traverse the anomaly detection model interpretation results, and move the signal parameters related to all anomaly detection models with normal interpretation results from the unknown set to the normal set to confirm the fault patterns with normal states; (3) Traverse the anomaly detection model interpretation results of all abnormal interpretation results. If there are no signal parameters in abnormal states related to it, but there are signal parameters in normal states related to this model, then move this signal parameter from the normal set to the suspicious set; (4) Traverse the anomaly detection model interpretation results of all abnormal interpretation results again. If there is only one signal parameter in abnormal state related to it, then move this signal parameter from the unknown set to the abnormal set; if the number of related signals ≥ 2, move the related signal parameters from the unknown set to the suspicious set.

[0054] The high-parallel computing method for multi-strategy anomaly detection in this solution is mainly for the signal-based anomaly detection tasks of complex equipment, aiming to build a signal-level anomaly perception mechanism. This method realizes the multi-strategy anomaly detection method for complex equipment through three core technologies: the multi-strategy task normalization scheduling method based on the base class template, the multi-task parallel computing method based on the cross-process common data pool, and the signal-level anomaly attribution based on the weak branch and bound method, and further provides a general architecture for the application of the anomaly detection algorithm in actual projects.

[0055] Specifically, the multi-strategy task normalization scheduling method based on the base class template mainly includes inheriting the anomaly detection algorithm base class with normalized encapsulation and redeclaring some necessary interfaces. The normalized anomaly detection algorithm embedding mechanism constructed by the base class template can improve the scalability of the multi-strategy anomaly detection architecture, and the reservation of some necessary interfaces can improve the rapidity of the development of the multi-strategy anomaly detection algorithm. The multi-task parallel computing method based on the cross-process common data pool mainly includes a dynamic task scheduling mechanism oriented to scale constraints, and selects the most suitable process for each anomaly detection algorithm according to its computing performance requirements to perform their respective tasks. The signal-level anomaly attribution based on the weak branch and bound method locates the signal-level anomaly occurrence position by establishing the signal state-fault mode relationship D matrix and according to the judgment result of the multi-strategy anomaly detection model.

[0056] The above is only a preferred embodiment of the present invention, and does not impose any form of limitation on the present invention. Any simple modification or equivalent change made to the above embodiments based on the technical essence of the present invention shall fall within the protection scope of the present invention.

Claims

1. A highly parallel computing method for multi-strategy anomaly detection, characterized in that: The steps include: S1, standardized scheduling of multi-strategy tasks based on base class template; S2, multi-task parallel computing based on cross-process common data pool; S3. Determine the fault location based on the signal-level anomaly attribution based on weak branch delimitation.

2. A highly parallel computing method for multi-strategy anomaly detection according to claim 1, characterized in that: In step S1: the base class template covers the information required by the algorithm, including an ID for recording the model configuration location, the maximum and minimum values ​​on which normalization depends, a flag for marking whether training is performed to distinguish between model initialization and enhancement, basic model parameters, and data cache space for model timing discrimination requirements; The base class template provides common methods for in-frame algorithms in the model initialization phase, including normalization configuration, normalization reconfiguration in the model enhancement phase, normalization, import and storage of model configuration database, model training and retraining in the initialization and enhancement phases, timing parameter cache relationships, and quantitative fault interpretation; The base class template requires the algorithm designer to supplement the generation and parsing methods of binary configuration information in the model configuration database in the algorithm instance, as well as the training and detection logic of the algorithm itself.

3. A highly parallel computing method for multi-strategy anomaly detection according to claim 2, characterized in that: The normalization is responsible for converting the data into data between -0.5 and 0.

5. The normalized input data satisfies the following relationship (1): (1); Where: Representative i The flight parameters are in the output data t Frame value; x min,i and x max,i They represent the theoretical minimum and maximum values ​​of the ith flight parameter, corresponding to the minimum and maximum values ​​of the ith flight parameter in the training data set; sgn stands for sign function.

4. A highly parallel computing method for multi-strategy anomaly detection according to claim 2, characterized in that: The denormalization is responsible for converting the normalized data between -0.5 and 0.5 to the original data value range, drawing the auxiliary time series inferred by different algorithms for flight parameter interpretation, and the denormalization processing input data satisfies the following relationship (2): (2) Where: Representative i The flight parameters are in the output data t Frame value; x min,i and x max,i They represent the theoretical minimum and maximum values ​​of the i-th flight parameter, respectively, corresponding to the minimum and maximum values ​​of the i-th flight parameter in the training data set.

5. A highly parallel computing method for multi-strategy anomaly detection according to claim 2, characterized in that: The model parameter storage obtains the binary configuration information of the model by calling the parameter acquisition interface in each specific algorithm class, and stores the binary information in the location corresponding to the model identifier in the database to realize the permanent storage of the model parameters; Model parameter reading is responsible for reading the model binary information in the database according to the model identifier, thereby calling the model parameter configuration interface of the specific algorithm class with binary information as input to implement the configuration of the model parameters.

6. A highly parallel computing method for multi-strategy anomaly detection according to claim 2, characterized in that: It also includes the training and detection of flight parameters, and the processing method is: First, the data is improved to the ideal data quality through resampling, missing value filling, normalization and other steps; Then, the specific algorithm is called to implement the specific judgment through the internal training and detection logic with the array as input, thereby decoupling the flight parameter preprocessing from the actual training / detection task.

7. A highly parallel computing method for multi-strategy anomaly detection according to claim 2, characterized in that: The specific algorithm class is encapsulated in the base class template and uniformly accepts the scheduling of the detection architecture. The detection architecture includes two modes: offline training and online detection: During offline training, the architecture sequentially calls the model training and storage mechanism encapsulated by the parent class to process and learn the input flight parameter training data; During the online detection process, the architecture sequentially calls the model loading and model detection mechanisms encapsulated by the parent class to detect the input flight parameter training data.

8. The highly parallel computing method for multi-strategy anomaly detection according to claim 1, characterized in that: In step S2, the multi-process interaction architecture based on the cross-process common data pool includes three core parts: the scheduling process, the anomaly detection sub-process, and the anomaly result buffer pool. Before each anomaly detection task is executed, each anomaly detection subprocess loads the corresponding algorithm name, model identifier and three key information of the signal to be tested according to the configuration domain of the scheduling process; When the anomaly detection subprocess goes online, the scheduling process assigns tasks within the anomaly detection subprocess according to the configuration information. The anomaly detection subprocess sends a query request to the cross-process common data pool to load its own anomaly detection model and measured signal data. When the anomaly detection subprocess ends, the anomaly detection subprocess will push the anomaly judgment result consisting of the model identifier and the anomaly judgment result to the anomaly result cache pool; During the anomaly detection subprocess, the scheduling process will periodically pull down the anomaly detection results from the anomaly result cache pool and store them in the anomaly detection total result for use in signal-level anomaly attribution.

9. A highly parallel computing method for multi-strategy anomaly detection according to claim 1, characterized in that: In step S2, the multi-task parallel computing of the cross-process common data pool is a dynamic task allocation and multi-process communication method under the process scale constraint. The dynamic task allocation scheme under the process scale constraint is based on the expected memory of the task and the remaining allocated memory of the process. The more significant the memory demand between tasks is, the more it is necessary to consider the impact of this allocation on the subsequent task allocation when allocating tasks; the less significant it is, the more it is necessary to ensure that the task has sufficient computing space within the process. For dynamic task allocation under process scale constraints, whenever a new anomaly detection task is generated, the benefits of each process will be evaluated, and the process with the highest benefit will be selected to create an instance of the corresponding task;.

10. A highly parallel computing method for multi-strategy anomaly detection according to claim 9, characterized in that: The task estimated memory is determined through multiple experiments and evaluations of the algorithm to determine the constraint coefficient corresponding to the algorithm complexity; The remaining allocated memory of the process is determined based on the server configuration, reflecting the memory constraints of real-time processing that can be achieved when the server is running at full load; Based on the task's estimated memory and the process's remaining allocated memory, the benefit definition of the task in process allocation satisfies the following relationship (3): (3), in, task i Representative tasks i Estimated memory requirements, measured by the memory usage of the model during detection tasks on the training set at the end of the model training phase; rest j Representation process j Remaining memory; memory Represents the available memory size of the empty process; Q ij Representative tasks i In process j Benefits in distribution; task min and task max Represents the minimum and maximum memory requirements of the task; task i / rest j and max( rest j - task i ,0) / memory They represent the sufficiency benefit that a task brings to other processes and the availability benefit that a task brings within a process respectively; task min / task max Represents the difference coefficient of task memory usage.

11. A highly parallel computing method for multi-strategy anomaly detection according to claim 1, characterized in that: In step S3, firstly, an anomaly detection model-signal association matrix is ​​established, wherein the matrix is ​​composed of 0 and 1, and 0 indicates that the detection range of the corresponding anomaly detection model does not include the corresponding signal; 1 represents that the detection range of the corresponding anomaly detection model includes the corresponding signal; The abnormal status of each signal parameter can be divided into four states: normal, abnormal, suspicious, and unknown. Among them: Normal represents signal parameters that indicate that the abnormal detection model can confirm that the signal is normal if the partial judgment results are normal; Anomalies represent signal parameters that are within the detection range of a certain anomaly detection model, and the anomaly detection model does not have other signals that can serve as the source of the anomaly; Suspicious representative signal parameters are within the detection range of some anomaly detection models, but each anomaly detection model has other signals that can be the source of the anomaly and cannot be fully attributed; Unknown means that the signal is not within the detection range of any anomaly detection model.

12. A highly parallel computing method for multi-strategy anomaly detection according to claim 9, characterized in that: In step S3, the signal-level anomaly attribution method based on weak branch and bound is as follows: S3.

1. First, create an empty set of four states, add all signal patterns to the unknown set, input the anomaly detection model-signal association matrix and the anomaly detection model interpretation result; S3.2, traverse the judgment results of the anomaly detection model, move the signal parameters related to all the anomaly detection models with normal judgment results from the unknown set to the normal set, and confirm the fault mode with normal status; S3.3, traverse all the abnormal detection model judgment results that are judged as abnormal, if there is no abnormal state signal parameter related to it, but there is a normal state signal parameter related to the model, then move the signal parameter from the normal set to the suspicious set; S3.

4. Again traverse all the abnormal detection model judgment results that are judged as abnormal. If there is only one signal parameter in an abnormal state related to it, move the signal parameter from the unknown set to the abnormal set; if the number of associations is ≥ 2, move the associated signal parameter from the unknown set to the suspected set.

Citation Information

Patent Citations

  • Data detection method and apparatus

    CN107729751A

  • Ground reasoning platform for health assessment and management of all-aircraft of autonomous guarantee technology verification system

    CN110007662A

  • Power grid abnormal behavior detection and analysis method and system based on OCSVM

    CN110909811A

  • Memory collaborative DNN hierarchical scheduling method based on edge real-time system

    CN118227335A

  • Near real-time detection and classification of machine anomalies using machine learning and artificial intelligence

    US20200285997A1