Lightweight industrial internet time series data anomaly detection method

By adopting a lightweight global fragment sharing model with a global fragment sharing architecture in the timing data abnormality detection of industrial Internet, the bottlenecks in the existing methods in computing complexity and detection performance are solved, and efficient and fast abnormality detection is achieved, which is suitable for industrial Internet environments with limited resources.

CN120223443AActive Publication Date: 2025-06-27北京中关村实验室
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510694756.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-06-27
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

Existing unsupervised deep learning methods face computational complexity and detection performance bottlenecks in the detection of timing data in industrial Internet. Especially in environments with limited resources and high real-time security requirements, it is difficult to quickly detect abnormalities and adapt to distribution drift and overfitting problems.

Method used

A global fragment sharing architecture is used to build a lightweight global fragment sharing model, and the timing data is preprocessed through instance normalization and segmentation processing. Anomaly detection is performed using fragment-level global sharing learning method to reduce model complexity and suppress distribution drift.

Benefits of technology

It significantly reduces the computational volume and model complexity, avoids overfitting problems, improves detection efficiency and performance, and can quickly respond to volatility and emergencies in the industrial Internet environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223443A_ABST
    Figure CN120223443A_ABST
Patent Text Reader

Abstract

The invention relates to a lightweight industrial internet time series data anomaly detection method, and belongs to the technical field of network security. Comprising the following steps: performing instance normalization processing on time series data of each channel of the industrial internet to obtain normalized multivariate time series data; wherein the multiple elements correspond to a plurality of channels, and each channel corresponds to each sensor of the industrial internet; performing segmentation processing on the normalized multivariate time series data, and equally dividing each channel data into a plurality of fragments with the same number to obtain a plurality of time fragments; based on the plurality of time slices, performing time sequence anomaly detection on normalized multivariate time sequence data by using a lightweight global slice sharing model; the lightweight global fragment sharing model is implemented based on a global fragment sharing architecture. According to the method, the time and space complexity of an industrial internet time series data anomaly detection algorithm in the prior art is remarkably reduced, the problems of distribution drift and overfitting are effectively solved, and the method is suitable for being popularized in industrial internet scenes where resources are limited and detection needs to be executed frequently.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial Internet data analysis, and in particular, to a lightweight industrial Internet time-series data anomaly detection method. Background Art

[0002] The industrial Internet integrates communication and sensing technologies to achieve the interconnection of distributed industrial systems, thereby improving productivity and automation levels. Due to the inherent sensitivity of industrial processes and the vulnerabilities brought by the Internet, information security has become an important challenge for industrial Internet systems to fully realize their potential. Anomaly detection can provide early warnings for cyberattacks and system failures, and is an important technology in the field of industrial Internet security. Generally, industrial systems deploy a large number of sensors and devices to continuously collect time-series data generated by industrial processes, and the time-series data reflects the dynamic states and development trends of devices and the environment in industrial processes. Therefore, time-series data anomaly detection technology is usually adopted in the field of industrial Internet security to identify whether there are abnormal patterns, so as to achieve the goal of enhancing the overall stability and security of industrial Internet systems.

[0003] Due to the characteristics of time-series data such as temporality, volatility, and multidimensionality, as well as the randomness, dynamics, and diversity of anomalies, identifying anomaly points in time-series data is a challenging problem. In recent years, deep learning methods have achieved significantly superior performance compared with traditional statistical methods and classical machine learning methods due to their strong representation learning ability. Since anomaly points in time-series data are scarce and masked by a large number of normal points, data annotation is difficult and costly. Unsupervised deep learning-based methods can distinguish anomaly points through the normal patterns learned from all normal data, and thus have been widely used in time-series data anomaly detection.

[0004] However, existing unsupervised deep learning methods have encountered bottlenecks in both computational complexity and detection performance in time-series data anomaly detection, which limits their application in industrial Internet scenarios with limited resources and high real-time security requirements.

[0005] On the one hand, the training and inference time of existing models is not sufficient to adapt to the volatility of the industrial Internet environment and quickly detect anomalies; and due to privacy issues, time delays, and high communication overheads in cloud computing, industrial Internet time-series data anomaly detection should not be implemented through a cloud computing center, but should be realized on-site or on edge devices. However, the computing resources of on-site or edge devices are limited and are unable to handle the complex operations required for processing the large amount of time-series data generated by industrial Internet systems.

[0006] On the other hand, the anomaly detection of existing methods is also affected by distribution drift and overfitting in terms of performance. First, distribution drift is very common and obvious in industrial Internet time series data, which refers to the change of data distribution over time. Distribution drift is caused by various factors, such as sensor drift, equipment fatigue, environmental changes, and other dynamic factors inherent in the industrial Internet system. Distribution drift may reduce the detection accuracy of deep learning models. Second, industrial Internet systems usually deploy a large number of sensors and devices to collect time series data from multiple channels. However, the time series data of all channels come from the same industrial Internet system and industrial process, which makes them follow similar patterns and share the same underlying laws. In addition, a large amount of data collected from repetitive industrial processes usually has similarity, resulting in data redundancy. The above reasons lead to the fact that traditional methods often use complex models with a large number of parameters when extracting time information from large-scale high-dimensional time series data, resulting in overfitting problems. Therefore, the problems of distribution drift and overfitting have caused performance bottlenecks in the anomaly detection of industrial Internet time series data. Summary of the Invention

[0007] In view of the above analysis, the present invention aims to disclose a lightweight anomaly detection method for industrial Internet time series data, construct a lightweight global segment sharing model based on a global segment sharing architecture, and adopt a fine-grained segment-level global sharing learning method to achieve anomaly detection of industrial Internet time series data.

[0008] A lightweight anomaly detection method for industrial Internet time series data provided by the present invention specifically includes the following steps: Perform instance normalization processing on the time series data of each channel of the industrial Internet to obtain normalized multivariate time series data; the multivariate corresponds to multiple channels, and each channel corresponds to each signal source of the industrial Internet time series data; Perform segmentation processing on the normalized multivariate time series data, divide the data of each channel into multiple segments with the same number, and obtain multiple time segment data of each channel; Based on the multiple time segment data of each channel, use a lightweight global segment sharing model to perform anomaly detection on the normalized multivariate time series data; the lightweight global segment sharing model is based on a global segment sharing architecture, learns segment-level time series feature representations through a time series feature extractor, and is trained based on the reconstruction loss.

[0009] Further, for the global segment sharing architecture, the time segment data of each channel are used as inputs to train the same shared time series feature extractor to extract segment-level time series features.

[0010] Further, the using a lightweight global segment sharing model to perform anomaly detection on the normalized multivariate time series data based on the multiple time segment data of each channel includes: Take the time segment data of each channel as the input of the lightweight global segment sharing model to obtain the reconstructed data of the output; obtain the reconstructed data of the normalized multivariate time series data based on the reconstructed data of the time segment data of each channel; Calculate the point-level anomaly score at each time point based on the normalized multivariate time series data and the corresponding reconstructed data; Obtain the time series anomaly detection result of the normalized multivariate time series data based on the point-level anomaly score.

[0011] Further, the obtaining the time series anomaly detection result of the normalized multivariate time series data based on the point-level anomaly score includes: Compare the point-level anomaly score with a threshold. If the point-level anomaly score is less than the threshold, the data at this time point is normal; otherwise, the data at this time point is abnormal.

[0012] Further, the calculation method of the point-level anomaly score is: ; Wherein, is the point-level anomaly score at time point t; is the number of channels; and are respectively the original data and the reconstructed data of channel

[0013] Further, the construction method of the lightweight global segment sharing model is: Perform instance normalization processing on multiple multivariate time series data composed of normal values to obtain multiple normalized multivariate time series normal data, and construct a training set based on the multiple normalized multivariate time series normal data; Perform segmentation processing on each normalized multivariate time series normal data in the training set to obtain the time segment data of multiple channels corresponding to each normalized multivariate time series normal data; Take the time segment data of the multiple channels as the input of the time series feature extractor, extract the time series features of each segment of each channel respectively, and reconstruct each segment of each channel based on the extracted time series features to obtain the corresponding reconstructed data; Calculate the corresponding reconstruction loss based on the original segment data and the corresponding reconstructed data of each channel, and iteratively train the network parameters of the time series feature extractor based on the reconstruction loss to obtain the trained time series feature extractor, that is, the lightweight global shared segment model.

[0014] Further, the training set includes multiple batches, each batch includes multiple normalized multivariate time series normal data, and each normalized multivariate time series normal data is respectively segmented into time segment data of multiple channels; The network parameters for iteratively training the temporal feature extractor based on the reconstruction loss include: Calculating the reconstruction loss of the corresponding normalized multivariate temporal normal data based on each of the reconstruction losses; Calculating the reconstruction loss of this batch based on the reconstruction losses of all the normalized multivariate temporal normal data in the same batch; Iteratively updating the network parameters of the temporal feature extractor based on the reconstruction losses of each batch.

[0015] Further, calculating the reconstruction loss of the corresponding normalized multivariate temporal normal data based on each of the reconstruction losses includes: ; Wherein, represents the reconstruction loss of the normalized multivariate temporal normal data; represents the number of channels of the normalized multivariate temporal normal data; is the number of channel segments; is the number of time points of each segment; and respectively represent the original segment data and the corresponding reconstructed data of the th segment and the th time point in channel ; represents the reconstruction loss of the th segment and the th time point in channel

[0016] Further, calculating the reconstruction loss of this batch based on the reconstruction losses of all the normalized multivariate temporal normal data in the same batch includes: ; represents the reconstruction loss of the batch; is the number of the normalized multivariate temporal normal data in this batch.

[0017] Further, taking the time segment data of each channel as the input of the lightweight global segment sharing model to obtain the output reconstructed data includes: ; Wherein, is the reconstructed data of the th segment and the th time point in channel ; is the original segment data of the th segment and the th time point in channel ; is the channel the data at the last time point in the is the channel the number of time points in the and are the weight matrix and the bias vector respectively.

[0018] The present invention can at least achieve one of the following beneficial effects: By segmenting multivariate time series data and adopting a global segment sharing architecture that shares network parameters among all channels and all time segments, the number of parameters is reduced, the time complexity and space complexity of the model are reduced, the amount of computation is significantly reduced, and the overfitting problem is avoided. By calculating the overall loss of all channels and all segments in a segment-level fine-grained manner to train the model, the distribution drift is further suppressed. The lightweight of anomaly detection for industrial Internet time series data is realized, and the detection efficiency and detection performance are improved.

[0019] The lightweight global segment sharing model of the present invention is the first multivariate time series data anomaly detection model that only uses a simple single-layer linear network to extract time features, reconstruct time segment data, and alleviate the overfitting problem.

[0020] Other features and advantages of the present invention will be described in the following specification, and some advantages can be made obvious from the specification, or understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained from the content specifically pointed out in the specification, the claims, and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The drawings are only for the purpose of showing specific embodiments and are not considered as a limitation of the present invention. Throughout the drawings, the same reference signs represent the same components; Figure 1 is the flowchart of the method of the present invention; Figure 2 is a comparison diagram of the global segment sharing architecture of the present invention with the channel-independent architecture and the channel hybrid architecture in the prior art; Figure 3 is a comparison diagram of the global segment sharing architecture of the present invention with the channel-independent architecture in the prior art. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0022] The following will specifically describe the preferred embodiments of the present invention with reference to the drawings, where the drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, and are not used to limit the scope of the present invention.

[0023] An embodiment of the present invention discloses a lightweight anomaly detection method for time-series data in the industrial Internet, which specifically includes the following steps: S1. Perform instance normalization processing on the time-series data of each channel in the industrial Internet to obtain normalized multi-channel time-series data; the "multi-channel" corresponds to multiple said channels, and each said channel corresponds to a signal source of the industrial Internet, and the signal source includes sensors or other measurement dimensions; it should be noted that all channel data of the multi-channel time-series data in the industrial Internet comes from the same industrial process; S2. Perform segmentation processing on the normalized multi-channel time-series data, evenly divide the data of each channel into multiple segments with the same quantity to obtain the time segment data of each channel; wherein, the time segment data of each channel includes data of multiple time points; S3. Based on the time segment data of each channel, use a lightweight global segment sharing model to perform anomaly detection on the normalized multi-channel time-series data; the lightweight global segment sharing model is based on a global segment sharing architecture, learns segment-level time-series feature representations through a time-series feature extractor, and is trained based on the reconstruction loss.

[0024] The lightweight global segment sharing model adopts a Global Patch-Shared (GPS) architecture, aiming to learn a segment-level representation (representation, extract the time-series features of the input P-dimensional time segment, and reconstruct and output P-dimensional reconstructed data based on the extracted time-series features), and all segments of all channels share this representation. The global segment sharing architecture takes the segment data of all channels as inputs respectively to train the same shared time-series feature extractor to extract segment-level time-series features. The network parameters of the global shared time-series feature extractor can globally fuse the time-series information of the time segment data from all channels, implicitly capturing the correlations between all time segment data and between channels.

[0025] In this embodiment, by using a lightweight global segment sharing model, based on a global segment sharing architecture, through adopting fine-grained segment-level processing, the multi-channel time-series data is segmented into time segments of each channel for anomaly detection, reducing the computational complexity of detection, thereby shortening the inference detection time, realizing lightweight and high-performance anomaly detection of time-series data in the industrial Internet, and being able to cope with the volatility of the industrial Internet environment, quickly discovering and preventing emergencies such as cyberattacks and system failures.

[0026] In a specific embodiment of the present invention, in step S1, the multi-channel time-series data in the industrial Internet with C channels and T timestamps is represented as . It should be noted that in the method of the present invention, when training the lightweight global segment sharing model and performing time-series anomaly detection based on the model, the number of channels in the industrial Internet is the same.

[0027] Further, represent the data of each channel as , ; The calculation method of its normalized data is: ; Among them, represents the normalized data corresponding to channel c at timestamp ; represents the mean value of all data of this channel; represents the standard deviation of all data of this channel; ; is the stability factor of variance, which is a very small positive number used to prevent the situation of division by zero.

[0028] The normalized multivariate time series data is represented as: , .

[0029] In this embodiment, by applying instance normalization technology to the data of each channel, the influence of the value range between different channels is reduced, the distribution drift is alleviated, the generalization ability of the model is improved, and the model convergence is accelerated.

[0030] In a specific embodiment of the present invention, in step S2, the normalized multivariate time series data is segmented, and the time series data of each channel is evenly divided into a plurality of segments with the same number (that is, the data of each channel is independently segmented). It should be noted that the data of each segment in each channel do not overlap with each other.

[0031] Specifically, the normalized multivariate time series data is regarded as C independent univariate time series data . Each univariate time series data (that is, the time series data of each channel) is divided into N non-overlapping segments , where T = N×P is the length of, P is the segment size (that is, the number of time points of the segment), N is the number of segments, represents the i-th segment of. Then the normalized multivariate time series data is represented as .

[0032] In this embodiment, by segmenting the normalized multi-temporal data, the temporal patterns in the normalized multi-temporal data can be locally analyzed, and more refined details can be extracted. On the one hand, compared with the point-by-point model, this embodiment aggregates time points into sub-sequence-level segments, thereby enhancing locality and capturing more comprehensive semantic information. On the other hand, compared with the sequence-level model, the sharding design reduces the input length from T to the segment size P = T / N, thereby reducing the computational complexity quadratically by a factor of N. Therefore, this embodiment adopts a segmented design. Using segment analysis not only retains local time information, realizes a finer-grained analysis, but also significantly reduces the computational complexity, thereby improving the accuracy and efficiency of sequence data analysis.

[0033] In a specific embodiment of the present invention, step S3 further includes steps S31 - S33.

[0034] S31. Take the time segment data of each channel as the input of the lightweight global segment sharing model to obtain the reconstructed data of the output; based on the reconstructed data of the time segment data of each channel, obtain the reconstructed data of the normalized multi-temporal data.

[0035] Specifically, the lightweight global segment sharing model aims to learn a segment-level representation f: → , which represents extracting the temporal features of the input P-dimensional time segment data by the lightweight global segment sharing model, and reconstructing and outputting P-dimensional reconstructed data based on the extracted temporal features. That is, taking the time segment data as the input of the lightweight global segment sharing model, the output is the reconstructed data of the original time segment data of each channel. As shown in Figure 2 the "global segment sharing architecture" in the upper left (the network parameters of each channel data are shared) is the schematic diagram of the lightweight global segment sharing model of the present invention. Under the global segment sharing architecture, each segment of each channel (a total of C channels, with N segments per channel) is used as the input, mapped to the shared embedding space, and then reconstructed into a segment data. It should be noted that the computational complexity of the lightweight global segment sharing model is independent of the number of channels and the sequence length.

[0036] Specifically, the lightweight global segment sharing model adopts the strategy of subtracting the value of each time point in the original segment from the value of its last time point, and applies it locally to each segment, that is, subtracting the last data of each segment from each time point in segment , which is expressed as: ; where represents the i-th segment of ​For the channel The data at the th time point in the th segment of the channel The number of time points in the

[0037] th segment of the channel Furthermore, segment ; wherein and respectively represent the weight matrix and bias vector of the linear layer

[0038] Furthermore, the part to be subtracted is added back to to reconstruct the original segment. The reconstructed data at the th time point in the th segment of the channel is represented as ; Then the reconstructed data of the th segment of the channel is .

[0039] Furthermore, the reconstructed data of the normalized multivariate time series data is obtained based on the reconstructed data of the original segment data of each channel

[0040] Specifically, each channel of the reconstructed data Z of the normalized multivariate time series data is the concatenation of all segments in the th channel. Therefore, the reconstructed data of this channel can be represented as , that is

[0041] S32. Calculate the point - level anomaly score at each time point based on the normalized multivariate time series data and the corresponding reconstructed data

[0042] The calculation method of the point - level anomaly score is ; wherein is the point - level anomaly score at time point t; is the number of channels; and are respectively the original data and the reconstructed data of the th channel at time point t

[0043] ​S33. Obtain the time - series anomaly detection result of the normalized multivariate time - series data based on the point - level anomaly score. Specifically, it includes: Compare the point - level anomaly score with the threshold δ. If the point - level anomaly score is less than the threshold δ, the data at this time point is normal; otherwise, the data at this time point is abnormal. The threshold δ is determined based on the empirical rule.

[0044] In step S3, filtering out the local fluctuations in each segment based on the lightweight global segment sharing model helps to alleviate the distribution drift in each segment and effectively extract the inherent time - series pattern of the time - series data.

[0045] The lightweight global segment sharing model in this embodiment significantly reduces the time and space complexity of lightweight time - series anomaly detection in the industrial Internet. By adopting the "global segment sharing architecture" that shares network parameters for each channel's data (as shown in the upper left of Figure 2 ), although the correlation between the time segments of each channel is not explicitly expressed, it can globally fuse the time - series information from all time segments. This global processing process implicitly captures the correlation between time segments and between channels, reduces the number of parameters, and reduces the model complexity. Since all channels of the multivariate time - series data in the industrial Internet come from the same industrial process, there is a potential consistency between the univariate time - series data of each channel, which makes the channel - independent strategy adopted in this embodiment reasonable in the time - series data anomaly detection of the industrial Internet and achieves low time complexity and low space complexity.

[0046] In a specific embodiment of the present invention, the construction method of the lightweight global segment sharing model is as follows: Perform instance normalization processing on multiple multivariate time - series data composed of normal values to obtain multiple normalized multivariate time - series normal data, and construct a training set based on the multiple normalized multivariate time - series normal data; Perform segmentation processing on each normalized multivariate time - series normal data in the training set to obtain multiple segment - level multivariate time - series normal data corresponding to each normalized multivariate time - series normal data; Use the segment - level multivariate time - series normal data as the input of the NLinear network, extract the time - series features of the segment data of each channel respectively, and reconstruct the segment data of each channel based on the extracted time - series features to obtain the corresponding reconstructed data; Calculate the corresponding reconstruction loss based on the original segment data and the corresponding reconstructed data of each channel, and iteratively train the NLinear network parameters based on the reconstruction loss to obtain the trained NLinear network, that is, the lightweight global sharing segment model.

[0047] Further, the training set includes multiple batches, and each batch includes multiple normalized multivariate time series normal data, and each normalized multivariate time series normal data corresponds to multiple segment-level multivariate time series normal data.

[0048] Further, the iterative training of the NLinear network parameters based on the reconstruction loss includes: Calculating the reconstruction loss of the corresponding normalized multivariate time series normal data based on each of the reconstruction losses, and the calculation method is: ; where represents the reconstruction loss of the normalized multivariate time series normal data; represents the number of channels of the normalized multivariate time series normal data; is the number of segment pieces for each channel; is the number of time points for each segment; and respectively represent the original segment data and the corresponding reconstructed data at the th segment and the th time point in the th channel; represents the reconstruction loss at the th segment and the th time point in the th channel; Calculating the reconstruction loss of the batch based on the reconstruction losses of all the normalized multivariate time series normal data in the same batch, , where represents the reconstruction loss of the batch; is the number of the normalized multivariate time series normal data in this batch; Iteratively updating the NLinear network parameters based on the reconstruction losses of each batch with the goal of a smaller reconstruction loss until the convergence condition (preset convergence value or maximum number of iterations) is reached, and obtaining the trained NLinear network.

[0049] In this embodiment, when facing the problem of unsupervised time series data anomaly detection, a training set consisting of only normal points is adopted, which solves the problem of difficult data annotation in time series data due to the scarcity of anomaly points and being masked by a large number of normal points. By adopting a global segment sharing architecture with shared network parameters for each channel's data, the overfitting problem caused by using complex models with a large number of parameters when extracting time information from large-scale high-dimensional time series data in traditional methods is avoided. By subtracting the last value from each segment of data, the local fluctuations in each segment are filtered out, effectively alleviating the influence of distribution drift.

[0050] In this embodiment, the complexity of the model is reduced by adopting a global patch - shared (GPS) architecture for sharing network parameters among channels. As mentioned above, the "global patch - shared architecture" is an architecture for sharing network parameters among channels.

[0051] The following will compare the lightweight global patch - shared model (LGPAD) of the invention with the channel - mixing (CM) architecture and the channel - independent (CI) architecture in the prior art to further illustrate the beneficial effects of the invention.

[0052] Specifically, in the channel - mixing architecture, all channels are regarded as a whole. The features of all channels are taken as inputs and projected into a mixed embedding space to capture the relationships among all channels. The method based on the channel - mixing architecture aims to learn a mapping , which usually leads to high dimensions and high complexity. The computational complexity of the method based on the channel - mixing architecture increases with the increase of the number of channels C and the time length T of multivariate time - series data. This inherent complexity may pose significant challenges to real - time and resource - constrained application scenarios.

[0053] Specifically, the channel - independent architecture treats each channel of multivariate time - series data as a separate univariate time - series data , and projects each channel independently into a shared channel - specific embedding space. The time feature extractors of all channels share the same weights, which enables the channel - independent architecture to reduce the complexity of the model. Research shows that the channel - independent architecture exhibits higher robustness than the channel - mixing architecture when dealing with the distribution shift of real - world non - stationary time - series data. The method based on the channel - independent architecture aims to learn a mapping function . The complexity of the method based on the channel - independent architecture grows with the increase of the length T of multivariate time - series data, but is independent of the number of channels and remains constant.

[0054] Specifically, the global patch - shared architecture adopted by the lightweight global patch - shared model of the invention significantly reduces the model complexity compared with the channel - mixing architecture and the channel - independent architecture. The input of the lightweight global patch - shared model is a patch , whose dimension is lower than the inputs of the models based on the channel - mixing architecture and the channel - independent architecture. The reduction of the input dimension enables the lightweight global patch - shared model based on global patch - sharing to adopt a simpler network as the time feature extractor, while increasing the learning sample size to avoid overfitting. In addition, the global patch - shared architecture enhances the local semantic information in the patch by using the patch - level representation and improves the robustness of the model by alleviating the distribution shift.

[0055] As shown in Table 1, the following is a comparative analysis of the computational complexity when using NLinear to extract temporal features under the channel mixing architecture, channel independent architecture, and global segment sharing architecture: Table 1 Analysis of the Computational Complexity of Linear Models under the Channel Mixing Architecture, Channel Independent Architecture, and Global Segment Sharing Architecture

[0056] As can be seen from Table 1, when using NLinear to extract temporal features, for the input : The weights of NLinear based on the global segment sharing architecture are and , and its number of parameters is , and the FLOPs is ; The weights of the NLinear network based on the channel independent architecture are and , the number of parameters is , and the FLOPs is ; The weights of the NLinear network based on the channel mixing architecture are and , the number of parameters is , and the FLOPs is .

[0057] The lightweight global segment sharing model of the present invention reduces the time complexity by 3 to 5 orders of magnitude and the space complexity by 3 to 6 orders of magnitude compared with the models of other architectures. Compared with the baseline method with millions of parameters, the lightweight global segment sharing model with only 20 parameters improves the average F1 score by at least 2.80%.

[0058] As Figure 2 , is a comparative diagram of the computational complexity of the global segment sharing architecture, channel independent architecture, and channel mixing architecture. The diagrams below each architecture in the figure correspond to the data input dimensions of the corresponding architecture, and the diagrams more intuitively represent the computational complexity comparison analyzed in Table 1. As Figure 3 is a comparison between the lightweight global segment sharing model of the global segment sharing architecture of the present invention and the linear model of the channel independent architecture (the reversible feature normalization part is omitted).

[0059] In the global fragment sharing architecture, each data block of all channels shares the same model weights and performs embedding processing independently. Experimental results show that, compared with the channel-independent architecture, the global fragment sharing architecture further reduces the number of parameters. By taking each data block as an independent input, the global fragment sharing architecture constructs a more concise time series feature extraction network, which not only reduces the model complexity, but also effectively alleviates the overfitting problem in industrial Internet of Things time series anomaly detection by increasing the effective learning sample size and combining the simple characteristics of NLinear.

[0060] Regarding the distribution drift problem, the loss function of the model based on the channel mixing architecture calculates the overall loss of all channels. The summation operation adopted by the channel-independent architecture can alleviate the distribution drift. While the global fragment sharing architecture calculates the total loss of all data blocks of all channels in a finer-grained manner, thus being able to further suppress the distribution drift.

[0061] Compared with the models based on the channel mixing architecture and the channel-independent architecture, the lightweight global fragment sharing model of the present invention significantly reduces the time and space complexity of lightweight time series anomaly detection in the industrial Internet. Through the synergistic effect of the global fragment sharing architecture and the NLinear network, the lightweight global fragment sharing model of the present invention performs excellently in dealing with distribution drift and overfitting problems, and is particularly suitable for industrial Internet scenarios with resource constraints and frequent real-time detection requirements, and can provide a fast and accurate response for time series anomaly detection.

[0062] It should be noted that the above embodiments are based on the same inventive concept, and for the parts not repeatedly described, reference can be made to each other.

[0063] The above is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.

Claims

1. A lightweight anomaly detection method for industrial Internet time-series data, characterized in that, It includes the following steps: Perform instance normalization processing on the time-series data of each channel in the industrial Internet to obtain normalized multivariate time-series data; the multivariate corresponds to multiple channels, and each channel corresponds to each signal source of the industrial Internet time-series data; Perform segmentation processing on the normalized multivariate time-series data, evenly divide the data of each channel into multiple segments with the same quantity, and obtain multiple time segment data of each channel; Based on the multiple time segment data of each channel, use the lightweight global segment sharing model to perform anomaly detection on the normalized multivariate time-series data; the lightweight global segment sharing model is based on the global segment sharing architecture, learns segment-level time-series feature representations through a time-series feature extractor, and is trained based on the reconstruction loss.

2. The lightweight industrial Internet of Things time-series data anomaly detection method according to claim 1, wherein, For the global segment sharing architecture, use the time segment data of each channel as input to train the same shared time-series feature extractor to extract segment-level time-series features.

3. The lightweight industrial Internet of Things time-series data anomaly detection method according to claim 2, wherein The performing anomaly detection on the normalized multivariate time-series data by using the lightweight global segment sharing model based on the multiple time segment data of each channel includes: Use the time segment data of each channel as the input of the lightweight global segment sharing model to obtain the reconstructed data of the output; obtain the reconstructed data of the normalized multivariate time-series data based on the reconstructed data of the time segment data of each channel; Calculate the point-level anomaly scores of each time point based on the normalized multivariate time-series data and the corresponding reconstructed data; Obtain the time-series anomaly detection result of the normalized multivariate time-series data based on the point-level anomaly scores.

4. The lightweight industrial Internet of Things time-series data anomaly detection method according to claim 3, wherein, The obtaining the time-series anomaly detection result of the normalized multivariate time-series data based on the point-level anomaly scores includes: Compare the point-level anomaly scores of each time point with the threshold respectively. If the point-level anomaly score is less than the threshold, the data at the corresponding time point is normal, otherwise the data at this time point is abnormal.

5. The lightweight industrial Internet of Things time-series data anomaly detection method according to claim 4, wherein The calculation method of the point-level anomaly score is: ; Among them, is the point-level anomaly score at time point t; is the number of channels; and are respectively the original data and the reconstructed data of channel at time point t.

6. The lightweight industrial Internet of Things time-series data anomaly detection method according to any one of claims 2-5, characterized in that The construction method of the lightweight global segment sharing model is: Perform instance normalization processing on multiple multivariate time-series data composed of normal values to obtain multiple normalized multivariate time-series normal data, and construct a training set based on the multiple normalized multivariate time-series normal data; Perform segmentation processing on each normalized multivariate time-series normal data in the training set to obtain the time segment data normal data of multiple channels corresponding to each normalized multivariate time-series normal data; Use the time segment data normal data of the multiple channels as the input of the time-series feature extractor, extract the time-series features of each segment of each channel respectively, and reconstruct each segment of each channel based on the extracted time-series features to obtain the corresponding reconstructed data; Calculate the corresponding reconstruction loss based on the original segment data and the corresponding reconstructed data of each channel, and iteratively train the network parameters of the time-series feature extractor based on the reconstruction loss to obtain the trained time-series feature extractor, namely the lightweight global shared segment model.

7. The lightweight industrial Internet of Things time-series data anomaly detection method according to claim 6, wherein, The training set includes multiple batches, each batch respectively includes multiple normalized multivariate time-series normal data, and each normalized multivariate time-series normal data is respectively segmented into multi-channel time segment data; The iteratively training the network parameters of the time-series feature extractor based on the reconstruction loss includes: Calculating the reconstruction loss of the corresponding normalized multivariate time series normal data based on each of the reconstruction losses; Calculating the reconstruction loss of this batch based on the reconstruction losses of all the normalized multivariate time series normal data in the same batch; Iteratively updating the network parameters of the time series feature extractor based on the reconstruction losses of each batch.

8. The lightweight industrial Internet of Things time-series data anomaly detection method according to claim 7, characterized in that The calculating the reconstruction loss of the corresponding normalized multivariate time series normal data based on each of the reconstruction losses includes: ; Among them, represents the reconstruction loss of the normalized multivariate time series normal data; represents the number of channels of the normalized multivariate time series normal data; is the number of segments for each channel; is the number of time points for each segment; and respectively represent the original segment data and the corresponding reconstructed data of the th segment and the th time point in the channel; th segment and the th time point in the channel.

9. The lightweight industrial Internet of Things time series data anomaly detection method according to claim 8, wherein, The calculating the reconstruction loss of this batch based on the reconstruction losses of all the normalized multivariate time series normal data in the same batch includes: ; Represents the reconstruction loss of the batch; Is the number of normalized multivariate time series normal data in this batch.

10. The lightweight industrial Internet of Things time series data anomaly detection method according to claim 3, wherein, The taking the time segment data of each channel as the input of the lightweight global segment sharing model to obtain the output reconstructed data includes: ; Among them, is the reconstruction data at the th time point in the th segment; is the original segment data at the th time point in the th segment; is the data at the last time point in the th segment, is the number of time points in the th segment; and are the weight matrix and the bias vector respectively.

Citation Information

Patent Citations

  • Multivariate time sequence anomaly detection method and device, computer equipment and storage medium

    CN115840774A

  • Industrial internet time series data anomaly detection method and system

    CN118898045A

  • Industrial Internet of Things system anomaly detection method based on multivariable time series data

    CN119363624A

  • Automated window based feature generation for time-series forecasting and anomaly detection

    US20200097810A1