Abnormality detection method, device and equipment
Through the adaptive threshold and target clustering center method, the detection standards are dynamically adjusted, and the problem of insufficient abnormal detection caused by dynamic changes in sensor data in the prior art is solved, efficient and reliable abnormality monitoring is achieved, and the load and power consumption of the substrate management controller is reduced.
Patent Information
- Application Number
- CN202510494898.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-08
AI Technical Summary
Existing anomaly detection methods are difficult to flexibly respond to dynamically changing sensor data in complex real-time environments, resulting in insufficient real-time and accuracy. Relying on the substrate management controller can easily lead to excessive load pressure and excessive power consumption, affecting normal operation.
The abnormal detection is performed using the adaptive threshold and target clustering center method. The detection standards and sensitivity are dynamically adjusted by obtaining the current historical sensor data sequence, reducing the dependence on the substrate management controller, and the tasks are performed jointly by the microcontroller unit and the substrate management controller to share the load.
提高了异常检测的灵活性和准确性,降低了基板管理控制器的负载压力和功耗,实现了在复杂环境中的高效可靠监测。
Smart Images

Figure CN120276905A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical fields of computer devices and anomaly detection, and more particularly, to an anomaly detection method, apparatus, and device. Background Art
[0002] With the wide application of data centers, cloud computing, and high-performance servers, the stability and reliability of servers have become increasingly critical. To ensure the stable operation of servers, server sensors can be used to monitor and manage the operating status of servers in real time.
[0003] However, the continuously changing external environmental conditions and internal loads of the servers will cause the sensor data to change dynamically. Related anomaly detection methods are difficult to flexibly handle the dynamically changing sensor data in a complex real-time environment, resulting in deficiencies in the real-time performance and accuracy of anomaly detection. In addition, related anomaly detection methods mainly rely on the baseboard management controller to execute, which easily leads to an excessive load pressure and high power consumption of the baseboard management controller, affecting its normal operation and the exertion of management functions. Summary of the Invention
[0004] In view of the above problems, the present application provides an anomaly detection method, apparatus, device, medium, and program product.
[0005] According to one aspect of the present application, there is provided a sensor anomaly detection method, including: obtaining sensor data collected by a target sensor at the current moment; detecting the sensor data according to an adaptive threshold and a target clustering center to obtain a detection result, where the adaptive threshold and the target clustering center are determined based on a current historical sensor data sequence corresponding to the current moment, and the current historical sensor data sequence includes a predetermined number of previous sensor data arranged in chronological order; and determining that an anomaly event exists when the detection result meets a preset condition.
[0006] Another aspect of the present application provides an anomaly detection apparatus, including: an obtaining module, configured to obtain sensor data collected by a target sensor at the current moment; a detecting module, configured to detect the sensor data according to an adaptive threshold and a target clustering center to obtain a detection result, where the adaptive threshold and the target clustering center are determined based on a current historical sensor data sequence corresponding to the current moment, and the current historical sensor data sequence includes a predetermined number of previous sensor data arranged in chronological order; and a determining module, configured to determine that an anomaly event exists when the detection result meets a preset condition.
[0007] Another aspect of the present application provides an electronic device, including: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0008] Another aspect of the present application further provides a computer-readable storage medium, on which computer programs or instructions are stored, and when the computer programs or instructions are executed by a processor, the steps of the above method are implemented.
[0009] Another aspect of the present application further provides a computer program product, including computer programs or instructions, and when the computer programs or instructions are executed by a processor, the steps of the above method are implemented.
[0010] According to an embodiment of the present application, for the dynamically changing sensor data stream, since the adaptive threshold and the target clustering center are determined based on the current historical sensor data sequence, the adaptive threshold and the target clustering center can effectively reflect the real-time dynamic changes of the sensor data stream. Compared with the anomaly detection mechanism based on a preset fixed threshold or preset rules, by performing anomaly detection on the sensor data collected at the current moment based on the adaptive threshold and the target clustering center, the anomaly detection method provided by the embodiment of the present application can adjust the criteria and sensitivity of anomaly detection in real time and dynamically according to the fluctuations of the sensor data, so as to flexibly adapt to the fluctuations of the sensor data caused by the changes in the hardware environment of the server under different working conditions, thereby effectively improving the flexibility and accuracy of anomaly detection and ensuring efficient and reliable anomaly monitoring in a complex and changing real-time environment.
[0011] The anomaly detection method provided by the embodiment of the present application can be jointly executed by a micro control unit and a baseboard management controller, so as to effectively reduce the degree of dependence on the baseboard management controller and reduce the load pressure and power consumption of the baseboard management controller by reasonably allocating the tasks respectively undertaken by the micro control unit and the baseboard management controller, and further enable the baseboard management controller to centrally process more complex tasks. In addition, by selecting a low-power micro control unit, the overall power consumption of the micro control unit and the baseboard management controller can be reduced, achieving an energy-saving effect, so as to be applicable to a server environment with strict power consumption requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Through the following description of the embodiments of the present application with reference to the drawings, the above content and other objects, features and advantages of the present application will become clearer. In the drawings:
[0013] Figure 1 Schematically shows an application scenario diagram of an anomaly detection method, device, equipment, medium and program product according to an embodiment of the present application;
[0014] Figure 2 Schematically shows a flowchart of an anomaly detection method according to an embodiment of the present application;
[0015] Figure 3 Schematically shows a flowchart of anomaly detection according to an embodiment of the present application;
[0016] Figure 4 Schematically shows a schematic diagram for determining the existence of an abnormal event according to an embodiment of the present application;
[0017] Figure 5 Schematically shows a structural block diagram of an anomaly detection device according to an embodiment of the present application; and
[0018] Figure 6 Schematically shows a block diagram of an electronic device suitable for implementing the anomaly detection method according to an embodiment of the present application. Detailed implementation manners
[0019] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present application. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present application. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present application.
[0020] The terms used herein are merely for describing specific embodiments and are not intended to limit the present application. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0021] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0022] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0023] In the technical solution of the present application, the user information involved (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) are all information and data authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, all complies with relevant laws, regulations, and standards, takes necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for users to choose to authorize or refuse.
[0024] Some block diagrams and / or flowcharts are shown in the accompanying drawings. It should be understood that some blocks or combinations of blocks in the block diagrams and / or flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, so that when executed by the processor, these instructions can create a device for implementing the functions / operations illustrated in these block diagrams and / or flowcharts.
[0025] Therefore, the technology of the present application can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). Additionally, the technology of the present application can take the form of a computer program product on a computer-readable medium storing instructions, and this computer program product can be used by or in combination with an instruction execution system. In the context of the present application, a computer-readable medium can be any medium capable of containing, storing, transmitting, propagating, or transporting instructions. For example, a computer-readable medium can include but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, components, or propagation media. Specific examples of computer-readable media include: magnetic storage devices, such as magnetic tapes or hard disk drives (HDDs); optical storage devices, such as compact discs (CD-ROMs); memories, such as random access memories (RAMs) or flash memories; and / or wired / wireless communication links.
[0026] With the wide application of data centers, cloud computing, and high-performance servers, the stability and reliability of servers have become increasingly critical. To ensure the stable operation of servers, server sensors can be used to monitor and manage the operating status of servers in real time.
[0027] However, the continuous changes in the external environmental conditions and internal loads of servers will cause the sensor data to also change dynamically. Relevant anomaly detection methods are difficult to flexibly handle the dynamically changing sensor data in a complex real-time environment, resulting in deficiencies in the real-time performance and accuracy of anomaly detection. In addition, relevant anomaly detection methods mainly rely on the baseboard management controller to execute, which easily leads to an overly heavy load and high power consumption of the baseboard management controller, affecting its normal operation and the exertion of management functions.
[0028] In the application scenario of server sensor anomaly detection, the relevant anomaly detection methods mainly rely on the baseboard management controller to collect sensor data, and adopt a fixed threshold judgment mechanism or a rule-based anomaly detection method to determine whether the sensor data exceeds the normal range. If the sensor data exceeds the normal range, it is considered that an anomaly exists, and a system error event log can be generated to trigger an alarm notification. However, as the hardware monitoring and control center, the baseboard management controller itself needs to handle numerous server management tasks, and its resources (such as processor performance, memory capacity, etc.) are limited. If all tasks such as a large amount of sensor data collection, anomaly detection, and alarm are entrusted to the baseboard management controller, it will cause an excessive load pressure on the baseboard management controller, affecting its normal operation and the exertion of management functions. In addition, the relevant anomaly detection methods usually rely on preset fixed thresholds to determine whether sensor data is abnormal, but the sensor data will fluctuate due to the dynamic changes in the server hardware environment. In this case, anomaly detection based on fixed thresholds is not only inaccurate but also prone to false negatives or false positives of anomaly events, thus affecting the reliability and effectiveness of anomaly detection.
[0029] Embodiments of the present application provide a sensor anomaly detection method, device, equipment, medium, and program product. The method includes: obtaining sensor data collected by a target sensor at the current moment; detecting the sensor data according to an adaptive threshold and a target clustering center to obtain a detection result, where the adaptive threshold and the target clustering center are determined based on the current historical sensor data sequence, the current historical sensor data sequence corresponds to the current moment, and the current historical sensor data sequence includes a predetermined number of previous sensor data arranged in chronological order; and determining that an anomaly event exists when the detection result meets a preset condition.
[0030] Figure 1 FIG. schematically shows an application scenario diagram of the sensor anomaly detection method, device, equipment, medium, and program product according to an embodiment of the present application.
[0031] As Figure 1 shown, the application scenario 100 according to an embodiment of the present application may include, for example, a server 101, a power supply 102, a baseboard management controller 103 (Baseboard Management Controller, BMC), a server sensor 104, and a microcontroller unit 105 (Microcontroller Unit, MCU).
[0032] Server 101 can be a server that provides various services, such as a background management server (for example only) that supports the content browsed by users using terminal devices. The background management server can analyze and process data such as user requests received, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.
[0033] Server 101 can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services ("Virtual Private Server", or simply "VPS" for short). Server 101 can also be a server of a distributed system, or a server combined with a blockchain.
[0034] Power supply 102 can provide a stable power supply for server 101 and server sensor 104 to ensure that server 101 and server sensor 103 can operate normally. Power supply 102 can have functions such as overload protection, short circuit protection, and overheat protection. Once an abnormal situation occurs, power supply 102 can automatically cut off the power output to protect server 101, server sensor 104 and other devices from damage. In one embodiment, multiple power supplies 102 can be provided to prevent a single power supply 102 from failing and affecting the overall operation of the system.
[0035] Server sensor 104 can be used to monitor the operating status of server 101 in real time, including key indicators such as temperature, humidity, voltage, and fan speed. Exemplarily, server sensor 104 can include, for example, but not limited to at least one of the following: temperature sensor, humidity sensor, voltage sensor, fan speed sensor, etc.
[0036] Baseboard Management Controller 103 can be used to remotely manage and monitor the hardware status of server 101. Baseboard Management Controller 103 can operate independently of the main system of server 101. Even when server 101 is shut down or the operating system crashes, Baseboard Management Controller 103 can still work normally. The functions of Baseboard Management Controller 103 can include, for example, server information management, server status management, remote control management, firmware update, log management, anomaly detection and recording, alarm notification, and so on.
[0037] The microcontroller unit 105 can be programmed to implement specific control functions, featuring low power consumption, high integration, and flexible programmability. For example, the microcontroller unit 105 can control the rotation speed of the fan and dynamically adjust the rotation speed of the fan according to the data of the temperature sensor to optimize the heat dissipation effect (for example only). For example, the microcontroller unit 105 can also be used for power management to ensure the stable operation of the power supply 102 (for example only).
[0038] It should be noted that the anomaly detection method provided by the embodiments of the present application can generally be executed by the baseboard management controller 103. Correspondingly, the anomaly detection device provided by the embodiments of the present application can generally be arranged in the baseboard management controller 103. More preferably, the anomaly detection method provided by the embodiments of the present application can also be executed by the microcontroller unit 105. Correspondingly, the anomaly detection device provided by the embodiments of the present application can also be arranged in the microcontroller unit 105.
[0039] Exemplarily, the microcontroller unit 105 can execute the anomaly detection method to relieve the load pressure on the baseboard management controller 103, enabling the baseboard management controller 103 to centrally process more complex tasks. As Figure 1 shown, the microcontroller unit 105 can obtain the sensor data collected in real time by the server sensor 104 through communication protocols such as I2C, PECI, and SPI. The microcontroller unit 105 can execute at least one step in the anomaly detection method provided by the embodiments of the present application based on the obtained sensor data. The microcontroller unit 105 can, for example, report the anomaly event to the baseboard management controller 103. Exemplarily, the microcontroller unit 105 can preferably be a low-power microcontroller unit to reduce the overall power consumption of the system, so as to be applicable to a server environment with strict power consumption requirements. Through reasonable task allocation, the continuous working burden on the baseboard management controller 103 can be effectively reduced, thereby achieving an energy-saving effect.
[0040] Optionally, the anomaly detection method provided by the embodiments of the present application can be executed by at least one of the microcontroller unit 105 and the baseboard management controller 103. Correspondingly, the anomaly detection device provided by the embodiments of the present application can be arranged in at least one of the microcontroller unit 105 and the baseboard management controller 103.
[0041] It should be understood that Figure 1 the numbers of servers, power supplies, server sensors, etc. in
[0042] Figure 2 are merely illustrative. According to actual needs, there can be any number of servers, power supplies, and server sensors.
[0043] AsFigure 2 As shown, the method 200 includes operations S210 to S230.
[0044] In operation S210, obtain the sensor data collected by the target sensor at the current moment.
[0045] In operation S220, detect the sensor data according to the adaptive threshold and the target clustering center to obtain a detection result, where the adaptive threshold and the target clustering center are determined based on the current historical sensor data sequence, the current historical sensor data sequence corresponds to the current moment, and the current historical sensor data sequence includes a predetermined number of previous sensor data arranged in chronological order.
[0046] In operation S230, when the detection result meets the preset conditions, it is determined that an abnormal event exists.
[0047] The target sensor can be a service sensor, and the sensor data can be a monitoring metric of the server. For example, the target sensor can be a temperature sensor, and the sensor data can be the temperature of the server. For example, the target sensor can be a voltage sensor, and the sensor data can be the voltage of the server. For example, the target sensor can be a fan speed sensor, and the sensor data can be the fan speed of the server.
[0048] For example, based on a preset frequency, the sensor data collected in real time by the target sensor can be obtained through a hardware interface to obtain the sensor data stream of the target sensor. The sensor data stream can include a plurality of sensor data arranged in chronological order according to the collection time. Only as an example, the sensor data stream can be denoted as , where x i is the i-th sensor data collected at the i-th moment.
[0049] Optionally, after obtaining the sensor data stream of the target sensor, preprocessing operations such as denoising, moving average, and standardization can be performed on the plurality of sensor data to improve the data quality of the sensor data, thereby facilitating the improvement of the accuracy and reliability of anomaly detection.
[0050] The sensor data collected by the target sensor at the current moment can be obtained from the sensor data stream. Based on the current moment, the current historical sensor data sequence corresponding to the current moment can be determined. The current historical sensor data sequence can include a plurality of predetermined numbers of previous sensor data arranged in chronological order. Exemplarily, the current historical sensor data sequence can be determined from the above-mentioned sensor data stream. For example, a predetermined number of previous sensor data adjacent to the sensor data collected at the current moment can be selected from the sensor data stream as the current historical sensor data sequence for the current moment.
[0051] It should be noted that those skilled in the art can reasonably set the predetermined number according to actual needs or application scenarios, etc. For example, it can be set to 10, and no limitation is made here.
[0052] As an example, the current moment can be, for example, t 11 At the moment, the target sensor t 11 The sensor data collected at the moment is, for example, x 11 The current historical sensor data sequence can, for example, include the previous sensor data x1 to x collected at the target sensor from time t1 to t 10 At the moment respectively 10 The aforementioned x1 to x 10 Are arranged in chronological order of the collection time.
[0053] An adaptive threshold and a target cluster center for detecting the sensor data at the current moment can be determined based on a predetermined number of previous sensor data.
[0054] The sensor data can be detected according to the adaptive threshold and the target cluster center to obtain a detection result. The detection result can, for example, characterize whether there is an abnormality in the sensor data at the current moment.
[0055] When the detection result meets the preset conditions, an abnormal event can be determined. For example, the abnormal event can include that the sensor is abnormal and / or the server is abnormal.
[0056] It can be understood that for a dynamically changing sensor data stream, since the adaptive threshold and the target cluster center are determined based on the current historical sensor data sequence, this enables the adaptive threshold and the target cluster center to effectively reflect the real-time dynamic changes of the sensor data stream. Compared with the abnormal detection mechanism based on a preset fixed threshold or a preset rule, by performing abnormal detection on the sensor data collected at the current moment based on the adaptive threshold and the target cluster center, the abnormal detection method provided by the embodiments of the present application can adjust the abnormal detection criteria and sensitivity in real time and dynamically according to the fluctuations of the sensor data, so as to flexibly adapt to the sensor data fluctuations caused by the changes in the hardware environment of the server under different working conditions, thereby effectively improving the flexibility and accuracy of abnormal detection and ensuring that efficient and reliable abnormal monitoring can be achieved in a complex and changeable real-time environment.
[0057] According to an embodiment of the present application, the sensor abnormal detection method further includes: adding the sensor data to the current historical sensor data sequence, and deleting the earliest previous sensor data in the current historical sensor data sequence in terms of the collection time to obtain a subsequent historical sensor data sequence corresponding to the subsequent moment.
[0058] For example, based on a preset sliding window, the current historical sensor data sequence corresponding to the current moment can be determined from the sensor data stream. Those skilled in the art can set the window length and sliding step of the preset sliding window according to actual requirements or application scenarios, etc., which are not limited herein. For example, the window length of the preset sliding window can be set to 10, and the sliding step can be set to 1. Optionally, the window length of the preset sliding window can be adjusted according to the acquisition frequency of the sensor data.
[0059] As an example, the current moment can be, for example, t 11 moment, and the sensor data collected by the target sensor at time t 11 is, for example, x 11 . The current historical sensor data sequence can, for example, include the previous sensor data x1 to x 10 collected by the target sensor at times t1 to t 10 . The sensor data x 11 collected at the current moment (time t 11 ) can be added to the current historical sensor data sequence, and the earliest previous sensor data x1 in the current historical sensor data sequence can be deleted to obtain the subsequent historical sensor data sequence corresponding to the subsequent moment (time t 12 ). Among them, the subsequent historical sensor data sequence includes the sensor data x2 to x 11 collected by the target sensor at times t2 to t 11 , and the aforementioned x2 to x 11 are arranged in the chronological order of the acquisition time.
[0060] According to the embodiments of the present application, by determining the current historical sensor data sequence corresponding to the current moment from the sensor data stream based on a preset sliding window, the characteristics of the sensor data stream within a local time range, such as numerical range, discreteness, change trend, etc., can be effectively captured according to the current historical sensor data sequence. The adaptive threshold and clustering center for detecting the sensor data at the current moment can be determined based on the current historical sensor data sequence, thereby enabling real-time and dynamic adjustment of the anomaly detection criteria and sensitivity according to the fluctuations of the sensor data, so as to flexibly adapt to the fluctuations of the sensor data caused by the changes in the hardware environment of the server under different working conditions.
[0061] Optionally, for different target sensors, different anomaly detection mechanisms can be correspondingly selected. For example, pattern recognition based on machine learning can also be selected to perform anomaly detection on the sensor data. Optionally, based on the historical operation data of the server, an adaptive learning algorithm can be used to predict the time point of an abnormal event, improve the fault prevention ability, and achieve intelligent early warning and predictive maintenance.
[0062] According to an embodiment of the present application, the sensor anomaly detection method further includes: determining a target cluster center for detecting sensor data according to a preset clustering algorithm and a current historical sensor data sequence; determining an adaptive threshold for detecting sensor data according to a preset threshold algorithm and the current historical sensor data sequence.
[0063] The preset clustering algorithm can be selected as, for example, the K-means clustering algorithm. The K-means clustering algorithm belongs to the distance-based clustering algorithm, aiming to divide multiple data points in a dataset into K cluster clusters. The goal of the algorithm is to minimize the sum of the distances from the points within the cluster to the cluster center (cluster center). The K-means clustering algorithm uses distance as an evaluation index of similarity, that is, it is considered that the closer the distance between two data points, the greater their similarity.
[0064] Exemplarily, the K-means clustering algorithm can be used to perform unsupervised learning on a predetermined number of previous sensor data in the current historical sensor data sequence to obtain the cluster centers of each of the multiple cluster clusters. The algorithm process can be as follows, for example:
[0065] 1. Select the value of K
[0066] Set the number of cluster clusters K, where K is a positive integer and K≥2.
[0067] 2. Initialize the cluster center
[0068] Randomly select K previous sensor data as the initial cluster centers.
[0069] 3. Assign each data point to the cluster cluster to which the nearest cluster center belongs
[0070] For each previous sensor data in the current historical sensor data sequence, assign it to the cluster cluster corresponding to the nearest cluster center. Among them, the distance can be, for example, the Euclidean distance.
[0071] 4. Recalculate the cluster center of each cluster cluster
[0072] According to the current cluster cluster assignment, recalculate the cluster center of each cluster cluster. Calculate the mean value of all data points within the cluster cluster as the new cluster center.
[0073] 5. Repeat steps 3 and 4 until the cluster center converges or reaches the specified maximum number of iterations.
[0074] Optionally, those skilled in the art can select a suitable clustering algorithm according to actual needs or application scenarios, etc., such as the hierarchical clustering algorithm, the density-based clustering algorithm, etc., which are not specifically limited herein.
[0075] For example, among multiple cluster centers, the cluster center closest to the sensor data at the current moment can be determined as the target cluster center.
[0076] As an example, the preset threshold algorithm can, for example, include determining an adaptive threshold for detecting sensor data based on statistical information of a predetermined number of previous sensor data.
[0077] As another example, the preset threshold algorithm can, for example, include classifying or regressing a predetermined number of previous sensor data based on a machine learning algorithm (such as random forest, linear regression, etc.) to determine an adaptive threshold for detecting sensor data.
[0078] According to an embodiment of the present application, the cluster center can represent the mean of the data points within the cluster, and the cluster center and the adaptive threshold can change dynamically with the fluctuations of the current historical sensor data sequence. Therefore, the cluster center and the adaptive threshold can better define the normal range of the sensor data in real time and can dynamically adapt to the fluctuations of the sensor data, thereby facilitating the improvement of the flexibility and adaptability of anomaly detection.
[0079] According to an embodiment of the present application, determining an adaptive threshold for detecting sensor data according to the preset threshold algorithm and the current historical sensor data sequence includes: determining the adaptive threshold based on the statistical information of the current historical sensor data sequence, where the statistical information includes at least one of the following: mean, standard deviation, median absolute deviation, empirical percentile, and data change trend.
[0080] The adaptive threshold for detecting sensor data can be determined based on the mean and standard deviation of a predetermined number of previous sensor data in the current historical sensor data sequence.
[0081] As an example, the current historical sensor data sequence can be denoted as , where n is the predetermined number. The calculation process of the adaptive threshold can be as follows:
[0082] 1) Calculate the mean
[0083]
[0084] where is the mean, and x i is the i-th previous sensor data collected at the i-th moment.
[0085] 2) Calculate the standard deviation
[0086]
[0087] where is the standard deviation.
[0088] 3. Calculate the adaptive threshold
[0089]
[0090]
[0091] Among them, and can be used as the upper limit value and the lower limit value of the normal range of the sensor data respectively. K is the sensitivity coefficient, and the value of K can be, for example, 2 or 3. When K = 2, about 95.4% of the data points can be covered; when K = 3, about 99.7% of the data points can be covered.
[0092] The adaptive threshold for detecting sensor data can be determined based on the median absolute deviation of a predetermined number of previous sensor data in the current historical sensor data sequence.
[0093] As an example, the current historical sensor data sequence can be denoted as , where n is the predetermined number. The calculation process of the adaptive threshold can be as follows:
[0094] 1) Calculate the median
[0095]
[0096] Among them, M is the median of the current historical sensor data sequence X.
[0097] 2) Calculate the absolute deviation of each data point from the median
[0098]
[0099]
[0100] Among them, is the absolute deviation of the data point from the median M, and D is the set of absolute deviations formed by n absolute deviations .
[0101] 3) Calculate the median absolute deviation
[0102]
[0103] Among them, MAD is the median of the absolute deviation set D.
[0104] 4) Calculate the adaptive threshold
[0105]
[0106] Among them, is the adaptive threshold, K is the sensitivity coefficient (for example, it can take the value of 1.4826), and K can be used to adjust the MAD to a measure similar to the standard deviation.
[0107] The adaptive threshold for detecting sensor data can be determined based on the empirical percentile of a predetermined number of previous sensor data in the current historical sensor data sequence.
[0108] As an example, the current historical sensor data sequence can be denoted as , where n is the predetermined number. For example, it can be set that the data outside the p1% to p2% percentile is abnormal, p1 < p2, and p1 and p2 can be set based on experience. The calculation process of the adaptive threshold can be as follows:
[0109] 1) Sort the data. First, sort the data in in ascending order of numerical value to obtain
[0110]
[0111] 2) Calculate the percentile position. The formula for the p% percentile position is:
[0112]
[0113] where the p% is a value such that at least p% of the data points in are less than or equal to this value, and at least (100 - p)% of the data items are greater than or equal to this value. K is the position of the p% in . K can be an integer or a decimal. If K is an integer, directly take the value at the corresponding position; if K is a decimal, linear interpolation can be used. The formula for linear interpolation is:
[0114]
[0115] where is the p% percentile, is the ceiling function, is the floor function.
[0116] 3) Calculate the adaptive threshold. Assuming that 5% and 95% are selected as the adaptive thresholds, then:
[0117]
[0118]
[0119] where and can be used as the upper and lower limit values of the normal range of the sensor data, respectively.
[0120] An adaptive threshold for detecting sensor data can be determined based on the data change trend of a predetermined number of previous sensor data in the current historical sensor data sequence.
[0121] As an example, the current historical sensor data sequence can be denoted as , where n is the predetermined number. The calculation process of the adaptive threshold can be as follows:
[0122] 1) Data preprocessing, normalizing or standardizing the data to facilitate subsequent calculations
[0123]
[0124] Among them, is the i-th previous sensor data collected at the i-th moment, is the average value, is the standard deviation.
[0125] 2) Trend extraction, using the moving average method, smoothing the data with a sliding window, and calculating the trend value:
[0126]
[0127] Among them, is 's trend value, and N is the size of the sliding window.
[0128] 3) Calculate the residual, calculate the difference between the actual value and the trend value to obtain the residual
[0129]
[0130] Among them, is the residual.
[0131] 4) Calculate the adaptive threshold
[0132]
[0133] Among them, is the adaptive threshold, K is the sensitivity coefficient, and K can take values of 2 to 3, for example, is the residual 's standard deviation.
[0134] According to the embodiments of the present application, determining the adaptive threshold based on the statistical information of the current historical sensor data sequence includes: determining the adaptive threshold based on the statistical information and the weight corresponding to the statistical information, and the weight is determined according to the confidence level of the statistical information.
[0135] Statistical information may include, for example, the mean and standard deviation, median absolute deviation, empirical percentiles, and data trends. For example, the first method may calculate a first intermediate adaptive threshold based on the mean and standard deviation, the second method may calculate a second intermediate adaptive threshold based on the median absolute deviation, the third method may calculate a third intermediate adaptive threshold based on the empirical percentiles, and the fourth method may calculate a fourth intermediate adaptive threshold based on the data trend.
[0136] Exemplarily, based on the confidence levels of the first method, the second method, the third method, and the fourth method respectively, the weights corresponding to the first intermediate adaptive threshold, the second intermediate adaptive threshold, the third intermediate adaptive threshold, and the fourth intermediate adaptive threshold may be determined. Based on the first intermediate adaptive threshold, the second intermediate adaptive threshold, the third intermediate adaptive threshold, and the fourth intermediate adaptive threshold, and their respective corresponding weights, an adaptive threshold for detecting sensor data may be determined.
[0137] As an example, the calculation formula for the adaptive threshold may be as follows:
[0138]
[0139] Where, is the adaptive threshold, is the intermediate adaptive threshold corresponding to the i-th method, is the corresponding weight.
[0140] The weight may be set as follows:
[0141] In the initialization stage without sufficient historical data, initial weights may be assigned according to experience. Assuming there are four methods, the initial weights corresponding to the first method, the second method, the third method, and the fourth method may be 30%, 30%, 20%, and 20% respectively, and the initial weight vector may be determined.
[0142] After sufficient historical data has been accumulated, the weights may be dynamically adjusted according to the historical accuracy. Exemplarily, the detection results of each method may be recorded, including true positive (TP), true negative (TN), false positive (FP), and false negative (FN).
[0143] 1) Calculate the accuracy of each method
[0144]
[0145] Where, is the accuracy of the i-th method.
[0146] 2) Normalize and calculate weights
[0147]
[0148] Among them, is the normalized weight corresponding to the intermediate adaptive threshold calculated based on the i-th method.
[0149] In the actual anomaly detection stage, confidence dynamic weights can be used for fine-tuning. Each method will output an anomaly score and a confidence level. The calculation method of the confidence level is as follows:
[0150]
[0151] Among them, is the confidence level of the i-th method, is the anomaly score of the i-th method, is the maximum anomaly score among all current methods.
[0152] 3) Adjust weights in real time
[0153]
[0154] Among them, is the adjusted weight corresponding to the intermediate adaptive threshold calculated by the i-th method.
[0155] In practical applications, a certain method may generate more false positives. To reduce the impact of false positives, the idea of game theory can be used for weight optimization. For example, if the false positive rate continues to increase, game theory optimization can be used to readjust the weights. The specific optimization method can be as follows:
[0156] 1) Define the false positive cost, false positive cost (Cost_{FP}), and false negative cost (Cost_{FN}). Use the false positive cost to correct the weights:
[0157]
[0158] Among them, is the corrected weight corresponding to the intermediate adaptive threshold calculated based on the i-th method. represents the reciprocal of the false positive cost, which is used to reduce the weight of high-cost false positives.
[0159] 2) The final comprehensive weight consists of three parts, and the adaptive threshold for detecting sensor data is obtained therefrom.
[0160]
[0161] Among them: , , are coefficients, , for example, it can be set as = 0.5, = 0.4, = 0.1.
[0162] According to the embodiments of the present application, by comprehensively using multiple methods based on statistical information to calculate multiple intermediate adaptive thresholds respectively, and setting weights for the multiple intermediate adaptive thresholds according to the confidence levels of the multiple methods, the characteristics of the current historical sensor data sequence can be captured more comprehensively, the risk of inaccurate adaptive thresholds caused by a single method can be reduced, and thus it is beneficial to improve the accuracy of anomaly detection. By dynamically adjusting the weights according to the historical accuracy, more accurate methods can play a greater role, which is beneficial to further improving the accuracy of anomaly detection. When the misjudgment rate of a certain method is relatively high, by optimizing the weights based on game theory, the detection strategy can be further optimized to reduce false alarms and missed detections, which is beneficial to further improving the accuracy of anomaly detection.
[0163] According to the embodiments of the present application, the sensor data is detected according to the adaptive threshold and the target clustering center, and the obtained detection results include: the sensor data is first detected according to the adaptive threshold to obtain a first detection result; in the case where the first detection result indicates that the sensor data exceeds the adaptive threshold, the sensor data is second detected according to the clustering center to obtain a second detection result; in the case where the second detection result indicates that the distance between the sensor data and the target clustering center is greater than the preset distance threshold, it is determined that the detection result indicates an anomaly.
[0164] For example, the current moment can be, for example, t 11 moment, and the sensor data collected by the target sensor at t 11 moment is, for example, x 11 . It is possible to determine whether the sensor data x 11 exceeds the normal range according to the adaptive threshold to obtain a first detection result.
[0165] As an example, the adaptive threshold for detecting the sensor data x 11 can be . In the case of x 11< or x 11 > , it can be determined that the first detection result indicates that the sensor data exceeds the adaptive threshold.
[0166] As another example, the adaptive threshold for detecting the sensor data x 11 can be . In the case of x 11 > In this case, it can be determined that the first detection result indicates that the sensor data exceeds the adaptive threshold.
[0167] As another example, for detecting the sensor data x 11 the adaptive threshold can be . When x 11 > in this case, it can be determined that the first detection result indicates that the sensor data exceeds the adaptive threshold.
[0168] When the first detection result indicates that the sensor data exceeds the adaptive threshold, it is possible to determine whether the sensor data x 11 is an outlier based on the cluster center, obtaining a second detection result.
[0169] As an example, it is possible to calculate the distance d between the sensor data x 11 and the target cluster center closest to it. When d is greater than the preset distance threshold, it can be determined that the detection result indicates an anomaly.
[0170] According to the embodiments of the present application, obtaining the sensor data collected by the target sensor at the current moment includes: obtaining the sensor data stream from the target sensor, the sensor data stream including a plurality of initial sensor data arranged in chronological order of the collection time; performing a preprocessing operation on the plurality of initial sensor data to obtain a plurality of preprocessed sensor data; determining the sensor data based on the plurality of preprocessed sensor data according to the current moment; the sensor anomaly detection method further includes: after determining that there is an abnormal event, sending the sensor data and the detection result to the baseboard management controller, so that the baseboard management controller: in response to receiving the sensor data and the detection result, sending an alarm notification to the target object, the alarm notification being generated based on the sensor data and the detection result; and optimizing the algorithm parameter information for determining the adaptive threshold and the target cluster center based on the sensor data and the detection result, and sending the optimized algorithm parameter information; receiving the optimized algorithm parameter information from the baseboard management controller.
[0171] In view of the fact that the related anomaly detection methods mainly rely on the baseboard management controller to execute, there are technical problems such as easily causing excessive load pressure and high power consumption of the board management controller, affecting the normal operation and management function of the management controller. The anomaly detection method provided by the embodiments of the present application can be jointly executed by the micro control unit and the baseboard management controller, thereby reducing the degree of dependence on the baseboard management controller and reducing the load pressure and power consumption of the baseboard management controller. Exemplarily, the micro control unit can preferably be a low-power micro control unit, for example, it can be selected as the micro control unit of the STM32L433 series.
[0172] Exemplarily, the microcontroller unit can obtain the sensor data collected in real time by the target sensor based on a preset frequency through communication protocols such as I2C, PECI, SPI, etc., to obtain a sensor data stream. The sensor data stream includes a plurality of initial sensor data arranged in chronological order of the collection time.
[0173] The microcontroller unit can perform preprocessing operations such as denoising, moving average, and normalization on the plurality of initial sensor data to obtain a plurality of preprocessed sensor data. Among them, the plurality of preprocessed sensor data are arranged in chronological order of the collection time.
[0174] The microcontroller unit can determine the sensor data collected by the target sensor at the current moment and the current historical sensor data sequence corresponding to the current moment from the plurality of preprocessed sensor data based on the current moment and a preset sliding window.
[0175] The microcontroller unit can respectively determine an adaptive threshold and a target clustering center for detecting sensor data based on the current historical sensor data sequence according to the preset threshold algorithm and the preset clustering algorithm in the above text.
[0176] The microcontroller unit can detect the sensor data according to the adaptive threshold and the target clustering center to obtain a detection result. When the detection result meets the preset conditions, the microcontroller unit can determine that an abnormal event exists.
[0177] When it is determined that an abnormal event exists, the microcontroller unit can send the detection result and the corresponding sensor data to the baseboard management controller through a communication interface.
[0178] Exemplarily, the baseboard management controller can generate a system error event log (SEL) based on the sensor data and the detection result.
[0179] The baseboard management controller can generate an alarm notification based on the detection result and the corresponding sensor data, and send the alarm notification to the target object (such as an operation and maintenance personnel) by means of email or text message, etc., so that the operation and maintenance personnel can troubleshoot system anomalies in time.
[0180] The baseboard management controller can optimize the parameter information of the preset threshold algorithm and the preset clustering algorithm respectively based on the detection result and the corresponding sensor data, and send the optimized parameter information to the microcontroller unit. For example, the baseboard management controller can optimize the K value in the K-means clustering algorithm based on the detection result and the corresponding sensor data. For example, the baseboard management controller can optimize the calculation method of the adaptive threshold based on the detection result and the corresponding sensor data.
[0181] Exemplarily, the microcontroller unit can receive the optimized parameter information of the preset threshold algorithm and the preset clustering algorithm respectively, and update the preset threshold algorithm and the preset clustering algorithm based on this.
[0182] It can be understood that jointly executing the anomaly detection method by the microcontroller unit and the baseboard management controller can effectively reduce the degree of dependence on the baseboard management controller, and reduce the load pressure and power consumption of the baseboard management controller by reasonably allocating the tasks undertaken by the microcontroller unit and the baseboard management controller respectively. Furthermore, the baseboard management controller can be enabled to centrally process more complex tasks. In addition, by selecting a low-power microcontroller unit, the overall power consumption of the microcontroller unit and the baseboard management controller can be reduced, achieving an energy-saving effect, so as to be applicable to a server environment with strict power consumption requirements.
[0183] Figure 3 Schematically shows the anomaly detection flow chart according to an embodiment of the present application.
[0184] As Figure 3 shown, in operation S301, based on a preset frequency, sensor data collected in real time by a target sensor can be obtained through a hardware interface to obtain a sensor data stream of the target sensor. In operation S302, a preprocessing operation can be performed on multiple sensor data in the sensor data stream. The preprocessing operation can, for example, include denoising, moving average, normalization, etc. In operation S303, the sensor data collected by the target sensor at the current moment and the current historical sensor data sequence corresponding to the current moment can be determined from the sensor data stream. In operation S304, it can be determined whether the sensor data exceeds an adaptive threshold, where the adaptive threshold is determined based on the current historical sensor data sequence.
[0185] As Figure 3 shown, in the case where the sensor data does not exceed the adaptive threshold, it can be considered that the sensor data collected at the current moment is normal data, and the sensor data collected by the target sensor at the next moment can be obtained. In the case where the sensor data exceeds the adaptive threshold, operation S305 can be executed.
[0186] As Figure 3 shown, in operation S305, it can be determined whether the distance between the sensor data and the nearest target clustering center is greater than a preset distance threshold. The target clustering center is determined based on the current historical sensor data sequence.
[0187] As Figure 3As shown, when the distance d is less than or equal to a preset distance threshold, it can be considered that the sensor data collected at the current moment is normal data, and the sensor data collected by the target sensor at the next moment can be obtained. When the distance d is greater than the preset distance threshold, operation S306 can be executed. In operation S306, it can be determined that the detection result indicates the existence of an abnormal event.
[0188] Optionally, as Figure 3 shown, for the sensor data collected at the current moment, steps S304 - S305 can be repeatedly executed multiple times. For example, the detection result can be obtained by repeating the execution 3 times to improve the accuracy and reliability of anomaly detection.
[0189] As Figure 3 shown, in operation S307, when it is determined that there is an abnormal event, an alarm notification can be sent. The alarm notification can be generated based on the detection result and the corresponding sensor data.
[0190] As Figure 3 shown, in operation S308, according to the abnormal sensor data indicated by the alarm notification, the preset threshold algorithm and the preset clustering algorithm can be dynamically adjusted and optimized. For example, the parameters of the preset clustering algorithm, the calculation method of the adaptive threshold, etc. can be optimized.
[0191] According to the embodiments of the present application, by adopting a method that combines an adaptive threshold with a target clustering center to perform anomaly detection on sensor data, the accuracy of anomaly detection can be effectively improved, and the risks of missed reports and false reports can be reduced.
[0192] According to the embodiments of the present application, the sensor data includes the Nth sensor data collected at the Nth moment; when the detection result meets the preset conditions, determining the existence of an abnormal event includes: when the detection results obtained for the Nth sensor data to the (N + n)th sensor data collected at the (N + n)th moment all indicate anomalies, it is determined that there is an abnormal event, where N is a positive integer and n is greater than or equal to 2.
[0193] The sensor data collected by the target sensor in real time can be obtained based on a preset frequency to obtain the sensor data stream of the target sensor. Anomaly detection can be sequentially performed on multiple data points in the sensor data stream from the earliest to the latest based on the chronological order of the collection times.
[0194] Only as an example, if the 11th sensor data x collected at time t 11 、the 12th sensor data x collected at time t 11 、and the 13th sensor data x collected at time t 12 、 12 as well as the 13th sensor data x collected at time t 13 、 13If the detection results obtained respectively all indicate abnormalities, it can be determined that there is an abnormal event. The abnormal event may include, for example, an abnormality in the sensor and / or an abnormality in the server.
[0195] Figure 4 Schematically shows a schematic diagram for determining the existence of an abnormal event according to an embodiment of the present application.
[0196] As Figure 4 shown, in the case where the detection results obtained from the Nth sensor data collected at the Nth moment to the (N + n)th sensor data collected at the (N + n)th moment all indicate abnormalities, it can be determined that there is an abnormal event. Wherein, N is a positive integer, and n is greater than or equal to 2.
[0197] According to an embodiment of the present application, in the case where the detection results of consecutive multiple sensor data all indicate abnormalities, it is determined that there is an abnormal event, thereby reducing the influence of accidental errors or data fluctuations, improving the robustness of the anomaly detection mechanism, and further improving the reliability and accuracy of anomaly detection.
[0198] Figure 5 Schematically shows a structural block diagram of a sensor anomaly detection device according to an embodiment of the present application.
[0199] As Figure 5 shown, the device 500 includes an acquisition module 510, a detection module 520, and a determination module 530.
[0200] The acquisition module 510 is configured to acquire sensor data collected by a target sensor at the current moment.
[0201] The detection module 520 is configured to detect the sensor data according to an adaptive threshold and a target clustering center, and obtain a detection result. Wherein, the adaptive threshold and the target clustering center are determined based on the current historical sensor data sequence, the current historical sensor data sequence corresponds to the current moment, and the current historical sensor data sequence includes a predetermined number of previous sensor data arranged in chronological order.
[0202] The determination module 530 determines that there is an abnormal event when the detection result meets a preset condition.
[0203] According to an embodiment of the present application, the anomaly detection device may further include a clustering center determination module and an adaptive threshold determination module.
[0204] The clustering center determination module is configured to determine a target clustering center for detecting sensor data according to a preset clustering algorithm and the current historical sensor data sequence.
[0205] An adaptive threshold determination module, configured to determine an adaptive threshold for detecting sensor data according to a preset threshold algorithm and a current historical sensor data sequence.
[0206] According to an embodiment of the present application, the adaptive threshold determination module may include an adaptive threshold determination sub-module.
[0207] The adaptive threshold determination sub-module is configured to determine an adaptive threshold based on statistical information of the current historical sensor data sequence, where the statistical information includes at least one of the following: average value, standard deviation, median absolute deviation, empirical percentile, and data change trend.
[0208] According to an embodiment of the present application, the adaptive threshold determination sub-module may include an adaptive threshold determination unit.
[0209] The adaptive threshold determination unit is configured to determine an adaptive threshold based on the statistical information and the weight corresponding to the statistical information, and the weight is determined according to the confidence level of the statistical information.
[0210] According to an embodiment of the present application, the detection module may include a first detection sub-module, a second detection sub-module, and a first determination sub-module.
[0211] The first detection sub-module is configured to perform a first detection on the sensor data according to the adaptive threshold to obtain a first detection result.
[0212] The second detection sub-module is configured to perform a second detection on the sensor data according to the target clustering center when the first detection result indicates that the sensor data exceeds the adaptive threshold, to obtain a second detection result.
[0213] The first determination sub-module is configured to determine that the detection result indicates an abnormality when the second detection result indicates that the distance between the sensor data and the target clustering center is greater than a preset distance threshold.
[0214] According to an embodiment of the present application, the sensor data includes the Nth sensor data collected at the Nth moment; the determination module may include a second determination sub-module.
[0215] The second determination sub-module is configured to determine that an abnormal event exists when the detection results obtained for the Nth sensor data to the (N + n)th sensor data collected at the (N + n)th moment all indicate abnormalities, where N is a positive integer and n is greater than or equal to 2.
[0216] According to an embodiment of the present application, the abnormal detection device may further include an update module.
[0217] An update module, configured to add sensor data to the current historical sensor data sequence, and delete the earliest acquired previous sensor data in the current historical sensor data sequence, so as to obtain a subsequent historical sensor data sequence corresponding to a subsequent time.
[0218] According to an embodiment of the present application, the anomaly detection device may further include an alarm module.
[0219] The alarm module is configured to send an alarm notification when it is determined that there is an abnormal event, and the alarm notification is generated based on the sensor data and the detection result.
[0220] According to an embodiment of the present application, any one or more of the acquisition module 510, the detection module 520, and the determination module 530 may be combined and implemented in one module, or any one of them may be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present application, at least one of the acquisition module 510, the detection module 520, and the determination module 530 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on substrate, a system on package, an application specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in any suitable combination of several of them. Alternatively, at least one of the acquisition module 510, the detection module 520, and the determination module 530 may be at least partially implemented as a computer program module, and when the computer program module is run, it can execute corresponding functions.
[0221] Figure 6 A block diagram of an electronic device suitable for implementing the sensor anomaly detection method according to an embodiment of the present application is schematically shown.
[0222] As Figure 6 shown, the electronic device 600 according to an embodiment of the present application includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603. The processor 601 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 601 may also include on-board memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present application.
[0223] In the RAM 603, various programs and data required for the operation of the electronic device 600 are stored. The processor 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. The processor 601 performs various operations of the method flow according to the embodiments of the present application by executing the programs in the ROM 602 and / or the RAM 603. It should be noted that the programs may also be stored in one or more memories other than the ROM 602 and the RAM 603. The processor 601 may also perform various operations of the method flow according to the embodiments of the present application by executing the programs stored in the one or more memories.
[0224] As Figure 6 shown, the electronic device 600 may further include an input / output (I / O) interface 605, and the input / output (I / O) interface 605 is also connected to the bus 604. The electronic device 600 may further include one or more of the following components connected to the input / output (I / O) interface 605: an input portion 606 including a keyboard, a mouse, etc.; an output portion 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 608 including a hard disk, etc.; and a communication portion 609 including a network interface card such as a LAN card, a modem, etc. The communication portion 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that a computer program read from it can be installed into the storage portion 608 as needed.
[0225] The present application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist alone without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the sensor anomaly detection method according to the embodiments of the present application is implemented.
[0226] A computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present application, a computer-readable storage medium may include the ROM 602 and / or RAM 603 described above and / or one or more memories other than the ROM 602 and RAM 603.
[0227] An embodiment of the present application further includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs in a computer system, the program code is used to enable the computer system to implement the sensor anomaly detection method provided by the embodiment of the present application.
[0228] When the computer program is executed by the processor 601, it executes the above functions defined in the system / apparatus of the embodiment of the present application. According to an embodiment of the present application, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0229] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program may also be transmitted and distributed in the form of a signal on a network medium and be downloaded and installed through the communication part 609, and / or be installed from the removable medium 611. The program code included in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0230] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or be installed from the removable medium 611. When the computer program is executed by the processor 601, it executes the above functions defined in the system of the embodiment of the present application. According to an embodiment of the present application, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0231] The program code for executing the computer program provided by the embodiments of the present application can be written in any combination of one or more programming languages. For example, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, such as Java, C++, Python, the "C" language, or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by connecting through the Internet using an Internet service provider).
[0232] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0233] Those skilled in the art can understand that the features described in the various embodiments of the present application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present application. In particular, without departing from the spirit and teachings of the present application, the features described in the various embodiments of the present application can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present application.
[0234] The above describes the embodiments of the present application. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present application. Although the embodiments are described separately above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of the present application, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present application.
Claims
1. An anomaly detection method, characterized in that, The method includes: Obtaining sensor data collected by a target sensor at the current moment; Detecting the sensor data according to an adaptive threshold and a target clustering center to obtain a detection result, where the adaptive threshold and the target clustering center are determined based on a current historical sensor data sequence corresponding to the current moment, and the current historical sensor data sequence includes a predetermined number of previous sensor data arranged in chronological order; Determining that an abnormal event exists when the detection result meets a preset condition.
2. The method according to claim 1, characterized in that, It further includes: Determining a target clustering center for detecting the sensor data according to a preset clustering algorithm and the current historical sensor data sequence; Determining an adaptive threshold for detecting the sensor data according to a preset threshold algorithm and the current historical sensor data sequence.
3. The method according to claim 2, wherein The determining an adaptive threshold for detecting the sensor data according to a preset threshold algorithm and the current historical sensor data sequence includes: Determining the adaptive threshold based on statistical information of the current historical sensor data sequence, where the statistical information includes at least one of the following: mean, standard deviation, median absolute deviation, empirical percentile, and data change trend.
4. The method according to claim 3, characterized in that, The determining the adaptive threshold based on the statistical information of the current historical sensor data sequence includes: Determining the adaptive threshold based on the statistical information and the weight corresponding to the statistical information, where the weight is determined according to the confidence level of the statistical information.
5. The method according to claim 1, characterized in that, The detecting the sensor data according to an adaptive threshold and a target clustering center to obtain a detection result includes: Performing a first detection on the sensor data according to the adaptive threshold to obtain a first detection result; When the first detection result indicates that the sensor data exceeds the adaptive threshold, performing a second detection on the sensor data according to the target clustering center to obtain a second detection result; Determining that the detection result indicates an abnormality when the second detection result indicates that the distance between the sensor data and the target clustering center is greater than a preset distance threshold.
6. The method according to claim 1, wherein The sensor data includes the Nth sensor data collected at the Nth moment; The determining that an abnormal event exists when the detection result meets a preset condition includes: Determining that an abnormal event exists when the detection results obtained for the Nth sensor data to the (N + n)th sensor data collected at the (N + n)th moment all indicate abnormalities, where N is a positive integer and n is greater than or equal to 2.
7. The method according to any one of claims 1-6, characterized in that, It further includes: Adding the sensor data to the current historical sensor data sequence and deleting the earliest collected previous sensor data in the current historical sensor data sequence to obtain a subsequent historical sensor data sequence corresponding to a subsequent moment.
8. The method according to any one of claims 1 - 6, wherein The obtaining sensor data collected by a target sensor at the current moment includes: Obtaining a sensor data stream from the target sensor, where the sensor data stream includes a plurality of initial sensor data arranged in chronological order of the collection moment; Perform preprocessing operations on the multiple initial sensor data to obtain multiple preprocessed sensor data; Based on the current time, determine the sensor data based on the multiple preprocessed sensor data; The method further includes: After determining that an abnormal event exists, send the sensor data and the detection result to the baseboard management controller, so that the baseboard management controller: in response to receiving the sensor data and the detection result, send an alarm notification to the target object, the alarm notification being generated based on the sensor data and the detection result; and based on the sensor data and the detection result, optimize the algorithm parameter information for determining the adaptive threshold and the target cluster center, and send the optimized algorithm parameter information; Receive the optimized algorithm parameter information from the baseboard management controller.
9. An anomaly detection device, characterized in that, The device includes: An acquisition module, configured to acquire sensor data collected by a target sensor at the current time; A detection module, configured to detect the sensor data according to an adaptive threshold and a target cluster center to obtain a detection result, where the adaptive threshold and the target cluster center are determined based on a current historical sensor data sequence corresponding to the current time, and the current historical sensor data sequence includes a predetermined number of previous sensor data arranged in chronological order; A determination module, configured to determine that an abnormal event exists when the detection result meets a preset condition.
10. An electronic device, including: One or more processors; A memory, configured to store one or more computer programs, Characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.
Citation Information
Cited By
File co-processing method and system based on cloud computing
CN120561626A
Motion event classification method and device, equipment and medium
CN120899236A