Multi-disaster-type disaster internet-of-things time sequence adaptive anomaly detection method and system

By constructing an adaptive anomaly detection method for IoT time series in multiple disasters, using technologies such as multi-scale time convolution networks, adaptive spectrum feature modules and radial basis function layers, the problem of false alarms and missed responses in multiple disaster detection in harsh environments in the wild is solved, and the detection accuracy and robustness are improved, ensuring the timeliness and effectiveness of emergency responses.

CN120277447AActive Publication Date: 2025-07-08XIHUA UNIV

Patent Information

Application Number
CN202510759886.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-07-08
Estimated Expiration
2045-06-09

Smart Images

  • Figure CN120277447A_ABST
    Figure CN120277447A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-disaster-type disaster internet-of-things time sequence adaptive anomaly detection method and system, and relates to the field of internet of things, and the method comprises the steps: S1, constructing an anomaly detection model; s2, acquiring a training data set; s3, training an anomaly detection model; s4, acquiring to-be-detected data; s5, analyzing the reconstruction structure of the to-be-detected data; s6, analyzing an abnormal score; the emergency disaster early warning system comprises an acquisition unit, a storage unit, a calculation unit and an early warning unit. A multi-scale time convolutional network and a self-adaptive spectrum feature module are fused, the characteristics of time sequence data in a time domain and a frequency domain are deeply mined, a gating memory mechanism is introduced, normal time-frequency features in the data can be accurately captured and enhanced, and the recognition capability is improved; by adding the radial basis function layer, the detection capability of the model on tiny anomalies is remarkably improved, so that the model can detect tiny abnormal changes more accurately.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of the Internet of Things, and in particular to a multi-disaster Internet of Things time series adaptive anomaly detection method and system. Background Art

[0002] The Internet of Things sensor technology has become an important technical support for the modern disaster warning system. In disaster-prone areas, we have deployed a large-scale multi-functional intelligent sensor network. These networks are equipped with various types of sensors at each monitoring point and can collect monitoring information on multiple disasters such as debris flows, forest fires, flash floods, and earthquakes in real time and continuously. Due to the frequent occurrence of concurrent disasters, our monitoring points are widely distributed, covering multiple potential disaster points. The data collected by these sensor networks is transmitted to the data center and aggregated into complex multi-source time series data. However, simply collecting data is not enough to cope with the complexity and uncertainty of disasters. The key lies in how to efficiently and accurately analyze this data and identify potential disaster anomaly signals from it.

[0003] In the Internet of Things environment, most data presents in the form of time series, and the dependency relationship of data over time has become a key feature for identifying anomalies, having a profound impact on the prediction and analysis of data. Therefore, in the Internet of Things scenario, the core problem of anomaly detection often boils down to time series anomaly detection, that is, identifying anomaly points or anomaly patterns that deviate significantly from the normal pattern from time series data.

[0004] Most traditional anomaly detection methods rely on empirical judgment and static threshold setting, which not only limits the detection accuracy but also may lead to false positives and false negatives, affecting the timeliness and effectiveness of emergency response. Therefore, it is increasingly difficult for traditional technologies to meet modern requirements. As a key component in the field of machine learning, deep learning has received great attention in many industries in recent years, especially in time series analysis and anomaly detection, where it has been widely applied. For example, by using deep learning methods to extract features from time series data, the accuracy of time series prediction and anomaly detection can be effectively improved. Models commonly used in deep learning for time series anomaly detection include models based on recurrent neural network (RNN), convolutional neural network (CNN), graph neural network (GNN), etc. The gated recurrent unit (GRU) is a special type of RNN. In the prior art, an unsupervised method combining GRU and attention mechanism is proposed for anomaly detection in multivariate time series, where GRU captures the deep information of the time series, and the attention mechanism dynamically adjusts the feature weights to jointly improve the accuracy and efficiency of anomaly detection; the EdgeConvFormer model integrates Time2vec embedding, dynamic graph CNN, and Transformer to extract the global and local spatio-temporal information of the time series and improve the anomaly detection accuracy of complex time series. The graph convolutional network (GCN) is a variant of GNN. An unsupervised method MTGFlow combining GCN uses GCN to capture variable relationships and captures complex interdependencies and the sparse characteristics of different entities through dynamic graph structure learning and entity-aware normalization processes.

[0005] Patent CN202411396506.9, "A Hydrological Time Series Anomaly Detection Method Based on Spatiotemporal Features", combines the Time Domain Convolutional Network (TCN) and the Graph Convolutional Neural Network (GCN), effectively solving the problems of difficult detection of multi-site hydrological time series data and difficult learning of spatiotemporal features. Patent CN202410538278.8, "Time Series Anomaly Detection Method and System Based on Time-Frequency Mask Autoencoder", enables the deep autoencoder to avoid being misled by abnormal data by removing potential abnormal time patterns and time points, thus more accurately detecting anomalies in time series. Patent CN202410421523.7, "A Multivariate Time Series Anomaly Detection Method Based on Time-Frequency Two-Stream Graph Interaction", constructs a relationship matrix using the graph attention mechanism and extracts features through spectral graph convolution, ultimately achieving more accurate anomaly detection. Patent CN202410041936.2, "An Unsupervised Time Series Anomaly Detection Method Based on Multidimensional Feature Fusion", realizes more accurate anomaly detection through a multi-dimensional feature extraction network and a fusion strategy, combined with self-supervised training. Patent CN202310823653.9, "A Sensor Data Anomaly Detection Method Based on Adaptive Graph Attention Network", proposes a method based on GAT and GRU for anomaly detection of sensor data. Patent CN202311440486.6, "An Electric Energy Meter Anomaly Detection Method Based on Dual Memory Enhanced Autoencoder", constructs an anomaly detection model using the dual memory enhanced autoencoder.

[0006] However, the IoT time series data in the harsh natural environment in the wild where disasters are prone to occur are characterized by complexity and high dimensionality. Consider how to further improve the accuracy of model anomaly detection; sensor data is vulnerable to interference such as temperature fluctuations, extreme weather, and unstable power supply. How to effectively improve the detection performance of the model under noise interference; in view of the characteristics of the natural disaster emergency system such as dynamics and multi-anomaly concurrency, how to continuously optimize the anomaly detection system through technologies such as statistical analysis and feature learning to enhance its robustness and accuracy, ensuring that the research and practical applications can be closely combined, thereby effectively guaranteeing the high availability of natural disaster emergency services. All of these have certain difficulties. Summary of the Invention

[0007] The object of the present invention is to design a multi-disaster IoT time series adaptive anomaly detection method and system to solve the above problems.

[0008] The present invention realizes the above object through the following technical solutions:

[0009] The multi-disaster IoT time series adaptive anomaly detection method includes:

[0010] S1. Construct an initial anomaly detection model. The anomaly detection model includes an encoding embedding layer, a multi-scale temporal convolutional network, an adaptive spectral feature module, a fusion layer, a gated control memory mechanism, a radial basis function layer RBF, and a decoder. The output of the encoding embedding layer is used as the input of both the multi-scale temporal convolutional network and the adaptive spectral feature module. The outputs of the multi-scale temporal convolutional network and the adaptive spectral feature module are both used as the input of the fusion layer. The output of the fusion layer is used as the input of the gated control memory mechanism. The output of the gated control memory mechanism is used as the input of the radial basis function layer RBF. The outputs of the gated control memory mechanism and the radial basis function layer RBF are both used as the input of the decoder. The encoding embedding layer is used to perform positional encoding and embedding on the input data. The multi-scale temporal convolutional network is used to capture temporal features of different scales in the time series. The adaptive spectral feature module is used to perform high-frequency denoising from the frequency domain perspective and extract periodic frequency domain features of the time series. The fusion layer is used to perform weighted fusion on the temporal features and frequency domain features to obtain time-frequency features, which are used as the query vector q i ; The gated control memory mechanism is used to strengthen the extracted time-frequency features. The radial basis function layer RBF is used to extract similarity features. The decoder is used to process and transform the features to obtain a reconstructed sequence. The original time series S is defined as a set of a series of subsequences , where N represents the total number of subsequences, and the subsequence is a sequence of observation vectors, and the sequence of observation vectors is expressed as ; The vector corresponding to the nth dimension in the sequence X i obtained after encoding S by the encoding embedding layer i , where , , , L, d, and represent the subsequence length, the original data dimension, and the observation vector at time t respectively, t ∈ L , and

[0011] S2. Obtain a training data set;

[0012] S3. Import the training data set into the initial anomaly detection model and perform training optimization to obtain an optimized anomaly detection model;

[0013] S4. Obtain the data to be detected;

[0014] S5. Use the optimized anomaly detection model to analyze the data to be detected to obtain the reconstruction result of the data to be detected;

[0015] S6. Analyze the anomaly score of the data to be detected according to the reconstruction result.

[0016] The multi-disaster disaster Internet of Things time series adaptive anomaly detection system includes:

[0017] A memory; a computer program is stored in the memory;

[0018] An actuator; when the actuator executes the computer program stored in the memory, it implements the multi-disaster IoT time series adaptive anomaly detection method as described above.

[0019] An emergency disaster warning system, comprising:

[0020] Multiple acquisition units; the acquisition units are used to acquire monitoring data of each area in real time;

[0021] A storage unit; a computer program is stored in the storage unit;

[0022] A calculation unit; the calculation unit is communicatively connected to each acquisition unit and the storage unit; when the calculation unit executes the computer program stored in the storage unit to analyze the monitoring data, it implements the above-mentioned multi-disaster IoT time series adaptive anomaly detection method to obtain an anomaly score;

[0023] A warning unit; the warning unit is communicatively connected to the calculation unit, and the warning unit calculates the anomaly event level according to the anomaly score output by the calculation unit, generates and sends a warning message.

[0024] The beneficial effects of the present invention are as follows: (1) It solves the challenge of anomaly detection for emergency disaster multivariate time series data. (2) It uses a multi-scale time convolutional network module to capture complex long-term and short-term dependencies in time series data, overcoming the conflicts caused by long-term and short-term dependencies in the data. (3) It uses an adaptive spectrum feature module to perform high-frequency denoising from the frequency domain perspective to reduce the impact of high-frequency noise on the model performance and extract potential periodic features existing in the time series through global recurrent convolution. (4) It introduces a gated memory mechanism to capture the prototype features of the normal mode in the data to strengthen the extracted time-frequency features, thereby improving the generalization ability of the model. (5) It introduces a layer of radial basis function layer RBF, combines the similarity score obtained from this layer with the reconstruction error, solves the problem that most unsupervised models are difficult to detect subtle anomalies in complex datasets, and improves the model's ability to detect subtle anomalies. Description of the Drawings

[0025] Figure 1 It is the overall architecture diagram of the multi-disaster IoT time series adaptive anomaly detection method of the present invention; Figure 2 It is the structural schematic diagram of the multi-scale time convolutional network of the present invention; Figure 3 It is the structural schematic diagram of the adaptive spectrum feature module of the present invention; Figure 4 It is the model training flow chart of the multi-disaster IoT time series adaptive anomaly detection method of the present invention; Figure 5 This is the system architecture diagram of the present invention applied to the multi-disaster emergency large-scale disaster warning system; Figure 6 This is the system flow chart of the present invention applied to the multi-disaster multi-disaster point large-scale disaster monitoring and warning system. Detailed implementation manners

[0026] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. Generally, the components of the embodiments of the present invention described and illustrated herein can be arranged and designed in various different configurations.

[0027] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0028] It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it does not require further definition and explanation in subsequent drawings.

[0029] In the description of the present invention, it should be understood that, in addition, terms such as "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.

[0030] In the description of the present invention, it should also be noted that unless otherwise clearly defined and limited, terms such as "set", "connected", etc. should be understood in a broad sense. For example, "connected" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the internal communication of two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0031] The following will describe the detailed implementation manners of the present invention with reference to the accompanying drawings.

[0032] Figure 1 The blue line in the bottommost box is the analyzed anomaly score, and the red line is the set threshold.

[0033] The multi-disaster disaster Internet of Things time series adaptive anomaly detection method includes:

[0034] S1. Construct an initial anomaly detection model, such as Figure 1 shown. The anomaly detection model includes an encoding embedding layer, a multi-scale temporal convolutional network, an adaptive spectral feature module, a fusion layer, a gated memory mechanism, a radial basis function layer RBF, and a decoder. The output of the encoding embedding layer is used as the input of the multi-scale temporal convolutional network and the adaptive spectral feature module respectively. The outputs of the multi-scale temporal convolutional network and the adaptive spectral feature module are both used as the input of the fusion layer. The output of the fusion layer is used as the input of the gated memory mechanism. The output of the gated memory mechanism is used as the input of the radial basis function layer RBF. The output of the gated memory mechanism and the output of the radial basis function layer RBF are both used as the input of the decoder. The encoding embedding layer is used to perform positional encoding and embedding on the input data. The multi-scale temporal convolutional network is used to capture temporal features of different scales in the time series. The adaptive spectral feature module is used to perform high-frequency denoising from the frequency domain perspective and extract periodic frequency domain features of the time series. The fusion layer is used to perform weighted fusion on the temporal features and frequency domain features to obtain time-frequency features, which are used as the query vector q i ; The gated memory mechanism is used to strengthen the extracted time-frequency features. The radial basis function layer RBF is used to extract similarity features. The decoder is used to process and transform the features to obtain the reconstructed sequence. The original time series S is defined as a set of a series of subsequences , where N represents the total number of subsequences, and the subsequence is a sequence of observation vectors, and the sequence of observation vectors is expressed as ; The vector corresponding to the nth dimension of the sequence X i obtained after encoding S by the encoding embedding layer i , where , , , L, d, and represent the subsequence length, the original data dimension, and the observation vector at time t respectively, t ∈ L , and

[0035] such as Figure 2 shown, the multi-scale temporal convolutional network includes K convolutional kernels of different sizes and an average pooling layer. The output of the encoding embedding layer is used as the input of the K convolutional kernels respectively. The outputs of the K convolutional kernels are both used as the input of the average pooling layer. One-dimensional convolutional kernels of different sizes are used to act on each dimension of the encoded sequence to extract its features. These convolutions can be dilated without increasing the kernel size to increase their receptive fields. For the vector corresponding to the nth dimension of the sequence X i obtained after encoding , the convolutional kernel extracts features from the vector and is expressed as: , where Denote the output at time using the k-th convolutional kernel, , is the weight of the k-th convolutional kernel at position j, and w k is the size of the k-th convolutional kernel; average pooling combines the features extracted by each convolutional kernel into a unified output, denoted as , is responsible for aggregating the outputs of different convolutional scales into a unified vector, and the output of the multi-scale convolutional network is , which is composed of the results of convolution on each dimension in X i . In this embodiment, convolutional kernels with sizes of 3, 5, and 7 are adopted to flexibly cover diverse time-scale requirements. Finally, the output of the multi-scale temporal convolutional network is which is composed of the results of convolution on each dimension in X i , effectively capturing temporal features at different scales and better extracting their long-term and short-term dependencies. Among them, represents the set of all real number matrices of size .

[0036] As shown in Figure 3 , the adaptive spectral feature module performs high-frequency denoising and extracts the periodic features of the time series from the frequency domain perspective, specifically including:

[0037] ① For the embedded sequence X i , the frequency-domain data F i is obtained by using the fast Fourier transform along the spatial dimension, denoted as: , where F[∙] represents the one-dimensional FFT operation, represents the length of the frequency-domain sequence after transformation, represents the set of complex numbers. Due to the implementation method of FFT and the characteristics of time series data, L and may be different. The transformation is performed separately on each time series channel of X i to obtain the frequency-domain representation F i that combines the information of all channels, which encapsulates the spectral characteristics of the original time series;

[0038] ② Analyze the power spectrum P i from the frequency-domain data F i to identify the main frequency components, denoted as: , and perform adaptive filtering according to a preset threshold to obtain the frequency-domain data after adaptive filtering. This application uses a trainable threshold to achieve this, and this threshold will be dynamically adjusted according to the spectral characteristics of the data. Therefore, the adaptive threshold is set to: , where represents pointwise multiplication in the frequency domain, is a binary mask, where frequencies with power higher than the threshold are retained and other frequencies are filtered out; by adaptively setting the frequency threshold, not only the key information in the sequence is retained, but also high-frequency noise is effectively removed. This adaptive frequency selection enables the filtering of ASFM to adapt to the characteristics of each time series dataset, thereby improving the overall performance of the model when dealing with a wide range of data environments;

[0039] ③ Use two sets of learnable filters to learn features from the frequency domain data F i and the frequency domain data respectively, to obtain the features and the feature , expressed as: , , W G and W L represent the global and local filters respectively; represents pointwise multiplication in the frequency domain, which is equivalent to the circular convolution operation in the time domain;

[0040] ④ Fuse the features and the feature to obtain the comprehensive spectral feature , expressed as: , and circular convolution is used to capture the periodic features in the time series data because it can cover a wide perception range of the entire sequence.

[0041] ⑤ Use the inverse fast Fourier transform to convert the fused spectral feature back to the time domain to obtain the frequency domain feature of the original sequence, expressed as ;

[0042] The Adaptive Spectral Feature Module (ASFM) based on Fourier transform processing reduces the impact of high-frequency noise on the model performance and extracts the periodic features of the time series through global circular convolution.

[0043] To integrate the information in the time domain and the frequency domain, the fusion layer fuses the time domain feature and the frequency domain feature by weighted fusion to obtain the time-frequency feature of the multivariate time series, that is, the query vector , is a single query vector at time t. This fusion strategy enables us to utilize both the time domain feature and the frequency domain feature simultaneously, thereby improving the model's ability to understand time series data. Weight is set to 10 -2 , and the fusion process is expressed as: .

[0044] The gated control memory mechanism includes a memory module, a retrieval module, and a splicing layer. The memory module consists of M memory items . Each memory item is trained to capture the normal patterns in the original time series. The retrieval module is used to retrieve the memory items of the normal model stored in the memory module according to the query vector q i . The splicing layer concatenates the query vector with the memory item in the feature dimension to generate a new query vector , , where is the dimension of each memory item;

[0045] Define the memory attention score according to the query vector to incrementally update the memory cell, which is expressed as: ;

[0046] τ is the temperature parameter of the SoftMax function, and its value is set to 10 -1 , calculates the probability distribution, represents the exponential function. To make the training of the memory module more flexible, the memory module uses an update gate to control the range of new normal patterns that the memory module should obtain from the query, which is expressed as:

[0047] ;

[0048] ;

[0049] where and represent linear projections, and represent sigmoid activation and element-wise multiplication respectively.

[0050] The update of the memory item is only executed during the training phase. Once the training process is completed, the memory item will no longer be updated;

[0051] The retrieval module generates an updated query by retrieving the features of the normal model stored in the memory module , and then uses it as the input of the subsequent module. The retrieval process first defines the conditional query attention score on each memory item, which is calculated by applying softmax to the dot product between each query and memory item: ;

[0052] Then, use to perform a weighted sum on the memory item m c to obtain the retrieved memory item , expressed as: ;

[0053] Concatenate the query vector with the retrieved memory item in the feature dimension to generate a new query vector . This new query vector not only contains the information of the original query but also incorporates the normal pattern information of the original time series retrieved from the memory items, thereby weakening the abnormal characteristics and making the reconstruction result of the abnormal data closer to the normal samples. Although this characteristic increases the difficulty of reconstructing anomalies, it also prompts the model to learn more refined feature representations during the training process. Such feature representations enable the model to more effectively distinguish normal and abnormal data, thereby improving the generalization performance of the model.

[0054] The radial basis function layer RBF solves the problem of unsupervised models in complex datasets for detecting subtle anomalies. The radial basis function layer RBF can calculate the similarity scores between data points and a set of learnable centers, and this score is particularly effective for anomaly detection tasks. Since the anomaly points usually deviate from the normal pattern, their similarity scores with the learnable centers tend to be low, which directly reflects the degree of anomaly of the data points. This similarity score is a useful supplement to the reconstruction error, especially when detecting subtle anomalies that may be overlooked by the reconstruction error, and its detection ability is more prominent. Apply the radial basis function layer RBF to the updated query , by calculating the similarity of each query vector to a set of learnable centers Z, where , , represents a real vector of dimension H, represents a set of H center vectors, and H is the total number of center points in the radial basis function layer RBF, which is randomly initialized at the beginning of training and updated during training. The output of the radial basis function layer RBF , where the similarity is expressed as: ; where the parameter γ is responsible for regulating the function width, which determines how the distance between the query vector and the learnable center is converted into different weights. At the initial stage of model training, the parameter γ is randomly initialized and adjusted and optimized as the training progresses. Utilizing the exponential property of γ can ensure that the scale parameter is always positive.

[0055] Finally, the output R of the radial basis function layer RBFi As the input to the decoder consisting of two fully connected layers, the reconstruction result finally obtained by the model is denoted as . Through this process, the model can make full use of the similarity features extracted by the radial basis function layer RBF, as well as the further processing and transformation of the features by the decoder, so as to achieve the accurate reconstruction of the input data.

[0056] S2. Obtain the training data set;

[0057] S3. Import the training data set into the initial anomaly detection model and train and optimize it to obtain the optimized anomaly detection model; as Figure 4 shown, the training process specifically includes:

[0058] (1) The encoding embedding layer performs positional encoding and embedding on the training data, and then inputs it into the multi-scale temporal convolutional network and the adaptive spectral feature module to respectively capture the temporal domain features and the frequency domain features.

[0059] (2) The fusion layer performs weighted fusion on the temporal domain features and the frequency domain features to obtain the time-frequency features, which are used as the query vector q i ;

[0060] (3) Use the gated memory mechanism to retrieve the memory items related to the query vector , and splice the two to obtain a new query vector ;

[0061] (4) The radial basis function layer RBF analyzes the similarity R of the query vector i to a set of learnable centers;

[0062] (5) The output R i of the radial basis function layer RBF and the query vector are used as the input to the decoder to obtain the reconstruction sequence ;

[0063] (6) During the training process, optimize the model by reducing the reconstruction loss. The reconstruction loss is expressed as: , the dense W i matrix will cause the model to pay attention to all memory items indiscriminately, even if some memory items are not relevant to the current input data. This will cause outliers to have a high association with multiple memory items, making it difficult for the model to distinguish between normal patterns and abnormal patterns. W i is 's matrix representation, where and , to solve the above problems, the entropy loss is introduced as an auxiliary loss function for Wi Perform sparse regularization on the matrix and entropy loss It is expressed as: ;

[0064] (7) Analyze the final loss value according to the reconstruction loss and entropy loss It is expressed as: , where β is the weighting coefficient, and the value in this embodiment is 10 ; -2 ;

[0065] (8) Input the parameters of the anomaly detection model into the Adam optimizer to obtain the gradients of the model parameters, and then update the parameters of the entire anomaly detection model through backpropagation;

[0066] (9) Determine whether the number of training times is less than the preset number. If so, end the training, and the current anomaly detection model is used as the optimized anomaly detection model.

[0067] The training of the anomaly detection model of the present invention adopts two-stage training. The main purpose of the first-stage training is to use K-means clustering to initialize each memory item and set it as an approximate normal prototype pattern of the original sequence data. Specifically, it is trained through a self-supervised task of reconstructing the input. The trained time-frequency feature extraction module generates a query q for 10% of the randomly sampled training data i . Then, apply the K-means clustering algorithm to cluster q i and specify each centroid as the initial value of the memory item. In the second stage, the entire model is mainly trained on the anomaly detection task using these initialized memory items.

[0068] The performance comparison of the model uses several main performance metrics based on the confusion matrix: precision, recall, and F1-score. For these three metrics, the higher the value, the better the performance.

[0069] Precision (Pre) refers to the proportion of correctly predicted samples among the samples predicted as positive examples based on the prediction results of the model. The results predicted as positive examples are divided into two types, either actually positive examples TP or actually negative examples FP. It is expressed by the formula: ;

[0070] Recall (Rec) refers to the proportion of correctly predicted positive examples among the actually positive examples based on the actual samples. Among the samples that are actually positive examples, either they are correctly predicted TP in the prediction or they are predicted incorrectly FN in the prediction. It is expressed by the formula: ;

[0071] The F1 value is the harmonic mean of precision and recall, and its calculation formula is: .

[0072] S4. Obtain the data to be detected;

[0073] S5. Use the optimized anomaly detection model to analyze the data to be detected to obtain the reconstruction result of the data to be detected;

[0074] S6. Analyze the anomaly score of the data to be detected according to the reconstruction result, expressed as: ; where is the anomaly score at each time point, measures the dissimilarity. Among them, H is the number of center points in the radial basis function layer RBF, represents an L-dimensional real vector. The anomaly score improves the detection performance and integrates the normalized radial basis function layer RBF similarity score, the latent space deviation, and the reconstruction error of the original sequence. The normalization process uses the MinMax method to ensure the comparability of each score. The radial basis function layer RBF similarity score reflects the degree of closeness of the data point aligned with the learned center. A high similarity indicates normal behavior, while a low similarity indicates an anomaly. This score is obtained by averaging the outputs of the radial basis function layer RBF for all learnable centers ; the latent space deviation is defined as the distance in the latent space between each query vector and its nearest memory item . Since each memory item represents a prototype of a normal pattern, the latent space deviation of an anomaly will be greater than that of a normal time point; the reconstruction error is the squared difference between the actual data S i and its reconstructed value . Through this anomaly score, the model can more comprehensively evaluate the anomaly degree of the data, thereby improving the detection performance. Points with an anomaly score exceeding a certain threshold are determined to be anomalies.

[0075] To solve the conflict between local features and global features in time series over a long period, this invention designs a multi-scale temporal convolutional network to capture fine-grained temporal dependencies. The multi-scale temporal convolutional network has one-dimensional convolutional kernels of different sizes, which can capture temporal features at different scales in the time series. These convolutions can be dilated without increasing the kernel size to increase their receptive fields; to extract the periodic features of the time series and reduce the impact of noise on the model performance, an adaptive spectral feature module is used to perform high-frequency denoising and extract features from the frequency domain perspective; to solve the problem that most unsupervised models are difficult to detect subtle anomalies in complex datasets, a layer of Radial Basis Function (RBF) is introduced, and the similarity scores obtained from this layer are combined with the reconstruction error to improve the ability to detect subtle anomalies; finally, a gated memory mechanism is introduced to enhance the previously extracted time-frequency features by capturing the prototype features of the normal patterns in the data, thereby further improving the generalization ability of the model and enabling it to be more widely applicable to new data.

[0076] Experimental comparison results: The experimental results of the method proposed in this paper on five public datasets are shown in Table 1. The five public datasets are the MSL dataset, the SWaT dataset, the WADI dataset, the PSM dataset, and the AstrosetHigh dataset. Compared with 13 baseline time series anomaly detection methods, the proposed method has achieved the best results, with an average F1-score improvement of 19.21% compared to all comparison methods. The specific methods compared are as follows: Method 1 is Deep Support Vector Data Description (DeepSvDD); Method 2 is Deep Autoencoding Gaussian Mixture Model for Unsupervised Anomaly Detection (DAGMM); Method 3 is Multivariate Anomaly Detection for Time Series Data with Generative Adversarial Networks (MAD-GAN); Method 4 is Robust Anomaly Detection for Multivariate Time Series through Stochastic Recurrent Neural Network (OmniAnomaly); Method 5 is UnSupervised Anomaly Detection on Multivariate Time (USAD); Method 6 is Deep Semi-Supervised Anomaly Detection (DeepSAD); Method 7 is Graph Neural Network-Based Anomaly Detection in Multivariate Time Series (GDN); Method 8 is Anomaly transformer: Time series anomaly detection with association discrepancy (Anomaly transformer);Method 9 is the Deep Transformer Networks for Anomaly Detection in Multivariate Time Series Data (TranAD); Method 10 is the Temporal 2D-Variation Modeling for General Time Series Analysis (TimesNet); Method 11 is the Memory-guided Transformer for Multivariate Time Series Anomaly Detection (MEMTO); Method 12 is the Dual Attention Contrastive Representation Learning for Time Series Anomaly Detection (DCdetector); Method 13 is the Self-Supervised Spatial-Temporal Normality Learning for Time Series Anomaly Detection (STEN).;

[0077] The multi-hazard disaster Internet of Things time series adaptive anomaly detection system includes:

[0078] A storage; a computer program is stored in the storage;

[0079] An actuator; when the actuator executes the computer program stored in the storage, the multi-hazard disaster Internet of Things time series adaptive anomaly detection method as described above is implemented.

[0080] The emergency disaster warning system includes:

[0081] Multiple acquisition units; the acquisition units are used to acquire the monitoring data of each region in real time;

[0082] A storage unit; a computer program is stored in the storage unit;

[0083] Computing unit; The computing unit is communicatively connected to each acquisition unit and storage unit; When the computing unit executes the computer program stored in the storage unit to analyze the monitoring data, the above-mentioned multi-disaster Internet of Things time series adaptive anomaly detection method is implemented to obtain an anomaly score;

[0084] Warning unit; The warning unit is communicatively connected to the computing unit. The warning unit calculates the anomaly event level according to the anomaly score output by the computing unit, and generates and sends a warning message.

[0085] This method is applied to a large-scale monitoring and warning system for multi-disasters and multi-disaster points in the field of emergency disasters, such as Figure 5 shown, which shows the monitoring areas of 4 typical disasters (mudslides, forest fires, floods, earthquakes). The system implementation process is shown in Figure 6 , and the detailed system implementation plan is as follows:

[0086] 1. Deploy an adaptive disaster anomaly warning system: Deploy the anomaly detection model of this method in the data center, and ensure the communication connection between the data center and the sensors at the monitoring site;

[0087] 2. Preprocess historical data and train model parameters using historical data:

[0088] (1) Standardize the format of historical data on mudslides, fires, floods, and earthquakes;

[0089] (2) Integrate historical data in multiple dimensions into multivariate time series data.

[0090] (3) Use this historical multivariate time series data as the input of the anomaly detection model to train the anomaly detection model;

[0091] 3. Preprocess real-time monitoring data:

[0092] (1) Collect real-time on-site monitoring data from each area, send it to the data center, and standardize the format of the real-time monitoring data;

[0093] (2) Preprocess the real-time collected data, and integrate the monitoring data in multiple dimensions into multivariate time series data;

[0094] (3) Use the real-time multivariate time series data as the input of the trained anomaly detection model for calculation;

[0095] 4. Anomaly detection of real-time monitoring data:

[0096] Calculate the anomaly event level using the anomaly score, and generate and output a warning message (id, monitoring point, time, risk level, etc.);

[0097] 5. Repeat steps 3 - 4 to perform real-time disaster anomaly event detection and simultaneously update the model parameters iteratively online.

[0098] Table 1 Comparison table of performance metrics of the present invention and 13 baseline methods on 5 datasets

[0099]

[0100] The technical solution of the present invention is not limited to the limitations of the above specific embodiments. Any technical deformation made according to the technical solution of the present invention falls within the protection scope of the present invention.

Claims

1. An adaptive anomaly detection method for time series of the Internet of Things for multi-hazard disasters, characterized in that, Including: S1. Construct an initial anomaly detection model, which includes an encoding embedding layer, a multi-scale temporal convolutional network, an adaptive spectral feature module, a fusion layer, a gated control memory mechanism, a radial basis function layer RBF, and a decoder. The output of the encoding embedding layer is used as the input of the multi-scale temporal convolutional network and the adaptive spectral feature module respectively. The outputs of the multi-scale temporal convolutional network and the adaptive spectral feature module are both used as the input of the fusion layer. The output of the fusion layer is used as the input of the gated control memory mechanism. The output of the gated control memory mechanism is used as the input of the radial basis function layer RBF. The output of the gated control memory mechanism and the output of the radial basis function layer RBF are both used as the input of the decoder. The encoding embedding layer is used to perform positional encoding and embedding on the input data. The multi-scale temporal convolutional network is used to capture temporal features at different scales in the time series. The adaptive spectral feature module is used to perform high-frequency denoising from the frequency domain perspective and extract periodic frequency domain features of the time series. The fusion layer is used to perform weighted fusion on the time-domain features and frequency-domain features to obtain time-frequency features, which serve as the query vector q i ; the gate control memory mechanism is used to enhance the extracted time-frequency features; the radial basis function layer RBF is used to extract similarity features; The decoder is used to process and transform features to obtain a reconstructed sequence; the original time series S is defined as a set of a series of subsequences , where N represents the total number of subsequences, and the subsequence is a sequence of observation vectors, and the sequence of observation vectors is expressed as ; the encoded embedding layer encodes the vector i corresponding to the nth dimension in the obtained sequence X i , where , , , L, d, and respectively represent the subsequence length, the original data dimension, and the observation vector at time t, t ∈ L, represents the set of real numbers; S2. Obtain a training data set. S3. Import the training data set into the initial anomaly detection model and train and optimize it to obtain an optimized anomaly detection model. S4. Obtain the data to be detected. S5. Use the optimized anomaly detection model to analyze the data to be detected to obtain the reconstruction result of the data to be detected. S6. Analyze the anomaly score of the data to be detected according to the reconstruction result.

2. The multi-hazard disaster Internet of Things time series adaptive anomaly detection method according to claim 1, wherein, The multi-scale temporal convolutional network includes K convolutional kernels of different sizes and an average pooling layer. The output of the encoding embedding layer is used as the input of each of the K convolutional kernels, and the outputs of the K convolutional kernels are used as the input of the average pooling layer. The convolutional kernel extracts features from the vector and is expressed as: , where represents the output of the k-th convolutional kernel at time t, , is the weight of the k-th convolutional kernel at position j, and w k is the size of the k-th convolutional kernel; average pooling combines the features extracted by each convolutional kernel into a unified output, which is expressed as , is responsible for aggregating the outputs of different convolutional scales into a unified vector. The output of the multi-scale convolutional network is , which is composed of the results of convolution in each dimension of X i . Among them, represents the set of all real matrices of size .

3. The multi-disaster disaster Internet of Things time series adaptive anomaly detection method according to claim 1, characterized in that The adaptive spectral feature module performs high-frequency denoising from the frequency domain perspective and extracts periodic features of the time series, specifically including: ①For the embedded sequence X i , the frequency-domain data F of it is obtained by using the fast Fourier transform along the spatial dimension i ; ②Analyze the power spectrum P based on the frequency-domain data F i and perform adaptive filtering according to a preset threshold to obtain the frequency-domain data after adaptive filtering i ; ; ③ Use two groups of learnable filters to learn features from the frequency-domain data F i and the frequency-domain data respectively, obtaining the feature and the feature ; ④Fuse the feature and the feature to obtain the comprehensive spectral feature ; ⑤ Use the inverse fast Fourier transform to transform the fused spectral features back to the time domain, and obtain the frequency domain features of the original sequence , which is expressed as .

4. The multi-hazard disaster Internet of Things time series adaptive anomaly detection method according to claim 1, characterized in that The door control memory mechanism includes a memory module, a retrieval module, and a splicing layer. The memory module consists of M memory items Each memory item is trained to capture the normal patterns in the original time series. The retrieval module is used to retrieve the memory items of the normal model stored in the memory module according to the query vector q i The splicing layer concatenates the query vector with the memory item in the feature dimension to generate a new query vector where is the dimension of each memory item ​ The retrieval module is used to retrieve, according to the query vector q i memory items of the normal model stored in the memory module Specifically: the conditional query attention score defined on each memory item , which is calculated by applying the softmax function to the dot product between each query and memory item, and then the retrieved memory item is obtained by weighted summation of the memory item m using the attention score c . The attention score is expressed as: ; the memory item is expressed as: , where τ is the temperature parameter of the softmax function , and calculates the probability distribution , representing the exponential function; During memory item training, memory attention scores are defined according to the query vector to incrementally update the memory module, expressed as: , and the memory module adopts an update gate to control the range of the new normal mode that the memory module should obtain from the query, expressed as: ; ; Among them, and represent linear projections, and represent sigmoid activation and element-wise multiplication respectively.

5. The multi-hazard disaster Internet of Things time series adaptive anomaly detection method according to claim 1, wherein The radial basis function layer RBF analyzes all query vectors The similarity with respect to each learning center Z , For each query vector The similarity to each learning center Z, expressed as: , where , , represents a real vector of dimension H, represents a set of H center vectors, where H is the total number of center points in the radial basis function layer RBF, is the subsequence, and the parameter γ is responsible for regulating the function width.

6. The multi-disaster IoT time series adaptive anomaly detection method according to claim 1, wherein The training and optimization to obtain an optimized anomaly detection model specifically includes: (1) The encoding embedding layer performs positional encoding and embedding on the training data, and then inputs it into the multi-scale temporal convolutional network and the adaptive spectral feature module to respectively capture the temporal features and frequency domain features. (2)The fusion layer performs weighted fusion on the time-domain features and the frequency-domain features to obtain time-frequency features, which are used as the query vector q i ; (3) Use a gated memory mechanism to retrieve memory items related to the query vector , and concatenate the two to obtain a new query vector ; (4)Radial basis function layer RBF analyzes the query vector Similarity R to a set of learnable centers i ; The output R of the radial basis function layer RBF i and the query vector are used as the input to the decoder to obtain the reconstructed sequence ; (6) Analyze the reconstruction loss and the entropy loss ; (7) Analyze the final loss value according to the reconstruction loss and the entropy loss ; (8) Input the parameters of the anomaly detection model into the Adam optimizer to obtain the gradients of the model parameters, and then update the parameters of the entire anomaly detection model through backpropagation. (9) Determine whether the number of training times is less than the preset number of times. If so, end the training, and the current anomaly detection model is used as the optimized anomaly detection model.

7. The multi-hazard disaster Internet of Things time series adaptive anomaly detection method according to claim 6, wherein Reconstruction loss is expressed as: , the entropy loss is expressed as: ; the final loss value is expressed as: , where β is the weighting coefficient.

8. The multi-hazard disaster Internet of Things time series adaptive anomaly detection method according to claim 5, wherein In S6, the anomaly score Score is expressed as: ; is the anomaly score at each time point, measures the dissimilarity, where H is the total number of center points in the radial basis function layer RBF, represents an L-dimensional real vector.

9. The multi-hazard disaster Internet of Things time series adaptive anomaly detection system is characterized in that Including: A storage; The storage stores a computer program; An actuator; When the actuator executes the computer program stored in the storage, it implements the multi-hazard disaster Internet of Things time series adaptive anomaly detection method according to any one of claims 1-8.

10. Emergency disaster warning system, characterized in that, Including: Multiple acquisition units; The acquisition units are used to collect monitoring data of each area in real time; A storage unit; The storage unit stores a computer program; A calculation unit; The calculation unit is communicatively connected to each acquisition unit and the storage unit; When the calculation unit executes the computer program stored in the storage unit to analyze the monitoring data, it implements the multi-hazard disaster Internet of Things time series adaptive anomaly detection method according to any one of claims 1-8 to obtain an anomaly score. An early warning unit; The early warning unit is communicatively connected to the calculation unit. The early warning unit calculates the anomaly event level according to the anomaly score output by the calculation unit and generates and sends an early warning message.

Citation Information

Patent Citations

  • Monitoring and early warning device for identifying thermal runaway of battery and operation method of monitoring and early warning device

    CN119471412A

  • Adaptive disaster anomaly identification method and early warning system based on multi-prime convolution kernel

    CN119848747A

  • Water conservancy equipment life prediction and fault monitoring method, equipment and storage medium

    CN120011781A

  • Using an adaptive threshold for anomaly detection

    US20240095308A1

Cited By

  • Electric energy meter data anomaly detection method

    CN120561747A

  • Method for detecting abnormal data of electric energy meter

    CN120561747B

  • Forest fire occurrence real-time prediction method and system

    CN121189155A