Satellite telemetry data anomaly detection method and system based on graph learning
Through graph learning-based methods, the multivariate graph structure of satellite telemetry data is adaptively constructed, combined with graph neural network and attention mechanism, the problem of relying on expert experience and ignoring multivariate relationships in the existing technology is solved, and efficient satellite telemetry data abnormal detection is achieved.
Patent Information
- Application Number
- CN202510415353.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-18
AI Technical Summary
The existing satellite telemetry data anomaly detection methods rely too much on expert experience to identify unknown anomalies, ignore or explicitly model the relationship between multivariables, and the initial relationship between multivariables of telemetry data is difficult to construct.
Using graph learning methods, dynamic graph learning module is constructed through preprocessing, dynamic graph learning, graph structure extraction, spatiotemporal feature extraction and variational autoencoder training, and dynamic graph learning modules are adaptively learned the relationship between multivariables of satellite telemetry data, and graph neural networks and attention mechanisms are introduced to perform abnormal detection.
Unsupervised anomaly detection without prior knowledge and expert experience is realized, which can effectively capture the relationship between multivariables, improve the accuracy and generality of detection, and measure the importance of variables in different time windows.
Smart Images

Figure CN120337068A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite data processing, and particularly to a method and system for anomaly detection of satellite telemetry data based on graph learning, which can be applied to the anomaly detection of telemetry data during satellite operation. Background Art
[0002] A satellite is a complex system composed of components such as machinery, propulsion, and thermal control. There are correlations and synergistic effects among these components. However, due to the satellite being in outer space for a long time and often operating in harsh environments such as high temperature, severe cold, and vibration, its performance will decline, and some functions may fail, ultimately resulting in the entire satellite malfunctioning and shutting down. Therefore, real-time monitoring and positioning of anomalies are of great significance for the daily maintenance and life extension of on-orbit satellites. During satellite operation, multiple sensors installed on various satellite components collect the on-orbit operation data of each component of the satellite, and then transmit it to the ground monitoring center and store it as time series data, that is, satellite telemetry data. These satellite telemetry data record key information such as the temperature, voltage, and current of each part of the system. By analyzing this information, the interaction process between each component of the satellite and their respective status information can be obtained, which is an important basis for detecting the operating state of the satellite system. Therefore, during satellite operation, the anomaly detection of telemetry data is crucial for ensuring the safe operation of the satellite. However, the existing anomaly detection methods have the following problems:
[0003] 1. Overly dependent on expert experience and unable to identify unknown anomalies. Many traditional anomaly detection methods rely on expert experience to define rules and features. This method often performs poorly when faced with unknown anomaly patterns. For example, rule-based methods can only identify known types of anomalies and cannot handle new anomaly situations.
[0004] 2. Ignoring or not clearly modeling the relationships between multiple variables. Satellite anomalies usually involve complex relationships between multiple variables, but many existing methods cannot effectively capture these relationships. For example, traditional statistical methods such as Z-score detection and IQR detection usually only consider a single variable and ignore the interaction between variables.
[0005] 3. Difficulty in constructing the initial relationships between multiple variables in telemetry data. The multivariate relationships in telemetry data are complex and dynamically changing, and traditional graph construction methods often have difficulty accurately describing these relationships. For example, in social networks and traffic networks, the graph structure is usually fixed, while in satellite telemetry data, the relationships between variables may change over time. Summary of the Invention
[0006] In view of some or all of the problems in the prior art, the present invention provides a method for anomaly detection of satellite telemetry data based on graph learning, and the method includes the following steps:
[0007] Input satellite telemetry data and preprocess the satellite telemetry data, where the preprocessing includes noise reduction, missing value imputation, and normalization to obtain preprocessed satellite telemetry data;
[0008] Construct a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data and obtain the graph structure among the multivariate preprocessed satellite telemetry data;
[0009] Based on the graph structure, extract the spatial and temporal features of the preprocessed satellite telemetry data;
[0010] Divide the preprocessed satellite telemetry data into a training set and a test set. The training set is used for training an anomaly detection model, and learn the features of the training set based on a variational autoencoder; and
[0011] Input the test set containing anomaly data into the trained anomaly detection model to obtain an anomaly detection result, and use evaluation metrics to evaluate the performance of the anomaly detection model.
[0012] Further, the preprocessing includes noise reduction, missing value imputation, and normalization, and obtaining the preprocessed satellite telemetry data includes:
[0013] The satellite telemetry data is M-dimensional data, where M is a natural number greater than 1;
[0014] Noise reduction is to remove high-frequency noise in the satellite telemetry data through low-pass filtering, and filter each channel data of the satellite telemetry data respectively;
[0015] Use mean imputation or median imputation or K-nearest neighbor imputation to impute the missing values of the satellite telemetry data; and
[0016] Use maximum-minimum normalization to scale the satellite telemetry data to 0 to 1.
[0017] Further, constructing a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data and obtain the graph structure among the multivariate preprocessed satellite telemetry data includes:
[0018] Constructing a dynamic graph learning module is,
[0019]
[0020] Where V 1 ∈R N×s ,V2 ∈R N×s ,V 1 and V 2 are neural networks with randomly initialized embedding matrices, with dimensions of N×d, where N is the number of variables and d is the network node dimension; and are trainable parameter weight matrices with dimensions of d×d. δ is a non-linear hyperparameter used to adjust the network activation saturation rate; A ij is the adjacency matrix;
[0021] The update formula for the graph structure is
[0022] A = αA0+(1 + α)A learn
[0023] where A is the dynamically updated adjacency matrix, α is the decay coefficient, A0 is the initial adjacency matrix, and A learn is the learned adjacency matrix;
[0024] The top-K algorithm is introduced to keep only the top k nearest neighbor elements of each node in the adjacency matrix. The formula is
[0025]
[0026] where the argmax function is used to find the top k maximum value elements of each node in the adjacency matrix A, and K is determined according to the number of variables in the dataset and the anomaly detection effect.
[0027] Furthermore, based on the graph structure, extracting the spatial and temporal features of the preprocessed satellite telemetry data includes:
[0028] Using a graph sampling aggregation network to sample the local neighbor nodes of each node;
[0029] Aggregating the features of the neighbor nodes of each node k times through the Aggregate function to obtain the embedding features of each node in the graph. The formula is
[0030]
[0031] where is the aggregated feature of the k-th layer neighbor nodes, is the set of neighbor aggregation features of all nodes, AGGREEGATE (k) is the aggregation function, u is the neighbor node of node v, N(v) is the set of neighbor nodes of node v, CONCAT is the concatenation function, W (k) is the weight matrix of the k-th layer, σ is the activation function, is the embedding feature of node v in the (k - 1)-th layer;
[0032] Use a gated recurrent unit to extract the temporal features of the preprocessed satellite telemetry data. The formula is
[0033]
[0034] where x t is the input data, W (z) and U (z) are the weight matrices of the update gate, W (r) and U (r) are the weight matrices of the reset gate, h t-1 is the historical state, σ is the sigmoid activation function, tanh is the tanh activation function, Z t is the update gate, R t is the reset gate, h′ t is the candidate hidden state, h t is the hidden state at the current time step, Wx t is the result of the linear transformation of the input data, Uh t-1 is the result of the linear transformation of the historical state, and ⊙ is the Hadamard product;
[0035] Construct an attention feature extraction mechanism. The formula is
[0036]
[0037] where is the attention score of the k-th feature at time step t, is the corresponding weight coefficient, is the k-th input feature, b is the bias term, is the attention score of the remaining features;
[0038] The output of the gated recurrent unit is
[0039]
[0040] where is the GRU output adjusted by attention, and y n is the input feature sequence.
[0041] Furthermore, dividing the preprocessed satellite telemetry data into a training set and a test set includes:
[0042] Divide the preprocessed satellite telemetry data into a training set and a test set according to a data sample ratio of 7:3 or 8:2;
[0043] The training set includes normal data, and the test set includes abnormal data and labels.
[0044] Further, the training set is used for training the anomaly detection model. Learning the features of the training set based on the variational autoencoder includes:
[0045] The variational autoencoder approximates the posterior distribution q θ (z t │x t ) through variational inference and minimizing the KL divergence, transforming the Bayesian problem into an optimization problem. The formula is
[0046] p θ (z t , x t ) = p θ (z t )p θ (x t |z t )
[0047]
[0048]
[0049] where z t is the latent variable and x t is the input data, is the posterior distribution, p θ (x t │z t ) is the prior distribution, p θ (z t |x t ) is the joint distribution, argmin is to take the minimum value, Q is the variational distribution family, q * is the optimal variational distribution, and ELBO is the variational lower bound;
[0050] The loss function of the anomaly detection model is
[0051] Loss = L MSE + L KL
[0052] = L MSE + KL[N(μ x , σ x ),N(0,1)]
[0053] where N(μ x , σ x ) is the latent variable distribution output by the encoder, and N(0,1) is the standard normal distribution;
[0054] where L MSE is the mean squared error loss function,
[0055]
[0056] Among them, N is the number of samples, and z t is the true latent variable, and is the latent variable reconstructed by the decoder;
[0057] The anomaly score is
[0058]
[0059] Furthermore, input the test set containing anomaly data into the trained anomaly detection model to obtain the anomaly detection result. Evaluating the performance of the anomaly detection model using evaluation metrics includes:
[0060] The evaluation metrics include
[0061]
[0062]
[0063] Among them, TP is the true positive, which is the number of samples correctly predicted as the positive class by the model; FP is the false positive, which is the number of negative class samples wrongly predicted as the positive class by the model; FN is the false negative, which is the number of samples wrongly predicted as the negative class by the model; F1-score is the harmonic mean of precision and recall.
[0064] The present invention also provides a system for the above-mentioned graph learning-based satellite telemetry data anomaly detection method, and this system includes the following modules:
[0065] A preprocessing module, configured to input satellite telemetry data and preprocess the satellite telemetry data. The preprocessing includes noise reduction, missing value imputation, and normalization to obtain the preprocessed satellite telemetry data;
[0066] A graph learning construction module, configured to construct a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data and obtain the graph structure among multiple variables of the preprocessed satellite telemetry data;
[0067] A spatio-temporal feature extraction module, configured to extract the spatial and temporal features of the preprocessed satellite telemetry data based on the graph structure;
[0068] A data reconstruction module, configured to divide the preprocessed satellite telemetry data into a training set and a test set. The training set is used for training the anomaly detection model, and learn the features of the training set based on the variational autoencoder; and
[0069] A performance evaluation module, configured to input the test set containing anomaly data into the trained anomaly detection model to obtain the anomaly detection result, and evaluate the performance of the anomaly detection model using evaluation metrics.
[0070] The present invention also provides a computer system, including:
[0071] A processor configured to execute machine-readable instructions;
[0072] A graphics card with an artificial intelligence chip, configured to train the above-mentioned anomaly detection method for satellite telemetry data based on graph learning; and
[0073] A memory configured to store machine-readable instructions, and the machine-readable instructions execute the steps of the anomaly detection method for satellite telemetry data based on graph learning when being executed by the processor and / or the graphics card.
[0074] The present invention also provides a computer-readable storage medium, on which machine-readable instructions are stored, and the machine-readable instructions execute the steps of the anomaly detection method for satellite telemetry data based on graph learning when being executed by the processor.
[0075] The technical solution provided by the present invention has the following advantages:
[0076] 1. The anomaly detection method for satellite telemetry data based on graph learning proposed by the present invention learns data features in an unsupervised manner, and only normal data is required to learn data features, without prior knowledge and expert experience.
[0077] 2. The anomaly detection method for satellite telemetry data based on graph learning proposed by the present invention considers the relationship between multiple variables of the data during feature extraction, introduces a graph neural network, and has stronger interpretability.
[0078] 3. The anomaly detection method for satellite telemetry data based on graph learning proposed by the present invention designs a method for constructing a graph structure of telemetry data, obtains the initial relationship between multiple variables, and has better versatility.
[0079] 4. The anomaly detection method for satellite telemetry data based on graph learning proposed by the present invention introduces an attention mechanism when extracting time series features, and can measure the importance of variables in different time windows. BRIEF DESCRIPTION OF THE DRAWINGS
[0080] To further clarify the above and other advantages and features of the embodiments of the present invention, a more specific description of the embodiments of the present invention will be presented with reference to the accompanying drawings. It can be understood that these drawings only depict typical embodiments of the present invention and will not be considered as limiting its scope. In the drawings, for clarity, the same or corresponding components will be denoted by the same or similar reference numerals.
[0081] Figure 1 A flowchart showing the anomaly detection method for satellite telemetry data based on graph learning according to an embodiment of the present invention;
[0082] Figure 2 The schematic diagram of the principle of the anomaly detection method for satellite telemetry data based on graph learning according to an embodiment of the present invention is shown;
[0083] Figure 3 The schematic diagram of the attention feature extraction mechanism according to an embodiment of the present invention is shown; and
[0084] Figure 4 The schematic diagram of the anomaly detection system for satellite telemetry data based on graph learning according to an embodiment of the present invention is shown. Detailed implementation manners
[0085] In the following description, the present invention is described with reference to the embodiments. However, those skilled in the art will recognize that the embodiments can be implemented without one or more specific details or in combination with other alternative and / or additional methods or components. In other cases, well-known structures or operations are not shown or described in detail to avoid obscuring the inventive points of the present invention. Similarly, for the purpose of explanation, specific numbers and configurations are set forth in order to provide a comprehensive understanding of the embodiments of the present invention. However, the present invention is not limited to these specific details.
[0086] In this specification, the reference to "an embodiment" or "the embodiment" means that the specific features, structures, or characteristics described in connection with the embodiment are included in at least one embodiment of the present invention. The phrase "in an embodiment" appearing throughout this specification does not necessarily refer to the same embodiment.
[0087] It should be noted that the embodiments of the present invention describe the method steps in a specific order. However, this is only for the purpose of elaborating the specific embodiment and does not limit the sequence of the steps. On the contrary, in different embodiments of the present invention, the sequence of the steps can be adjusted according to the actual requirements.
[0088] In the present invention, each module of the system according to the present invention can be implemented using software, hardware, firmware, or a combination thereof. When a module is implemented using software, the functions of the module can be realized through a computer program process. For example, the module can be implemented by a code segment (such as a code segment in languages like C, C++) stored in a storage device (such as a hard disk, memory, etc.), and when the code segment is executed by a processor, the corresponding functions of the module can be realized. When a module is implemented using hardware, the functions of the module can be realized by setting corresponding hardware structures. For example, the functions of the module can be realized by hardware programming of programmable devices such as field-programmable gate arrays (FPGAs), or by designing application-specific integrated circuits (ASICs) including multiple electronic devices such as transistors, resistors, and capacitors. When a module is implemented using firmware, the functions of the module can be written in a read-only memory such as an EPROM or EEPROM of the device in the form of program code, and when the program code is executed by a processor, the corresponding functions of the module can be realized. Additionally, certain functions of the module may need to be implemented by separate hardware or in cooperation with the hardware. For example, the detection function is realized through corresponding sensors (such as proximity sensors, acceleration sensors, gyroscopes, etc.), the signal emission function is realized through corresponding communication devices (such as Bluetooth devices, infrared communication devices, baseband communication devices, Wi-Fi communication devices, etc.), the output function is realized through corresponding output devices (such as displays, speakers, etc.), and so on.
[0089] To solve the problem of satellite telemetry data anomaly detection, the present invention proposes a method for satellite telemetry data anomaly detection based on graph learning. This method is different from other data-driven anomaly detection methods. This method first introduces a graph neural network (Graph Neural Network, GNN), combines the advantages of the graph neural network and the recurrent neural network (Recurrent Neural Network, RNN), and simultaneously obtains the relationships between multivariate telemetry data and temporal features, enabling the model to have a more powerful feature extraction ability. Secondly, according to the characteristics of high-dimensional and complex telemetry data, a method for dynamic graph learning of multivariate correlation is designed to adaptively learn and construct the initial relationships of telemetry data. Finally, through the learned data features, the reconstruction error and anomaly scores are calculated, effectively reducing the probability of misjudgment and missed judgment of the model and improving the accuracy of anomaly detection.
[0090] Figure 1 The flowchart of the method for satellite telemetry data anomaly detection based on graph learning according to an embodiment of the present invention is shown; Figure 2 The schematic diagram of the principle of the method for satellite telemetry data anomaly detection based on graph learning according to an embodiment of the present invention is shown. The following combines Figure 1 and Figure 2, the method for anomaly detection of satellite telemetry data based on graph learning proposed by the present invention will be described. In an embodiment of the present invention, the method for anomaly detection of satellite telemetry data based on graph learning can be executed by a computer. As Figure 1 shown, the method for anomaly detection of satellite telemetry data based on graph learning includes the following steps:
[0091] First, input satellite telemetry data and preprocess the satellite telemetry data. The preprocessing includes noise reduction, missing value imputation, and normalization to obtain preprocessed satellite telemetry data.
[0092] The satellite telemetry data can be high-dimensional telemetry data, i.e., M-dimensional telemetry data, where M is a natural number greater than 1.
[0093] Noise reduction is to remove high-frequency noise in the satellite telemetry data through low-pass filtering (Gaussian filtering). Gaussian filtering is based on the method of weighted average, and by replacing the value of each data point with the weighted average of the neighborhood, the weight decreases as the distance from the center point increases. The implementation method of Gaussian filtering can be to design a Gaussian convolution kernel and perform a convolution operation on the data or call the gaussian_filter function in the scipy library of python. The satellite telemetry data has multiple channels, and each channel data is filtered separately.
[0094] Use mean imputation or median imputation or K-nearest neighbor imputation to impute the missing values of the satellite telemetry data. Mean imputation or median imputation is applicable to the situation where the missing values of the telemetry data are few and the data distribution is uniform; if there are many missing values, K-nearest neighbor imputation can be used to impute using the values of adjacent samples.
[0095] The units of the satellite telemetry data variables are not unified, and normalization is required to adjust the data range to a unified scale. The present invention uses min-max normalization to scale the satellite telemetry data to 0 to 1.
[0096] Next, construct a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data and obtain the graph structure among the multi-variables of the preprocessed satellite telemetry data. The dynamic graph learning module can be a directly optimized dynamic graph learning module.
[0097] The dynamic graph learning module is specifically implemented through the following formula,
[0098]
[0099] where, V 1 ∈RN ×s , V 2 ∈R N×s , V 1 and V 2is a neural network with a randomly initialized embedding matrix, having dimensions of N×d, where N is the number of variables and d is the network node dimension; and is a trainable parameter weight matrix with dimensions of d×d, and δ is a non-linear hyperparameter used to adjust the network activation saturation rate; A ij is the adjacency matrix.
[0100] To construct the directivity between variables, by calculating the difference after multiplying two transformed node embedding matrices, and using non-linear activation functions Relu and tanh functions to express this directivity relationship, so that A ij is regularized between 0 and 1.
[0101] The present invention uses the initial input A0 constructed by cosine similarity as the first initial graph structure, and subsequent graph structures are dynamically updated according to the previous graph structure and the graph structure learned from the embedding vector and weight matrix. The update formula of the graph structure is,
[0102] A = αA0+(1 + α)A learn
[0103] where A is the dynamically updated adjacency matrix, α is the decay coefficient, A0 is the initial adjacency matrix, and A learn is the learned adjacency matrix.
[0104] where α gradually decreases with the number of iterations, gradually getting rid of the influence of the initial graph structure. The preprocessed satellite telemetry data is used as the input of the dynamic graph learning module. The feature vector of each sampling point consists of its own value and historical values, and is used as the initial input of the dynamic graph learning module and the components of V 1 and V 2 of.
[0105] In addition, in the actual scenario, not every sensor is relevant to each other. Therefore, the top-K algorithm is introduced to only retain the first k nearest neighbor elements of each node in the adjacency matrix, that is, only retain the relationships of the first K most relevant neighbor nodes of each node. In this way, the computational cost can be further reduced. The specific formula is,
[0106]
[0107] where the argmax function is used to find the first k maximum value elements of each node in the adjacency matrix A, and K is determined according to the number of variables in the dataset and the anomaly detection effect.
[0108] Introducing the top-K algorithm is more in line with the distribution of actual data. Not all variables have important relationships with each other. At the same time, for further extraction of the relationships in the space of telemetry data through the GraphSAGE of the graph neural network later, it can reduce the computational amount and improve the algorithm efficiency.
[0109] After the dynamic graph learning module constructs the graph structure and retains the most relevant neighbor relationships through Top-K, it obtains the adjacency matrix for subsequent input to the graph neural network. The specific implementation requires standardization and sparsification and is then used for feature aggregation and update of the graph neural network. Standardization can prevent numerical explosion and gradient vanishing, and the role of sparsification is similar to that of Top-K, both for saving storage space and computational amount.
[0110] Next, based on the graph structure, the spatial and temporal features of the preprocessed satellite telemetry data are extracted.
[0111] The graph neural network adopts a graph sampling aggregation network to sample the local neighbor nodes of each node. Since the number of neighbor nodes of each node is different, it is very inefficient to calculate all neighbor nodes. Randomly sample several nodes, and then select the first-order, second-order, and K-order neighbor nodes for sampling, which can improve the overall computational efficiency. The features of the neighbor nodes of each node are aggregated k times through the Aggregate function to obtain the embedding features of each node in the graph. The formula is,
[0112]
[0113] Among them, is the aggregated feature of the neighbor nodes of the k-th layer, is the set of aggregated features of the neighbors of all nodes, AGGREEGATE (k) is the aggregation function, u is the neighbor node of node v, N(v) is the set of neighbor nodes of node v, CONCAT is the concatenation function, W (k) is the weight matrix of the k-th layer, σ is the activation function, is the embedding feature of node v in the (k - 1)-th layer;
[0114] Use the Gated Recurrent Unit (GRU) to extract the temporal features of the preprocessed satellite telemetry data. The formula is,
[0115]
[0116] Among them, x t is the input data, W (z) and U (z) are the weight matrices of the update gate, W (r) and U (r) are the weight matrices of the reset gate, ht-1 is the historical state, σ is the sigmoid activation function, tanh is the tanh activation function, and Z t is the update gate, and R t is the reset gate, and h ′ t is the candidate hidden state, and h t is the hidden state at the current time step, and Wx t is the result of the linear transformation of the input data, and Uh t-1 is the result of the linear transformation of the historical state. ⊙ is the Hadamard product; the input at the current moment and the historical memory state after passing through the reset gate pass through a non-linear layer to obtain the new input information at the current moment, and then the result of the update gate is added to obtain the output of the GRU at the current moment.
[0117] In addition, an attention mechanism is introduced to obtain the importance of variables in different time windows. Given an n-dimensional feature sequence By combining the historical state h in the GRU model t-1 , and then feeding it into the linear layer to obtain Finally, the weight coefficient of each variable is calculated through the normalization layer Construct an attention feature extraction mechanism, and the formula is
[0118]
[0119] where is the attention score of the k-th feature at time step t, is the corresponding weight coefficient, n is the number of all features, is the k-th input feature, k ranges from 1 to n, b is the bias term, is the attention score of the remaining features;
[0120] The output of the gated recurrent unit is
[0121]
[0122] where is the GRU output adjusted by attention, and y n is the input feature sequence.
[0123] In this way, it is possible to selectively focus on more relevant variables instead of extracting the features of all input data variables, further capturing the time-dependent relationship of telemetry data and enabling the model to retain more important features.
[0124] Before inputting the embedded vector into the GRU, the attention mechanism is first used to combine the historical hidden states. At each time step, the input features are adaptively extracted, and then the weighted coefficients are calculated to assign different attention coefficients to different time steps. By combining the attention mechanism, the time feature extraction network can capture the long-term time dependencies of the time series while adaptively selecting the most relevant input features and improving the feature extraction ability.
[0125] Next, the preprocessed satellite telemetry data is divided into a training set and a test set. The training set is used for training the anomaly detection model, and the features of the training set are learned based on the variational autoencoder.
[0126] The preprocessed satellite telemetry data is divided into a training set and a test set according to a data sample ratio of 7:3 or 8:2. The training set and the test set are divided according to the actual data set situation. In the existing satellite telemetry data, there are few anomaly samples. The present invention is trained by an unsupervised method. That is, all the data in the training set is normal data, and the test set contains some anomaly data and labels. The training of the model uses the training set and does not require the use of anomaly data and labels. The test set is used to evaluate the effect of the model's anomaly detection. The training set data is input into the constructed model, reconstructed after extracting the time and space features, and the mean square error loss function is constructed according to the reconstruction result and the actual value to learn the features of the normal data. The features of the normal data are learned through the last reconstruction module based on the variational autoencoder, and the normal data features are reconstructed by learning the distribution of the features.
[0127] The variational autoencoder (VAE) is used as the reconstruction model to learn the complex distribution of the data in the latent space. The VAE consists of an encoder-decoder structure. The encoder can represent the input x t as a reduced-dimensional latent representation z t , which follows a certain conditional distribution p θ (x t │z t ). Then the decoder can reconstruct x t through z t . By updating the parameters of the model, the best model with the reconstruction having the closest data distribution of x t is obtained. It is very difficult to reconstruct x t from z t , and it is necessary to calculate the posterior distribution q θ (z t │x t ). The variational autoencoder approximates the posterior distribution q θ (z t │x t ) through variational inference and minimizing the KL divergence, transforming the Bayesian problem into an optimization problem. The formula is
[0128] p θ (z t ,x t ) = p θ (z t )p θ (x t |z t )
[0129]
[0130] where z t is a latent variable, x t is the input data, is the posterior distribution, p θ (x t │z t ) is the prior distribution, p θ (z t |x t ) is the joint distribution, argmin is to take the minimum value, Q is the variational distribution family, q * is the optimal variational distribution, ELBO (Evidence Lower Bound) is the variational lower bound.
[0131] When maximizing the marginal likelihood of the data p θ (x t ) (i.e., the probability that the model generates the data), it is difficult to directly calculate the marginal likelihood log(p θ (x t ). Therefore, by introducing the variational distribution to define an optimizable lower bound. θ and are the training parameters of the generation network and the inference network respectively, where the generation network is the VAE decoding part and the inference network is the VAE encoding part. The reconstruction loss generally includes two parts. The first part is the reconstruction loss. The reconstruction loss is used to measure the difference between the reconstructed data and the original data, and can be approximately solved by sampling multiple latent variables z θ (x t │z t ) from the prior distribution p t . If it is assumed that the data is a Gaussian distribution with a fixed variance, the objective function obtained after maximum likelihood estimation is equivalent to MSE. The second part is the regularization term in the latent space, and the KL divergence loss is usually used to measure the difference between the distribution of the latent variable and the standard normal distribution.
[0132] The model parameters are updated through the loss function, and the model is trained to learn the characteristic distribution of normal data. The loss function of the anomaly detection model is,
[0133] Loss = LMSE +L KL
[0134] =L MSE +KL[N(μ x ,σ x ),N(0, 1)]
[0135] where N(μ x , σ x ) is the distribution of the latent variables output by the encoder, and N(0, 1) is the standard normal distribution.
[0136] where L MSE is the mean squared error loss function.
[0137]
[0138] where N is the number of samples, z t is the true latent variable, is the latent variable reconstructed by the decoder.
[0139] The anomaly score is calculated by computing the absolute value of the difference between the input and output of the reconstruction model, and the influence of variables on anomalies can be evaluated according to the magnitudes of the anomaly scores of different variables. The anomaly score is
[0140]
[0141] If the anomaly score is low, it indicates that the input data can be reconstructed well, suggesting normal data; while if the anomaly score is high, exceeding the set threshold, it means that the data distribution is different from the learned normal data distribution and there is likely an anomaly. The threshold selection uses the POT (Peaks Over Threshold) method to screen out the data points (referred to as peaks over threshold) that exceed the set threshold from the overall anomaly scores, and then models these extreme value data. The distribution of the peaks over threshold is modeled using the Generalized Pareto Distribution (GPD). The local characteristics (mean) of the data are calculated using a sliding window and the threshold is updated accordingly to implement a dynamic threshold that adapts to the changes in the data. Normal data and anomaly data are distinguished based on the anomaly scores, and finally the monitoring results are output to achieve anomaly detection.
[0142] Finally, input the test set containing abnormal data into the trained abnormal detection model to obtain the abnormal detection results, and use evaluation metrics to evaluate the performance of the abnormal detection model. For the given satellite telemetry data, each sampling point and the historical data of a fixed length in front are input into the designed abnormal detection model through a sliding window, and the abnormal score of each sampling point is calculated. Time points with insufficient historical data are filled with zeros. By comparing with the set threshold, it is judged whether there is an abnormality at that time for the sampling point, and a binary label {0, 1} is output. The evaluation metrics are TP, FP, and FN of the binary classification model, and the precision, recall, and comprehensive metric F1-score are calculated.
[0143] The evaluation metrics include
[0144]
[0145] Among them, TP is the true positive, that is, the number of samples correctly predicted as the positive class by the model. FP is the false positive, that is, the number of negative class samples wrongly predicted as the positive class by the model. FN is the false negative, that is, the number of samples wrongly predicted as the negative class by the model. The F1-score is the harmonic mean of the precision and recall.
[0146] The present invention focuses on the relationships among multiple variables in telemetry data and can be applied to the situations where there is a large amount of telemetry data, but the number of abnormal data samples is small, the number of variables is large and the correlations are strong, especially when the occurring abnormalities may involve multiple variables.
[0147] The abnormal detection method for satellite telemetry data based on graph learning proposed by the present invention learns data features in an unsupervised manner and can learn data features only with normal data, without prior knowledge and expert experience; when extracting features, the relationships among multiple variables of the data are considered, a graph neural network is introduced, and it has stronger interpretability; a method for constructing the graph structure of telemetry data is designed to obtain the initial relationships among multiple variables, and it has better versatility; an attention mechanism is introduced when extracting time series features, which can measure the importance of variables in different time windows.
[0148] In an embodiment of the present invention, the present invention also provides an abnormal detection system for satellite telemetry data based on graph learning. Figure 4 The schematic diagram of the abnormal detection system for satellite telemetry data based on graph learning according to an embodiment of the present invention is shown. As Figure 4 shown, the system includes the following modules:
[0149] A preprocessing module, configured to input satellite telemetry data and preprocess the satellite telemetry data, where the preprocessing includes noise reduction, missing value imputation, and normalization to obtain preprocessed satellite telemetry data;
[0150] A graph learning construction module, configured to construct a dynamic graph learning module, adaptively learn the initial relationships of the preprocessed satellite telemetry data, and obtain the graph structure among multiple variables of the preprocessed satellite telemetry data;
[0151] A spatio-temporal feature extraction module, configured to extract the spatial and temporal features of the preprocessed satellite telemetry data based on the graph structure;
[0152] A data reconstruction module, configured to divide the preprocessed satellite telemetry data into a training set and a test set, where the training set is used for training an anomaly detection model, and learn the features of the training set based on a variational autoencoder; and
[0153] A performance evaluation module, configured to input the test set containing anomaly data into the trained anomaly detection model to obtain an anomaly detection result, and evaluate the performance of the anomaly detection model using evaluation metrics.
[0154] In an embodiment of the present invention, the present invention further provides a computer system, which includes a processor, a graphics card with an artificial intelligence chip, and a memory. The memory is configured to store machine-readable instructions, the graphics card is configured to train the anomaly detection method for satellite telemetry data based on graph learning, and the processor is configured to execute the machine-readable instructions. When the processor and / or the graphics card execute the machine-readable instructions, the following processing steps are implemented: input satellite telemetry data, and preprocess the satellite telemetry data, where the preprocessing includes noise reduction, missing value imputation, and normalization, to obtain preprocessed satellite telemetry data; construct a dynamic graph learning module, adaptively learn the initial relationships of the preprocessed satellite telemetry data, and obtain the graph structure among multiple variables of the preprocessed satellite telemetry data; extract the spatial and temporal features of the preprocessed satellite telemetry data based on the graph structure; divide the preprocessed satellite telemetry data into a training set and a test set, where the training set is used for training an anomaly detection model, and learn the features of the training set based on a variational autoencoder; input the test set containing anomaly data into the trained anomaly detection model to obtain an anomaly detection result, and evaluate the performance of the anomaly detection model using evaluation metrics.
[0155] The graphics card may preferably be a graphics card with a GPU computing power higher than model 5.0. Since the amount of data to be trained is large, providing the graphics card configuration can significantly improve the training speed.
[0156] The memory includes various media that can store machine-readable instructions, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disc.
[0157] It can be understood that in addition to the memory and processor mentioned above, the above computer system further includes other software and hardware components not listed in this specification, which can be specifically determined according to the models of specific data processing devices in different application scenarios, and will not be listed and described in detail one by one in this specification.
[0158] In one embodiment of the present invention, the present invention further provides a computer-readable storage medium, on which machine-readable instructions are stored, and when the machine-readable instructions are executed by a processor, the following processing steps are implemented: input satellite telemetry data, and perform preprocessing on the satellite telemetry data, the preprocessing includes noise reduction, missing value imputation, and normalization, to obtain preprocessed satellite telemetry data; construct a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data, and obtain the graph structure among multiple variables of the preprocessed satellite telemetry data; based on the graph structure, extract the spatial and temporal features of the preprocessed satellite telemetry data; divide the preprocessed satellite telemetry data into a training set and a test set, the training set is used for training an anomaly detection model, and learn the features of the training set based on a variational autoencoder; input the test set containing anomaly data into the trained anomaly detection model to obtain an anomaly detection result, and use evaluation metrics to evaluate the performance of the anomaly detection model.
[0159] Although the embodiments of the present invention have been described above, it should be understood that they are presented only as examples and not as limitations. It is obvious to those skilled in the relevant art that various combinations, variations, and changes can be made to them without departing from the spirit and scope of the present invention. Therefore, the width and scope of the present invention disclosed herein should not be limited by the exemplary embodiments disclosed above, but should be defined according to the technical solutions of the present invention and their equivalent replacements.
Claims
1. A satellite telemetry data anomaly detection method based on graph learning, characterized in that, It includes the following steps: Input satellite telemetry data and preprocess the satellite telemetry data. The preprocessing includes noise reduction, missing value imputation, and normalization to obtain preprocessed satellite telemetry data; Construct a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data and obtain the graph structure among multiple variables of the preprocessed satellite telemetry data; Based on the graph structure, extract the spatial and temporal features of the preprocessed satellite telemetry data; Divide the preprocessed satellite telemetry data into a training set and a test set. The training set is used for training an anomaly detection model, and learn the features of the training set based on a variational autoencoder; And Input the test set containing anomaly data into the trained anomaly detection model to obtain anomaly detection results, and use evaluation metrics to evaluate the performance of the anomaly detection model.
2. The anomaly detection method for satellite telemetry data based on graph learning according to claim 1, characterized in that, Input satellite telemetry data and preprocess the satellite telemetry data. The preprocessing includes noise reduction, missing value imputation, and normalization to obtain preprocessed satellite telemetry data, including: The satellite telemetry data is M-dimensional data, where M is a natural number greater than 1; Noise reduction is to remove high-frequency noise in the satellite telemetry data through low-pass filtering, and filter each channel data of the satellite telemetry data separately; Use mean imputation or median imputation or K-nearest neighbor imputation to impute missing values in the satellite telemetry data; and Use maximum-minimum normalization to scale the satellite telemetry data to 0 to 1.
3. The anomaly detection method for satellite telemetry data based on graph learning according to claim 1, wherein Construct a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data and obtain the graph structure among multiple variables of the preprocessed satellite telemetry data, including: Construct a dynamic graph learning module as where, V 1 ∈ R N×d , V 2 ∈ R N×d , V 1 and V 2 are neural networks with randomly initialized embedding matrices, having dimensions of N × d, where N is the number of variables and d is the network node dimension; and are trainable parameter weight matrices with dimensions of d × d, and δ is a non-linear hyperparameter used to adjust the network activation saturation rate; A ij is the adjacency matrix; The update formula of the graph structure is A = αA0+(1 + α)A learn Among them, A is an adjacency matrix updated dynamically, α is an attenuation coefficient, A0 is an initial adjacency matrix, and A learn is the learned adjacency matrix; Introduce the top-K algorithm to only retain the first k nearest neighbor elements of each node in the adjacency matrix. The formula is where the argmax function is used to find the first k maximum value elements of each node in the adjacency matrix A, and K is determined according to the number of variables in the dataset and the anomaly detection effect.
4. The anomaly detection method for satellite telemetry data based on graph learning according to claim 1, wherein Based on the graph structure, extract the spatial and temporal features of the preprocessed satellite telemetry data, including: Use a graph sampling aggregation network to sample the local neighbor nodes of each node; Perform k aggregation operations on the features of the neighbor nodes of each node through the Aggregate function to obtain the embedding features of each node in the graph. The formula is Among them, is the aggregated feature of the k-th layer neighbor nodes, is the set of neighbor aggregation features of all nodes, AGGREEGATE (k) is the aggregation function, u is the neighbor node of node v, N(v) is the set of neighbor nodes of node v, CONCAT is the concatenation function, W (k) is the weight matrix of the k-th layer, and σ is the activation function, is the embedding feature of node v at the (k - 1)-th layer; Use a gated recurrent unit to extract the temporal features of the preprocessed satellite telemetry data. The formula is where x t is the input data, W (z) and U (z) are the weight matrices of the update gate, W (r) and U (r) are the weight matrices of the reset gate, h t-1 is the historical state, σ is the sigmoid activation function, tanh is the tanh activation function, Z t is the update gate, R t is the reset gate, h′ t is the candidate hidden state, h t is the hidden state at the current time step, Wx t is the result of the linear transformation of the input data, Uh t-1 is the result of the linear transformation of the historical state, ⊙ is the Hadamard product; Construct an attention feature extraction mechanism. The formula is wherein, is the attention score of the k-th feature at time step t, is the corresponding weight coefficient, is the k-th input feature, b is the bias term, is the attention score of the remaining features; The output of the gated recurrent unit after combining the attention mechanism is Among them, is the output of the GRU after attention adjustment, and y n is the input feature sequence.
5. The method for anomaly detection of satellite telemetry data based on graph learning according to claim 1, wherein Divide the preprocessed satellite telemetry data into a training set and a test set, including: Divide the preprocessed satellite telemetry data into a training set and a test set according to a data sample ratio of 7:3 or 8:2; The training set includes normal data, and the test set includes anomaly data and labels.
6. The anomaly detection method for satellite telemetry data based on graph learning according to claim 1, characterized in that The training set is used for training an anomaly detection model. Learning the features of the training set based on a variational autoencoder includes: The variational autoencoder approximates the posterior distribution q through variational inference and minimizing the KL divergence θ (z t │x t ), transforming the Bayesian problem into an optimization problem. The formula is p θ (z t ,x t ) = p θ (z t )p θ (x t ||z t ) where z t is a latent variable, x t is the input data, is the posterior distribution, p θ (x t │z t ) is the prior distribution, p θ (z t |x t ) is the joint distribution, argmin is to take the minimum value, Q is the variational distribution family, q * is the optimal variational distribution, and ELBO is the variational lower bound; The loss function of the anomaly detection model is Loss=L MSE +L KL = L MSE + KL[N(μ x , σ x ), N(0,1)] Among them, N(μ x ,σ x ) is the distribution of the latent variables output by the encoder, and N(0,1) is the standard normal distribution; Among them, L MSE is the mean square error loss function, where N is the number of samples, and z t is the true latent variable, and is the latent variable reconstructed by the decoder; The anomaly score is 7. The anomaly detection method for satellite telemetry data based on graph learning according to claim 1, characterized in that Input the test set containing abnormal data into the trained abnormal detection model to obtain the abnormal detection result. Evaluating the performance of the abnormal detection model using evaluation metrics includes: The evaluation metrics include where TP is the true positive, which is the number of samples correctly predicted as positive by the model; FP is the false positive, which is the number of negative samples wrongly predicted as positive by the model; FN is the false negative, which is the number of samples wrongly predicted as negative by the model; and F1-score is the harmonic mean of precision and recall.
8. A system for the graph learning-based satellite telemetry data anomaly detection method according to any one of claims 1-7, characterized in that, It includes the following modules: A preprocessing module, configured to input satellite telemetry data and preprocess the satellite telemetry data, where the preprocessing includes noise reduction, missing value imputation, and normalization, to obtain preprocessed satellite telemetry data; A graph learning construction module, configured to construct a dynamic graph learning module to adaptively learn the initial relationships of the preprocessed satellite telemetry data and obtain the graph structure among multiple variables of the preprocessed satellite telemetry data; A spatio-temporal feature extraction module, configured to extract the spatial and temporal features of the preprocessed satellite telemetry data based on the graph structure; A data reconstruction module, configured to divide the preprocessed satellite telemetry data into a training set and a test set. The training set is used for training the abnormal detection model, and the features of the training set are learned based on a variational autoencoder; and A performance evaluation module, configured to input the test set containing abnormal data into the trained abnormal detection model to obtain the abnormal detection result, and evaluate the performance of the abnormal detection model using evaluation metrics.
9. A computer system, characterized in that, It includes: A processor, configured to execute machine-readable instructions; A graphics card with an artificial intelligence chip, configured to train the method for abnormal detection of satellite telemetry data based on graph learning; and A memory, configured to store machine-readable instructions, and the machine-readable instructions, when executed by the processor and / or the graphics card, execute the steps of the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, On which machine-readable instructions are stored, and the machine-readable instructions, when executed by the processor, execute the steps of the method according to any one of claims 1-7.