Intrusion detection method of food processing remote control system

By deploying edge data acquisition nodes in the food processing system and building multimodal data sets, performing timing encoding and physical constraints, the robustness and consistency of intrusion detection in the food processing process in the prior art is solved, and high-precision intrusion detection and security guarantee are achieved.

CN120342690AActive Publication Date: 2025-07-18GUANGDONG XIANHUA TECH CO LTD

Patent Information

Application Number
CN202510484731.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-18
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

The existing technology lacks the ability to model the correlation relationship between actual physical process parameters and equipment behavior in food processing, cannot effectively couple process states and invasion behavior, it is difficult to identify abnormal behaviors hidden by tiny perturbations, and the model generalization ability is insufficient, so it is unable to adapt to mutated attacks in complex industrial scenarios.

Method used

By deploying edge data acquisition nodes, synchronously collecting PLC control instructions and sensor data, building a multimodal food processing data set, performing timing encoding and injecting physical constraints, extracting weak nodes of the food processing system, building a food processing remote intrusion detection model, and using multi-dimensional detection indicators for intrusion detection.

Benefits of technology

It realizes high-precision intrusion detection of food processing systems in remote environments, improves the recognition and response efficiency of abnormal behaviors, and enhances the system's security guarantee capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342690A_ABST
    Figure CN120342690A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intrusion detection, in particular to an intrusion detection method of a food processing remote control system. The method comprises the following steps: deploying an edge data acquisition node, synchronously acquiring a PLC control instruction and sensor data, and generating a multi-modal industrial data set; constructing an industrial protocol network by using the multi-modal food processing data set; performing time sequence coding on the food processing protocol network, and injecting food processing physical constraints to obtain food processing time sequence-constraint feature data; therefore, through a mode of combining multi-modal data fusion and physical constraint embedding, the problems that a traditional intrusion detection method based on a single data source or static characteristics is poor in detection robustness and weak in physical consistency in a dynamic processing environment are solved; and the intrusion detection accuracy and the safety guarantee capability of the food processing system in a remote environment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intrusion detection, and particularly to an intrusion detection method for a remote control system of food processing. Background Art

[0002] Existing technologies generally lack the ability to model the correlation between actual physical process parameters (such as temperature, pressure, valve state, etc.) and equipment behavior during food processing, and cannot effectively couple and judge the process state and intrusion behavior; secondly, traditional intrusion detection methods often rely on static rules or historical attack features, and cannot cope with the strategy of attackers hiding abnormal behavior through small perturbations in the food processing control system, resulting in insufficient response ability to low-frequency or slow attacks; thirdly, current technologies rarely consider the hierarchical structure inside the food processing system, such as the linkage rules between device-level, process-level, and production line-level data, thus limiting the ability of multi-granularity intrusion clue fusion and attack path recognition; in addition, existing methods lack an abnormal recognition mechanism based on physical constraints, and have extremely poor recognition effects on attack behaviors that achieve the purpose of physical deception by tampering with sensor or controller signals, and are easily disguised as legal states to avoid detection; finally, current technologies generally ignore the problem of scarce attack samples during the model training process, resulting in poor generalization ability of the model and being difficult to adapt to variant attacks in complex industrial scenarios. Summary of the Invention

[0003] Based on this, it is necessary to provide an intrusion detection method for a remote control system of food processing to solve at least one of the above technical problems.

[0004] To achieve the above object, an intrusion detection method for a remote control system of food processing, the method includes the following steps:

[0005] Step S1: Deploy edge data acquisition nodes, synchronously collect PLC control instructions and sensor data, and generate a multi-modal food processing data set;

[0006] Step S2: Use the multi-modal food processing data set to construct a food processing protocol network; perform time series encoding on the food processing protocol network, and use the remote control system for binary mask hard constraints to obtain food processing time series-constrained feature data;

[0007] Step S3: Mark and extract system weak points according to the food processing time series-constrained feature data to obtain food processing system weak nodes; use the food processing time series-constrained feature data and food processing system weak nodes to construct a food processing remote intrusion detection model;

[0008] Step S4: Construct food processing detection indicators based on the food processing remote control system; perform intrusion detection on the food processing remote intrusion detection model using multi-dimensional detection indicators to obtain a food processing intrusion detection report.

[0009] The beneficial effects of the present invention are as follows. By deploying edge data acquisition nodes, PLC control instructions and sensor observation data are synchronously obtained in real time, forming a multi-modal industrial data set covering the device instruction layer and the perception layer. At the data level, heterogeneous information such as control logic, physical state, and process behavior is effectively fused, making the device behavior and physical process in the food processing process have associativity and traceability. Further, an industrial protocol network is constructed based on this multi-modal data, and a multi-scale time series coding technology is introduced to capture the dynamic evolution law in the processing process. By injecting physical constraint parameters of food processing, the collaborative embedding of data-driven and domain knowledge constraints is realized, ensuring that the extracted features not only have the expression ability of time series changes but also can reflect the physical consistency and device response law in the food processing process. On this basis, key control nodes are extracted using time series-physical constraint feature data, and the core control points in the food processing process are effectively identified from the data structure level, which helps to construct a remote intrusion detection model with local sensitivity and global relevance. This model conducts refined evaluation by introducing multi-dimensional detection indicators, including dimensions such as time response consistency, physical state deviation rate, and abnormal instruction frequency, forming a complete data-driven food processing safety analysis framework, improving the detection accuracy and response efficiency of abnormal behaviors. Therefore, the present invention solves the problems of poor detection robustness and weak physical consistency of traditional intrusion detection methods based on single data sources or static features in dynamic processing environments by combining multi-modal data fusion and physical constraint embedding, improving the intrusion detection accuracy and security guarantee ability of the food processing system in a remote environment.

[0010] Preferably, step S1 includes the following steps:

[0011] Step S11: Collect operation codes and food processing process parameters with a collection frequency greater than or equal to 200 Hz to generate PLC instruction data;

[0012] Step S12: Set a temperature sensor with 16-bit ADC quantization to collect food processing temperature data;

[0013] Step S13: Set a vibration sensor with a sampling rate of 10 kHz to collect the three-axis acceleration waveform data of components;

[0014] Step S14: Synchronize the PLC instruction data, food processing temperature data, and the three-axis acceleration waveform data of components at a 5 ms level to construct a spatio-temporal alignment data matrix;

[0015] Step S15: Use wavelet filtering to reduce the dimensionality of the spatio-temporal aligned data matrix to obtain a multi-modal food processing dataset.

[0016] Through the joint acquisition and processing of different data sources with high frequency, high precision, and multi-channels, the present invention significantly improves the quality of industrial data and the data fusion ability in the food processing process. At the data acquisition level, the sampling frequency is set to be greater than or equal to 200 Hz to collect PLC operation codes and food processing process parameters, ensuring the high timeliness and continuity of capturing control instructions, so that the control behavior has sufficient time resolution in the data dimension; a temperature sensor with a quantization accuracy of 16-bit ADC is used to sample the key temperature states during the processing with high precision, effectively reflecting the changes in the thermal process; and a vibration sensor with a high sampling rate of 10 kHz is used to collect the three-axis acceleration waveform data of the components during the processing, accurately recording the minute disturbances and dynamic responses in the equipment operation state. Further, by aligning the above three types of heterogeneous data with a 5 ms time window, a spatio-temporal unified data matrix is constructed, realizing the synchronous fusion of control instructions, temperature changes, and mechanical vibrations at the data level, providing a solid data foundation for subsequent feature extraction and dynamic correlation analysis. Using wavelet filtering to perform multi-scale dimensionality reduction processing on the high-dimensional spatio-temporal aligned data can retain key frequency components and abnormal fluctuation signals, while reducing data redundancy and computational complexity, thus forming a multi-modal industrial dataset with complete semantics, good physical consistency, and less noise interference. This dataset not only realizes the fine-grained modeling of the entire food processing process, but also significantly enhances the system's perception ability of processing anomalies, structural responses, and process deviations, providing high-quality data support for intelligent monitoring, fault warning, and remote diagnosis.

[0017] Preferably, the construction of the food processing protocol network using the multi-modal industrial dataset in step S2 includes the following:

[0018] Parse the OPC-UA protocol fields according to the PLC instruction data to obtain device node label data;

[0019] Extract communication frequency data according to the three-axis acceleration waveform data of the components;

[0020] Map the device node label data to a low-dimensional vector to obtain node low-dimensional vector data;

[0021] Define the initial edge weights according to the communication frequency data; use the initial edge weights to construct a network for the node low-dimensional vector data, and verify the graph structure with the industrial protocol rule IEC 62443, thereby obtaining the food processing protocol graph structure network.

[0022] By parsing and extracting the OPC-UA protocol fields from the PLC instruction data, the present invention can restore the device control logic and node communication structure from the data communication content, forming device node label data with semantic directivity. Secondly, by performing time-frequency analysis on the three-axis acceleration waveform data of components, the communication frequency characteristics are extracted, effectively revealing the coupling relationship between the dynamic behavior of the device under different working conditions and the communication frequency response. On this basis, the device node label data is vectorized and mapped to form a node representation in the low-dimensional embedding space, enabling the original discrete labels to have computability and similarity measurement capabilities at the data level. Furthermore, an initial edge weight is constructed based on the communication frequency data, enabling the network connection structure to have a physical response basis and dynamic feature support in modeling. The graph structure constructed in this way not only maintains the spatio-temporal correspondence relationship between the device control and response mechanisms, but also introduces the industrial protocol rule IEC 62443 for structure verification, effectively removing potential illegal structures and redundant edges in the communication path, and ensuring the protocol consistency and security integrity of the network structure. The finally formed industrial protocol graph structure network realizes the multi-dimensional collaborative expression from control commands, physical responses to protocol specifications at the data level, improves the semantic accuracy and structure analysis ability of the food processing system to understand the behavior of edge nodes, and lays a high-quality data foundation for subsequent intelligent identification, anomaly detection and control optimization.

[0023] Preferably, the time series encoding of the food processing protocol network in step S2 and the injection of food processing physical constraints include the following:

[0024] The multi-modal food processing data set is divided into data extractions with different granularities according to the sliding window length to obtain multi-scale time series hierarchical data, where the multi-scale time series hierarchical data includes device-level granularity data, process-level granularity data, and production line-level granularity data; the division length is:

[0025] When the sliding window is 10 s, the instantaneous fluctuation characteristics of the valve switching frequency are extracted to obtain device-level granularity data;

[0026] When the sliding window is 5 min, the synchronization data of the steam valve and the temperature sensor during the sterilization stage is extracted to obtain process-level granularity data;

[0027] When the sliding window is 1 h, the energy consumption trend and device degradation data of the motor current energy consumption are extracted to obtain production line-level granularity data;

[0028] Time series encoding is performed according to the multi-scale time series hierarchical data to obtain multi-scale encoded data;

[0029] Binary mask hard constraints are imposed on the multi-scale encoded data using a remote control system to obtain food processing time series-constraint feature data.

[0030] Through the use of a sliding window mechanism to perform time series partitioning at different granularities on a multi-modal industrial dataset, the present invention realizes the dynamic expression and structural reconstruction of data at three levels: the device level, the process level, and the production line level, significantly enhancing the hierarchical modeling ability of time series behavior in the food processing process. During the data extraction process, the 10-second sliding window focuses on the fast response characteristics of control behavior, and can accurately capture instantaneous fluctuation data such as valve switching frequencies, forming high-frequency time series features reflecting changes in the device action state; the 5-minute window covers a typical process cycle, and extracts synchronization and process coordination data for the dynamic coupling relationship between the steam valve action and the temperature sensor feedback during, for example, the sterilization stage, thereby forming process-level granularity features; while the 1-hour window reflects the energy consumption trend and long-term performance changes of the overall system operation, such as the motor current fluctuation trend and the equipment degradation process, and then constructs production line-level feature data reflecting the operation efficiency and health status of the entire process. By uniformly encoding the time series hierarchical data at the above different granularities, key dynamic features at each time level can be extracted through multi-scale time series encoding technology, achieving cross-scale alignment and feature fusion in the time dimension. Further, embedding constraint information in the physical process into the multi-scale encoded data, such as processing physical laws like thermal inertia, energy conservation, and mechanical response delay, can guide the physical consistency and context dependence of model learning at the data level, improving the recognition ability for problems such as process anomalies, equipment failures, and system coordination deviations. Overall, this method forms a system with parallel strong physical constraints and multi-scale expressions in data structure construction and time series feature fusion, providing a feature data basis with high robustness, high resolution, and physical semantic support for subsequent intelligent analysis tasks.

[0031] Preferably, performing time series encoding according to the multi-scale time series hierarchical data includes the following:

[0032] Perform millisecond-level fluctuations on the device-level granularity data with a length of 3 and a step size of 1, and construct a first-order direct connection device convolution kernel to obtain the ST-GCN device branch layer;

[0033] Perform a complete sub-process stage analysis on the process-level granularity data with a length of 15 and a step size of 5, and construct a device group global convolution kernel to obtain the ST-GCN sub-process branch layer;

[0034] Perform daily degradation trend extraction on the production line-level granularity data with a length of 60 and a step size of 20, and construct a global system convolution kernel to obtain the ST-GCN global branch layer;

[0035] Use the gated recurrent unit formula to perform hierarchical feature fusion on the ST-GCN device branch layer, the ST-GCN sub-process branch layer, and the ST-GCN global branch layer, and perform time series encoding to obtain multi-scale encoded data, where the gated recurrent unit formula is as follows:

[0036] h t+1 = GRU(h t , ST-GCN(A t , X t ));

[0037] Among them, h t+1 represents the implicit memory of the model at the time step, h t represents storing historical information, ST-GCN represents the spatio-temporal graph convolutional network, A t represents the adjacency matrix, X t represents the node feature matrix.

[0038] The present invention performs time slicing on industrial data at the device level, process level, and production line level through a multi-granularity sliding window mechanism, and constructs a hierarchical spatio-temporal graph convolutional network (ST-GCN) model to achieve dynamic modeling and feature extraction of industrial behaviors at multiple time scales. At the data level, device-level granularity data is divided into high-frequency fine-grained data in the way of length 3 and step size 1, which can capture the device operation fluctuation characteristics under second-level perturbations, establish a tight local dynamic response relationship, and extract local spatio-temporal correlation information through the ST-GCN branch network; process-level granularity data is divided in the way of length 15 and step size 5, covering the complete process sub-process interval, enabling the model to identify device collaborative actions and stage feature evolution at the medium scale level and extract medium-range dependence relationships; production line-level granularity data is sliced and analyzed in the way of length 60 and step size 20, focusing on the long-term operation trend of the device group and the system performance degradation characteristics, so as to extract the data patterns of system-level stability and long-term behavior changes. The spatio-temporal slices of the above three granularities are respectively subjected to convolutional encoding processing through constructing ST-GCN local branches, sub-process branches, and global branch networks, and a gated recurrent unit (GRU) is introduced in the control link for historical state memory and information fusion in the time sequence dimension, constructing multi-scale time sequence encoded data with time continuity, spatial topological structure, and process logic constraints. Especially at each moment, the current ST-GCN encoding state and historical hidden information are integrated through GRU to ensure that the model has time sequence consistency and feature transfer ability for different scale information at the data level. Generally speaking, this method realizes multi-granularity analysis and encoding of local rapid perturbations, phased process behaviors, and global system trends at the data level, effectively improving the expression integrity and modeling accuracy of industrial data in the time, space, and process logic dimensions.

[0039] Preferably, step S3 includes the following steps:

[0040] Step S31: Mark and extract the system weak points according to the food processing time sequence-constraint feature data to obtain the weak nodes of the food processing system;

[0041] Step S32: Construct a perception intrusion detection model using food processing time-series - constraint feature data and weak nodes of the food processing system, and create adversarial sample training data;

[0042] Step S33: Conditionally optimize the perception intrusion detection model using the adversarial sample training data, and incrementally update it with the key nodes of the food processing system to obtain a food processing remote intrusion detection model.

[0043] Through in-depth analysis of the food processing time-series - constraint feature data, the present invention first extracts key control points in the system that have a high degree of control sensitivity and strong correlation with process constraints, achieving precise positioning and node screening of high-risk decision-making links during the system operation process at the data level, and forming a set of key nodes of the food processing system with priority detection value. On this basis, combined with the dynamic behavior characteristics and physical state transition information of the context of the key nodes, a perception-level intrusion detection model is constructed, making the boundary division between the normal process state and the potential abnormal state of the model at the data level have physical rationality and temporal coherence. To enhance the robustness of the model in real attack scenarios, adversarial sample training data is further constructed based on the original features, generating confusable data samples by injecting micro-perturbations, challenging and expanding the model recognition boundary without destroying the physical logic of the process. By training and optimizing on the adversarial samples, the model can adapt to various minor anomalies, gradually evolving attack postures, and stealthy operation behaviors at the data level, thereby improving the sensitivity of anomaly detection and the ability to suppress misjudgments. In addition, to cope with process changes and node dynamic evolution during food processing, the model introduces an incremental update mechanism with key nodes as the core, realizing continuous learning and knowledge supplementation of newly emerging features within the time window at the data level, effectively enhancing the model's adaptability to structural changes and control strategy adjustments in heterogeneous data scenarios. Overall, this method is based on feature extraction, strengthened by adversarial training, and led by key nodes, realizing a complete data closed-loop processing flow from high-dimensional feature fusion, abnormal boundary optimization to dynamic evolution of knowledge structure, and improving the real-time performance, accuracy, and sustainable update ability of the remote intrusion detection model in the intelligent control scenario of food processing.

[0044] Preferably, step S32 includes the following steps:

[0045] Step S321: Construct a three-level feature curve of equipment - process - production line for the food processing time-series - constraint feature data;

[0046] Step S322: Conduct weighted feature curve slope analysis on the three-level feature curve of equipment - process - production line, and construct a perception intrusion detection model;

[0047] Step S323: Obtain the training data set; input the training data set into the perception intrusion detection model for white-box attack simulation, and perform temperature perturbation to obtain adversarial sample training data.

[0048] Through the hierarchical processing of food processing time-series - constraint feature data, the present invention first constructs three-level feature curves at the device level, process level, and production line level, realizing hierarchical structure modeling in terms of data dimensions, and then enabling coupled analysis and correlation modeling of dynamic behaviors at different scales. Among them, the device-level feature curve mainly reflects the response characteristics of the micro control unit, the process-level feature curve reflects the physical parameter change process under the cooperation of multiple devices, and the production line-level feature curve captures the macroscopic evolution trajectory of energy consumption and degradation trend during long-term process operation. By applying different weights to these three-level feature curves and introducing a curve slope analysis mechanism at the data level, the gradient trend and mutation characteristics of the system operation state under time-series changes are effectively captured, enabling the perception intrusion detection model to not only have the overall perception ability of abnormal states but also have the dynamic expression ability of the multi-layer response structure caused by tiny perturbations. After constructing the perception intrusion detection model, a white-box attack simulation mechanism is introduced, and the training data set is input into the model in a controllable manner and its structure parameters are opened, so as to explore the vulnerable boundary of the model to potential attacks driven by data. On this basis, temperature perturbation is applied to simulate abnormal conditions at the physical layer, generating adversarial sample training data with realistic attack characteristics and model misleading ability, enhancing the diversity and attack coverage rate of the training set from the data level, and effectively enhancing the adaptability and robustness of the model to complex attack scenarios. Overall, this method enhances the ability of the perception intrusion detection model to capture multi-scale dynamic anomalies of the system through three data mechanisms: hierarchical feature construction, weighted slope analysis, and adversarial sample generation, solves the problem of insufficient recognition performance of traditional intrusion detection methods in dealing with cascading attack and temperature control perturbation scenarios, and improves the comprehensive detection ability of the system for multi-level and multi-source intrusion behaviors.

[0049] Preferably, step S4 includes the following steps:

[0050] Step S41: Construct food processing detection indicators based on the food processing remote control system;

[0051] Step S42: Obtain historical attack logs; use multi-dimensional detection indicators to perform intrusion detection on the food processing remote intrusion detection model and historical attack logs to obtain multi-dimensional intrusion detection evaluation data;

[0052] Step S43: Generate a high-frequency attack portrait of food processing according to the multi-dimensional intrusion detection evaluation data to obtain a high-frequency attack portrait of food processing; use the high-frequency attack portrait of food processing to supplement the system firewall vulnerabilities and generate a food processing intrusion detection report.

[0053] The present invention significantly improves the recognition ability and discrimination accuracy of the model for complex intrusion behaviors by introducing a multi-dimensional detection index system to conduct structural evaluation and attack response analysis on the food processing remote intrusion detection model. Specifically, the multi-dimensional detection indexes cover multiple dimensions such as detection accuracy, response delay, abnormal threshold offset, degree of deviation from physical constraints, and change in node behavior confidence. Data observation points are set both at the output layer of the model and on the time axis to ensure the consistency of abnormal discrimination of the model in terms of time dynamics and spatial distribution. After obtaining the historical attack logs, this method further conducts joint analysis of the multi-dimensional detection indexes and the log data through a data alignment and feature reconstruction mechanism, thereby constructing multi-dimensional intrusion detection evaluation data. This evaluation data not only includes traditional binary classification results but also introduces the temporal distribution characteristics of attack events, interference mode annotations, and physical-side impact quantification parameters, realizing multi-angle and multi-level analysis of intrusion behaviors. On this basis, frequency analysis and clustering algorithms are used to extract high-frequency attack pattern features from the evaluation data to generate a high-frequency attack portrait of food processing. This portrait can represent information such as the triggering conditions, attack paths, and response results of attack behaviors that repeatedly occur in the target system, which is an abstract expression of attack patterns at the data level. Finally, based on this attack portrait, the system firewall rules and response strategy library are further updated to supplement the vulnerability types not covered or repeatedly ineffective in the historical logs, thereby enhancing the forward-looking and adaptive defense capabilities of the intrusion detection system. This method is based on multi-dimensional data fusion, temporal log parsing, and attack portrait extraction, realizing a closed-loop optimization from detection evaluation to defense feedback, effectively solving the problems of single-dimensional traditional intrusion detection results, lagging model updates, and static firewall responses, and improving the response speed and defense coverage breadth of the food processing system in the face of high-frequency attack events.

[0054] Preferably, the construction of the food processing detection indexes in step S41 includes the following steps:

[0055] Based on the food processing remote control system, conduct equipment-level instantaneous attack analysis to obtain the instantaneous attack analysis trend; mark the key trends of the instantaneous attack analysis trend and generate instantaneous attack detection indexes;

[0056] Extract the temperature-pressure mismatch alarm time-consuming data based on the food processing remote control system; conduct data mapping on the temperature-pressure mismatch alarm time-consuming data and calculate the average time-consuming to obtain the process-level collaborative detection indexes;

[0057] Extract the data during the sterilization stage of the food processing remote control system to obtain the food processing sterilization temperature data; conduct complete sterilization rule detection based on the food processing sterilization temperature data to obtain the rule coverage detection indexes.

[0058] The present invention realizes the refined expression and structural quantification of the detection ability at the data level by performing multi-level and multi-perspective data analysis and index reconstruction on the output results of the food processing remote intrusion detection model, effectively enhancing the response sensitivity and recognition breadth of the system to various types of attack behaviors. Specifically, the device-level instantaneous attack analysis captures the fluctuation trend caused by abnormal PLC instructions, sensor response delays, or sudden changes in device behavior with a millisecond-level sampling granularity, generates an instantaneous attack analysis trend, and forms a trend marker through joint feature modeling of the fluctuation slope and duration, thereby constructing an instantaneous attack detection index reflecting sudden intrusion behaviors; at the process level, this method extracts the non-linear corresponding data between temperature and pressure in the key stage, constructs a response time-consuming curve for alarm events, performs mapping transformation on the data and statistically analyzes its stability characteristics, thereby constructing a process-level collaborative detection index characterizing the abnormal response performance of process collaboration; at the system level, further extracts the change data of the core parameter, i.e., the sterilization temperature, in the sterilization stage, compares it with the preset sterilization process rule library, and constructs a rule coverage detection index using the rule matching degree to measure the completeness of the detection model in covering and constraining the recognition of attack behaviors in complex process stages. Finally, the three types of detection indexes comprehensively evaluate the system from dimensions such as local response, stage collaboration, and full-process rule adaptation, and complete the construction of multi-dimensional detection indexes by setting a weighted fusion strategy, forming a unified quantitative criterion to support application scenarios such as model optimization, attack warning, and policy feedback. This data construction path has the characteristics of clear hierarchy, traceable source, and complementary features, significantly improving the multi-dimensional expression ability of the intrusion detection system for attack dynamics, process complexity, and rule adaptability, overcoming problems such as the limitations of single-dimensional detection indexes of traditional models, lack of response collaboration mechanisms, and process constraint desensitization, and enhancing the security monitoring efficiency and protection reliability of the food processing system in complex industrial scenarios.

[0059] Preferably, step S42 includes the following steps:

[0060] Step S421: Obtain historical attack logs;

[0061] Step S422: Use the food processing remote intrusion detection model and historical attack logs to perform detection according to the instantaneous attack detection index. When the recognition rate of abnormal valve switching within 10 s is less than or equal to 75%, an alarm is triggered, and an instantaneous attack detection log is generated;

[0062] Step S423: Use the food processing remote intrusion detection model and historical attack logs to calculate the average mismatch time. If it is greater than or equal to the process-level collaborative detection index, an alarm is triggered, and a process-level collaborative detection log is generated;

[0063] Step S424: Use the coverage detection index to perform sterilization process rule coverage detection on the food processing remote intrusion detection model and historical attack logs. If the temperature rule coverage is less than 100%, an alarm is triggered and a physical compliance detection log is generated;

[0064] Step S425: Evaluate the intrusion detection results of the instantaneous attack detection log, the process-level collaborative detection log, and the physical compliance detection log to obtain multi-dimensional intrusion detection evaluation data.

[0065] The present invention constructs a multi-dimensional deep interpretation mechanism for historical attack logs by introducing instantaneous indicators, collaborative response time indicators and physical rule coverage indicators, which significantly enhances the intrusion detection system's ability to analyze the evolution process of attack behavior and the ability to trace back abnormal patterns. At the data level, the mechanism first performs a line-by-line detection of the valve switching frequency recognition rate within a 10-second sliding window based on the comparison between historical attack logs and remote intrusion detection models. If it is lower than the set threshold, an instantaneous attack detection log is automatically generated. Such logs can be used to extract the response capability distribution of key equipment under short-cycle burst behavior, thereby locating the changing trend of abnormal behavior patterns at the equipment level. Furthermore, through the average mismatch time consumption index, the response time difference between collaborative variables such as temperature and pressure is statistically analyzed and compared with the process-level collaborative detection index. If the delay time is significantly abnormal, an alarm is triggered and a collaborative detection log is generated. The log reflects the degradation characteristics of the collaborative efficiency between process variables under the attack background. At the same time, the system uses the rule coverage detection method to align the process rules of the sterilization stage (such as whether the temperature curve meets the time coverage) with the model detection results. Once there is a situation where the rules are not fully covered, it is recorded as a physical compliance detection log. Such logs can reflect the characteristic performance of the weakened adaptability of system rules under multi-step attacks. Finally, this method structurally integrates the above three types of logs, extracts the characteristic responses of intrusion behaviors in multiple dimensions to form intrusion detection evaluation data, and realizes systematic retrospective evaluation of model detection effectiveness, rule adaptability, and process stability. This evaluation data not only improves the utilization efficiency of historical attack logs, but also supports subsequent model fine-tuning, defense mechanism correction, and attack portrait reconstruction. It effectively breaks through the difficulties of traditional detection systems in terms of single data hierarchy, insensitive indicator settings, and insufficient closed-loop rule responses, and provides a data foundation and strategic basis for building a dynamic and evolvable food processing industry safety system. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 A schematic flow chart of the steps of an intrusion detection method for a food processing remote control system;

[0067] Figure 2 for Figure 1 Detailed implementation steps of step S3 in FIG.

[0068] The realization, functional features and advantages of the present invention will be further described in conjunction with embodiments with reference to the accompanying drawings. Specific embodiments

[0069] The technical method of the present invention for a patent will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those skilled in the art within the scope of the present invention without creative efforts belong to the scope of protection of the present invention.

[0070] In addition, the accompanying drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the drawings represent the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor methods and / or microcontroller methods.

[0071] It should be understood that although terms such as "first" and "second" may be used here to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit may be referred to as the second unit, and similarly the second unit may be referred to as the first unit. The term "and / or" used here includes any and all combinations of one or more of the listed associated items.

[0072] To achieve the above object, please refer to Figures 1 to 2 , an intrusion detection method for a remote control system of food processing, the method comprising the following steps:

[0073] Step S1: Deploy edge data acquisition nodes, synchronously collect PLC control instructions and sensor data, and generate a multi-modal food processing data set;

[0074] Step S2: Use the multi-modal food processing data set to construct a food processing protocol network; perform temporal encoding on the food processing protocol network, and use the remote control system for binary mask hard constraints to obtain food processing temporal-constrained feature data;

[0075] Step S3: Mark and extract the weak points of the system according to the food processing temporal-constrained feature data to obtain the weak nodes of the food processing system; use the food processing temporal-constrained feature data and the weak nodes of the food processing system to construct a food processing remote intrusion detection model;

[0076] Step S4: Construct food processing detection indicators based on the food processing remote control system; use multi-dimensional detection indicators to perform intrusion detection on the food processing remote intrusion detection model to obtain a food processing intrusion detection report.

[0077] In the embodiment of the present invention, referring to Figure 1 As shown, it is a schematic diagram of the step flow of an intrusion detection method for a food processing remote control system of the present invention. In this example, the intrusion detection method for the food processing remote control system includes the following steps:

[0078] Step S1: Deploy edge data collection nodes to synchronously collect PLC control instructions and sensor data, and generate a multi-modal food processing data set;

[0079] In the embodiment of the present invention, edge computing nodes are deployed at key positions in the production site to collect control instructions from PLC (Programmable Logic Controller) and physical quantity data collected by various sensors (such as temperature, humidity, pressure, flow, etc.) in real time. To ensure the timeliness and accuracy of the data, the data collection nodes use high-performance embedded devices that can perform preliminary data processing, filtering, and compression locally to reduce the bandwidth pressure of data transmission, while improving the response speed and efficiency of the system. Secondly, PLC control instruction data usually contains information such as the operating status, execution instructions, and set targets of production equipment. By combining with sensor data, different types of time-series data are formed. These data communicate with the edge node through industrial protocols (such as Modbus, OPC UA, etc.) and are transmitted to the cloud platform or data center in real time for further processing and analysis.

[0080] Step S2: Use the multi-modal food processing data set to construct a food processing protocol network; perform time-series encoding on the food processing protocol network and use the remote control system for binary mask hard constraints to obtain food processing time-series-constrained feature data;

[0081] In the embodiments of the present invention, the construction of the industrial protocol network is based on the heterogeneous graph structure formed by different data sources in the multi-modal industrial dataset (such as PLC control instructions, sensor data, equipment status information, etc.). The nodes in this graph structure represent entities such as industrial equipment, sensors, and control instructions, while the edges represent the mutual relationships or dependencies between them. Through this graph structure, the complex relationships between various devices and sensors can be effectively captured, and the high-order dependencies and information transmission paths between nodes can be extracted through graph convolution operations. In order to make full use of the dynamic characteristics of time-series data, a multi-scale time-series coding method is adopted to process the time-series information in the industrial protocol graph. Specifically, the time-series coding technology encodes the time-series data based on the historical data of each node in the network through methods such as convolutional neural network (CNN), recurrent neural network (RNN), or long short-term memory network (LSTM) to extract the dynamic change characteristics at different time scales. In addition, for the specific application scenario of food processing, binary mask hard constraints play a crucial role in time-series modeling. Binary mask hard constraints usually refer to the physical constraints in the food processing process, such as the control requirements of physical parameters such as temperature, humidity, and reaction rate. These constraints are embedded into the time-series feature learning process in a certain mathematical form, enabling the network to maintain the rationality and interpretability of the physical process while learning the data features.

[0082] Step S3: Mark and extract the weak points of the system according to the food processing time-series-constraint feature data to obtain the weak nodes of the food processing system; construct a food processing remote intrusion detection model using the food processing time-series-constraint feature data and the weak nodes of the food processing system;

[0083] In the embodiments of the present invention, the technical means for extracting key control points is based on food processing time-series - constraint feature data, aiming to identify the control points that have the greatest impact on system performance and security from large-scale and multi-dimensional data. This process usually involves feature selection and dimensionality reduction techniques, using statistical methods (such as principal component analysis, mutual information quantification, information gain, etc.) or model-based feature selection methods (such as LASSO, random forest feature importance assessment) to screen out the most representative features. Through these techniques, it is possible to identify those time-series data points that are crucial for the food processing process, such as key parameters like temperature, humidity, pressure, etc., and their change trends in space and time. These control points directly determine the efficiency and quality of food processing. Then, based on the extracted key control points and time-series data, a remote intrusion detection model for food processing can be constructed. This model uses anomaly detection algorithms in machine learning, such as support vector machine (SVM), Isolation Forest, Autoencoder, etc., to identify abnormal patterns and intrusion behaviors in the system. At the data level, these algorithms establish a robust model by analyzing the differences between normal patterns and abnormal patterns in historical data. This model can automatically detect behaviors inconsistent with normal operations when faced with new data, thereby identifying potential intrusion risks.

[0084] Step S4: Construct food processing detection indicators based on the food processing remote control system; perform intrusion detection on the food processing remote intrusion detection model using multi-dimensional detection indicators to obtain a food processing intrusion detection report.

[0085] In the embodiments of the present invention, the core technical means for constructing multi-dimensional detection indicators is to extract different-dimensional features and performance indicators based on various data sources in the food processing process (such as sensor data, control instructions, equipment status, etc.). These detection indicators include but are not limited to the time series changes of the system, parameter fluctuations, equipment response time, sensor accuracy, deviation between control instructions and sensor data, etc., and can comprehensively reflect potential abnormal behaviors or external intrusion impacts in the food processing process. For example, the deviation degree of time series data, sudden changes in sensor readings, inconsistencies between operation instructions and feedback, etc. can all be used as components of the detection indicators. The extraction of these indicators is completed through feature-based analysis techniques (such as statistical feature extraction, signal processing methods) and model-based techniques (such as supervised learning, unsupervised learning). Next, these multi-dimensional detection indicators are used to evaluate the remote intrusion detection model, and various performance evaluation methods are adopted, such as accuracy, recall rate, F1 score, ROC curve, and AUC value, etc., to quantify the detection ability of the model. During the evaluation process, the model is compared with known intrusion behavior data to evaluate its performance in different scenarios, including the recognition ability of different types of intrusions, false alarm rate, and missed alarm rate, etc. At the same time, in order to comprehensively understand the robustness and generalization ability of the model, techniques such as cross-validation and confusion matrix can also be introduced to comprehensively evaluate the impact of different detection indicators. Finally, through the comprehensive evaluation of the model performance, a food processing intrusion detection report is generated.

[0086] Preferably, step S1 includes the following steps:

[0087] Step S11: Collect operation codes and food processing process parameters with a frequency greater than or equal to 200 Hz to generate PLC instruction data;

[0088] Step S12: Set a temperature sensor with 16-bit ADC quantization to collect food processing temperature data;

[0089] Step S13: Set a vibration sensor with a sampling rate of 10 kHz to collect the three-axis acceleration waveform data of components;

[0090] Step S14: Synchronize the PLC instruction data, food processing temperature data, and the three-axis acceleration waveform data of components at a 5 ms level to construct a spatio-temporal alignment data matrix;

[0091] Step S15: Use wavelet filtering to reduce the dimension of the spatio-temporal alignment data matrix to obtain a multi-modal food processing data set.

[0092] In the embodiments of the present invention, the acquisition frequency of the operation code and food processing process parameters is greater than or equal to 200 Hz, aiming to obtain PLC (Programmable Logic Controller) instructions and related process data in real time. The operation code data usually includes control instructions and device status information, while the food processing process parameter data includes indicators such as temperature, pressure, and flow rate. These data are collected at a high frequency to ensure that subtle operation changes can be captured, thereby providing high-resolution data support for subsequent analysis. The food processing temperature data collected by the temperature sensor is quantified by setting a 16-bit ADC (Analog-to-Digital Converter). The high resolution of the 16-bit ADC can provide more accurate temperature change information and is suitable for food processing processes with high requirements for temperature control accuracy. The data acquisition of this sensor ensures that the real-time changes in temperature can be accurately recorded to support subsequent data analysis. Regarding the acquisition of the vibration sensor, the sampling rate is 10 kHz. This sensor is used to collect the three-axis acceleration waveform data of components, aiming to capture the subtle changes in the vibration state of the device. Since vibration data usually contains rich frequency and amplitude information, the high sampling rate of 10 kHz can ensure that high-frequency vibration characteristics are captured, which helps to accurately evaluate the operating state of the device and potential failure risks. The key technical steps are data synchronization and spatio-temporal alignment. Since the sampling frequencies of different sensors (operation code, temperature, vibration) are different, time alignment is required first. By synchronizing the PLC instruction data, temperature data, and vibration data according to a time window of 5 ms level, various types of data can be aligned on the same time axis. This process is usually completed through interpolation methods or timestamp matching techniques to ensure that various types of data can accurately correspond to the same moment. The spatio-temporal aligned data matrix is reduced in dimension through wavelet filtering technology. Wavelet transform can effectively extract important features in the data from a multi-scale perspective, removing high-frequency noise and redundant information.

[0093] Preferably, the construction of the food processing protocol network using the multi-modal industrial dataset in step S2 includes the following:

[0094] Parse the OPC-UA protocol fields according to the PLC instruction data to obtain device node label data;

[0095] Extract communication frequency data according to the three-axis acceleration waveform data of components;

[0096] Map the device node label data to a low-dimensional vector to obtain node low-dimensional vector data;

[0097] Define the initial edge weights according to the communication frequency data; use the initial edge weights to construct a network for the node low-dimensional vector data, and verify the graph structure with the industrial protocol rule IEC 62443 to obtain the food processing protocol graph structure network.

[0098] In the embodiments of the present invention, when parsing PLC instruction data, the PLC instruction fields are parsed through the OPC-UA (Open Platform Communications Unified Architecture) protocol. The main objective is to extract the tag data of device nodes from the OPC-UA protocol. OPC-UA is a standard protocol for communication between industrial automation devices. By parsing its fields, detailed information about the device can be obtained, such as device identification, status, control instructions, etc. This process usually uses a specific protocol parsing library that can extract the key fields in the PLC control instructions, and then obtain the device node tag data. The communication frequency data is extracted according to the three-axis acceleration waveform data of the components. This process involves performing frequency-domain analysis on the three-axis acceleration signals collected by the vibration sensor, mainly through Fourier transform or other spectrum analysis techniques to calculate the vibration frequency of the components. The communication frequency in the vibration data can reveal the frequency characteristics and dynamic changes during the operation of the device, and has high timeliness and correlation, which can provide a basis for assigning weights to the edges in the subsequent network. After obtaining the device node tag data and the communication frequency data, node low-dimensional vector mapping is performed. Specifically, the device node tag data is mapped to a low-dimensional vector space through an embedding technique (such as word embedding or graph-based embedding method). This process can be achieved by using classical embedding algorithms (such as PCA, t-SNE, or graph-based node embedding methods such as DeepWalk or Node2Vec) to compress the original high-dimensional node information into a low-dimensional vector, which is convenient for the subsequent construction and analysis of the network. Then, according to the communication frequency data, the initial edge weights are defined. In a network, the weight of an edge usually reflects the strength of the relationship or the interaction frequency between nodes. By using the communication frequency between devices as the weight of the edge, the degree of mutual influence between each node can be represented. Devices with high communication frequency have a stronger interaction relationship or a greater impact on the system performance. Therefore, the corresponding edge weight is larger. The network is constructed by using the defined initial edge weights and the node low-dimensional vector data. This step models the device nodes and their relationships as a graph structure through a graph neural network (GNN) or other graph-based construction methods. In the graph, nodes represent devices, and edges represent the communication relationships or dependencies between devices. This graph structure can be used to capture information such as the interaction between devices, data flow, and control command transmission. Finally, to ensure the rationality and security of the graph structure, the constructed network is verified using the industrial protocol rule IEC 62443. IEC 62443 is a standard for the security of industrial automation and control systems, which provides requirements for device communication, data protection, and system security.

[0099] Preferably, the time series encoding of the food processing protocol network and the injection of food processing physical constraints in step S2 include the following:

[0100] The multi-modal food processing dataset is divided into data extractions with different granularities according to the sliding window length to obtain multi-scale time series hierarchical data, where the multi-scale time series hierarchical data includes device-level granularity data, process-level granularity data, and production line-level granularity data; the division lengths are as follows:

[0101] When the sliding window is 10s, the instantaneous fluctuation characteristics of the valve switching frequency are extracted to obtain device-level granularity data;

[0102] When the sliding window is 5 minutes, the synchronization data of the steam valve and the temperature sensor during the sterilization stage is extracted to obtain process-level granularity data;

[0103] When the sliding window is 1 hour, the energy consumption trend and equipment degradation data of the motor current are extracted to obtain production line-level granularity data;

[0104] Time series encoding is performed on the multi-scale time series hierarchical data to obtain multi-scale encoded data;

[0105] Binary mask hard constraints are imposed on the multi-scale encoded data using a remote control system to obtain food processing time series-constrained feature data.

[0106] In the embodiments of the present invention, for the division of multi-modal industrial data sets, a sliding window method is used to extract data at different granularities. The sliding window is a commonly used method for segmenting time series data. It extracts the data features within the window by setting a window of a fixed length in the data stream and sliding it at a certain step size. Specifically, when the length of the sliding window is set to 10 seconds, the instantaneous fluctuation features of the valve switching frequency are mainly extracted. By analyzing these high-frequency instantaneous changes, device-level granularity data can be obtained, reflecting the rapid dynamic characteristics of a single device. For a window length of 5 minutes, it is used to extract the synchronization data between the steam valve and the temperature sensor during the sterilization stage, mainly focusing on the time synchronization and parameter changes in the process, and then generating process-level granularity data to reveal the key changes in the entire process. Finally, when the window length is 1 hour, the energy consumption trend of the motor current and the equipment degradation information are mainly extracted. This long-time-scale data reflects the overall trend at the production line level and the long-term health status of the system operation, thus obtaining production line-level granularity data. Then, after obtaining these multi-scale time series data, multi-scale time series encoding is performed. The purpose of time series encoding is to convert time series data at different scales into a format suitable for model processing. In multi-scale time series encoding, deep learning methods such as convolutional neural networks (CNNs) or recurrent neural networks (RNNs), especially long short-term memory networks (LSTMs), are usually used to capture the long-term and short-term dependence characteristics in the time series. Multi-scale encoding can process data from different granularities simultaneously, enabling the model to fuse information at the device level, process level, and production line level during processing, thereby obtaining a more comprehensive system performance. Finally, after the time series encoding is completed, the injection of food processing physical constraints is performed. Physical constraint injection is a method of introducing domain knowledge into a machine learning model. By combining known physical rules (such as the relationship between temperature, pressure, and equipment load) with time series data, the model's understanding of the actual production process is enhanced. For example, the temperature change range can be adjusted through constraint conditions, or the output can be restricted through an equipment performance degradation model, thereby obtaining food processing time series-constrained feature data.

[0107] Preferably, the time series encoding according to the multi-scale time series hierarchical data includes the following:

[0108] Perform millisecond-level fluctuations on the device-level granularity data with a length of 3 and a step size of 1, and construct a first-order direct connection device convolution kernel to obtain the ST-GCN device branch layer;

[0109] Perform a complete sub-process stage analysis on the process-level granularity data with a length of 15 and a step size of 5, and construct a device group global convolution kernel to obtain the ST-GCN sub-process branch layer;

[0110] Extract the daily degradation trend of production line-level granularity data with a length of 60 and a step size of 20, and construct a global system convolution kernel to obtain the ST-GCN global branch layer;

[0111] Use the gated recurrent unit formula to perform hierarchical feature fusion on the ST-GCN device branch layer, the ST-GCN sub-process branch layer, and the ST-GCN global branch layer, and perform temporal encoding to obtain multi-scale encoded data. The gated recurrent unit formula is as follows:

[0112] h t+1 = GRU(h t , ST-GCN(A t , X t ));

[0113] Among them, h t+1 represents the hidden memory of the model at the time step, h t represents storing historical information, ST-GCN represents the spatio-temporal graph convolutional network, A t represents the adjacency matrix, and X t represents the node feature matrix.

[0114] In the embodiment of the present invention, the core of this technical means is to realize the hierarchical feature extraction and fusion of industrial multi-modal data from the instantaneous behavior of the microscopic device level to the long-term trend of the macroscopic production line level through the collaborative architecture of the multi-scale spatio-temporal graph convolutional network (ST-GCN) and the gated recurrent unit (GRU). Specifically, first, for device-level granularity data (such as high-frequency sensor signals within a 10-second window), a spatio-temporal convolution kernel with a length of 3 and a step size of 1 is used, combined with a first-order adjacency matrix (only including the physical or control relationship of directly connected devices), to construct the ST-GCN device branch layer. Its adjacency matrix A t dynamically reflects the instantaneous interaction intensity between devices (such as the direct coupling weight between the valve switch signal and the temperature sensor), and the node feature matrix X tIt contains millisecond-level fluctuation features (such as change rate, instantaneous extreme values), and captures abnormal patterns such as equipment jitter and drift through short-time convolution kernels. For process-level granularity data (such as the device collaboration time series within a 5-minute window), a convolution kernel with a length of 15 and a stride of 5 covers the complete process sub-stage (such as the sterilization heating period), and a ST-GCN sub-process branch layer is constructed based on the global adjacency matrix of the device group (defining cross-device collaboration rules through a process knowledge graph, such as the strong association weight between the steam valve and the temperature sensor). The node feature matrix fuses the state correlation coefficient and the phase synchronization index of the device group. The spatial convolution kernel enhances the cross-device collaboration relationship modeling through high-order neighborhood aggregation. In the production line-level granularity data (such as the energy consumption and degradation trend within a 1-hour window), a long-time convolution kernel with a length of 60 and a stride of 20 is adopted, combined with the global adjacency matrix (constructed based on the historical material flow and energy transfer ratio between subsystems). Through the graph attention mechanism, the weights of the production line subsystems are dynamically adjusted (such as the priority of high-energy consumption units in degradation modeling). The node feature matrix contains long-term indicators such as trend slope and degradation index. Subsequently, through the gated recurrent unit (GRU), the multi-scale output features of the device, sub-process, and global branch layers are cross-level fused. The hidden state h t of the GRU serves as a temporal memory unit, receiving the spatio-temporal encoding results of the current STGCN branch at each time step, dynamically screening the relevance between the historical state and the current features through the update gate and the reset gate, and finally outputting the multi-dimensional fused feature h t+1 , achieving a full-scale joint representation of device instantaneous anomalies, process collaboration deviations, and production line health decline. In this process, the adjacency matrix A t of each layer and the node feature X t both strictly follow industrial physical constraints (such as equipment safety thresholds, process stage rules), ensuring the consistency between feature generation and actual production logic, thereby providing a high-fidelity multi-modal data basis for subsequent intrusion detection and system optimization.

[0115] Of particular importance, the binary mask hard constraints using the remote control system include:

[0116] Generating mask constraint control instructions according to the remote control system;

[0117] Using the mask constraint control instructions to perform binary mask hard constraint filtering on the multi-scale encoded data to obtain forced discard of illegal feature values;

[0118] Using the forced discard of illegal feature values to construct a soft constraint gradient rule to obtain forward constraint filtered data;

[0119] Performing reverse physical knowledge law enhancement according to the forward constraint filtered data to obtain food processing time series-constrained feature data.

[0120] In the embodiments of the present invention, the multi-scale encoded data is subjected to binary masking, that is, according to the equipment operation state constraints in the food processing process (such as valve state, temperature threshold, upper and lower limits of current, etc.), a masking matrix corresponding to the time axis is constructed, where 1 represents the normal eigenvalue that conforms to the process logic, and 0 represents the illegal feature points that violate the physical rules or process flows. The mask acts on the original encoded data, and all illegal feature points corresponding to 0 are directly removed through the AND operation, so as to achieve hard constraint filtering and form a data subset that forcibly discards illegal eigenvalues. After the hard constraint screening, in order to avoid insufficient expression ability caused by a sudden drop in the feature dimension, a soft constraint mechanism is further introduced. Based on the change trends and gradient slopes of different feature dimensions in the retained data, a weighted gradient rule function is established, and a forward-directed soft constraint filtering framework is constructed. This function is used to adjust the expression priorities of the remaining features, enhance the expression density of key features such as temperature change rate, pressure response delay, current fluctuation law, etc., and weaken the participation weights of edge or low-correlation features, forming a directional forward filtering feature set. Finally, based on the soft constraint results, reverse physical knowledge is fused for temporal enhancement. In this step, according to the reverse constraint logic between the physical states of food processing equipment (for example, there should be no high heat flux density during the cooling process, the pressure should be kept stable during the valve closing period, and there should be no frequent speed jumps during the stirring process, etc.), the data is scanned reversely and conditionally retrieved through a logic rule set, so as to generate reverse physical eigenvalues for enhancement and supplement the dynamic details not covered in the forward encoding.

[0121] As an example of the present invention, refer to Figure 2 shown, in this example, step S3 includes:

[0122] Step S31: Mark and extract the weak points of the system according to the food processing time series-constraint feature data to obtain the weak nodes of the food processing system;

[0123] Step S32: Use the food processing time series-constraint feature data and the weak nodes of the food processing system to construct a perception intrusion detection model and create adversarial sample training data;

[0124] Step S33: Conditionally optimize the perception intrusion detection model using the adversarial sample training data, and incrementally update it with the key nodes of the food processing system to obtain a food processing remote intrusion detection model.

[0125] In the embodiments of the present invention, key control points are extracted based on food processing time series-constraint feature data. The core of the method lies in the feature sensitivity analysis and mutation point detection of multi-dimensional time series data. In the specific operation process, methods such as gradient change, mutation rate determination, and mutual information entropy analysis are used to identify the nodes where physical quantities mutate or the control state changes significantly during the production process. These nodes are defined as the key control points in the food processing system. The identification of key control points depends on the causal dependencies in the data, the coupling strength of equipment-process, and the historical operation state change trajectory, so as to obtain the set of key nodes in the food processing system. Then, a perception intrusion detection model is constructed using the food processing time series-constraint feature data. The construction process usually uses structures such as graph attention network (GAT) or variational autoencoder (VAE) to fuse time series dynamics and structural data, model the feature patterns of multi-modal data streams under normal operating conditions, and use them as discrimination benchmarks. In the model training stage, adversarial sample training data is introduced. Through adversarial attack generation algorithms such as projected gradient descent (PGD) or Fast Gradient Sign Method (FGSM), pseudo-samples with perturbations but not significantly deviating from the true distribution are constructed. These adversarial samples and normal samples together form the training set to improve the robustness and recognition ability of the model for potential intrusion behaviors. Subsequently, the perception intrusion detection model is conditionally optimized using these adversarial sample training data. An adversarial loss function and a robustness regularization term are introduced during training to enhance the stability of the model under abnormal inputs. Finally, the model also needs to be incrementally updated through the key nodes of the food processing system, that is, by continuously accessing new key node data during the actual operation process to achieve dynamic optimization of the model structure or parameters. Incremental updates generally use online learning methods, such as using a recursively updated gradient descent algorithm or a model weight reallocation strategy based on a sliding window, to ensure that the model remains sensitive to pattern drift and control strategy adjustments during long-term operation, and finally form a food processing remote intrusion detection model.

[0126] Preferably, step S32 includes the following steps:

[0127] Step S321: Construct a three-level feature curve of equipment-process-production line for the food processing time series-constraint feature data;

[0128] Step S322: Conduct weighted feature curve slope analysis on the three-level feature curve of equipment-process-production line, and construct a perception intrusion detection model;

[0129] Step S323: Obtain a training data set; input the training data set into the perception intrusion detection model for white-box attack simulation, and perform temperature perturbation to obtain adversarial sample training data.

[0130] In the embodiments of the present invention, a three - level feature curve of equipment - process - production line for food processing time - sequence - constraint feature data is constructed. Based on the time series, key variables at different spatial levels are extracted through data - dimension layering, and curve modeling is performed. Specifically, the equipment - level feature curve is usually constructed based on the actuator actions, local temperature, or pressure response changes with high - frequency sampling; the process - level feature curve is constructed by calculating the parameter coupling degree between different process units, the temperature - control process response, and the execution delay; the production - line - level feature curve covers the energy - consumption trend, quality fluctuation, and system - stability index on a long - time scale. The construction process uses a sliding window to extract key time - sequence points, and interpolation and smoothing techniques are combined to uniformly align different dimensions, thereby ensuring the spatio - temporal comparability between data at each level. Next, weighted feature - curve slope analysis is performed on the above - mentioned three - level feature curves, aiming to capture the change rate of each feature curve under different operating states. Usually, the linear - regression sliding - window method or the first - order difference operation is used to extract the local slope change, and then different weight coefficients are assigned based on historical operating experience, so that features with large changes or sensitive responses obtain a higher modeling priority. This weighted - slope analysis can reveal the dynamic evolution process of the food - processing system under multi - level operating states and be used as input features to construct a perception - based intrusion - detection model. This model is generally trained using a lightweight neural network or an ensemble - learning structure (such as a random forest or a gradient - boosting tree), with the goal of learning the correlation between different slope - change patterns and abnormal operating conditions to form the ability to perceive intrusion or abnormal behavior. After the model is constructed, the robustness of the model is improved by obtaining a training data set and simulating a white - box attack. A white - box attack means that the attacker has full access to the model structure and parameters and can generate adversarial samples based on gradient information. In this context, the Fast Gradient Sign Method (FGSM) or the Projected Gradient Descent (PGD) method is often used to slightly perturb the input data according to the loss function to interfere with the model discrimination boundary. In addition, temperature perturbation is introduced during the attack process, that is, perturbation values within the upper and lower limits of industrial operation are injected into temperature - control - type feature variables. This perturbation operation can be achieved by superimposing Gaussian - distribution noise or fitting historical abnormal samples.

[0131] Particularly importantly, step S33 includes the following steps:

[0132] Step S331: Use the adversarial - sample training data to perform projection - gradient - descent parameter restriction on the perception - based intrusion - detection model to obtain a preliminary intrusion - optimized detection model;

[0133] Step S332: Obtain a temperature - pressure correlation table; use the adversarial - sample training data to identify the sterilization - valve state parameters of the preliminary intrusion - optimized detection model, and use the temperature - pressure correlation table for loop verification to obtain the optimized parameters of the intrusion model;

[0134] Step S333: Use the intrusion model optimization parameters to incrementally update the preliminary intrusion optimized detection model to obtain a food processing remote intrusion detection model.

[0135] In the embodiment of the present invention, by introducing an adversarial sample training data set to perform a constrained Projected Gradient Descent (PGD) operation on the perceived intrusion detection model, a perturbation amplitude limit is set for the parameter space of the model to prevent the model from failing in feature generalization or increasing the false detection rate under attack samples. The PGD method limits the weight adjustment amplitude in each round of parameter iteration, keeping the update direction within the neighborhood of the original parameters, so that the model can still stably output the attack judgment probability in the face of adversarial perturbations, thereby constructing a preliminary intrusion optimized detection model. Subsequently, a temperature-pressure correlation table is introduced as the basis for physical rule mapping, and the preliminary model is collaboratively verified and identified with the adversarial sample training data. In specific implementation, the system uses the preliminary model to automatically identify the state parameters of the sterilization valve, extracts the valve opening and closing state sequence and its corresponding temperature response change data during the sterilization process, and identifies the parameter prediction sections that do not conform to the physical laws by matching and comparing with the temperature-pressure correlation table, such as abnormal behaviors such as the continuous rise of the corresponding temperature in the valve closed state, and locates these model output intervals that deviate from the process logic. The system further constructs a correction gradient or error backpropagation amount based on the matching offset degree, generates intrusion model optimization parameters, and is used to fine-tune the sensitive feature channels and classification boundaries of the model. Finally, taking the intrusion model optimization parameters as the increment basis, input them into the preliminary intrusion optimized detection model, and complete the convergence adjustment of the remote detection model through an incremental parameter update method with a finite step size. This process maintains the stability of the model structure and only performs local updates on the weight layer or feature transformation path of the target neural channel, thereby enhancing the robustness and stability of the model in the face of perturbations of the actual physical characteristics of food processing, and finally forming a food processing remote intrusion detection model with constraint consistency and dynamic adaptability.

[0136] Preferably, step S4 includes the following steps:

[0137] Step S41: Construct food processing detection indicators based on the food processing remote control system;

[0138] Step S42: Obtain historical attack logs; use multi-dimensional detection indicators to perform intrusion detection on the food processing remote intrusion detection model and historical attack logs to obtain multi-dimensional intrusion detection evaluation data;

[0139] Step S43: Generate a high-frequency attack portrait of food processing according to the multi-dimensional intrusion detection evaluation data to obtain a high-frequency attack portrait of food processing; use the high-frequency attack portrait of food processing to supplement the system firewall vulnerabilities and generate a food processing intrusion detection report.

[0140] In the embodiments of the present invention, in the process of constructing multi-dimensional detection indicators for the food processing remote intrusion detection model, the model output is structurally extended, so that it expands from a single classification or anomaly scoring dimension to a composite index system that comprehensively reflects detection performance, response path, attack behavior, and process impact. Common multi-dimensional indicators include the confidence distribution of model determination, detection delay, alarm frequency, the mapping distance between the alarm and the device topology, the number of process nodes affected, the duration of anomalies, and the false alarm / miss rate. The construction of these indicators depends on the multi-angle comparison calculation between the model prediction results and the labels, and combines time-series sliding window statistics and event-level clustering analysis to generate multi-dimensional detection vectors. Obtaining historical attack logs and conducting matching evaluations means comparing the multi-dimensional detection indicators generated by the model under the current data with the archived attack event database. The historical attack logs contain tag information such as the event occurrence time, attack source IP, attack strategy category, target device, operation path, and handling records. By constructing a multi-dimensional space distance metric function (such as Mahalanobis distance or cosine similarity), the vector matching between the model output indicators and the label fields in the logs can be realized, so as to obtain key evaluation data such as the spatio-temporal effectiveness, behavior consistency, and process impact superposition effect of the intrusion detection results, that is, to form multi-dimensional intrusion detection evaluation data. These evaluation data not only provide a reference for comparing the model performance in actual attack scenarios, but also provide label support for further attack pattern recognition. The process of generating a high-frequency attack profile using multi-dimensional evaluation data is to perform vector clustering, frequency statistics, and behavior trajectory reconstruction on frequently occurring attack behavior patterns, and finally generate a high-frequency attack profile. This profile usually includes information such as the attacker's operation path pattern, the perturbation direction of attack parameters, the sequence of response process devices, the distribution of the impact duration, and the periodic trend of the attack occurrence time. Its generation can use clustering algorithms such as K-Means and DBSCAN to group attack events in the multi-dimensional feature space, and use time-series alignment technology to structurally represent the same type of attack events. Finally, according to the generated high-frequency attack profile, the firewall policy of the existing system is supplemented with rules. The specific method is to convert the typical attack path and the parameter perturbation range into whitelist filtering conditions, intrusion behavior feature signatures, or boundary constraint rules and embed them into the firewall policy table. This operation forms an intrusion detection report for the food processing system. This report includes a review of the model performance, the reconstruction of the high-frequency attack path, suggestions for policy enhancement, and corresponding data support entries, realizing a closed-loop update of the data-driven defense ability.

[0141] Preferably, the construction of food processing detection indicators in step S41 includes the following:

[0142] Based on the food processing remote control system, perform device-level instantaneous attack analysis to obtain the instantaneous attack analysis trend; mark the key trends of the instantaneous attack analysis trend and generate instantaneous attack detection indicators;

[0143] Extract the temperature-pressure mismatch alarm time-consuming data based on the food processing remote control system; perform data mapping on the temperature-pressure mismatch alarm time-consuming data, and calculate the average time-consuming to obtain the process-level collaborative detection index;

[0144] Extract the data during the sterilization stage of the food processing remote control system to obtain the food processing sterilization temperature data; perform a complete sterilization rule detection based on the food processing sterilization temperature data to obtain the rule coverage detection index.

[0145] In the embodiments of the present invention, in device-level instantaneous attack analysis, through time series statistics and trend extraction of the real-time determination results output by the model, the sliding window technology is used to cluster high-frequency abnormal points in the detection results and detect mutation points, so as to identify potential instantaneous attack peaks or mutation anomalies. Subsequently, a time series fitting curve is established by combining device operation state data such as current, voltage, and switch commands, and indicators such as the change rate, duration, and number of affected devices of the trend mutation are extracted to form a trend vector; further, by setting a threshold determination mechanism, the trend segments with obvious fluctuations are marked as key trends, and the characteristic values in the marked segments, such as the maximum fluctuation rate, average fluctuation energy, and fluctuation duration, are used as instantaneous attack detection indicators for structured expression. At the process level, around the collaborative logic between temperature and pressure sensors, the response delay data of temperature-pressure mismatch alarms are extracted, that is, taking the alarm trigger time point as a reference, the time taken from the occurrence of temperature deviation anomaly to the start of the pressure response mechanism is calculated to form a time stamp pair. By constructing a mapping function, the time-consuming sequence is normalized to the standard process cycle scale, and indicators such as the average mismatch time-consuming, maximum delay, and variance within multiple process cycles are statistically analyzed, so as to form a collaborative detection indicator reflecting process collaboration. Such data mapping can adopt methods such as Z-score standardization or time-normalized linear mapping. In the rule integrity detection link, taking the data in the sterilization stage as the main line, the continuous data of the temperature sensor in this stage are extracted and compared with the preset sterilization curve rules for food processing. The rules can include the time-temperature window function structure of the set temperature rise rate, stable duration, and cooling rate. By constructing a rule curve template and aligning it with the real data through Dynamic Time Warping (DTW), features such as rule interval coverage, temperature offset rate, and continuous compliance ratio can be calculated, so as to obtain the rule coverage detection indicator. Finally, the above instantaneous attack detection indicators, process-level collaborative detection indicators, and rule coverage detection indicators are vector spliced, and a weighted fusion mechanism is constructed. The weight calculation method can adopt the entropy weight method, the Analytic Hierarchy Process (AHP), or the empirical distribution estimation method based on Bayesian update. After projecting the three types of indicators into a unified indicator space, weighted summation is performed to form a unified multi-dimensional detection indicator output, providing a highly consistent and highly interpretable input structure for the subsequent evaluation and decision-making of the model.

[0146] Preferably, step S42 includes the following steps:

[0147] Step S421: Obtain historical attack logs;

[0148] Step S422: Use the food processing remote intrusion detection model and historical attack logs to detect according to the instantaneous attack detection indicators. When the recognition rate of abnormal valve switches within 10s is less than or equal to 75%, an alarm is triggered, and an instantaneous attack detection log is generated;

[0149] Step S423: Calculate the average mismatch time using the food processing remote intrusion detection model and the historical attack logs. If it is greater than or equal to the process-level collaborative detection index, trigger an alarm and generate a process-level collaborative detection log.

[0150] Step S424: Use the coverage detection index to detect the coverage rate of the sterilization process rules for the food processing remote intrusion detection model and the historical attack logs. If the temperature rule coverage rate is less than 100%, trigger an alarm and generate a physical compliance detection log.

[0151] Step S425: Evaluate the intrusion detection results of the instantaneous attack detection log, the process-level collaborative detection log, and the physical compliance detection log to obtain multi-dimensional intrusion detection evaluation data.

[0152] In the embodiments of the present invention, by loading historical attack logs, the valve control signals involved therein are replayed in time sequence, mapped into a 10-second sliding window, and the event density, switching frequency, and duration of valve state changes within each window are extracted, and compared with the real-time recognition results of the remote intrusion detection model for accuracy. When the recognition accuracy of the model for abnormal switch events within a certain window is lower than 75%, it is regarded as the trigger condition for the lower limit of the instantaneous attack detection ability, and then an instantaneous attack detection log is generated in this window, which records key indicators such as the model prediction result, actual label, detection delay, and misrecognition location. In the process collaborative detection link, the interaction timeline of temperature and pressure signals is extracted from the historical attack logs, the time points of abnormal temperature signal drift and the difference between its corresponding pressure response time are identified, and the mismatch time consumption of each event is calculated accordingly. Subsequently, all the mismatch time consumptions are weighted and averaged within the process interval, and compared with the preset process-level collaborative detection index. When the average mismatch time consumption is equal to or higher than this index, it indicates that the process collaborative response has an abnormal lag, thereby triggering a process-level alarm and generating a process-level collaborative detection log. This log contains core fields such as alarm number, mismatch event list, average mismatch time consumption, process type, and section number. In the physical compliance detection part, by calling the coverage detection index to regularize the temperature time sequence in the sterilization stage, and using the methods of sliding window matching and template comparison, it is checked whether the temperature in the historical data fully meets all the stage rules of the sterilization curve, including the heating rate, constant temperature duration, and cooling integrity. When it is detected that any stage is not fully covered or there are problems such as temperature drift, interruption, and abnormal rate deviation, it is marked as insufficient rule coverage, and a physical compliance detection log is generated. The log content includes the start and end times of the uncovered interval, missing type, rule offset value, and coverage percentage. The above three types of logs are integrated through a unified data structure standard to form multi-dimensional intrusion detection evaluation data with unified time stamps, event types, associated indicators, and model response data. This evaluation data has the structural characteristics of historical comparability, model verification, and indicator linkage, and is the basic data carrier for subsequent high-frequency attack profiling and defense mechanism generation.

[0153] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, it is intended to cover all changes falling within the meaning and scope of the equivalent elements of the application documents within the present invention.

[0154] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features invented herein.

Claims

1. An intrusion detection method for a remote control system of food processing, characterized in that, It includes the following steps: Step S1: Deploy edge data acquisition nodes to synchronously collect PLC control instructions and sensor data, and generate a multi-modal food processing data set; Step S2: Use the multi-modal food processing data set to construct a food processing protocol network; perform temporal encoding on the food processing protocol network, and use a remote control system for binary mask hard constraints to obtain food processing temporal-constraint feature data; Step S3: Mark and extract system weak points according to the food processing temporal-constraint feature data to obtain food processing system weak nodes; use the food processing temporal-constraint feature data and food processing system weak nodes to construct a food processing remote intrusion detection model; Step S4: Based on the food processing remote control system, construct food processing detection indicators; use multi-dimensional detection indicators to perform intrusion detection on the food processing remote intrusion detection model to obtain a food processing intrusion detection report.

2. The intrusion detection method of the food processing remote control system according to claim 1, characterized in that, Step S1 includes the following steps: Step S11: Collect operation codes and food processing process parameters with a collection frequency greater than or equal to 200Hz to generate PLC instruction data; Step S12: Set a temperature sensor with 16-bit ADC quantization to collect food processing temperature data; Step S13: Set a vibration sensor with a sampling rate of 10kHz to collect the three-axis acceleration waveform data of components; Step S14: Synchronize the PLC instruction data, food processing temperature data, and the three-axis acceleration waveform data of components at a 5ms level to construct a spatio-temporal alignment data matrix; Step S15: Use wavelet filtering to reduce the dimension of the spatio-temporal alignment data matrix to obtain a multi-modal food processing data set.

3. The intrusion detection method of the remote control system for food processing according to claim 1, characterized in that, The construction of the food processing protocol network using the multi-modal industrial data set in Step S2 includes: Parse the OPC-UA protocol fields according to the PLC instruction data to obtain device node label data; Extract communication frequency data according to the three-axis acceleration waveform data of components; Map the device node label data to low-dimensional vectors to obtain node low-dimensional vector data; Define initial edge weights according to the communication frequency data; use the initial edge weights to construct a network for the node low-dimensional vector data, and use the industrial protocol rule IEC 62443 to verify the graph structure, thereby obtaining a food processing protocol graph structure network.

4. The intrusion detection method of the food processing remote control system according to claim 1, characterized in that The temporal encoding of the food processing protocol network and the injection of food processing physical constraints in Step S2 include: Extract data of different granularities from the multi-modal food processing data set according to the sliding window length to obtain multi-scale temporal sequence hierarchical data, where the multi-scale temporal sequence hierarchical data includes device-level granularity data, process-level granularity data, and production line-level granularity data; the division length is: When the sliding window is 10s, the instantaneous fluctuation characteristics of the valve switching frequency are extracted to obtain device-level granularity data; When the sliding window is 5min, the synchronization data of the steam valve and the temperature sensor during the sterilization stage are extracted to obtain process-level granularity data; When the sliding window is 1h, the energy consumption trend and equipment degradation data of the motor current energy consumption are extracted to obtain production line-level granularity data; Perform temporal encoding according to the multi-scale temporal sequence hierarchical data to obtain multi-scale encoded data; Perform binary mask hard constraint on the multi-scale encoded data using a remote control system to obtain food processing time-series - constraint feature data.

5. The intrusion detection method of the food processing remote control system according to claim 4, characterized in that The time-series encoding based on the multi-scale time-series hierarchical data includes: Perform step millisecond-level fluctuations on the device-level granularity data with a length of 3 and a step size of 1, and construct a first-order direct-connected device convolution kernel to obtain the ST-GCN device branch layer; Perform a complete sub-process stage analysis on the process-level granularity data with a length of 15 and a step size of 5, and construct a device group global convolution kernel to obtain the ST-GCN sub-process branch layer; Extract the daily degradation trend of the production line-level granularity data with a length of 60 and a step size of 20, and construct a global system convolution kernel to obtain the ST-GCN global branch layer; Use the gated recurrent unit formula to perform hierarchical feature fusion on the ST-GCN device branch layer, ST-GCN sub-process branch layer, and ST-GCN global branch layer, and perform time-series encoding to obtain multi-scale encoded data, where the gated recurrent unit formula is as follows: h t+1 = GRU(h t , ST-GCN(A t , X t )); Among them, h t+1 represents the hidden memory of the model at the time step, h t represents the stored historical information, ST-GCN represents the spatio-temporal graph convolutional network, A t represents the adjacency matrix, X t represents the node feature matrix.

6. The intrusion detection method of the food processing remote control system according to claim 1, characterized in that Step S3 includes the following steps: Step S31: Mark and extract the system weak points based on the food processing time-series - constraint feature data to obtain the food processing system weak nodes; Step S32: Use the food processing time-series - constraint feature data and the food processing system weak nodes to construct a perception intrusion detection model and create adversarial sample training data; Step S33: Use the adversarial sample training data to optimize the conditions of the perception intrusion detection model, and perform incremental updates with the key nodes of the food processing system to obtain the food processing remote intrusion detection model.

7. The intrusion detection method of the food processing remote control system according to claim 6, characterized in that, Step S32 includes the following steps: Step S321: Construct a device-process-production line three-level feature curve for the food processing time-series - constraint feature data; Step S322: Perform weighted feature curve slope analysis on the device-process-production line three-level feature curve and construct a perception intrusion detection model; Step S323: Obtain a training data set; input the training data set into the perception intrusion detection model for white-box attack simulation, and perform temperature perturbation to obtain adversarial sample training data.

8. The intrusion detection method of the food processing remote control system according to claim 1, characterized in that, Step S4 includes the following steps: Step S41: Construct food processing detection indicators based on the food processing remote control system; Step S42: Obtain historical attack logs; use multi-dimensional detection indicators to perform intrusion detection on the food processing remote intrusion detection model and historical attack logs to obtain multi-dimensional intrusion detection evaluation data; Step S43: Generate a high-frequency attack portrait based on the multi-dimensional intrusion detection evaluation data to obtain the food processing high-frequency attack portrait; use the food processing high-frequency attack portrait to supplement the system firewall vulnerabilities and generate a food processing intrusion detection report.

9. The intrusion detection method of the food processing remote control system according to claim 8, characterized in that, The construction of food processing detection indicators in Step S41 includes: Perform device-level instantaneous attack analysis based on the food processing remote control system to obtain the instantaneous attack analysis trend; mark the key trends of the instantaneous attack analysis trend and generate instantaneous attack detection indicators; Extract the temperature-pressure mismatch alarm time-consuming data based on the food processing remote control system; perform data mapping on the temperature-pressure mismatch alarm time-consuming data and calculate the average time-consuming to obtain the process-level collaborative detection indicator; Extract data in the sterilization stage of the food processing remote control system to obtain food processing sterilization temperature data; perform complete sterilization rule detection based on the food processing sterilization temperature data to obtain a rule coverage detection index.

10. The intrusion detection method of the food processing remote control system according to claim 1, characterized in that, Step S42 includes the following steps: Step S421: Obtain historical attack logs; Step S422: Use the food processing remote intrusion detection model and historical attack logs to perform detection according to the instantaneous attack detection index. When the recognition rate of abnormal valve switching within 10s is less than or equal to 75%, an alarm is triggered, and an instantaneous attack detection log is generated; Step S423: Use the food processing remote intrusion detection model and historical attack logs to calculate the average mismatch time. If it is greater than or equal to the process-level collaborative detection index, an alarm is triggered, and a process-level collaborative detection log is generated; Step S424: Use the coverage detection index to perform sterilization process rule coverage detection on the food processing remote intrusion detection model and historical attack logs. If the temperature rule coverage is less than 100%, an alarm is triggered, and a physical compliance detection log is generated; Step S425: Evaluate the intrusion detection results of the instantaneous attack detection log, the process-level collaborative detection log, and the physical compliance detection log to obtain multi-dimensional intrusion detection evaluation data.

Citation Information

Patent Citations

  • Industrial control network security monitoring and early warning method and system

    CN116074044A

  • Quality safety traceability management method and system for food processing

    CN117094611A

  • Industrial control multi-mode generation type pre-training model construction method based on data and mechanism fusion

    CN118940108A

  • Multi-modal enhanced food illegal addition monitoring method and system

    CN119579200A

  • Machine learning for industrial processes

    US20210064983A1

Cited By

  • Method and system for monitoring displacement of cathode rays in electric precipitator

    CN120740685A

  • Method and system for monitoring displacement of cathode wires inside an electrostatic precipitator

    CN120740685B

  • Intelligent monitoring method and system for construction environment of energy storage power station

    CN120875460A

  • Energy storage power station construction environment intelligent monitoring method and system

    CN120875460B

  • Automatic control system and method for sauce stir-frying process

    CN121832311A