Intelligent early warning system for industrial safety production situation
By generating fingerprint flow in industrial networks and building timing adjacency graphs, using multi-subject energy diffusion model to identify and quantify hidden threats in real time, the anomaly detection problem under variable topology and hidden channels is solved, and efficient early warning and risk management is achieved.
Patent Information
- Application Number
- CN202510702880.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In industrial networks where variable topology and hidden channels coexist, it is difficult for the existing technology to splice hidden anomaly sequences in real time and quantify the dangerous potential energy across subnets, making it difficult to prevent the critical evolution of chain accidents.
By synergistically generating fingerprint flows with incremental topological markers and time seeds, combining multi-scale wavelet packet decomposition and virtual node re-interpolation, a timing adjacency graph is constructed, and a multi-subject energy diffusion model and risk matrix are used to draw the risk potential value propagation gradient in real time, triggering a hierarchical warning.
Accurate detection of hidden threats has been achieved, the advance warning volume and coverage range has been improved, the false alarm rate has been reduced, and the security resilience and situation transparency of industrial networks have been enhanced.
Smart Images

Figure CN120342835A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial network security. More specifically, the present invention relates to an intelligent early warning system for industrial production safety situation. Background Art
[0002] Multi-level industrial networks form variable topologies through switch rings, temporary wireless links, and redundant channels. To compress round-trip delays, the field controller encapsulates the event parsing logic into the local PLC or edge industrial control computer, and only performs immediate diagnosis on the measurement point thresholds and outputs summaries; weak signs such as instantaneous current surges, vibration shocks, and sudden temperature and humidity jumps are filtered out during the compression process. At the same time, the network load balancing strategy guides some packets to the backup link, forming hidden channels lacking probe coverage. The centralized analysis platform relies on the static link table to reconstruct the causal chain, but due to the lack of abnormal sequences in the hidden channels, the time axis is broken, the cross-node context is difficult to penetrate, and the chain trigger chain cannot be closed.
[0003] However, when the load migration triggers the reallocation of redundant chains, the hidden channels continuously accumulate unresolvable risks, and the dangerous potential energy climbs synchronously across subnets. However, the global warning threshold has not been triggered for a long time due to the lack of microscopic evidence; the local event processing engine only issues low-level prompts in the absence of a cross-node view, resulting in chain accidents breaking out suddenly. The core technical problem arising therefrom is: how to splice hidden abnormal sequences in real time and quantify the cross-subnet dangerous potential energy in an industrial network with variable topologies and hidden channels coexisting, so as to output credible early warnings in advance and block the critical evolution of chain accidents.
[0004] To solve the above problems, a technical solution is provided now. Summary of the Invention
[0005] To overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides an intelligent early warning system for industrial production safety situation, which generates fingerprint streams by incrementally coordinating topology markers and time seeds to track the dynamic state of the entire network; the transient waveform is decomposed by multi-scale wavelet packets to form a micro-impact fingerprint index for accurate detection of abnormalities; combined with gap virtual node interpolation and energy vector interpolation, the time slot compression potential and energy jump amplitude are calculated to identify hidden threats in the time domain and energy domain respectively; the double logarithmic spiral mapping extracts the intersection criticality to drive the multi-agent energy diffusion model to real-time depict the propagation gradient of the dangerous potential value; by comparing with the risk matrix and the dynamic inflection point criterion, the early warning lead time and the range of covered subnets are significantly improved, the outbreak of the chain trigger chain is avoided, the sensitivity of abnormality identification is enhanced, the link repair period is shortened, and the false alarm rate is reduced, so as to solve the problems raised in the above background art.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] An intelligent early warning system for industrial production safety includes: a data injection module, a waveform analysis module, an adjacency construction module, a risk propagation module, and an early warning trigger module;
[0008] Data injection module: Inject an increasing topological sequence and a time seed into the outbound data packet to generate a traceable fingerprint stream;
[0009] Waveform analysis module: Extract the uncompressed transient waveform through the backplane mirror port, and use multi-scale wavelet packet decomposition to obtain the micro-impact feature vector and register the fingerprint index;
[0010] Adjacency construction module: Construct a time-series adjacency graph based on the fingerprint stream and the fingerprint index. After inserting virtual nodes into the gap section, obtain the time slot compression potential and the energy jump amplitude in two levels, and then fuse them into the intersection critical degree by double logarithmic spiral mapping and update the cumulative risk potential value;
[0011] Risk propagation module: The multi-agent energy diffusion model is driven by the intersection critical degree as the source weight, and deduces the propagation trajectory of the cumulative risk potential value on the time-series adjacency graph and outputs the risk gradient matrix;
[0012] Early warning trigger module: Compare the risk gradient matrix with the dynamic inflection point criterion in real time. When the curve approaches the inflection point, issue a hierarchical early warning to the relevant subnets according to the preset advance amount.
[0013] In a preferred embodiment, the data injection module includes the following:
[0014] Before each outbound data packet is sent, embed a unique number that increases in sequence as the increasing topological sequence, and at the same time embed a time stamp recording the sending moment as the time seed; combine the increasing topological sequence and the time seed into an ordered pair to generate a traceable fingerprint stream; associate the traceable fingerprint stream with the outbound data packet, and record the transmission path and time sequence information of the outbound data packet in the ring network, wired link, wireless link, and redundant channel through the log mechanism of the network node or the monitoring device to ensure the complete traceability of the outbound data packet in all transmission channels.
[0015] In a preferred embodiment, the waveform analysis module includes the following:
[0016] Extract the uncompressed transient waveform data of the device from the backplane mirror port. The uncompressed transient waveform data includes the original time-domain waveforms of current, voltage, vibration, and temperature; apply the multi-scale wavelet packet decomposition technology to the uncompressed transient waveform data, layer the signal into multiple frequency sub-bands through multi-layer decomposition, and calculate the energy components of each frequency sub-band; arrange the energy components of all frequency sub-bands in frequency order to form a micro-impact feature vector.
[0017] In a preferred embodiment, the waveform analysis module further includes the following:
[0018] Associate the micro-impact feature vector with the identifier of the device, the timestamp of the collected data, and the micro-impact feature vectors and fingerprint indices in the traceable fingerprint stream to form index entries; register the index entries into the fingerprint index.
[0019] In a preferred embodiment, the adjacency construction module includes the following:
[0020] Construct a temporal adjacency graph based on the fingerprint stream and the fingerprint index. The nodes of the temporal adjacency graph include data packet transmission nodes and abnormal feature nodes, and the edges represent the temporal and topological associations between the nodes; identify the segments where the time seeds or the increasing topological sequences are discontinuous in the temporal adjacency graph, and insert virtual nodes to repair the broken segments. The attributes of the virtual nodes are generated by interpolation of the nodes at both ends of the broken segments.
[0021] In a preferred embodiment, the adjacency construction module further includes the following:
[0022] Arrange the gap segments after inserting the virtual nodes in the increasing topological sequence, calculate the discrete curvature of the gap intervals, then stretch the discrete curvature with the time seeds as the scale, and calculate the time slot compression potential;
[0023] Perform multiple change rate calculations on the attribute vectors of the virtual nodes to obtain the jump features, then take the absolute value of the jump features within the time range of the broken segment and accumulate them to calculate the energy jump amplitude.
[0024] In a preferred embodiment, the adjacency construction module further includes the following:
[0025] Perform arctangent processing and cosine fusion on the logarithms of the time slot compression potential and the energy jump amplitude to calculate the dimensionless intersection criticality; accumulate the intersection criticality into the cumulative risk potential value to update the cumulative risk potential energy across subnets in the industrial network.
[0026] In a preferred embodiment, the risk propagation module includes the following:
[0027] Define the nodes in the temporal adjacency graph as risk propagation entities. The initial risk potential value of the abnormal feature nodes is assigned by the intersection criticality, and the initial risk potential values of the other nodes are set to zero; through iterative calculation, the risk potential values are transmitted from the abnormal feature nodes along the edges of the temporal adjacency graph to the adjacent nodes; within each time step, the risk potential value of a node is updated to the current risk potential value plus the total risk amount received from the adjacent nodes, minus the total risk amount transmitted to the adjacent nodes, and the iteration continues until the risk potential value is stable or the preset time step ends.
[0028] In a preferred embodiment, the risk propagation module further includes the following:
[0029] Map the nodes to the spatio-temporal coordinate system determined by the time seed and the increasing topological sequence, calculate the change rates of the final risk potential values of each node in the time dimension and the topological dimension to obtain the local risk gradients, and organize the local risk gradients of all nodes into a risk gradient matrix.
[0030] In a preferred embodiment, the early warning trigger module includes the following:
[0031] Monitor the risk gradient matrix in real time and extract the risk evolution curves of the key areas;
[0032] Calculate the change rate of the slope of the risk evolution curve to identify the inflection points in the risk evolution curve;
[0033] Calculate the difference between the current slope of the risk evolution curve and the slope at the inflection point as the approximation degree, set an approximation determination criterion to judge whether the risk evolution curve is close to the inflection point; trigger a hierarchical early warning when the approximation degree is less than the approximation determination criterion and the risk gradient value exceeds the predetermined standard, and the early warning levels are divided into low-level early warning, medium-level early warning and high-level early warning according to the risk gradient value and the approximation degree.
[0034] The technical effects and advantages of an intelligent early warning system for industrial production safety situation of the present invention:
[0035] Under the coordination of the increasing topological marker and the fingerprint flow of the time seed throughout the network, the transient waveform is decomposed by multi-scale wavelet packet to form a micro-impact fingerprint index, and then combined with the gap virtual node interpolation and the energy vector interpolation. The time slot compression potential and the energy jump amplitude accurately measure the hidden anomalies in the time domain and the energy domain respectively. The double logarithmic spiral mapping is further condensed into a dimensionless intersection critical degree, providing a high-sensitivity source weight for the multi-agent energy diffusion model, so as to depict the propagation gradient of the dangerous potential value in real time; the risk matrix synchronously compares the dynamic inflection point criteria, significantly improves the early warning lead time, has a more comprehensive early warning coverage subnet, avoids the sudden outbreak of the chain trigger chain, and provides a basis for cross-device horizontal comparison for operation and maintenance decision-making, overall significantly enhancing the security resilience and situation transparency of the industrial network in the face of variable topology and hidden channel scenarios; the comprehensive benefits show that the anomaly recognition sensitivity is significantly improved, the link repair period is shortened, the false alarm rate is decreased, and the production continuity and resource utilization rate are improved synchronously. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is a schematic structural diagram of an intelligent early warning system for industrial production safety situation of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0037] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0038] Embodiment 1: Figure 1 An intelligent early warning system for industrial production safety situation of the present invention is given, including: a data injection module, a waveform analysis module, an adjacency construction module, a risk propagation module, and an early warning trigger module;
[0039] Data injection module: Inject an increasing topological sequence and a time seed into the outbound data packet to generate a traceable fingerprint stream;
[0040] Waveform analysis module: Extract the uncompressed transient waveform through the backplane mirror port, and use multi-scale wavelet packet decomposition to obtain the micro-impact feature vector and register the fingerprint index;
[0041] Adjacency construction module: Construct a time-sequence adjacency graph according to the fingerprint stream and the fingerprint index, insert virtual nodes into the gap section, and then obtain the time-slot compression potential and the energy jump amplitude in two levels, and then fuse them into the intersection criticality by double-logarithmic spiral mapping and update the cumulative risk potential value;
[0042] Risk propagation module: The multi-agent energy diffusion model is driven by the intersection criticality as the source weight, and the propagation trajectory of the cumulative risk potential value is deduced on the time-sequence adjacency graph and the risk gradient matrix is output;
[0043] Early warning trigger module: Compare the risk gradient matrix with the dynamic inflection point criterion in real time. When the curve approaches the inflection point, a hierarchical early warning is sent to the relevant subnets according to the preset advance amount.
[0044] In modern industrial production, the scale and complexity of industrial networks continue to grow, and their security and stable operation have become key factors in ensuring production continuity. Industrial networks often consist of multiple transmission paths such as switch rings, temporary wireless links, and redundant channels, forming a dynamically changing network topology. At the same time, to reduce round-trip latency, field controllers usually encapsulate event parsing logic in local PLCs or edge industrial computers, only perform immediate diagnosis on measurement point thresholds, and output summary data. When compressing data in this way, weak abnormal signals such as instantaneous current surges, vibration shocks, and sudden temperature and humidity jumps will be filtered out. In addition, network load balancing strategies may direct some data packets to backup links lacking probe coverage, forming hidden channels. The existence of these hidden channels makes it difficult for traditional centralized analysis platforms relying on static link tables to reconstruct a complete event causal chain, resulting in broken timelines and missing cross-node contexts. When load migration triggers redundant link reallocation, unresolved risks accumulate in the hidden channels, and the potential danger rises synchronously within the scope of cross-subnets. However, the global alarm threshold has not been triggered for a long time due to the lack of microscopic evidence, and finally leads to the outbreak of chain accidents in a sudden form. Therefore, the core challenge faced by industrial safety production is: how to monitor and analyze potential risks in real time, splice hidden abnormal sequences, quantify cross-subnet potential danger, and issue credible early warnings in an environment where variable topologies and hidden channels coexist, so as to block the critical evolution of chain accidents. An intelligent early warning system for industrial safety production situation proposed by the present invention precisely aims at this practical requirement and solves the above problems through technical means.
[0045] The data injection module is designed to inject an increasing topological sequence and a time seed into the outbound data packets in the industrial network, generate a traceable fingerprint stream, and write it into the ring network, wireless link, and redundant channel, so as to achieve accurate tracking and timing fidelity of data packets in an environment with variable topologies and hidden channels.
[0046] The data injection module includes the following:
[0047] S1-1. Injecting an increasing topological sequence and a time seed into data packets:
[0048] In an industrial network, each datagram (hereinafter referred to as datagram) to be sent from a source node needs to be embedded with two key pieces of information before leaving the source node: an increasing topology sequence and a time seed. The increasing topology sequence is a unique number that increases in sequence and is used to identify the location and transmission path of the datagram in the network topology. This number provides each datagram with a unique identifier in the entire network, and these identifiers are arranged in sequence in the order of sending, which facilitates the subsequent tracking and sorting of datagrams. The time seed is an accurate record of the moment when the datagram is sent, usually in the form of a high-precision timestamp, such as a time stamp in milliseconds or higher precision. The increasing topology sequence and time seed are embedded in the header of the datagram or in a specially reserved field to ensure that the normal function of the datagram is not interfered with during the transmission process, and it is convenient for subsequent extraction and analysis.
[0049] The purpose of embedding an increasing topology sequence and a time seed into each datagram is to accurately record the datagram transmission path and timing. The increasing topology sequence provides the location information of the datagram in the network. Even if the network topology changes dynamically or the datagram is transmitted through a hidden channel, the datagram transmission path can be reconstructed through this sequence. The time seed records the time when the datagram is sent, ensuring that its timing information is preserved and avoiding timing confusion caused by network delays or path changes. The combination of these two pieces of information can fully characterize the behavior characteristics of the datagram in the network, thereby providing accurate data support for anomaly detection and risk analysis.
[0050] In industrial networks, the dynamic changes in network topology and the existence of hidden channels make it difficult to accurately track the transmission path and timing of datagrams, which in turn poses a challenge to anomaly detection. The data injection module embeds an incremental topology sequence and time seed for each datagram and generates a traceable fingerprint stream, achieving a high-precision characterization of datagram transmission behavior. Subsequently, the traceable fingerprint stream is written into all transmission channels to ensure the full traceability of the data.
[0051] S1-2. Generate traceable fingerprint stream:
[0052] Based on the incremental topological sequence and time seed embedded in each datagram, the system generates a traceable fingerprint stream for each datagram. The traceable fingerprint stream is an ordered information pair consisting of an incremental topological sequence and a time seed, which is used to uniquely identify each datagram in the network. Specifically, the incremental topological sequence, as one part of the information pair, provides the path information of the datagram; the time seed, as the other part of the information pair, provides the timing information of the datagram. These two parts of information together constitute the unique identification of the datagram, so that the transmission process of each datagram in the network can be accurately tracked and recorded. The traceable fingerprint stream is associated with the datagram after generation and maintains consistency in subsequent transmissions.
[0053] The purpose of generating the traceable fingerprint stream is to establish a unified data tracking mechanism in the industrial network. By combining the incremental topological sequence and the time seed into the traceable fingerprint stream, this mechanism can not only identify the transmission path of the datagram, but also record its temporal relationship, thus completely describing the transmission behavior of the datagram. In the industrial network, the dynamic changes of the network topology and the existence of hidden channels may make the transmission path and timing of the datagram difficult to predict, while the generation of the traceable fingerprint stream ensures that this information is retained. It can effectively meet the data tracking requirements in complex network environments, provide clear and reliable basis for anomaly detection and risk analysis, and at the same time enhance the controllability of network data management.
[0054] S1-3. Write to the ring network, wireless link and redundant channel:
[0055] Each generated traceable fingerprint stream is written and recorded along with the corresponding datagram in all transmission channels of the industrial network. These transmission channels include ring networks, wired links, wireless links, and redundant channels.
[0056] The traceable fingerprint stream follows the datagram in the network and is recorded at the passing nodes or monitoring devices. For example, in the ring network, the traceable fingerprint stream follows the datagram along the circular path and is recorded by the passing nodes; in the wireless link, the traceable fingerprint stream is carried by the extended field of the wireless protocol frame; in the redundant channel, the traceable fingerprint stream ensures that the datagrams in the backup path are also traceable. This comprehensive writing method ensures that no matter which path the datagram passes through, its traceable fingerprint stream can be completely recorded.
[0057] The purpose of writing the traceable fingerprint stream to all transmission channels is to achieve comprehensive monitoring and recording of the datagram transmission process. In the industrial network, the datagram may be transmitted through different paths due to load balancing or failover, including various forms such as ring networks, wireless links, or redundant channels. Traditional monitoring methods may only cover some paths, resulting in the loss of transmission information of some datagrams. By writing the traceable fingerprint stream in all transmission channels, this method ensures that the transmission information of the datagram can be captured and recorded throughout the network. This comprehensiveness enhances the visualization and management capabilities of the network, enabling anomaly detection and risk analysis to be based on a complete dataset, thereby improving the accuracy and reliability of detection.
[0058] The processing logic of the data injection module assigns a unique identifier based on an increasing topological sequence and a time seed to each data packet in the industrial network, and realizes path and timing tracking across the entire network in the form of a traceable fingerprint stream. The writing of the traceable fingerprint stream covers ring networks, wireless links, and redundant channels, ensuring the information integrity of data in complex network environments. This technical solution significantly improves the accuracy and comprehensiveness of network data management, providing strong support for anomaly detection and risk analysis.
[0059] In the industrial network environment, the data injection module generates a traceable fingerprint stream by injecting an increasing topological sequence and a time seed into outbound data packets, solving the problem of packet path tracking under variable topologies and hidden channels, and ensuring the timing integrity of data transmission. However, relying solely on information at the data packet level cannot capture weak anomaly signals during device operation. Therefore, the waveform analysis module extracts uncompressed transient waveform data from the backplane mirror port, uses multi-scale wavelet packet decomposition technology to extract micro-impact feature vectors, and registers them in the fingerprint index. This processing logic from signal acquisition to feature extraction and then to data management realizes the microscopic capture and efficient management of device anomaly features.
[0060] The waveform analysis module realizes the accurate detection and recording of early device anomalies by extracting uncompressed transient waveforms from the backplane mirror port, using multi-scale wavelet packet decomposition technology to obtain micro-impact feature vectors, and registering the fingerprint index.
[0061] The waveform analysis module includes the following:
[0062] S2-1, Extract uncompressed transient waveforms from the backplane mirror port:
[0063] In the industrial network, the backplane mirror port, as a network monitoring mechanism, is used to copy the real-time traffic data of devices without interfering with the original transmission. Uncompressed transient waveform data is directly extracted from devices (such as programmable logic controllers or edge industrial control machines) using the backplane mirror port. These data contain the time-domain waveforms of original signals such as current, voltage, vibration, and temperature, reflecting the complete form of the signal's change over time. Specifically, the uncompressed transient waveform data records the value of the signal at each moment, such as the peak amplitude of an instantaneous current surge, the short-time pulse shape of a vibration impact, and the transition characteristics of a temperature mutation. Different from the traditional method where the field controller compresses the collected data to reduce transmission delay and only retains the summary information after threshold judgment, the uncompressed transient waveforms extracted by the backplane mirror port retain the full picture of the signal without being filtered or simplified.
[0064] S2-2, Extract micro-impact feature vectors using multi-scale wavelet packet decomposition:
[0065] For the uncompressed transient waveform data obtained from the backplane mirror port, the multi-scale wavelet packet decomposition technique is applied for signal analysis. The uncompressed transient waveform data is decomposed into signal components in multiple frequency sub-bands to reveal the characteristics of the signal in different time and frequency ranges. The specific processing logic is as follows:
[0066] First, the uncompressed transient waveform data is input into the multi-scale wavelet packet decomposition process. Through a series of decomposition levels, the signal is hierarchically split into multiple frequency sub-bands. Each level of decomposition divides the signal of the previous level into a high-frequency part and a low-frequency part, and this process is repeated until the predetermined decomposition level is reached. The frequency sub-bands after each level of decomposition correspond to a set of wavelet packet coefficients, and these coefficients represent the energy distribution characteristics of the signal in that frequency sub-band. Then, for the wavelet packet coefficients of each frequency sub-band, the sum of the squares of all their values is calculated to obtain the energy component of that sub-band. Finally, the energy components of all frequency sub-bands are arranged in frequency order to form a micro-impact feature vector, which is used to describe the micro-impact characteristics in the uncompressed transient waveform data, such as the high-frequency spikes of current surges or the low-frequency oscillations of vibration shocks.
[0067] The multi-scale wavelet packet decomposition technique is suitable for analyzing non-stationary signals. Its advantage lies in being able to capture both the time-local changes and frequency distribution characteristics of the signal simultaneously, and it can better adapt to the instantaneous fluctuations of industrial equipment signals compared with traditional frequency-domain analysis methods. By decomposing the uncompressed transient waveform data into multiple frequency sub-bands, the frequency-domain characteristics of different abnormal patterns can be revealed, such as the concentrated energy of instantaneous current surges in high-frequency sub-bands or the continuous oscillations of vibration shocks in low-frequency sub-bands. The extracted micro-impact feature vector quantifies these characteristics in the form of energy components, which can accurately reflect the microscopic characteristics of early equipment anomalies, thus providing a fine-grained analysis basis for anomaly detection and improving the accuracy of detection.
[0068] S2-3, Register fingerprint index:
[0069] After extracting the micro-impact feature vector, it is registered in the fingerprint index, which is a data structure that supports efficient storage and retrieval.
[0070] The micro-impact feature vector is associated with the identifier of the corresponding device (such as the device unique number), the timestamp of the collected data, and the time seed in the traceable fingerprint stream generated in the data injection module to form a complete index entry. The micro-impact feature vector in the index entry is used as the core data, the device identifier is used to identify the data source, the timestamp records the data collection moment, and the time seed ensures the timing consistency with the data injection module. The fingerprint index stores these index entries using a hash map or tree organization method. By mapping the micro-impact feature vector to a unique key value or node position, the functions of persistent storage and fast query of data are realized.
[0071] The waveform analysis module extracts uncompressed transient waveform data from the backplane mirror port, uses multi-scale wavelet packet decomposition technology to extract micro-impact feature vectors, and registers them in the fingerprint index, successfully capturing and quantifying the characteristics of weak abnormal signals such as instantaneous current surges and vibration shocks. The persistent storage and efficient retrieval capabilities of these features ensure that the anomaly detection system can achieve higher sensitivity and accuracy based on comprehensive signal information and fine-grained feature analysis in variable topology scenarios of industrial networks, thereby enhancing the system's anomaly recognition and risk prevention and control capabilities.
[0072] The data injection module generates the path and time sequence information of data packet transmission through the traceable fingerprint stream, and the waveform analysis module registers the micro-impact features of early device anomalies through the fingerprint index. Based on the outputs of the first two steps, the adjacency construction module constructs a temporal adjacency graph and inserts virtual nodes to repair time sequence breaks, calculates the time slot compression potential and energy jump amplitude, fuses them into the convergence criticality, and updates the cumulative risk potential value, completing the splicing of hidden anomaly sequences and the quantification of cross-subnet risks.
[0073] The adjacency construction module constructs a temporal adjacency graph based on the traceable fingerprint stream generated by the data injection module and the fingerprint index registered by the waveform analysis module, repairs the temporal break by inserting virtual nodes, calculates the time slot compression potential and energy jump amplitude, fuses them into the convergence criticality, and updates the cumulative risk potential value, realizing the splicing of hidden anomaly sequences and the quantification of cross-subnet risks.
[0074] The adjacency construction module includes the following:
[0075] S3-1, constructing a temporal adjacency graph:
[0076] In an industrial network, the temporal adjacency graph is used to represent the relationship between data packet transmission events and device anomaly characteristics in terms of time sequence and network topology. The nodes of the temporal adjacency graph are divided into two categories:
[0077] The first category is data packet transmission nodes, which come from the traceable fingerprint stream generated by the data injection module, represent data packet transmission events in the network, and contain increasing topology sequence and time seed attributes;
[0078] The second category is anomaly feature nodes, which come from the fingerprint index registered by the waveform analysis module, represent the detection events of device micro-impact features, and contain timestamp and micro-impact feature vector attributes.
[0079] The edges of the temporal adjacency graph represent the time and topology associations between nodes, which are specifically divided into two categories: the edges between data packet transmission nodes, which are determined by the increasing topology sequence to connect adjacent transmission paths; the edges between anomaly feature nodes, which are determined by the time seed and timestamp to determine time continuity. The process of constructing the temporal adjacency graph is as follows:
[0080] First, sort the datagram transmission events and abnormal feature events according to the time seed and timestamp to form an event sequence arranged in chronological order; then, connect adjacent events to form edges according to the increasing topological sequence and time continuity, and finally generate a complete temporal adjacency graph.
[0081] Constructing a temporal adjacency graph maps the datagram transmission path and device abnormal features into the structure of time order and network topology to form a global view. It integrates multi-source data, reveals the correlation between events in the industrial network, and provides structural support for the splicing of abnormal sequences and risk propagation analysis. Compared with the traditional static link table, the temporal adjacency graph can dynamically adapt to changes in the network topology, ensuring the continuity and accuracy of anomaly detection in time and space.
[0082] S3-2, Insert virtual nodes to repair temporal breaks:
[0083] Hidden channels in the industrial network may lead to broken segments with missing event sequences in the temporal adjacency graph, affecting the integrity of abnormal sequences. Repair these broken segments by inserting virtual nodes. The specific operation is as follows: Identify the segments in the temporal adjacency graph where the time seed or increasing topological sequence is discontinuous, and insert virtual nodes between the two end nodes of the broken segment. The attributes of the virtual nodes are generated by interpolation of the two end nodes of the broken segment: The time seed takes the average value of the time seeds of the two end nodes of the broken segment; the increasing topological sequence takes the integer interpolation of the increasing topological sequences of the two end nodes of the broken segment; if abnormal feature nodes are involved, the micro-impact feature vector is generated by linear interpolation. After inserting the virtual nodes, the nodes of the broken segment are connected, repairing the time order break in the temporal adjacency graph.
[0084] Inserting virtual nodes restores the continuity of the event sequence by connecting the broken segments in the temporal adjacency graph, ensuring the integrity of anomaly detection and risk analysis. Using interpolation to generate the attributes of virtual nodes makes up for the data loss caused by hidden channels and enhances the robustness of the system in complex network environments.
[0085] S3-3, Calculate the time slot compression potential:
[0086] The time slot compression potential is used to quantify the degree of time order compression in the temporal adjacency graph, reflecting the aggregation trend of abnormal events in time. The process of calculating the time slot compression potential is as follows:
[0087] First, arrange the gap segments after inserting virtual nodes according to the increasing topological sequence, calculate the change rate of adjacent gap intervals, and then calculate the change rate of the change rate to obtain the discrete curvature. The discrete curvature represents the acceleration of the change in gap intervals and is used to characterize the local features of time order compression.
[0088] Then, using the time seed as a scale, stretch the discrete curvature and calculate the time slot compression potential. The specific operation is as follows:
[0089] Multiply the discrete curvature of each notch section by the time span of this section (the time span is calculated from the difference between the time seeds of adjacent nodes, with the unit of seconds), and then sum up the products of all notch sections to obtain the time slot compression potential, whose dimension is joule, representing the potential energy of time-order compression.
[0090] The time slot compression potential quantifies the degree of aggregation of events in the time sequence adjacency graph through the product of discrete curvature and time span, and can reveal the dense distribution characteristics of abnormal events. Compared with traditional time interval analysis, this method captures the acceleration of time-order changes by calculating the change rate of the change rate, and more accurately reflects the suddenness and aggregation of abnormal events. The calculation of the time slot compression potential provides an abnormal quantification index in the time domain, enhancing the sensitivity and accuracy of anomaly detection.
[0091] S3-3. Calculate the energy jump amplitude:
[0092] The energy jump amplitude is used to quantify the mutation amplitude of abnormal energy changes in the time sequence adjacency graph, reflecting the intensity change of abnormal characteristics. The process of calculating the energy jump amplitude is as follows:
[0093] First, perform multiple change rate calculations on the attribute vector of the virtual node (including the interpolation results of the time seed and the micro-impact feature vector) to obtain the jump characteristics. The jump characteristics are generated by calculating the multiple change rates (usually the second-order or third-order change rates) of the attribute vector with respect to the time seed, and are used to characterize the instantaneous change characteristics of abnormal characteristics.
[0094] Then, take the absolute value of the jump characteristics within the time range of the fracture section and accumulate them to obtain the energy jump amplitude, whose dimension is joule, representing the mutation amplitude of abnormal energy.
[0095] The energy jump amplitude quantifies the mutation intensity of abnormal characteristics in the time sequence adjacency graph through multiple change rate calculations and accumulations, and can capture the instantaneous impact characteristics of equipment anomalies. Compared with simple feature vector analysis, this method highlights the dynamic change characteristics of abnormal characteristics through multiple change rate calculations and accumulations, improving the accuracy of anomaly detection. The calculation of the energy jump amplitude provides an abnormal quantification index in the energy domain, making anomaly detection more comprehensive in terms of intensity evaluation.
[0096] S3-4. Fuse into the intersection criticality and update the cumulative risk potential value:
[0097] Fuse the time slot compression potential and the energy jump amplitude into a dimensionless intersection criticality, and update the cumulative risk potential value to achieve the comprehensive quantification of hidden anomalies. The specific operation is as follows:
[0098] First, the common logarithms of the time slot compression potential and the energy jump amplitude are calculated respectively to obtain two logarithmic values; then, the arctangent of the two logarithmic values is calculated to obtain the spiral angle; at the same time, the square sum of the two logarithmic values is calculated, and then the square root of the square sum is taken to obtain the spiral radius; finally, the spiral radius is multiplied by the cosine value of the spiral angle to obtain the intersection criticality. The intersection criticality is a dimensionless comprehensive indicator that integrates the information of the time slot compression potential and the energy jump amplitude. Then, the intersection criticality is accumulated to the cumulative risk potential value to update the cumulative risk potential energy across subnets in the industrial network.
[0099] Through logarithmic calculation, inverse tangent processing and cosine fusion, the time slot compression potential and energy jump amplitude are converted into intersection criticality, which can weaken the amplification effect of extreme values while retaining the sensitivity of local abnormal characteristics, ensuring the balance of abnormal quantification. As a dimensionless indicator, the intersection criticality is convenient for horizontal comparison between different devices and subnets. The update of the cumulative risk potential value realizes the continuous monitoring of hidden risks and provides a dynamic quantitative basis for risk assessment and abnormal warning of industrial networks.
[0100] The adjacency construction module successfully spliced the hidden anomaly sequence and quantified the dangerous potential energy across subnets of the industrial network by constructing a time-series adjacency graph, inserting virtual nodes, calculating the time slot compression potential and energy jump amplitude, merging them into the intersection criticality and updating the cumulative risk potential value. This process ensures the continuity of anomaly detection and the comprehensiveness of risk assessment in scenarios where network topology changes and hidden channels exist, and improves the system's anomaly identification ability and risk prevention and control effect.
[0101] The adjacency construction module constructs a temporal adjacency graph based on the fingerprint flow and fingerprint index, repairs the temporal breaks by inserting virtual nodes, calculates the time slot compression potential and energy jump amplitude, merges them into the intersection criticality and updates the cumulative risk potential value, and realizes the splicing of hidden abnormal sequences and the quantification of cross-subnet risks. However, in industrial networks with variable topology and hidden channels, risks not only need to be quantified, but also their propagation dynamics and impact range need to be revealed to cope with the synchronous rise of dangerous potential energy across subnets caused by load migration and redundant chain redistribution, thereby blocking the critical evolution of chain accidents. To this end, the risk propagation module introduces a multi-agent energy diffusion model, takes the intersection criticality generated by the adjacency construction module as the driving source, deduces the risk propagation process on the temporal adjacency graph, and outputs the risk gradient matrix to provide a basis for real-time warning.
[0102] The risk propagation module takes the intersection criticality generated by the adjacency building module as the driving source, and uses the multi-agent energy diffusion model to deduce the propagation trajectory of the cumulative risk potential value on the temporal adjacency graph constructed by the adjacency building module, and finally generates a risk gradient matrix to reveal the spatiotemporal distribution of risks in industrial networks.
[0103] The risk communication module includes the following:
[0104] S4-1, Construction of the multi-agent energy diffusion model:
[0105] In industrial network anomaly detection, the construction of the multi-agent energy diffusion model aims to simulate the transmission process of risk potential values in the temporal adjacency graph. The specific operation is as follows:
[0106] First, each node in the temporal adjacency graph generated by the adjacency construction module is defined as a risk propagation agent, including datagram transmission nodes and anomaly feature nodes, which can store and transmit risk potential values. The initial risk potential value of each node comes from the cumulative risk potential value calculated by the adjacency construction module. Among them, the initial risk potential value of the anomaly feature node is assigned by the convergence criticality determined by the adjacency construction module, representing the starting point of the risk potential energy caused by the anomaly event, while the initial risk potential values of the remaining nodes are set to zero. Secondly, set the risk potential value propagation rule: the risk potential value diffuses from the anomaly feature node along the edges of the temporal adjacency graph to adjacent nodes. The weight of the edge is jointly determined by the increasing topological sequence and time seed injected by the data injection module. Specifically, the increasing topological sequence reflects the topological distance between nodes, and the time seed reflects the temporal dependence of datagram transmission. The two are combined to calculate the weight value of the edge.
[0107] The multi-agent energy diffusion model realizes the dynamic simulation of the risk potential value transmission in the industrial network by defining the nodes in the temporal adjacency graph as risk propagation agents, and can clearly reveal the influence range and propagation path of the anomaly event on other nodes in the network. Compared with the traditional static analysis method, the multi-agent energy diffusion model can adapt to the dynamic changes of the industrial network topology, reflect the evolution process of risk propagation in real time, and thus provide more accurate risk assessment results. The design of the initial risk potential value and propagation rule makes full use of the convergence criticality and the topological characteristics of the temporal adjacency graph, ensuring that the microscopic characteristics of the anomaly event play a dominant role in risk propagation, and improving the sensitivity and accuracy of anomaly detection.
[0108] S4-2, Propagation deduction of risk potential values:
[0109] The propagation deduction of risk potential values is completed through iterative calculation based on the topological structure of the temporal adjacency graph and the convergence criticality. The specific operation is as follows:
[0110] First, assign the convergence criticality to the anomaly feature nodes in the temporal adjacency graph as the initial risk potential value, and set the initial risk potential values of the remaining nodes to zero. Then, within each time step, the risk potential value is transmitted from the current node to adjacent nodes, and the transmission amount is jointly determined by the risk potential value of the current node and the edge weight. The specific calculation process is as follows:
[0111] For each outgoing edge of the current node, the transfer amount is equal to the result of multiplying the risk potential value of the current node by the weight of that edge and dividing by the sum of the weights of all outgoing edges of the current node. Then, update the risk potential value of each node. The update method is: the new risk potential value is equal to the current node's risk potential value plus the sum of the risk amounts received from all adjacent nodes, minus the sum of the risk amounts transferred to all adjacent nodes. The iterative calculation continues until the risk potential value reaches a stable distribution in the temporal adjacency graph or the preset time step ends.
[0112] The propagation and deduction of the risk potential value dynamically simulates the process of risk propagation in the industrial network through iterative calculation, and can reflect the change trend and distribution of the risk potential value in real time. Compared with the one-time calculation method, iterative calculation can capture the cumulative effect of risks and the evolution characteristics of the propagation path, and provide a more comprehensive risk assessment result. The calculation of the transfer amount comprehensively considers the edge weight and the correlation strength between nodes, ensuring that the propagation process conforms to the topological characteristics and temporal dependence of the industrial network. The iterative update mechanism enables the model to adapt to the dynamic changes of the network topology, enhancing the robustness of the system and its adaptability to complex scenarios.
[0113] S4-3, Generation of the risk gradient matrix:
[0114] The generation of the risk gradient matrix is based on the result of the propagation and deduction of the risk potential value, and is completed using the time seed and the increasing topological sequence. The specific operation is as follows:
[0115] First, map the nodes in the temporal adjacency graph to a two-dimensional spatio-temporal coordinate system, where the horizontal axis represents the time dimension, determined by the time seed; the vertical axis represents the topological dimension, determined by the increasing topological sequence. Then, for the final risk potential value of each node, calculate its rate of change in the spatio-temporal coordinate system to obtain the local risk gradient. The calculation of the local risk gradient is divided into two parts:
[0116] The rate of change along the time dimension is the result of dividing the difference in risk potential values within adjacent time steps by the time interval;
[0117] The rate of change along the topological dimension is the result of dividing the difference in risk potential values between nodes at adjacent topological positions by the topological distance.
[0118] Finally, organize the local risk gradients of all nodes according to the arrangement of the spatio-temporal coordinate system into a risk gradient matrix, and each element in the matrix represents the risk gradient value at a specific time and topological position.
[0119] The risk gradient matrix provides an intuitive view of the risk distribution in an industrial network by organizing the spatio-temporal change rate of the risk potential value into a matrix form, which can clearly reveal the high-order gradient regions and propagation trends of risks. Compared with the method that only analyzes the risk potential value, the risk gradient matrix can more accurately locate high-risk links and risk concentration areas, providing an accurate positioning basis for anomaly detection and risk prevention and control. The mapping method of the spatio-temporal coordinate system combines time seeds and an increasing topological sequence, ensuring the dynamics and comprehensiveness of risk assessment, enabling the matrix to reflect the evolutionary characteristics of risks in time and space, thus enhancing the timeliness and pertinence of anomaly detection.
[0120] The risk propagation module, through a multi-agent energy diffusion model, uses the convergence criticality of the adjacency construction module as the driving source to deduce the propagation trajectory of the risk potential value on the temporal adjacency graph constructed by the adjacency construction module, and finally generates a risk gradient matrix, realizing the real-time delineation of the risk propagation dynamics and influence scope in the industrial network. In the complex scenarios with variable network topologies and hidden channels, the risk propagation module ensures the dynamics and comprehensiveness of risk assessment, providing high-precision analysis results and high-timeliness support for anomaly detection, and significantly improving the ability to identify and block the critical evolution of cascading accidents.
[0121] The risk propagation module uses the convergence criticality as the driving source, utilizes the multi-agent energy diffusion model to deduce risk propagation on the temporal adjacency graph, generates a risk gradient matrix, and reveals the spatio-temporal distribution of risks. However, relying solely on the risk gradient matrix cannot directly trigger an early warning. It is also necessary to identify the key turning points of risk evolution in real time to issue a hierarchical early warning in advance and block the critical evolution of cascading accidents. The early warning trigger module receives the risk gradient matrix of the risk propagation module, conducts real-time monitoring and analysis on it, and triggers a precise early warning according to the dynamic inflection point criterion.
[0122] The early warning trigger module includes the following:
[0123] S5-1, Real-time monitoring of the risk gradient matrix:
[0124] The risk gradient matrix is the output generated by the multi-agent energy diffusion model, used to reflect the gradient distribution of risks in the spatio-temporal coordinate system of the industrial network. The specific operation of real-time monitoring of the risk gradient matrix is as follows:
[0125] The risk gradient matrix is continuously updated according to the time dimension, and the matrix data at each moment reflects the dynamic changes of risks evolving over time; extract the risk evolution curves of key regions from the risk gradient matrix. The risk evolution curve represents the change trend of the risk gradient value of a specific topological position or high-risk link over time, and the key regions are determined by the regions with higher gradient values in the risk gradient matrix. The extraction process screens out the regions with higher gradient value rankings or exceeding the predetermined standard by comparing the gradient values of each position in the risk gradient matrix.
[0126] S5-2, Definition and Application of the Dynamic Inflection Point Criterion:
[0127] The dynamic inflection point criterion is used to identify the key turning points in the risk evolution curve, that is, the moments when the risk accelerates upward or undergoes a qualitative change. The specific operation is as follows:
[0128] Calculate the rate of change of the slope of the risk evolution curve to identify the concave and convex change points of the curve trend; when the rate of change of the slope becomes zero at a certain point and the further rate of change of the rate of change of the slope is not zero, confirm that point as the inflection point; to reduce misjudgment, set a dynamically adjusted judgment criterion, which is adjusted according to the historical risk data of the industrial network and the network topology complexity; when the slope of the risk evolution curve exceeds this dynamically adjusted judgment criterion, confirm that the risk enters the stage of accelerating upward, providing a basis for triggering subsequent early warnings.
[0129] The dynamic inflection point criterion accurately identifies the turning points in the risk evolution curve by analyzing the rate of change of the slope and its further rate of change, can capture the qualitative change moment of risk evolution, and ensures the timeliness of anomaly detection. The dynamically adjusted judgment criterion changes flexibly according to the network environment and historical data, enhancing the adaptability of the system and reducing the possibility of false alarms and missed reports.
[0130] S5-3, Real-time Comparison of the Curve Approaching the Inflection Point:
[0131] Through real-time calculation, determine whether the risk evolution curve is approaching the inflection point. The specific operation is as follows: Define the approximation degree as the difference between the current slope of the risk evolution curve and the slope at the inflection point; when the approximation degree is less than the pre-set approximation judgment criterion, determine that the risk evolution curve is approaching the inflection point; the approximation judgment criterion is determined according to the response time and risk sensitivity of the industrial network; at the same time, according to the slope change speed of the risk evolution curve and the historical accident evolution time, calculate the amount of time for early warning to ensure that the early warning is issued before the risk reaches the critical state. The amount of time for early warning is obtained by analyzing the corresponding relationship between the slope change speed and historical data.
[0132] Real-time comparison of whether the risk evolution curve is approaching the inflection point can identify the critical moment of risk evolution in advance, ensuring the timeliness of anomaly detection. The calculation of the approximation degree quantifies the degree of proximity between the curve and the inflection point through the slope difference, providing a clear basis for judgment. The amount of time for early warning combines the network response time and the risk evolution speed to ensure that the early warning is triggered before the risk is critical, effectively avoiding accidents.
[0133] S5-4, Issuing Hierarchical Early Warnings:
[0134] When the risk evolution curve approaches the inflection point, a graded early warning is sent to the relevant subnets according to the amount of time for early warning. The specific operation is as follows: According to the risk gradient value and approximation degree in the risk gradient matrix, the early warning levels are divided, including low-level early warning, medium-level early warning, and high-level early warning. The division criteria for the early warning levels are: when the risk gradient value is lower than the first standard value and the approximation degree is large, it is a low-level early warning; when the risk gradient value is between the first standard value and the second standard value and the approximation degree is at a medium level, it is a medium-level early warning; when the risk gradient value exceeds the second standard value and the approximation degree is less than the preset approximation determination standard, it is a high-level early warning. When the approximation degree is less than the approximation determination standard and the risk gradient value exceeds the predetermined standard, the corresponding level of early warning is triggered. The early warning information includes the risk location, early warning level, and recommended measures, and is sent to the relevant subnets and the decision-making end. At the same time, according to the risk propagation path deduced by the multi-agent energy diffusion model, the early warning coverage range expands in real time along the path to ensure that all affected subnets and devices receive the early warning.
[0135] The graded early warning mechanism flexibly adjusts the early warning level based on the comprehensive analysis of the risk gradient value and approximation degree, ensuring the pertinence and effectiveness of anomaly detection. The division criteria for the early warning levels can accurately reflect the evolution stage and potential impact of the risk, improving the accuracy of the early warning. The real-time sending of the early warning information and the dynamic expansion of the coverage range ensure the comprehensiveness and timeliness of anomaly detection, enabling the relevant subnets and devices to take corresponding measures in a timely manner. Compared with a single early warning method, the graded early warning mechanism is more adaptable to the complex environment of industrial networks, improving the practicality and reliability of anomaly detection.
[0136] The early warning trigger module successfully identifies the moment when the risk evolution curve approaches the inflection point through the real-time monitoring of the risk gradient matrix and the accurate comparison of the dynamic inflection point criterion, and sends a graded early warning to the relevant subnets according to the amount of time for early warning. In the industrial network scenario with variable topology and hidden channels coexisting, this step ensures the timeliness and accuracy of anomaly detection, effectively blocking the critical evolution of chain accidents, and enhancing the safety resilience and situation transparency of industrial safety production.
[0137] The above formulas are all dimensionless and take their numerical calculations. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters in the formulas are set by technicians in this field according to the actual situation.
[0138] It should be noted that the system of the present invention can be deployed on the device itself to achieve embedded applications, or can also run on a PC with a user interface or other terminals, so as to meet various hardware environments and usage requirements.
[0139] Only some exemplary embodiments of the present invention have been described by way of illustration. Undoubtedly, for those of ordinary skill in the art, the described embodiments can be modified in various different ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.
[0140] It should be noted that in this text, if there are relational terms such as first and second, they are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0141] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. An intelligent early warning system for the industrial production safety situation, characterized in that, include: Data injection module, waveform analysis module, adjacency construction module, risk propagation module and warning trigger module; Data injection module: injects increasing topological sequence and time seed into outbound datagrams to generate traceable fingerprint stream; Waveform analysis module: extracts uncompressed transient waveforms through the backplane mirror port, uses multi-scale wavelet packet decomposition to obtain micro-shock feature vectors and registers fingerprint indexes; Adjacency construction module: constructs a temporal adjacency graph based on fingerprint flow and fingerprint index, inserts virtual nodes into the gap segment, obtains the time slot compression potential and energy jump amplitude in two levels, and then fuses them into the intersection criticality with double logarithmic spiral mapping and updates the cumulative risk potential value; Risk propagation module: The multi-agent energy diffusion model uses the intersection criticality as the source weight drive, deduce the cumulative risk potential value propagation trajectory on the time-series adjacency graph and outputs the risk gradient matrix; Early warning trigger module: The risk gradient matrix is compared with the dynamic inflection point criterion in real time. When the curve approaches the inflection point, a graded early warning is issued to the relevant subnets according to the preset advance amount.
2. An intelligent early warning system for industrial production safety situation according to claim 1, characterized in that, The data injection module includes the following: Before each outbound datagram is sent, a unique number that increases in sequence is embedded as an increasing topological sequence, and a timestamp that records the sending time is embedded as a time seed; the increasing topological sequence and the time seed are combined into an ordered pair to generate a traceable fingerprint stream; the traceable fingerprint stream is associated with the outbound datagram, and the transmission path and timing information of the outbound datagram is recorded in the ring network, wired link, wireless link and redundant channel through the log mechanism or monitoring equipment of the network node, to ensure the complete traceability of the outbound datagram in all transmission channels.
3. An intelligent early warning system for industrial production safety situation according to claim 2, characterized in that, The waveform analysis module includes the following: Extract the uncompressed transient waveform data of the device from the backplane mirror port. The uncompressed transient waveform data includes the original time domain waveforms of current, voltage, vibration, and temperature. Apply multi-scale wavelet packet decomposition technology to the uncompressed transient waveform data, split the signal into multiple frequency sub-bands through multi-layer decomposition, and calculate the energy component of each frequency sub-band. The energy components of all frequency sub-bands are arranged in frequency order to form a microshock feature vector.
4. An intelligent early warning system for industrial production safety situation according to claim 3, characterized in that, The waveform analysis module also includes the following: The micro-shock feature vector is associated with the identifier of the device, the timestamp of the collected data, the micro-shock feature vector in the traceable fingerprint stream, and the fingerprint index to form an index entry; and the index entry is registered in the fingerprint index.
5. An intelligent early warning system for industrial production safety situation according to claim 4, characterized in that, The adjacency building blocks include the following: A temporal adjacency graph is constructed based on fingerprint stream and fingerprint index. The nodes of the temporal adjacency graph include datagram transmission nodes and abnormal feature nodes, and the edges represent the time and topological associations between nodes. Discontinuous segments of time seeds or increasing topological sequences are identified in the temporal adjacency graph, and virtual nodes are inserted to repair the broken segments. The attributes of the virtual nodes are generated by interpolation of the nodes at both ends of the broken segments.
6. The intelligent early warning system for industrial production safety situation according to claim 5, characterized in that, The adjacency building block also includes the following: Arrange the gap segments after the virtual nodes are inserted according to the increasing topological sequence, calculate the discrete curvature of the gap interval, and then stretch the discrete curvature with the time seed as the scale to calculate the time gap compression potential; Calculate the rate of change of the attribute vector of the virtual node multiple times to obtain the jump feature, then take the absolute value of the jump feature within the time range of the fracture section and accumulate it to calculate the energy jump amplitude.
7. An intelligent early warning system for industrial safety production situation according to claim 6, characterized in that, The adjacency construction module further includes the following: Perform arctangent processing and cosine fusion on the logarithm of the time slot compression potential and the energy jump amplitude to calculate the dimensionless intersection critical degree; accumulate the intersection critical degree into the cumulative risk potential value to update the cumulative risk potential energy across subnets in the industrial network.
8. An intelligent early warning system for industrial production safety situation according to claim 7, characterized in that The risk propagation module includes the following: Define the nodes in the temporal adjacency graph as risk propagation entities, assign the initial risk potential value of the abnormal feature node by the intersection critical degree, and set the initial risk potential value of the remaining nodes to zero; through iterative calculation, the risk potential value is transmitted from the abnormal feature node along the edges of the temporal adjacency graph to adjacent nodes; within each time step, the risk potential value of the node is updated to the current risk potential value plus the total risk amount received from adjacent nodes, minus the total risk amount transmitted to adjacent nodes, and the iteration continues until the risk potential value is stable or the preset time step ends.
9. An intelligent early warning system for industrial production safety situation according to claim 8, characterized in that, The risk propagation module further includes the following: Map the nodes to the spatio-temporal coordinate system determined by the time seed and the increasing topological sequence, calculate the rate of change of the final risk potential value of each node in the time dimension and the topological dimension to obtain the local risk gradient, and organize the local risk gradients of all nodes into a risk gradient matrix.
10. An intelligent early warning system for industrial production safety situation according to claim 9, characterized in that, The early warning trigger module includes the following: Monitor the risk gradient matrix in real time and extract the risk evolution curve of the key area; Calculate the rate of change of the slope of the risk evolution curve to identify the inflection point in the risk evolution curve; Calculate the difference between the current slope of the risk evolution curve and the slope at the inflection point as the approximation degree, and set an approximation determination criterion to judge whether the risk evolution curve is close to the inflection point; Trigger a hierarchical early warning when the approximation degree is less than the approximation determination criterion and the risk gradient value exceeds the predetermined standard. The early warning levels are divided into low-level early warning, medium-level early warning, and high-level early warning according to the risk gradient value and the approximation degree.
Citation Information
Cited By
Milk beverage production monitoring method and system based on AI vision and medium
CN120953689A