Power consumption behavior anomaly detection method and system based on deep learning

Through the combination of deep learning model and Bayesian optimization, the accuracy and adaptability of abnormal detection of abnormal electricity consumption is solved, and efficient and accurate abnormal electricity consumption is realized to adapt to complex and changeable modes of electricity consumption.

CN120354104APending Publication Date: 2025-07-22GUANGXI POWER GRID CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510267966.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing abnormal detection methods for electricity consumption behavior fail to effectively consider variability and complexity, resulting in low accuracy of abnormal detection, low feature extraction efficiency, and difficulty in automatically learning and extracting key features in electricity consumption data, and cannot flexibly respond to complex and changing user electricity consumption behavior patterns.

Method used

A deep learning-based method is adopted to extract key features by detecting change points, and a deep learning model is used to convert feature data into input embedding vectors. The global dependence relationship of the time series is captured in combination with the self-attention mechanism, and the detection threshold is dynamically adjusted through Bayesian optimization to generate anomaly score for abnormal judgment.

Benefits of technology

It improves the accuracy and adaptability of abnormal detection, reduces false alarms and missed reports, improves the system's adaptability and computing efficiency to complex electricity consumption behaviors, and meets the real-time monitoring needs of smart grids.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354104A_ABST
    Figure CN120354104A_ABST
Patent Text Reader

Abstract

The invention discloses a power consumption behavior anomaly detection method and system based on deep learning, and relates to the technical field of power consumption behavior analysis and anomaly detection, and the method comprises the steps: detecting a change point, carrying out the data sampling according to a detection result, and extracting key features. And converting the feature data into an input embedded vector by using a deep learning model, and generating an abnormal score. And performing anomaly detection based on the anomaly score, and judging whether anomaly occurs. According to the electricity consumption behavior anomaly detection method based on deep learning provided by the invention, key features in electricity consumption data are adaptively learned and extracted through the deep learning model, and a global dependency relationship in a time sequence is captured in combination with a self-attention mechanism, so that the anomaly detection precision is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electricity consumption behavior analysis and anomaly detection, and specifically to a method and system for electricity consumption behavior anomaly detection based on deep learning. Background Art

[0002] With the rapid growth of electricity demand in modern society, the analysis of user electricity consumption behavior data has become an important means for the optimal management of power systems. By monitoring and analyzing electricity consumption behavior, abnormal electricity consumption situations can be detected in a timely manner, avoiding power losses, equipment damage, and safety hazards caused by abnormal electricity consumption. Traditional methods for detecting abnormal electricity consumption mainly rely on fixed threshold rules or statistical models, and these methods have significant limitations in dealing with large-scale non-linear time series data and are difficult to adapt to complex and changeable user electricity consumption behavior patterns.

[0003] In recent years, anomaly detection methods based on deep learning have demonstrated powerful data modeling and anomaly detection capabilities in multiple fields. Using deep learning technology to analyze user electricity consumption data can not only extract key features from massive data but also more accurately capture the complex characteristics of abnormal behaviors.

[0004] The present invention proposes a method for detecting abnormal electricity consumption behavior based on deep learning, which solves the problem of insufficient detection accuracy of traditional methods. By using a dynamic threshold strategy and multi-scale feature extraction technology, efficient and accurate detection of abnormal electricity consumption behavior is achieved. Summary of the Invention

[0005] In view of the above problems, the present invention is proposed.

[0006] Therefore, the technical problems solved by the present invention are: existing methods for detecting abnormal electricity consumption behavior do not consider variability and complexity, have low accuracy in anomaly detection, inefficient feature extraction, and how to automatically learn and extract key features in electricity consumption data, use self-attention mechanisms to capture global dependencies in time series, and at the same time combine Bayesian optimization to dynamically adjust the detection threshold.

[0007] To solve the above technical problems, the present invention provides the following technical solution: A method for detecting abnormal electricity consumption behavior based on deep learning, comprising:

[0008] Collect electricity consumption behavior data to detect change points, and extract key features according to the detection results;

[0009] Use a deep learning model to convert the key features into input embedding vectors and generate an electricity consumption behavior anomaly score;

[0010] Perform anomaly judgment based on the electricity consumption behavior anomaly score to determine whether it is abnormal.

[0011] As a preferred solution of the method for abnormal power consumption behavior detection based on deep learning according to the present invention, wherein: the detection of change points includes cleaning and filling power consumption behavior data, using the power consumption behavior time series data as input. There are m change points in the time series data. The time series is divided into multiple segments with the change points as boundaries. Each segment corresponds to a probability distribution. According to the probability distribution of each segment, the posterior probability distribution is calculated through the Bayesian formula; according to the posterior probability distribution, the data likelihood of each time point t as a change point is calculated; when the likelihood of time point t as a change point exceeds the preset threshold δ, it is determined that time point t is a change point; when the likelihood of time point t as a change point is lower than the preset threshold δ, it is determined that time point t is not a change point;

[0012] The posterior probability distribution represents the probability distribution of model parameters after observing the data; the calculation of the posterior probability distribution through the Bayesian formula includes multiplying the probability of the data appearing under fixed parameters by the expectation of the parameters before observing the data, and dividing by the total probability of the data appearing;

[0013] The data likelihood is the probability of the observed data appearing when a given time point t is a change point.

[0014] As a preferred solution of the method for abnormal power consumption behavior detection based on deep learning according to the present invention, wherein: the data sampling and key feature extraction according to the detection result includes sampling the data according to the obtained change points. For the time period between every two adjacent change points, according to the sampling density, N i points are collected in the observation point set using the uniform sampling method to obtain a time series, and feature extraction is performed on the time series through wavelet transform as the key feature of the power consumption behavior data.

[0015] As a preferred solution of the method for abnormal power consumption behavior detection based on deep learning according to the present invention, wherein: the conversion into an input embedding vector includes mapping the feature data into an input embedding vector through the linear embedding layer of the deep learning model, using the self-attention mechanism to capture the global dependencies in the time series, calculating for the position of each input embedding vector, using the multi-head attention mechanism to perform parallel calculations on multiple groups of weight heads, and encoding the input embedding vector using the multi-head attention mechanism and the feed-forward network;

[0016] The encoder is composed of multiple layers of attention mechanisms and feed-forward networks. Each layer is optimized and trained through residual connections. The encoded vector is extracted by the encoder and transmitted to the decoder for data reconstruction. The decoder receives the information of the encoder through calculating cross-attention. The decoder receives the target sequence and generates an encoded vector through the embedding layer and position encoding, and introduces attention to calculate the decoded vector.

[0017] As a preferred solution of the method for detecting abnormal electricity consumption behavior based on deep learning according to the present invention, wherein: the generation of the anomaly score includes generating a predicted value by passing the decoded vector, the weight matrix of the decoder output layer, and the bias vector of the decoder output layer through a fully connected layer, taking the predicted value and the original time series as inputs to calculate the reconstruction error, normalizing the obtained anomaly score, predicting the anomaly probability for each time point through a classification head, and combining the reconstruction error and the anomaly probability to calculate the anomaly score;

[0018] The calculation of the reconstruction error includes taking the time series generated by the decoder through the deep learning model and the electricity consumption behavior data as the predicted value and the original time series inputs, comparing the time series generated by the deep learning model and the electricity consumption behavior data one by one, and obtaining the difference between the time series generated by the deep learning model and the electricity consumption behavior data;

[0019] The reconstruction error is the difference between the time series generated by the deep learning model and the electricity consumption behavior data;

[0020] Combining the reconstruction error and the anomaly probability includes that when the difference value measures the inconsistency between the predicted value and the original data, it indicates that the greater the gap between the predicted value and the original data, the higher the anomaly possibility;

[0021] When the difference value measures the consistency between the predicted value and the original data, it indicates that the gap between the predicted value and the original data is small and the anomaly possibility is low;

[0022] For the features generated through the self-attention mechanism, the anomaly detection model calculates the anomaly probability for each time point, and combines the reconstruction error and the anomaly probability in a weighted manner to form a comprehensive anomaly score.

[0023] As a preferred solution of the method for detecting abnormal electricity consumption behavior based on deep learning according to the present invention, wherein: for the anomaly detection through the anomaly score, determining whether it is abnormal includes using Bayesian optimization to perform dynamic threshold search and minimizing the comprehensive loss function; initially setting the parameter range, updating the distribution of the optimal parameters according to the Gaussian process regression model, finding the candidate points for the next evaluation by maximizing the acquisition function, and then performing iterative updates until converging to the optimal threshold to adjust the parameters;

[0024] The use of Bayesian optimization for dynamic threshold search includes setting the range of parameters and updating the distribution of parameters according to the Gaussian process regression model. The Gaussian process regression model constructs a posterior distribution through regression analysis of historical data for adjusting the optimal parameters;

[0025] The construction of the posterior probability distribution includes fitting historical data points to obtain the posterior distribution; setting an initial parameter range based on prior knowledge and the experience of historical data, constructing a surrogate model using existing data through a Gaussian process, and predicting under new input parameters by the surrogate model to output the predicted value and the uncertainty estimate of the predicted value; continuously updating the posterior distribution through Gaussian process regression to obtain new evaluation data and corresponding optimal parameters;

[0026] The adjustment of the optimal parameters includes selecting the optimal next evaluation point according to the mean and variance of the posterior distribution, performing anomaly detection on this evaluation point to obtain the evaluation result, inputting the evaluation result and the evaluation result of the previous evaluation point into the model, updating the model, and continuously optimizing the performance and accuracy of the model until convergence.

[0027] As a preferred solution of the method for detecting abnormal electricity consumption behavior based on deep learning according to the present invention, wherein: the anomaly detection by anomaly scoring and the determination of whether there is an anomaly further include determining whether there is an anomaly according to the comprehensive anomaly score and the dynamic threshold; comparing the comprehensive anomaly score of each time point with the dynamic threshold to determine whether there is an anomaly;

[0028] When the comprehensive anomaly score is greater than the dynamic threshold, it is determined that the electricity consumption behavior at the time point is abnormal, and the anomaly value is set to 1;

[0029] When the comprehensive anomaly score is less than or equal to the dynamic threshold, it is determined that the electricity consumption behavior at the time point is normal, and the anomaly value is set to 0;

[0030] According to the judgment result, each time point is marked, and the abnormal time point will trigger an alarm.

[0031] Another object of the present invention is to provide a system for detecting abnormal electricity consumption behavior based on deep learning, which can solve the problem of the limitation of the current traditional electricity consumption anomaly detection system that relies on fixed thresholds and rules through the collaborative work of the acquisition and extraction module, the conversion and scoring module, and the anomaly detection module.

[0032] As a preferred solution of the system for detecting abnormal electricity consumption behavior based on deep learning according to the present invention, wherein: it includes an acquisition and extraction module, a conversion and scoring module, and an anomaly detection module.

[0033] The acquisition and extraction module is used to detect change points, perform data sampling according to the detection results, and extract key features.

[0034] The conversion and scoring module is used to convert feature data into input embedding vectors using a deep learning model and generate an anomaly score.

[0035] The anomaly detection module is used to perform anomaly detection based on the anomaly score.

[0036] A computer device includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of a method for detecting abnormal electricity consumption behavior based on deep learning.

[0037] A computer-readable storage medium stores a computer program thereon. When the computer program is executed by a processor, it implements the steps of a method for detecting abnormal electricity consumption behavior based on deep learning.

[0038] Advantages of the present invention: The method for detecting abnormal electricity consumption behavior based on deep learning provided by the present invention adaptively learns and extracts key features in electricity consumption data through a deep learning model, and combines a self-attention mechanism to capture global dependencies in time series, greatly improving the accuracy of abnormal detection. The Bayesian optimization method is used to dynamically adjust the threshold, which can flexibly cope with changes in different electricity consumption patterns and avoid false alarms or missed alarms caused by fixed thresholds in traditional methods. The system can effectively handle noise and complex data through multi-level feature extraction and model optimization, improving the system's adaptability to various electricity consumption behaviors. Compared with traditional methods, the present invention has higher computational efficiency when dealing with large-scale data, can perform abnormal detection and threshold optimization in real time, and meets the requirements of smart grids and large-scale electricity consumption monitoring. The present invention achieves better results in terms of accuracy, dynamics, and efficiency. Description of the Drawings

[0039] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for description in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0040] Figure 1 It is the overall flowchart of a method for detecting abnormal electricity consumption behavior based on deep learning provided by the first embodiment of the present invention.

[0041] Figure 2 It is the specific implementation diagram of a method for detecting abnormal electricity consumption behavior based on deep learning provided by the second embodiment of the present invention. Detailed Embodiments

[0042] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following detailed description of the specific embodiments of the present invention will be made in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0043] Example 1, referring to Figure 1-2 , which is an embodiment of the present invention, provides a method for detecting abnormal electricity consumption behavior based on deep learning, including:

[0044] S1: Detect change points, perform data sampling according to the detection results, and extract key features.

[0045] First of all, electricity consumption behavior refers to the power consumption pattern of users within a certain period of time, which reflects the electricity usage of one or more users in different time periods. Electricity consumption behavior is not only affected by personal living habits and needs, but also by environmental factors and economic factors. By analyzing electricity consumption behavior, it can help power companies optimize power resource allocation, improve power usage efficiency, and even achieve more accurate demand forecasting and load management in smart grids.

[0046] Taking the electricity consumption behavior time series data as input, there are m change points in the time series data. The time series is divided into multiple segments with the change points as boundaries. Each segment corresponds to a different probability distribution. According to the obtained probability distribution, the posterior probability distribution is obtained through Bayes' formula. For each time point based on the result of Bayesian inference, calculate the posterior probability of the change point to obtain the data likelihood when the time point t is the change point. When the data likelihood when the time point t is the change point exceeds the preset threshold δ, determine that this time point is a change point.

[0047] Furthermore, sample the data according to the obtained change points. For the time period between every two adjacent change points, select a representative set of observation points. Collect N i points in the set of observation points. Obtain the time series according to the sampling density, the positions of adjacent change points, and the number of sampling points in the time period. Perform feature extraction on the time series through wavelet transform as the key feature of electricity consumption data.

[0048] Specifically, for change point detection, calculate the probability distribution for the time series data through Bayesian inference. The electricity consumption behavior time series data is specifically expressed as:

[0049] X = {x1, x2, …, x T}

[0050] where T represents the length of the data, x T represents the observed value at the t-th time point, and X represents the electricity consumption behavior time series data.

[0051] There are m change points τ1, τ2, …, τ m in the electricity consumption behavior time series. With the change points as boundaries, the time series is divided into multiple segments, and each segment corresponds to a different probability distribution.

[0052] Suppose the data segment obeys a certain probability distribution, and the probability distribution model is specifically expressed as:

[0053]

[0054] where θ k represents the probability distribution model parameter of the k-th segment, and τ k represents the k-th change point.

[0055] According to Bayes' formula, the posterior probability distribution is:

[0056] p(X, τ, θ | λ) ∝ p(X | τ, θ) · p(τ | λ) · p(θ)

[0057] where p(X | τ, θ) is the likelihood function of the data, p(τ | λ) is the prior distribution of the change point, and p(θ) is the prior distribution of the parameter.

[0058] According to the result of Bayesian inference, for each time point t, the calculation method of the posterior probability of the change point is:

[0059]

[0060] where p(X | τ = t) represents the data likelihood when the time point t is the change point, p(τ = t | λ) represents the change point prior, and p(X) represents the marginal likelihood of the data. If it exceeds the preset threshold δ, then this time point is considered as the change point.

[0061] Sampling the data according to the obtained change point results. For the time period [t i-1 , t i between every two adjacent change points, a set of representative observation points is selected. If N i points need to be sampled, then the formula for uniform sampling is:

[0062]

[0063] where t i-1 and t i represent the positions of adjacent change points, N i represents the number of sampling points in the t time period, and the calculation method of the number of sampling points in the t time period is specifically expressed as:

[0064]

[0065] where α represents the sampling density coefficient.

[0066] After sampling, the data sampling result is obtained, and the sampling result is a time series.

[0067] Feature extraction is performed on the time series using wavelet transform to extract key features from the electricity consumption data. For the input time series, the discrete wavelet transform (DWT) is used to calculate the wavelet decomposition, and the input signal passes through the high-pass filter H and the low-pass filter L to obtain the detail component and the approximation component respectively.

[0068] For the detail component and the approximation component of each layer, they are combined into a feature vector, and the combined feature vector is used as the feature data denoted by E.

[0069] S2: Use a deep learning model to convert the feature data into an input embedding vector and generate an anomaly score.

[0070] Through the linear embedding layer of the model, the feature data is mapped into an input embedding vector. The self-attention mechanism is used to capture the global dependencies in the time series. For each position in the input embedding vector sequence, the multi-head attention mechanism is used to perform parallel calculations on multiple groups of weight heads. The multi-head attention mechanism and the feed-forward network are used to encode the input embedding vector.

[0071] The encoder consists of multiple layers of attention mechanism and feed-forward network. Each layer is optimized for training through residual connections. The encoded vector extracted by the encoder is passed to the decoder for data reconstruction. The decoder receives the information from the encoder through calculating cross-attention. The decoder receives the target sequence and generates the input through the embedding layer and position encoding, and introduces attention to calculate the decoded vector.

[0072] Furthermore, the decoded vector, the weight matrix of the decoder output layer, and the bias vector of the decoder output layer are passed through a fully connected layer to generate a predicted value. The predicted value and the original time series are used as inputs to calculate the reconstruction error. The obtained anomaly score is normalized, and the probability of each time point being abnormal is predicted through the classification head. The reconstruction error and the anomaly probability are combined to calculate the anomaly score.

[0073] The calculation of the reconstruction error includes taking the time series generated by the deep learning model and the electricity consumption behavior data generated by the decoder as the predicted value and the original time series input, comparing the time series generated by the deep learning model and the electricity consumption behavior data one by one, and obtaining the difference between the time series generated by the deep learning model and the electricity consumption behavior data. The difference between the time series generated by the deep learning model and the electricity consumption behavior data is the reconstruction error.

[0074] The combination of the reconstruction error and the anomaly probability includes that when the difference value measures the inconsistency between the predicted value and the original data, the larger the error, the greater the gap between the predicted value and the original data, and the higher the anomaly possibility; through the features generated by the self-attention mechanism, the model calculates the anomaly probability of each time point, and the reconstruction error and the anomaly probability are weighted and combined in a weighted manner to form a comprehensive anomaly score.

[0075] Specifically, for the feature data E after feature extraction, a deep learning model is used to generate an anomaly score. For the feature data E, the model first maps it to an input embedding vector Z:

[0076] Z = [z1, z2, …, z T = Embed(E) + PosEnc(T)

[0077] Among them, Embed(E) represents a linear embedding layer, which is used to map the input features to a unified dimension; PosEnc(T) represents positional encoding, which is used to introduce time position information. The calculation formula of positional encoding is specifically expressed as:

[0078]

[0079] Among them, t represents the time step, k represents the dimension index, and d model is the embedding dimension.

[0080] The self-attention mechanism is used to capture the global dependencies in the time series. For the input embedding vector sequence Z, the attention value A at each position i is calculated i

[0081] Q = ZW Q , K = ZW K , V = ZW V

[0082]

[0083] Among them, Q, K, and V respectively represent the query, key, and value of self-attention, respectively represent the trainable weight matrices corresponding to the query, key, and value, and d k represents the scaling factor for attention calculation, and softmax() represents the normalized weight.

[0084] The multi-head attention mechanism is used to perform parallel calculations on multiple groups of weight heads:

[0085] MultiHead(Z) = Concat(head1, head2, …, head h )W O

[0086] Among them, the output head of each attention head i = Attention(Q i , K i , V i ),W O represents the trainable matrix for linear projection.

[0087] The encoder consists of a multi-layer attention mechanism and a feed-forward network. Each layer is optimized for training through residual connections. The calculation formula for the encoded vector is specifically expressed as:

[0088]

[0089] Among them, represents the encoded vector of the i-th layer. The feed-forward network FFN is defined as:

[0090] FFN(x) = ReLU(xW1 + b1)W2 + b2

[0091] The H extracted by the encoder encoder is passed to the decoder for reconstructing data. It receives information from the encoder by calculating cross-attention. The cross-attention calculation method is:

[0092]

[0093] Among them, K encoder = V encoder = H encoder represents the output of the encoder, and Q represents the output of the self-attention module in the decoder.

[0094] The decoder receives the target sequence Y = {y1, y2, …, y T}, and generates the input Z decoder through the embedding layer and positional encoding:

[0095] Z decoder = Embed(Y) + PosEnc(T)

[0096] Attention is introduced to calculate the decoder output:

[0097]

[0098] Among them, represents the decoded vector of the j-th layer. CrossAttention(Q, K encoder , V encoder ) represents cross-attention, and FFN represents the feed-forward network.

[0099] Using the output in the decoder, an anomaly score is generated. First, the predicted value is generated through the fully connected layer

[0100]

[0101] Among them, H decoder represents the hidden state of the decoder output, W out represents the weight matrix of the decoder output layer, and b out represents the bias vector of the decoder output layer.

[0102] Generate anomaly scores by calculating the reconstruction error:

[0103]

[0104] where X represents the original time series.

[0105] Normalize the anomaly scores:

[0106]

[0107] where max(Score reconstruct ) and min(Score reconstruct ) represent the maximum and minimum values of the anomaly scores respectively.

[0108] Predict the probability of an anomaly at each time point through the classification head:

[0109] p = σ(H encoder W cls + b cls )

[0110] where p represents the anomaly probability and σ(·) represents the Sigmoid activation function.

[0111] Combine the reconstruction error and the anomaly probability to calculate the anomaly score:

[0112] AnomalyScore = α·Score norm + (1 - α)·(1 - p)

[0113] where α ∈ [0, 1] represents the weight parameter.

[0114] S3: Perform anomaly detection based on the anomaly score and determine whether it is an anomaly.

[0115] Use Bayesian optimization to find the dynamic threshold and minimize the comprehensive loss function.

[0116] Initially set the parameter range, update the distribution of the optimal parameters according to the Gaussian process regression model, find the candidate points for the next evaluation by maximizing the acquisition function, and then perform iterative updates until converging to the optimal threshold adjustment parameters.

[0117] Specifically, the use of Bayesian optimization to find the dynamic threshold includes setting the range of parameters and updating the distribution of parameters according to the Gaussian process regression model. The Gaussian process regression model constructs a posterior distribution through regression analysis of historical data to continuously adjust the optimal parameters.

[0118] The construction of the posterior probability distribution includes fitting historical data points to obtain the posterior distribution; setting an initial parameter range based on prior knowledge or the experience of historical data. The Gaussian process uses the existing data to construct a surrogate model, which can make predictions under new input parameters and output the predicted value and the uncertainty estimate of the predicted value; continuously update the posterior distribution through Gaussian process regression to obtain new evaluation data and corresponding optimal parameters.

[0119] The adjustment of the optimal parameters includes selecting the optimal next evaluation point according to the mean and variance of the posterior distribution, performing anomaly detection on this evaluation point to obtain the evaluation result, inputting the evaluation result and the evaluation result of the previous evaluation point into the model, and updating the model understanding repeatedly for multiple times. Each time, select the optimal evaluation point in the new parameter space to continuously optimize the performance and accuracy of the model until it converges to an optimal threshold and parameter settings that meet the preset criteria.

[0120] Judge whether it is abnormal according to the comprehensive anomaly score and the dynamic threshold; judge whether there is an anomaly by comparing the comprehensive anomaly score of each time point with the dynamic threshold.

[0121] When the comprehensive anomaly score is greater than the dynamic threshold, it is determined that the electricity consumption behavior at this time point is abnormal, and the anomaly value is set to 1.

[0122] When the comprehensive anomaly score is less than or equal to the dynamic threshold, it is determined that the electricity consumption behavior at this time point is normal, and the anomaly value is set to 0.

[0123] According to the judgment result, each time point will be marked as abnormal or normal, and the abnormal time points will trigger an alarm.

[0124] Specifically, use Bayesian optimization to find the dynamic threshold. The goal of Bayesian optimization is to minimize the comprehensive loss function L(β):

[0125] L(β) = μ·FPR(β) + (1 - μ)·FNR(β)

[0126] Among them, FPR and FNR respectively represent the functions of the false positive rate and the false negative rate, and μ ∈ [0, 1] represents the trade-off parameter.

[0127] The initial parameter range is set as β ∈ [β min , β max , according to the Gaussian process regression model P(L(β)), update the distribution of the optimal parameters, and find the candidate point for the next evaluation by maximizing the acquisition function Acq(β):

[0128]

[0129] Subsequently, perform iterative updates until it converges to the optimal threshold to adjust the parameter β opt, the optimized dynamic threshold calculation formula is specifically expressed as:

[0130] θ dynamic (t) = μ(t) + β opt ·σ(t)·(1 + ω·p(t))

[0131] Among them, μ(t) represents the moving average near time point t, σ(t) represents the moving standard deviation near time point t, ω represents the control parameter, and p(t) represents the change point probability at time point t.

[0132] Combining the anomaly score and the change point probability p, calculate the final comprehensive anomaly score:

[0133] Score combined (t) = γ·Score anomaly (t) + (1 - γ)·p(t)

[0134] Among them, γ ∈ [0, 1] represents the weighting parameter.

[0135] Judge whether it is abnormal according to the comprehensive anomaly score and the dynamic threshold:

[0136]

[0137] Among them, Anomaly(t) represents the state value at time t. When the value is 1, it means abnormal, and when it is 0, it means normal.

[0138] Embodiment 2, an embodiment of the present invention, provides a method for detecting abnormal electricity consumption behavior based on deep learning. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0139] First of all, in the experiment, by comparing the traditional threshold method and the detection method based on the deep learning model, the innovation and advantages of our invention can be clearly seen. The experimental data will be analyzed in detail below:

[0140] The training time of the traditional threshold method is 12 hours, which is relatively short. However, it depends on the manually set threshold and cannot adapt to the complex changing electricity consumption behavior. Therefore, the accuracy may be relatively low in some cases.

[0141] The model based on deep learning: The training time is increased to 15 hours. Since the deep learning model requires a more complex feature extraction and training process, the training time is longer. However, deep learning can automatically extract features and adapt to complex electricity consumption behavior patterns, so it shows higher detection accuracy.

[0142] Dynamic Threshold Adjustment: The training time is 14 hours, slightly shorter than that of the deep learning model. The introduction of dynamic thresholds optimizes the drawbacks of traditional threshold methods and improves the accuracy of anomaly detection.

[0143] Bayesian Optimization Enhancement: The training time is 16 hours, slightly longer than other methods, but by dynamically adjusting the threshold through Bayesian optimization, it further improves the model's adaptability and accuracy.

[0144] Detection Accuracy Analysis

[0145] Traditional Threshold Method: The detection accuracy is 85%. This method relies on fixed thresholds and cannot adapt well to changes in electricity consumption behavior, resulting in false alarms or missed detections in some complex situations.

[0146] Deep Learning-Based Model: The accuracy is improved to 92%. This is because the deep learning model can automatically learn the complex patterns of electricity consumption behavior, thereby reducing errors, especially performing well in the face of dynamic and non-linear electricity consumption behavior.

[0147] Dynamic Threshold Adjustment: The accuracy is further increased to 94%. The introduction of dynamic thresholds enables the model to adjust the detection threshold according to real-time data, adapt to different electricity consumption patterns, and further improve the detection accuracy.

[0148] Bayesian Optimization Enhancement: The accuracy reaches 96%. By continuously adjusting the optimal threshold through Bayesian optimization, the model can maintain high accuracy in various electricity consumption behaviors, especially performing outstandingly when detecting complex and highly variable electricity consumption behaviors.

[0149] False Alarm Rate Analysis

[0150] Traditional Threshold Method: The false alarm rate is 5%. Due to the lack of dynamic thresholds and intelligent optimization, the traditional method often generates false alarms in some normal electricity consumption behaviors.

[0151] Deep Learning-Based Model: The false alarm rate is reduced to 3%. The deep learning model significantly reduces the occurrence of false alarms through automatic feature learning and more precise pattern recognition.

[0152] Dynamic Threshold Adjustment: The false alarm rate is further reduced to 2%. By adjusting the threshold in real time, the model can more accurately distinguish normal and abnormal electricity consumption behaviors, thereby reducing false alarms.

[0153] Bayesian Optimization Enhancement: The false alarm rate is further reduced to 1.5%. Bayesian optimization continuously adjusts the optimal threshold to ensure that the model can accurately identify abnormal behaviors in various environments and minimize false alarms to the greatest extent.

[0154] Missed Detection Rate

[0155] Traditional threshold method: The false negative rate is 8%. The fixed threshold cannot capture minor anomalies in some cases, resulting in false negatives.

[0156] Deep learning-based model: The false negative rate is reduced to 4%. Deep learning can capture more features from the data, reducing false negatives.

[0157] Dynamic threshold adjustment: The false negative rate is further reduced to 3%. Dynamically adjusting the threshold enables the model to still sensitively capture anomalies in complex situations.

[0158] Bayesian optimization enhancement: The false negative rate is further reduced to 2%. By precisely adjusting the threshold through Bayesian optimization, the model can detect anomalies more accurately, further reducing false negatives.

[0159] Precision

[0160] Traditional threshold method: The precision is 90%. This method is relatively basic and limited by the threshold setting, resulting in low precision.

[0161] Deep learning-based model: The precision is increased to 96%. Through the automatic feature learning of deep learning, the model can more accurately identify abnormal and normal data, reducing false positives.

[0162] Dynamic threshold adjustment: The precision is further increased to 97%. By adjusting the threshold in real time, the model can further improve the detection accuracy, especially in unstable or highly variable environments.

[0163] Bayesian optimization enhancement: The precision is further increased to 98%. The introduction of Bayesian optimization further optimizes the model's detection ability, especially when dealing with complex and highly variable electricity consumption behaviors, resulting in a significant improvement in precision.

[0164] Recall rate analysis

[0165] Traditional threshold method: The recall rate is 87%. The recall ability of the traditional method is poor, and it is easy to miss abnormal events.

[0166] Deep learning-based model: The recall rate is increased to 94%. After learning more electricity consumption behavior features, the deep learning model can better identify anomalies and improve the recall rate.

[0167] Dynamic threshold adjustment: The recall rate is increased to 95%. By adjusting the threshold, the model can more sensitively capture minor abnormal behaviors and further improve the recall ability.

[0168] Bayesian optimization enhancement: The recall rate is increased to 97%. Bayesian optimization enhances the model's adaptability, especially in scenarios with high volatility and large changes, and can significantly improve the recall rate.

[0169] According to the tabular data, the deep learning-based abnormal power consumption behavior detection method has significant advantages and innovation. Compared with traditional methods, the solution based on deep learning and dynamic threshold adjustment has greatly improved the detection accuracy, reduced false alarms and missed detections, and the precision and recall rate have also been significantly improved. Especially in the solution enhanced by Bayesian optimization, the performance and accuracy of the model are further improved by dynamically adjusting the threshold and optimizing the detection process.

[0170] Embodiment 3 is an embodiment of the present invention, which provides a system for detecting abnormal power consumption behavior based on deep learning, including a collection and extraction module, a conversion and scoring module, and an abnormal detection module.

[0171] The collection and extraction module is used to detect change points, perform data sampling according to the detection results, and extract key features.

[0172] The conversion and scoring module is used to convert the feature data into input embedding vectors using a deep learning model and generate abnormal scores.

[0173] The abnormal detection module is used to perform abnormal detection based on the abnormal scores.

[0174] If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0175] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.

[0176] More specific examples (nonexhaustive list) of computer-readable media include the following: an electrical connection (electronic device) having one or more wirings, a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable media can even be paper or other suitable media on which a program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other suitable processing as necessary, and then stored in a computer memory.

[0177] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc. It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

[0178] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A method for detecting abnormal electricity consumption behavior based on deep learning, characterized in that, Including: Collecting electricity consumption behavior data to detect change points, and extracting key features according to the detection results; Using a deep learning model to transform the key features into input embedding vectors and generating an abnormal score for electricity consumption behavior; Making an abnormal judgment based on the abnormal score of electricity consumption behavior to determine whether it is abnormal.

2. The method for detecting abnormal electricity consumption behavior based on deep learning according to claim 1, wherein: The detection of change points includes cleaning and filling the electricity consumption behavior data. Using the electricity consumption behavior time series data as input, there are m change points in the time series data. The time series is divided into multiple segments with the change points as boundaries. Each segment corresponds to a probability distribution. According to the probability distribution of each segment, the posterior probability distribution is calculated through the Bayesian formula; according to the posterior probability distribution, the data likelihood at each time point t as a change point is calculated; when the likelihood at time point t as a change point exceeds the preset threshold δ, it is determined that time point t is a change point; when the likelihood at time point t as a change point is lower than the preset threshold δ, it is determined that time point t is not a change point; The posterior probability distribution represents the probability distribution of model parameters after observing the data; the calculation of the posterior probability distribution through the Bayesian formula includes multiplying the probability of the data appearing under fixed parameters by the expectation of the parameters before observing the data and dividing by the total probability of the data appearing; The data likelihood is the probability of the observed data given that time point t is a change point.

3. The method for abnormal power consumption behavior detection based on deep learning according to claim 2, wherein: Sampling data according to the detection results and extracting key features Including sampling the data according to the obtained change points, and for each time period between two adjacent change points, collecting N i points from the set of observation points using the uniform sampling method according to the sampling density, obtaining a time series, and extracting features from the time series through wavelet transform as the key features of the electricity consumption behavior data.

4. The method for detecting abnormal electricity consumption behavior based on deep learning according to claim 3, wherein: The transformation into input embedding vectors includes mapping the feature data into input embedding vectors through the linear embedding layer of the deep learning model, using the self-attention mechanism to capture the global dependencies in the time series, calculating for the position of each input embedding vector, using the multi-head attention mechanism to perform parallel calculations on multiple groups of weight heads, and encoding the input embedding vectors using the multi-head attention mechanism and the feed-forward network; The encoder consists of multiple layers of attention mechanisms and feed-forward networks. Each layer is optimized for training through residual connections. The encoded vectors are extracted by the encoder and passed to the decoder for data reconstruction. The decoder receives the information from the encoder through cross-attention. The decoder receives the target sequence and generates encoded vectors through the embedding layer and position encoding, and introduces attention to calculate the decoded vectors.

5. The method for detecting abnormal electricity consumption behavior based on deep learning according to claim 4, wherein: The generation of the abnormal score includes generating a prediction value by passing the decoded vector, the weight matrix of the decoder output layer, and the bias vector of the decoder output layer through the fully connected layer, using the prediction value and the original time series as input to calculate the reconstruction error, normalizing the obtained abnormal score, predicting the probability of each time point being abnormal through the classification head, and combining the reconstruction error and the abnormal probability to calculate the abnormal score; The calculation of the reconstruction error includes using the time series generated by the deep learning model through the decoder and the electricity consumption behavior data as the prediction value and the original time series input, comparing the time series generated by the deep learning model and the electricity consumption behavior data one by one to obtain the difference between the time series generated by the deep learning model and the electricity consumption behavior data; The reconstruction error is the difference between the time series generated by the deep learning model and the electricity consumption behavior data. Combining the reconstruction error and the anomaly probability includes that when the difference value measures the inconsistency between the predicted value and the original data, it indicates that the greater the gap between the predicted value and the original data, the higher the anomaly possibility; When the difference value measures the consistency between the predicted value and the original data, it indicates that the gap between the predicted value and the original data is small and the anomaly possibility is low; Based on the features generated by the self-attention mechanism, the anomaly detection model calculates the anomaly probability at each time point, and combines the reconstruction error and the anomaly probability in a weighted manner to form a comprehensive anomaly score.

6. The method for detecting abnormal electricity consumption behavior based on deep learning according to claim 5, wherein: The anomaly detection by the anomaly score and determining whether there is an anomaly includes using Bayesian optimization to find the dynamic threshold, minimizing the comprehensive loss function; initially setting the parameter range, updating the distribution of the optimal parameters according to the Gaussian process regression model, finding the candidate points for the next evaluation by maximizing the acquisition function, and then performing iterative updates until converging to the optimal threshold to adjust the parameters; The using Bayesian optimization to find the dynamic threshold includes setting the range of the parameters and updating the distribution of the parameters according to the Gaussian process regression model. The Gaussian process regression model constructs the posterior distribution through the regression analysis of historical data for adjusting the optimal parameters; The constructing the posterior probability distribution includes fitting the historical data points to obtain the posterior distribution; setting the initial parameter range based on prior knowledge and the experience of historical data, constructing a surrogate model using the existing data through the Gaussian process. The surrogate model makes predictions under the new input parameters, outputs the predicted value and the uncertainty estimate about the predicted value; continuously updating the posterior distribution through the Gaussian process regression to obtain the new evaluation data and the corresponding optimal parameters; The adjusting the optimal parameters includes selecting the optimal next evaluation point according to the mean and variance of the posterior distribution, performing anomaly detection on this evaluation point to obtain the evaluation result, inputting the evaluation result and the evaluation result of the previous evaluation point into the model to update the model, and continuously optimizing the performance and accuracy of the model until convergence.

7. The method for abnormal power consumption behavior detection based on deep learning as claimed in claim 6, wherein: The anomaly detection by the anomaly score and determining whether there is an anomaly also includes determining whether there is an anomaly according to the comprehensive anomaly score and the dynamic threshold; determining whether there is an anomaly by comparing the comprehensive anomaly score at each time point with the dynamic threshold; When the comprehensive anomaly score is greater than the dynamic threshold, it is determined that the electricity consumption behavior at the time point is abnormal, and the anomaly value is set to 1; When the comprehensive anomaly score is less than or equal to the dynamic threshold, it is determined that the electricity consumption behavior at the time point is normal, and the anomaly value is set to 0; According to the judgment result, each time point is marked, and the abnormal time points will trigger an alarm.

8. A system adopting the method for abnormal electricity consumption behavior detection based on deep learning according to any one of claims 1 to 7, characterized in that: It includes a data acquisition and extraction module, a score conversion module, and an anomaly detection module; The data acquisition and extraction module is used to acquire the electricity consumption behavior data to detect the change points and extract the key features according to the detection results; The score conversion module is used to convert the feature data into input embedding vectors using a deep learning model and generate an anomaly score; The anomaly detection module is used to perform anomaly detection on the anomaly score of the electricity consumption behavior to determine whether there is an anomaly.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method for anomaly detection of electricity consumption behavior based on deep learning according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method for detecting abnormal electricity consumption behavior based on deep learning according to any one of claims 1 to 7.