Vehicle-road cloud integrated complex time sequence real-time anomaly detection method and system

By introducing time context perception module, channel adaptive enhancement module and interactive convolution module into the vehicle-road cloud integrated architecture, feature extraction and abnormal detection are optimized, and the abnormal detection problems of high-dimensional, nonlinear and timing data under the vehicle-road cloud integrated architecture are solved, and more efficient and accurate abnormal detection is achieved, meeting the real-time and robustness requirements of intelligent transportation systems.

CN120354889AActive Publication Date: 2025-07-22XIHUA UNIV

Patent Information

Application Number
CN202510839378.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-07-22
Estimated Expiration
2045-06-23

AI Technical Summary

Technical Problem

The existing deep learning models are difficult to solve the time-dependence modeling, feature redundancy interference, diversified anomaly type identification and real-time requirements of high-dimensional, nonlinear and time-series data under the integrated vehicle-road cloud architecture, resulting in insufficient abnormal detection accuracy and efficiency in intelligent transportation systems.

Method used

The integrated vehicle-road cloud complex time series real-time anomaly detection method is adopted. By introducing a time context perception module, a channel adaptive enhancement module and an interactive convolution module, combined with the Transformer architecture, it optimizes feature extraction and abnormal detection, reduces the computational complexity, and improves model adaptability and real-timeness.

Benefits of technology

It improves the accuracy and robustness of abnormal detection, meets the real-time requirements in the Internet of Vehicles scenarios, can efficiently handle variable traffic scenarios and various types of abnormal events, reduces the computational complexity, and ensures the stability and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354889A_ABST
    Figure CN120354889A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle-road cloud integrated complex time sequence real-time anomaly detection method and system, and relates to the field of Internet of Vehicles, and the method comprises the steps: S1, constructing an initial anomaly detection model; s2, acquiring a training data set; s3, importing the training data set into the initial anomaly detection model, and carrying out training optimization on the training data set to obtain an optimized anomaly detection model; s4, acquiring data to be predicted; s5, performing anomaly detection on to-be-predicted data by using the optimized anomaly detection model to obtain an anomaly detection result; according to the method, time pooling and a channel attention mechanism are introduced for extracting a complex interaction relationship between a feature dimension and a time dimension; a module based on a channel weight adjustment mechanism is added, the calculation complexity of the model is reduced by dynamically adjusting the channel weight, and the expression ability of the model to key features is improved; and the integrated interactive convolution module is used for capturing a dependency relationship in a multi-dimensional space and supporting simultaneous detection of various types of abnormal events.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vehicle networking, and particularly to a method and system for real-time anomaly detection of complex time series in vehicle-road-cloud integration. Background Art

[0002] Autonomous driving technology is an important area attracting much attention in the current technological field, which provides new possibilities for people's travel. With the booming development of autonomous driving technology, the global intelligent transportation system is undergoing profound changes. In the intelligent transportation system, the in-vehicle terminal, roadside terminal and cloud work together (vehicle-road-cloud integration) to jointly ensure the safety and efficiency of traffic operation. Currently, the development path of autonomous driving mainly includes two major technical routes: single-vehicle intelligence and vehicle-road cooperation (V2X). Among them, the vehicle-road-cloud integration architecture, as shown in Figure 1 ..., as the core of the V2X mode, has become an important development direction for improving the safety, stability and intelligence level of autonomous driving systems. Vehicle-road-cloud integration closely combines the in-vehicle terminal, roadside terminal and cloud. The relationship among the three is as shown in Figure 2 .... Relying on technologies such as cloud computing, big data analysis, artificial intelligence, high-precision positioning (such as Beidou navigation), vehicle networking and Internet of Things, it realizes real-time data collection, centralized fusion and intelligent decision-making. Under this architecture, the data sensed by vehicles, the traffic information collected by roadside infrastructure and the computing resources of the cloud are highly coordinated to form an overall intelligent transportation system. Compared with single-vehicle intelligence that relies on the computing power of a single vehicle, vehicle-road-cloud integration can provide more accurate environment perception, risk prediction and anomaly detection in complex traffic scenarios through the centralized computing and global optimization capabilities of the cloud, so as to significantly improve the overall efficiency and safety of autonomous driving systems.

[0003] Vehicles are equipped with numerous sensors to monitor multi-dimensional states such as speed, acceleration, brake pressure, and tire pressure. The multi-dimensional data generated by vehicle sensor nodes are interrelated in a complex manner and exhibit dynamic and non-stationary characteristics. Accurately monitoring these high-dimensional dynamic features is crucial for ensuring traffic safety. Capturing these feature relationships across time and space requires the model to have strong time modeling capabilities and key feature recognition capabilities. First, abnormal behaviors in the Internet of Vehicles (IoV) usually do not occur in isolation at a single time step or in a single dimension, but involve the interaction of multiple time steps and multiple dimensions. For example, sudden acceleration accompanied by frequent sharp turns and braking may lead the system to determine driver fatigue or vehicle failure. Second, although the high-dimensional sensor data collected by IoV devices contain rich information, a large number of redundant features will increase the computational burden, especially in resource-constrained in-vehicle terminals, affecting the efficiency and real-time performance of the model. Due to the high data dimension and complex coupling relationships between variables, many features contribute little or are irrelevant to anomaly detection, while key monitoring indicators (such as emergency braking frequency, abnormal engine status, etc.) directly affect safety judgment. If key features cannot be accurately extracted and enhanced, the model may be interfered by redundant information, resulting in a decline in detection performance and an increase in the false positive rate (FPR). In addition, IoV anomaly events not only occur with a low frequency but also have extremely complex types, involving various situations such as hardware failures (temporary sensor failures), sudden behaviors (hard braking, collisions), and cyberattacks (short-term delays in V2X communication). Anomalies may exist across scales and resolutions. Existing methods have insufficient recognition accuracy when dealing with these short-cycle and low-amplitude anomaly patterns, and may miss the opportunity for early warning. Therefore, reasonably screening and optimizing features in the anomaly detection process is of great significance for improving detection accuracy and reliability.

[0004] As an important part of the intelligent transportation system, the roadside unit relies on a variety of sensors to monitor the road environment, traffic flow, and vehicle status in real time. Similar to the in-vehicle unit, the data collected by the roadside unit also exhibits high-dimensional, non-stationary, and complex coupling characteristics, posing a huge challenge to anomaly detection. Since abnormal behaviors usually involve multiple time steps and different data dimensions, it is difficult to accurately identify abnormal patterns relying solely on a single sensor or local data analysis. For example, a sudden fluctuation in traffic flow on a certain road section may be a normal phenomenon caused by a surge in vehicle flow, or it may be data anomalies caused by the failure of the roadside unit (RSU), limited edge computing resources, or network latency. If the detection model cannot correctly distinguish these situations, it may lead to false alarms or missed alarms, thus affecting traffic management and safety decisions. In addition, although the data collected by roadside sensors is rich, excessive redundant features will increase the computational overhead and affect the real-time analysis ability. Different features contribute differently to anomaly detection, and redundant irrelevant features will interfere with the system's judgment. Therefore, the detection model needs to have an efficient feature screening ability to accurately extract and enhance key monitoring indicators (such as abnormal signal light status, vehicle identification errors, temporary RSU failures, etc.), thereby improving the accuracy of anomaly detection and reducing the false alarm rate. It should be noted that some abnormal manifestations of the in-vehicle unit may actually be normal phenomena in the collaborative work between the in-vehicle unit and the roadside unit. For example, under the intelligent traffic signal control system, some vehicles may receive a green wave passing strategy through V2X communication and continuously accelerate at multiple intersections. This behavior may appear as abnormal acceleration from the perspective of single-vehicle data, but it is actually a normal result of the system optimizing traffic efficiency. Similarly, in an autonomous driving environment, if the roadside unit detects a sudden accident ahead and sends an obstacle avoidance instruction to the in-vehicle unit in a timely manner, the vehicle may quickly brake and change lanes. This sudden change in speed and trajectory may be misjudged as abnormal driving behavior when analyzed in isolation, but it is actually a manifestation of the vehicle-road collaborative system actively ensuring safety. Therefore, in the process of anomaly detection, it is necessary to combine the collaborative information of the in-vehicle unit and the roadside unit to avoid misreporting normal traffic behaviors, ensuring that the detection model can identify real abnormal situations without affecting the normal operation of vehicle-road collaborative optimization.

[0005] The cloud plays a core role in the vehicle-road-cloud integrated architecture. By integrating data from the vehicle side and the roadside unit, it conducts centralized anomaly detection and intelligent analysis. Data from the vehicle side and the roadside unit may have limitations from a local perspective, but the cloud can mine anomaly patterns across time and space from a global perspective. For example, if multiple vehicles in a certain area suddenly brake simultaneously, relying solely on the monitoring of the vehicle side or a single RSU may not be able to distinguish whether it is an individual driving anomaly or a road emergency. However, the cloud can combine multi-source data, analyze the overall traffic flow changes in the area, and consider external factors such as historical data, weather information, and construction conditions to improve the accuracy of anomaly detection. In addition, the computing power of the cloud can support more complex deep learning models to conduct fusion analysis on multi-dimensional data, further enhancing the robustness of anomaly detection. Therefore, under the vehicle-road-cloud integrated architecture, an accurate and efficient cloud-based centralized anomaly detection model is essential for ensuring the stable operation of the intelligent transportation system.

[0006] In recent years, deep learning-based methods have made significant progress in the field of multivariate time series anomaly detection. By constructing neural networks, they can extract information from unstructured data, learn the characteristics and distributions of normal data, and identify outliers in test data through reconstruction errors or prediction errors. Compared with traditional anomaly detection methods, deep learning shows better performance in processing high-dimensional, non-linear, and time-series data, especially in capturing complex dynamic patterns and anomaly events, and can better meet the requirements of real-time and accuracy in the intelligent transportation system.

[0007] Currently, researchers have proposed some deep learning algorithms. Among them, the ability of unsupervised anomaly detection methods and Transformer-based methods to extract time series features has received extensive attention:

[0008] 1. In the intelligent transportation system, due to the huge amount and diverse types of data generated by in-vehicle devices, roadside facilities, and cloud platforms, unsupervised learning methods are widely used in real-time time series anomaly detection because of their characteristic of not relying on a large amount of labeled data. Traditional unsupervised learning methods, such as clustering-based algorithms (e.g., k-means) and density-based algorithms (e.g., DBSCAN), can effectively discover potential abnormal behaviors in vehicles or traffic systems by identifying the deviation between data points and the normal data distribution. In recent years, with the development of deep learning technology, new unsupervised learning methods have greatly improved the model's anomaly detection ability. For example, models such as Autoencoders, Variational Autoencoders (VAEs), and the variant combined with Long Short-Term Memory network (LSTM-VAE) identify anomalies by analyzing the error changes in the data reconstruction process. These deep learning methods, with their powerful feature extraction ability and the ability to model non-linear and complex data patterns, provide more accurate and efficient anomaly detection means for the vehicle networking system. In addition, the ModernTCN model can effectively capture the dependencies between multivariate by introducing a convolutional neural network structure, thus improving the sensitivity to abnormal patterns. The TimesNet method enhances the modeling ability for intra-period and cross-period changes by converting time series data into a two-dimensional tensor form, providing a new solution for complex time-related anomaly detection in the vehicle networking system.

[0009] 2. The ability to analyze the correlation between time series is crucial for system anomaly detection.

[0010] By combining the self-attention mechanism in the Transformer architecture, the AnomalyTransformer model effectively captures the long-range dependencies in time series data and introduces an association difference metric to enhance the model's detection performance on complex datasets. In addition, a Squeeze-and-Excitation (SE) module is embedded in the adversarial autoencoder to improve its ability to capture the normal distribution of positive samples. This method enhances the model's attention to important features, making it more flexible and robust in dealing with complex patterns. However, existing methods still have some limitations, such as the difficulty in simultaneously solving problems such as long-term time dependency modeling, co-variation analysis of multi-dimensional data, selective enhancement of key channel features, and accurate identification of fine-grained abnormal patterns. These deficiencies make the current deep learning models appear inadequate when facing complex traffic scenarios and diverse abnormal patterns in the intelligent transportation environment. Therefore, how to design a more efficient algorithm framework to meet the strict requirements of the intelligent transportation system for real-time and accuracy remains a challenging research direction.

[0011] Due to the large scale and diverse types of data in the intelligent transportation system, the mutual influence of different features of multivariate time series and different time dimensions may lead to an increase in the false positive rate. At the same time, the diversity of abnormal events and the lack of labeled data pose greater challenges to system anomaly detection. Therefore, the existing anomaly detection methods still have the following deficiencies: ① Insufficient time-dependent modeling, resulting in complex dynamic anomalies. It is difficult to recognize that there are strong time dependencies and cross-scale dynamic characteristics in the sensor data of the intelligent transportation system, and different abnormal patterns may gradually appear in short-term bursts or long-term accumulations. Existing methods have limitations in modeling long-range time relationships and multi-time scale features, making it difficult to accurately capture complex time dynamic patterns and prone to missing potential risk events. ② Feature redundancy interference, reducing model performance and computational efficiency. In the high-dimensional data generated by in-vehicle devices and roadside facilities, there are a large number of irrelevant or low-contributing features, which are likely to interfere with the learning of abnormal patterns. Existing methods lack an effective feature screening mechanism, resulting in a decline in model performance under high-dimensional data, while increasing unnecessary computational overhead, especially limiting the real-time detection ability in resource-constrained in-vehicle terminals. ③ Diverse abnormal types and cross-scale existence, insufficient model adaptability. The abnormal events in the intelligent transportation system are complex in type, involving various scenarios such as hardware failures, abnormal driving behaviors, and cyber attacks. Abnormal features may exist across time steps and resolutions. Existing methods have limited recognition capabilities when facing multi-type and cross-dimensional abnormal patterns, resulting in low detection accuracy for specific types of anomalies and insufficient generalization ability, making it difficult to adapt to complex traffic environments. Summary of the Invention

[0012] The purpose of the present invention is to design a vehicle-road-cloud integrated complex time series real-time anomaly detection method and system to solve the above problems.

[0013] The present invention achieves the above purpose through the following technical solutions:

[0014] A vehicle-road-cloud integrated complex time series real-time anomaly detection method, comprising:

[0015] S1. Construct an initial anomaly detection model. The anomaly detection model includes an embedding encoding module, multiple encoders, a reconstruction module, and an anomaly analysis module. The output of the embedding encoding module is respectively used as the input of the multiple encoders, the output of the multiple encoders is used as the input of the reconstruction module, and the output of the reconstruction module is used as the input of the anomaly analysis module; the embedding encoding module is used to reduce the dimension of the input multi-dimensional time series data and add position encoding; the encoder is used to extract features to generate an encoded sequence; the reconstruction module is used to reconstruct the input sequence from the encoded sequence; the anomaly analysis module is used to calculate the anomaly score for each time step and compare it with the threshold δ to obtain the anomaly detection result;

[0016] S2. Obtain a training data set;

[0017] S3. Import the training dataset into the initial anomaly detection model, train and optimize it to obtain an optimized anomaly detection model;

[0018] S4. Obtain the data to be predicted;

[0019] S5. Use the optimized anomaly detection model to perform anomaly detection on the data to be predicted and obtain the anomaly detection result.

[0020] The vehicle-road-cloud integrated complex time series real-time anomaly detection system includes:

[0021] A memory; the memory is used to store computer programs;

[0022] An actuator; the actuator is used to execute the computer programs in the memory. When the computer programs are executed, the vehicle-road-cloud integrated complex time series real-time anomaly detection method as described above is implemented.

[0023] The vehicle-road-cloud integrated system includes:

[0024] The in-vehicle terminal; the in-vehicle terminal is used to obtain the sensor data of the vehicle in real time;

[0025] The roadside terminal; the roadside terminal is used to sense the traffic data in real time. The signal terminal of the in-vehicle terminal is connected to the signal terminal of the roadside terminal;

[0026] The cloud; the cloud includes the vehicle-road-cloud integrated complex time series real-time anomaly detection system as described above. The signal terminals of the cloud are respectively connected to the signal terminals of the in-vehicle terminal and the roadside terminal.

[0027] The beneficial effects of the present invention are as follows: (1) Improve detection accuracy: By introducing the Temporal Context-Aware Module (TCAM), the model can more accurately capture the anomaly features in the complex traffic environment, thereby improving the accuracy of anomaly detection. (2) Improve computational efficiency: The Squeeze-and-Excitation (SE) module based on the channel weight adjustment mechanism effectively reduces the computational complexity of the model, enabling it to operate efficiently on resource-constrained devices and meet the actual deployment requirements in the vehicle networking scenario. (3) Enhance robustness: The introduction of the Interactive Convolution Block (ICB) enables the model to have stronger adaptability, can cope with changing traffic scenarios, and at the same time supports the detection of multiple types of anomaly events, significantly improving the stability and reliability of the system. (4) Meet real-time requirements: Through the time pooling technology, the model can quickly process and make decisions on the real-time data stream, ensuring timely response in the case of high-speed vehicle movement and dynamic changes in the traffic environment, and fully meeting the real-time requirements in the vehicle networking scenario. Description of the Drawings

[0028] Figure 1 Schematic diagram of the vehicle-road-cloud integration system Figure 1 ;

[0029] Figure 2 Schematic diagram of the vehicle-road-cloud integration system Figure 2 ;

[0030] Figure 3 It is the architecture diagram of the interactive convolution module in the anomaly detection model of this method;

[0031] Figure 4 It is the overall architecture diagram of the anomaly detection model of this method;

[0032] Figure 5 It is the architecture diagram of the time context awareness module in the anomaly detection model of this method;

[0033] Figure 6 It is the architecture diagram of the channel adaptive enhancement module in the anomaly detection model of this method;

[0034] Figure 7 It is the overall average P, R, and F1 scores of this method and all baselines on five datasets;

[0035] Figure 8 It is the comparison chart of F1 scores between this method and all baseline methods on the SMD dataset;

[0036] Figure 9 It is the comparison chart of F1 scores between this method and all baseline methods on the PSM dataset;

[0037] Figure 10 It is the comparison chart of F1 scores between this method and all baseline methods on the MSL dataset;

[0038] Figure 11 It is the comparison chart of F1 scores between this method and all baseline methods on the SMAP dataset;

[0039] Figure 12 It is the comparison chart of F1 scores between this method and all baseline methods on the SWAT dataset. Detailed Implementation Manner

[0040] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Generally, the components of the embodiments of the present invention described and illustrated in the drawings here can be arranged and designed in various different configurations.

[0041] Accordingly, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0042] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not require further definition and explanation in subsequent drawings.

[0043] In addition, terms such as "first", "second", etc. are only used for descriptive distinction and should not be construed as indicating or implying relative importance.

[0044] In the description of the present invention, it should also be noted that, unless otherwise clearly defined and limited, terms such as "set", "connect", etc. should be understood in a broad sense. For example, "connect" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0045] The following will describe in detail the specific embodiments of the present invention with reference to the accompanying drawings.

[0046] A vehicle-road-cloud integration complex time series real-time anomaly detection method includes:

[0047] S1. Construct an initial anomaly detection model. As Figure 4 shown, the anomaly detection model includes an embedding encoding module, a plurality of encoders, a reconstruction module, and an anomaly analysis module. The output of the embedding encoding module is respectively used as the input of L encoders. The outputs of the plurality of encoders are all used as the input of the reconstruction module. The output of the reconstruction module is used as the input of the anomaly analysis module. The embedding encoding module is used to reduce the dimension of the input multi-dimensional time series data and add position encoding. The encoder is used to extract features to generate an encoded sequence. The reconstruction module is used to reconstruct the input sequence from the encoded sequence. The anomaly analysis module is used to calculate the anomaly score for each time step and compare it with the threshold δ to obtain the anomaly detection result.

[0048] Each encoder includes an anomaly attention module, a temporal context awareness module, a first residual connection and layer normalization module, a channel adaptive enhancement module, a second residual connection and layer normalization module, an interactive convolution module, a third residual connection and layer normalization module, a forward propagation module, and a fourth residual connection and layer normalization module. The output of the anomaly attention module is used as the input to the temporal context awareness module and the reconstruction module respectively. The output of the embedding encoding module is used as the input to the anomaly attention module and the first residual connection and layer normalization module. The output of the temporal context awareness module is used as the input to the first residual connection and layer normalization module. The output of the first residual connection and layer normalization module is used as the input to the channel adaptive enhancement module and the second residual connection and layer normalization module respectively. The output of the second residual connection and layer normalization module is used as the input to the interactive convolution module and the third residual connection and layer normalization module respectively. The output of the interactive convolution module is used as the input to the third residual connection and layer normalization module. The output of the third residual connection and layer normalization module is used as the input to the forward propagation module and the fourth residual connection and layer normalization module respectively. The output of the forward propagation module is used as the input to the fourth residual connection and layer normalization module. The output of the fourth residual connection and layer normalization module is used as the input to the reconstruction module. The anomaly attention module uses an anomaly attention mechanism to quantify the correlation difference to effectively distinguish normal points and anomaly points and amplify the anomaly point features. The temporal context awareness module is used to extract global features and local features and generate a temporal feature matrix. The channel adaptive enhancement module is used to strengthen key features. The interactive convolution module is used to capture short-term anomalies and long-term trends and splice the short-term anomalies and long-term trends.

[0049] As Figure 5 shown, the temporal context awareness module includes an attention pooling layer, an average pooling layer, a shared fully connected layer, two convolutional activation layers, and a first fusion layer. The output of the anomaly attention module is used as the input to the attention pooling layer and the average pooling layer respectively. The attention pooling layer is used to extract local features, and the average pooling layer is used to extract global features. The local features are weighted and summed and then jointly input to the shared fully connected layer for feature storage and fusion. The two convolutional activation layers calculate the interaction relationship between channels, dynamically adjust the importance of each channel, and strengthen the temporal dynamic information. The output of the shared fully connected layer is used as the input to the two convolutional activation layers respectively. The output of the two convolutional activation layers is used as the input to the first fusion layer. The first fusion layer uses an addition fusion strategy to fuse the features strengthened by the two convolutional activation layers and the output of the anomaly attention module to generate an enhanced temporal feature matrix. .

[0050] As Figure 6As shown in the figure, the channel adaptive enhancement module sequentially includes a global attention pooling layer, two fully connected layers, an activation layer, and an adjustment layer from input to output. The global attention pooling layer is used to perform global average pooling on the feature vectors at each time step to compress the channel dimension. The two fully connected layers are used to generate channel weights. The activation layer uses the sigmoid function for activation. The adjustment layer is used to adjust the original features according to the weights, expressed as .

[0051] As Figure 3 shown in the figure, the interactive convolution module includes a multi-scale convolution block and a splicing layer. The multi-scale convolution block captures short-term anomalies and long-term trends. The splicing layer is used to splice short-term anomalies and long-term trends to form a complete representation , and the multi-scale convolution block consists of multiple one-dimensional convolution layers with different kernel sizes.

[0052] The reconstruction module sequentially includes a linear mapping layer and a normalization layer from input to output. The linear mapping layer is used to reconstruct the input sequence to obtain a reconstruction result , and the outputs of the anomaly attention module and the fourth residual connection and layer normalization module are both used as inputs to the linear mapping layer.

[0053] S2. Obtain a training data set;

[0054] S3. Import the training data set into the initial anomaly detection model, train and optimize it to obtain an optimized anomaly detection model; use the reconstruction error to train the anomaly detection model, and the loss function is expressed as ;

[0055] S4. Obtain the data to be predicted;

[0056] S5. Use the optimized anomaly detection model to perform anomaly detection on the data to be predicted to obtain an anomaly detection result; the anomaly score is expressed as ; when the anomaly score exceeds the threshold δ, the anomaly detection result is an anomaly point; otherwise, the anomaly detection result is a normal point.

[0057] Improve the detection accuracy: By introducing a Temporal Context-Aware Module (TCAM), the model can more accurately capture anomaly features in a complex traffic environment, thereby improving the accuracy of anomaly detection.

[0058] Improve the computational efficiency: The channel adaptive enhancement module, which is a module based on the channel weight adjustment mechanism (Squeeze-and-Excitation, SE), effectively reduces the computational complexity of the model, enabling it to operate efficiently on resource-constrained devices and meet the actual deployment requirements in the vehicle networking scenario.

[0059] Enhanced Robustness: The introduction of the Interactive Convolution Block (ICB) enables the model to have stronger adaptability, cope with variable traffic scenarios, and support the detection of multiple types of abnormal events simultaneously, significantly improving the stability and reliability of the system.

[0060] Meeting Real-time Requirements: Through time pooling technology, the model can quickly process and make decisions on real-time data streams, ensuring timely responses in high-speed vehicle movement and dynamic traffic environment changes, fully meeting the real-time requirements in the vehicle networking scenario.

[0061] This method is based on Transformer for improvement to extract the interdependencies between vectors in multivariate time series. To make this method have better robustness, a cascaded feature extractor is used to extract more representative features, and finally, reconstruction is carried out for better anomaly detection. This method realizes relatively accurate anomaly detection by using the error between real data and predicted data.

[0062] This method combines the characteristics of the intelligent connected vehicle operating environment and makes innovative designs in the encoder part: First, time pooling and the Channel Attention Mechanism (TCAM) are introduced to extract the complex interaction relationships between feature dimensions and time dimensions; Second, a module based on the channel weight adjustment mechanism (SE) is added to reduce the computational complexity of the model by dynamically adjusting channel weights, while enhancing the model's ability to express key features; Finally, the Interactive Convolution Block (ICB) is integrated to capture the dependencies in the multi-dimensional space and support the simultaneous detection of multiple types of abnormal events. These improvements enable the model to have stronger robustness and real-time performance while improving the detection accuracy, and can efficiently handle the complex dynamic scenarios and high-dimensional data challenges in the intelligent transportation system environment.

[0063] The vehicle-road-cloud integrated complex time series real-time anomaly detection system includes:

[0064] A storage; the storage is used to store computer programs;

[0065] An actuator; the actuator is used to execute the computer programs in the storage, and when executing the computer programs, it realizes the vehicle-road-cloud integrated complex time series real-time anomaly detection method as described above.

[0066] As Figure 1 、 Figure 2 shown, the vehicle-road-cloud integrated system includes:

[0067] The vehicle-mounted terminal; the vehicle-mounted terminal is used to obtain the sensor data of the vehicle in real time;

[0068] Roadside unit; the roadside unit is used to sense traffic data in real time, and the signal terminal of the vehicle-mounted unit is connected to the signal terminal of the roadside unit;

[0069] Cloud; the cloud includes the vehicle-road-cloud integrated complex time series real-time anomaly detection system as described above, and the signal terminals of the cloud are respectively connected to the signal terminals of the vehicle-mounted unit and the roadside unit.

[0070] Experimental evaluation:

[0071] 1. Dataset:

[0072] Five representative complex multivariate time series benchmark datasets SMD, PSM, MSL, SMAP, and SWAT from real-world applications are used to evaluate the model of the proposed method.

[0073] 2. Model training process:

[0074] ① Data embedding and time encoding: The multi-dimensional time series data (such as speed, steering angle, tire pressure, battery voltage, GPS location, throttle opening, etc.) before being input into the model (where represents the data collected by the nth sensor at time step t, T represents the length of the time series, and N represents the total number of sensors), the input time series window of each layer needs to be first converted into an embedding representation through the embedding layer. Since the monitoring data in the vehicle networking system is often high-dimensional and heterogeneous, directly processing the original data may lead to insufficient feature representation and high computational complexity. Therefore, by embedding operation, the multi-dimensional monitoring index data is converted into a low-dimensional dense vector representation, which can effectively reduce the dimension of the data, strengthen the expression of key features, and at the same time retain the relative relationship of multi-dimensional characteristics; in order to make up for the time information that may be lost during the dimension reduction process and maintain the temporal characteristics of the sequence, position encoding is added to the embedding representation Z to explicitly represent the timestamp information, so that the model can better understand the order and dynamic changes in the time series data, expressed as:

[0075] ;

[0076] Z represents the input feature matrix after embedding, InputEmbedding() maps the input sequence X to a high-dimensional embedding space, and PositionEncoding() encodes the information.

[0077] The position encoding uses sine and cosine functions, expressed as:

[0078] ; ;

[0079] Among them, PE represents the result of position encoding, m represents the dimension index, d represents the total embedding dimension, and t is the time step index.

[0080] The monitoring data in the vehicle networking system has the following typical characteristics: high dimensionality, multiple variables, strong interdependence, etc.; the above embedding operation and position encoding processing not only reduce the computational complexity, but also enhance the model's understanding of multi-dimensional features and time dynamics. These characteristics make it challenging to directly process the data, such as insufficient feature expression and difficulty in capturing key patterns. Therefore, after the embedding operation, this method stacks L encoders with the same structure for further feature extraction. In order to accurately capture the key features of multi-dimensional monitoring data in the cloud system. In each layer of the encoder, a cascaded feature extractor combined with an anomaly attention mechanism is deployed.

[0081] ② Anomaly attention mechanism: The feature sequence after convolution is input into the encoder. Since the number of normal points dominates and suppresses the feature expression of abnormal points, this method uses the anomaly attention mechanism to quantify the association difference to effectively distinguish normal points and abnormal points. At the same time, the min-max strategy is used to amplify the association difference, and then the feature extraction is focused through the sparse distribution of abnormal points. The average of the association differences of L layers is obtained as the association loss AssDis, which is expressed as:

[0082] ;

[0083] where NLs is the number of network layers, represents the probability distribution of normal points in the c-th channel of the nls-th layer, represents the probability distribution of abnormal points in the c-th channel of the nls-th layer, KL represents the Kullback-Leibler divergence, which is used to measure the difference between two distributions, N represents the number of sensors, and c and nls both represent indices.

[0084] ③ Temporal context awareness: The time pooling and channel attention mechanism are introduced to extract the context information of the time series. The specific details are as Figure 5 shown. By sliding the window and using the attention pooling and average pooling strategies, the local and global features at different time scales are extracted to alleviate the redundancy problem brought by long sequences. The global feature is expressed as: ; The local feature is expressed as: ; where, represents the sliding window length, represents the embedded feature in the c-th channel at the t-th time step, represents the attention weight, which is used to emphasize the key time points, represents the global average feature, Represents local context features. And a shared storage filter bank is used for feature storage and fusion. Based on the pooled feature vectors, 1×1 convolutions and softmax operations are used to calculate the interaction relationships between channels, dynamically adjusting the importance of each channel and strengthening the temporal dynamic information. , (where represents the pooled features of channel c, w represents the weight parameter, o represents the index, and β represents the channel attention coefficient. represents the feature representation after reweighting), and then an addition fusion strategy is used to finally generate the enhanced temporal feature matrix , which is expressed as: ; thereby improving the model's ability to perceive outliers.

[0085] ④ Channel Adaptive Enhancement: As Figure 6 shown, first, the feature vectors at each time step are compressed through global average pooling of the input features to extract global channel information and compress the channel dimension. Subsequently, two fully connected layers and activation functions are used to learn the importance of each channel, and the Sigmoid activation function is used to generate the channel weights. Finally, these weights are used to adaptively adjust the channel intensity of the input features, thereby strengthening key features, suppressing irrelevant information, improving the discriminative ability of the model, and alleviating the problems of high-dimensional feature redundancy and limited device resources, which is expressed as :

[0086] ;

[0087] where represents the value at the (i, j) position in the input feature map , H and W represent the height and width of the feature map, and represent the weights of the fully connected layers, σ represents the Sigmoid activation function, represents the channel weight vector.

[0088] ⑤ Multi-scale Feature Fusion: To enhance the model's adaptability to complex anomalies, the enhanced temporal and channel features extracted are fed into an interactive convolution module. As Figure 3 shown, the multi-scale convolution module uses one-dimensional convolutions with different kernel sizes to capture short-term anomalies and long-term trends, and uses feature concatenation and non-linear transformations to model the complex correlations between channels to form a complete representation , which is expressed as:

[0089] ;

[0090] where and represent different convolution kernel sizes. denotes a one-dimensional convolution operation, and GELU denotes the Gaussian Error Linear Unit activation function. denotes layer normalization.

[0091] ⑥ Reconstruction and prediction: Reconstruct the input sequence through a linear mapping layer and calculate the reconstruction error. The final output of the model is the predicted value of the original sequence: , denotes the linear projection layer.

[0092] ⑦ Model training: Train the model using the reconstruction error and the association loss. The loss function adopts the mean squared error:

[0093] ;

[0094] where, denotes the Frobenius norm, AssDis denotes the association loss, and λ denotes the weight factor of the loss term.

[0095] ⑧ Anomaly detection: After training is completed, calculate the anomaly score at each time step through a sliding window , combine the reconstruction error and the association difference, and compare it with the threshold δ. If the anomaly score exceeds the threshold, it is determined as an anomaly point;

[0096] ;

[0097] where, the weight factor , denotes the squared reconstruction error of the matrix at time point t, and AssDis denotes the association loss.

[0098] 3. Model performance metrics:

[0099] The performance comparison of the model uses several main performance metrics based on the confusion matrix for classification: precision, recall, and F1-score.

[0100] Precision is the percentage of anomaly instances correctly detected among all instances; Recall is the percentage of anomaly instances correctly detected; The F1-score is the equally weighted average of Precision and Recall. TP (True Positive) refers to the number of samples correctly identified as positive; FP (False Positive) refers to the number of negative samples misclassified as positive, and FN (False Negative) refers to the number of positive samples misclassified as negative.

[0101] ; ; ;

[0102] is the F1 score, and F1 Average Rank is used to verify the robustness of the model. F1 Average Rank represents the average rank of the F1 score of each model in seven datasets.

[0103] 4. Model comparison results:

[0104] The model of the method in this paper was compared with 17 other baseline models in Figure 7 , Figure 8 , Figure 9 , Figure 10 , Figure 11 , Figure 12 , Tables 1 and 2. The 17 models correspond to the comparison methods 1, 2... 17 respectively. Comparison method 1: LOF, a density-based local outlier factor unsupervised anomaly detection algorithm; Comparison method 2: DAGMM, a deep autoencoder Gaussian mixture model; Comparison method 3: Transformer, a deep neural network model based on the self-attention mechanism; Comparison method 4: Deep-SVDD, a deep one-class anomaly detection model; Comparison method 5: InterFusion, an unsupervised anomaly detection algorithm that uses a hierarchical variational autoencoder, explicit low-dimensional mutual metric, and a time embedding layer to jointly learn robust multi-dimensional time series representations; Comparison method 6: DLinear, a decomposition linear prediction model that models trend and seasonal components; Comparison method 7: THOC, a time series anomaly detection method that combines an autoencoder and clustering; Comparison method 8: ITAD, an interpretable time series anomaly detection method; Comparison method 9: Autoformer, a long-term sequence prediction model based on a deep decomposition architecture and self-correlation mechanism; Comparison method 10: iTransformer, an inverted Transformer with an attention mechanism after encoding multi-time point data of a single feature as a sequence; Comparison method 11: FEDFormer, a frequency-enhanced decomposition Transformer model; Comparison method 12: ModernTCN, an improved model based on the traditional time convolutional network (TCN); Comparison method 13: CrossFormer, a multi-variable time series prediction model with cross-dimensional dependencies; Comparison method 14, OmniAnomaly, a robust anomaly detection model for multivariate time series based on a stochastic recurrent network; Comparison method 15: LSTM-VAE, a hybrid model that combines the long short-term memory network (LSTM) and the variational autoencoder (VAE); Comparison method 16: TimesNet, a time two-dimensional variational modeling method for general time series analysis; Comparison method 17: AnomalyTransformer, a time series anomaly detection method based on association differences.

[0105] FromFigure 7 , Figure 8 , Figure 9 , Figure 10 , Figure 11 , Figure 12 As can be seen from Tables 1 and 2, compared with the existing models, the experimental results of the model of the method in this paper on the real dataset are as follows:

[0106] (1) Table 1 presents the Precision (P), Recall (R), and F1-score values of the model of the method in this paper and 17 other baseline models on the SMD, PSM, SML, SMAP, and SWAT datasets. It can be observed that the model of the method in this paper outperforms all other baseline models on these five datasets. Compared with the model AnomalyTransformer of the comparative method 17, the F1-scores are increased by 4.74%, 13.07%, 0.61%, 2.79%, and 0.07% respectively. As shown in Table 2, in terms of the overall average performance, the model of the method in this paper also achieved excellent results compared with other baseline models. Specifically, the overall average accuracy of the model of the method in this paper is 93.14%, the average recall rate is 97.15%, and the average F1-score is 95.10%. The average accuracy is 0.27% higher than that of the model ModernTCN (92.87% → 93.14%) of the comparative method 12, and the average recall rate and F1-score are 7.27% (89.88% → 97.15%) and 4.26% (90.84% → 95.10%) higher than those of the model AnomalyTransformer of the comparative method 17 respectively. The robustness of the model of the method in this paper is better than that of all other baseline models. Its overall average accuracy, recall rate, and F1-score on the five datasets are all above 93%, which is a level that cannot be compared with any other baseline model. All the results in Tables 1 and 2 are expressed in %, the best results are in bold, and the second-best results are underlined. P, R, and F1 are the precision, recall rate, and F1-score respectively.

[0107] (2) As Figure 7 shown, it is obvious that the model of the method in this paper ranks the highest among the three average evaluation metrics of the five datasets.

[0108] (3) Figure 8 , Figure 9 , Figure 10 , Figure 11 , Figure 12 respectively show the F1-score performances of the model of the method in this paper and all baseline methods on the SMD, PSM, MSL, SMAP, and SWAT datasets. As can be seen from the figure, the model of the method in this paper performs well on the five datasets, demonstrating the superiority of the model of the method in this paper.

[0109] The present invention improves the key problems in real-time anomaly detection in the intelligent transportation system through the cloud centralized anomaly detection design of vehicle-road-cloud integration, which has important theoretical significance and practical application value.

[0110] Table 1 is a performance comparison table of the method in this paper and the baseline model on 5 datasets

[0111] Table 2 is a comparison result table of the overall mean of the method in this paper and all baseline models on 5 datasets

[0112] The technical solution of the present invention is not limited to the limitations of the above specific embodiments. Any technical deformation made according to the technical solution of the present invention falls within the protection scope of the present invention.

Claims

1. A real-time anomaly detection method for complex time series in vehicle-road-cloud integration, characterized in that, Including: S1. Construct an initial anomaly detection model. The anomaly detection model includes an embedding encoding module, multiple encoders, a reconstruction module, and an anomaly analysis module. The output of the embedding encoding module is used as the input of multiple encoders respectively, the output of multiple encoders is used as the input of the reconstruction module, and the output of the reconstruction module is used as the input of the anomaly analysis module. The embedding encoding module is used to reduce the dimension of the input multi-dimensional time series data and add positional encoding. The encoder is used for feature extraction to generate an encoded sequence. The reconstruction module is used to reconstruct the input sequence from the encoded sequence. The anomaly analysis module is used to calculate the anomaly score for each time step and compare it with the threshold δ to obtain the anomaly detection result. S2. Obtain a training data set. S3. Import the training data set into the initial anomaly detection model and train and optimize it to obtain an optimized anomaly detection model. S4. Obtain the data to be predicted. S5. Use the optimized anomaly detection model to perform anomaly detection on the data to be predicted to obtain the anomaly detection result.

2. The vehicle-road-cloud integration complex time series real-time anomaly detection method according to claim 1, wherein, Each encoder includes an anomaly attention module, a temporal context awareness module, a first residual connection and layer normalization module, a channel adaptive enhancement module, a second residual connection and layer normalization module, an interactive convolution module, a third residual connection and layer normalization module, a forward propagation module, and a fourth residual connection and layer normalization module. The output of the anomaly attention module is used as the input of the temporal context awareness module and the reconstruction module respectively. The output of the embedding encoding module is used as the input of the anomaly attention module and the first residual connection and layer normalization module. The output of the temporal context awareness module is used as the input of the first residual connection and layer normalization module. The output of the first residual connection and layer normalization module is used as the input of the channel adaptive enhancement module and the second residual connection and layer normalization module respectively. The output of the second residual connection and layer normalization module is used as the input of the interactive convolution module and the third residual connection and layer normalization module respectively. The output of the interactive convolution module is used as the input of the third residual connection and layer normalization module. The output of the third residual connection and layer normalization module is used as the input of the forward propagation module and the fourth residual connection and layer normalization module respectively. The output of the forward propagation module is used as the input of the fourth residual connection and layer normalization module. The output of the fourth residual connection and layer normalization module is used as the input of the reconstruction module. The anomaly attention module uses an anomaly attention mechanism to quantify the correlation difference to effectively distinguish normal points and anomaly points and amplify the features of anomaly points. The temporal context awareness module is used to extract global features and local features and generate a temporal feature matrix. The channel adaptive enhancement module is used to strengthen key features. The interactive convolution module is used to capture short-term anomalies and long-term trends and splice the short-term anomalies and long-term trends.

3. The vehicle-road-cloud integrated complex time series real-time anomaly detection method according to claim 2, wherein The time context awareness module includes an attention pooling layer, an average pooling layer, a shared fully connected layer, two convolutional activation layers, and a first fusion layer. The outputs of the anomaly attention module are respectively used as the inputs of the attention pooling layer and the average pooling layer. The attention pooling layer is used to extract local features , and the average pooling layer is used to extract global features ; the local features are weighted and summed and then jointly input into the shared fully connected layer for feature storage and fusion; the two convolutional activation layers calculate the interaction relationships between channels, dynamically adjust the importance of each channel, and strengthen the temporal dynamic information , the output of the shared fully connected layer is respectively used as the input of the two convolutional activation layers, the outputs of the two convolutional activation layers are used as the input of the first fusion layer, and the first fusion layer uses an addition fusion strategy to fuse the features strengthened by the two convolutional activation layers and the output of the anomaly attention module to generate an enhanced temporal feature matrix .

4. The vehicle-road-cloud integrated complex time series real-time anomaly detection method according to claim 2, wherein, The channel adaptive enhancement module sequentially includes a global attention pooling layer, two fully connected layers, an activation layer, and an adjustment layer from input to output. The global attention pooling layer is used to perform global average pooling on the feature vectors at each time step to compress the channel dimension. The two fully connected layers are used to generate channel weights. The activation layer uses the sigmoid function for activation. The adjustment layer is used to adjust the original features according to the weights to obtain the adjusted features .

5. The vehicle-road-cloud integration complex time series real-time anomaly detection method according to claim 2, wherein The interactive convolution module includes a multi-scale convolution block and a splicing layer. The multi-scale convolution block captures short-term anomalies and long-term trends, and the splicing layer is used to splice short-term anomalies and long-term trends to form a complete representation 。 6. The vehicle-road-cloud integration complex time series real-time anomaly detection method according to claim 2, characterized in that, The reconstruction module sequentially includes a linear mapping layer and a normalization layer from input to output, and the linear mapping layer is used to reconstruct the input sequence. The output of the anomaly attention module and the outputs of the fourth residual connection and the layer normalization module are both used as inputs to the linear mapping layer.

7. The vehicle-road-cloud integrated complex time series real-time anomaly detection method according to claim 1, wherein In S3, the reconstruction error is used to train the anomaly detection model.

8. The vehicle-road-cloud integrated complex time series real-time anomaly detection method according to claim 1, characterized in that, In S5, when the anomaly score exceeds the threshold δ, it is an anomaly point; otherwise, it is a normal point.

9. The vehicle-road-cloud integrated complex time series real-time anomaly detection system is characterized in that, Including: A storage; the storage is used to store a computer program. An executor; The actuator is used to execute the computer program in the storage. When the computer program is executed, the vehicle-road-cloud integrated complex time series real-time anomaly detection method described in any one of claims 1-8 is implemented.

10. The vehicle-road-cloud integrated system is characterized in that, It includes: On-vehicle terminal; The on-vehicle terminal is used to obtain the sensor data of the vehicle in real time; Roadside terminal; The roadside terminal is used to sense the traffic data in real time, and the signal terminal of the on-vehicle terminal is connected to the signal terminal of the roadside terminal; Cloud; The cloud includes the vehicle-road-cloud integrated complex time series real-time anomaly detection system described in claim 9, and the signal terminal of the cloud is respectively connected to the signal terminal of the on-vehicle terminal and the signal terminal of the roadside terminal.

Citation Information

Patent Citations

  • Time sequence anomaly detection method and device, electronic equipment and storage medium

    CN110909046A

  • Cloud platform system anomaly detection method and device based on parallel map attention network

    CN115758173A

  • Traffic anomaly detection method based on graph convolutional neural network auto-encoder

    CN116776269A

  • Multi-channel feature fusion Internet of Vehicles anomaly detection method and system

    CN118468197A

  • Method and system for detecting data anomaly of sensor of self-driving automobile

    CN118991806A

Cited By

  • Gas equipment remote control method and system based on Internet of Things data acquisition

    CN121165585A

  • Gas equipment remote control method and system based on internet of things data collection

    CN121165585B

  • ADS-B abnormal data detection method based on GTA-SVDD model

    CN122112923A

  • An ADS-B outlier detection method based on GTA-SVDD model

    CN122112923B