A method, system, apparatus, and medium for feature tagging based on a monitoring signal

By using power line signal monitoring equipment and knowledge graph construction, combined with region growing algorithm and quantum state modeling, the problem of inaccurate feature labeling of monitoring signals was solved, and efficient and intelligent feature labeling was achieved in complex electromagnetic environments.

CN120372309BActive Publication Date: 2025-11-21TIANJIN ANLIXIN COMM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510452222.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-11-21
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

Existing methods for marking the features of monitoring signals are inaccurate, lack specific criteria for judgment, and are difficult to achieve efficient and intelligent information recognition in complex electromagnetic environments.

Method used

Electromagnetic signals are collected by power line signal monitoring equipment, isolated and filtered, then converted from analog to digital, a knowledge graph is constructed, and feature analysis is performed using region growing algorithm and quantum state modeling. Combined with feature template matching and probabilistic reasoning, accurate labeling of the monitored signals is achieved.

Benefits of technology

It improves the accuracy and intelligence of monitoring signal identification, enhances the semantic expression and interpretability of the marking results, and is suitable for leakage signal monitoring and spectral analysis in complex electromagnetic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372309B_ABST
    Figure CN120372309B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of feature recognition, and discloses a feature marking method and system based on a monitoring signal, which comprises the following steps: collecting electromagnetic signals of a monitoring target through a power line signal monitoring device; after the collected electromagnetic signals are isolated and filtered, analog-to-digital conversion is performed, digital spectrum data containing time and amplitude are obtained, and the digital spectrum data are taken as monitoring signals; the monitoring signals are analyzed to obtain a candidate region to be marked; the relationship of the monitoring signals is constructed by using a knowledge graph, feature analysis is performed on the candidate region, and a feature marking result is obtained. Not only does the application have clear feature analysis and decision basis, but also the semantic expression and interpretability of the marking result are enhanced by introducing feature template matching and probability reasoning. The application has higher recognition accuracy and intelligence, is especially suitable for leak signal monitoring and graphing analysis in a complex electromagnetic environment, and has good engineering adaptability and practical application value.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of feature recognition, in particular to a feature marking method, system and device based on monitoring signals and a medium. BACKGROUND

[0002] With the increasing popularity of electronic information equipment, signal leakage problems caused by electromagnetic radiation have gradually become an important concern in the field of information security. Especially in scenarios involving sensitive data processing, unintended electromagnetic signals generated by various display devices, transmission interfaces and hardware circuits may constitute potential leakage channels. To effectively monitor and identify such leakage signals, spectrum analysis technology is widely used in the visualization analysis and interference tracing of electromagnetic environments. In traditional methods, frequency spectrum data is often presented in the form of static frequency distribution, which lacks deep modeling of time domain features and relies on manual experience for signal judgment, with limited efficiency and accuracy.

[0003] In addition, in the face of complex and variable electromagnetic environments, how to identify the part with key information characteristics from the complex monitoring signals has become a core difficulty restricting the improvement of intelligent analysis level. Therefore, it is urgent to establish an automatic analysis mechanism with signal semantic understanding ability to realize accurate identification and marking of potential information areas in time-frequency spectrum, so as to meet the technical needs of high-level information protection. SUMMARY

[0004] In view of the above problems, the present application is proposed.

[0005] Therefore, the technical problems solved by the present application are: the existing feature marking method of monitoring signal is inaccurate, has no specific judgment basis, and how to enhance the explainability of marking and other problems.

[0006] To solve the above technical problems, the present application provides the following technical scheme: a feature marking method based on monitoring signals, comprising:

[0007] Through the power line signal monitoring device, the electromagnetic signals of the monitoring target are collected;

[0008] After isolating and filtering the collected electromagnetic signals, analog-to-digital conversion is completed to obtain digital frequency spectrum data containing time and amplitude as monitoring signals;

[0009] The monitoring signals are analyzed to obtain a candidate area to be marked;

[0010] The relationship of the monitoring signals is constructed by using a knowledge graph, the candidate area is analyzed for features, and the result of feature marking is obtained;

[0011] The feature analysis includes: regarding each candidate region as a two-dimensional quantum state, and determining the final state of the candidate region through analysis verification.

[0012] As a preferred scheme of the feature marking method based on the monitoring signal, the power line signal monitoring device includes a device interface and a body.

[0013] The body is internally integrated with a coupling circuit, which receives the transmission signal on the power line, realizes the collection, storage and analysis of the power network signal, integrates an isolation module, which isolates the transient high-power signal in the power network and filters out the power frequency signal in the power grid to remove the monitoring interference caused, and continuously monitors the electromagnetic environment in the region range, and alarms the signal marked as abnormal.

[0014] The protocol of the device interface supports security authentication, remote management, work order configuration, real-time data and state uploading, alarm log and historical data query.

[0015] As a preferred scheme of the feature marking method based on the monitoring signal, the analog-to-digital conversion includes: converting the continuous analog electromagnetic signal into a digital time domain signal at a sampling frequency, performing Fourier transform on the digital time domain signal to obtain frequency spectrum data containing frequency and amplitude information, and setting a time stamp at each sampling time.

[0016] As a preferred scheme of the feature marking method based on the monitoring signal, the analysis of the monitoring signal includes: performing regional division on a two-dimensional time-frequency matrix formed by each frequency spectrum data of the monitoring signal and the time stamp of each frequency spectrum data at the sampling time, dividing the entire frequency spectrum graph into multiple continuous regions as candidate regions for feature marking.

[0017] Among them, the edge overlap between adjacent regions is allowed.

[0018] As a preferred scheme of the feature marking method based on the monitoring signal, the region division process includes: based on a region growing algorithm, expanding from an initial high-energy point to form a signal region with time and frequency continuity.

[0019] The region growing algorithm includes: in the digitized frequency spectrum, using a binary classification method to identify a part with local feature anomaly as a seed point; and setting the seed node to grow to the front and back sides, and constructing a dynamic candidate region through the feature analysis.

[0020] In the growing process, if the feature marks of the two seed points are the same, and the candidate regions of the two seed points are adjacent or overlap, the candidate regions of the two adjacent seed points are merged as a candidate region for division.

[0021] As a preferred scheme of the feature mark method based on the monitoring signal, wherein: the knowledge graph comprises: preset content of each feature mark, each content as a node, and the relationship between each two nodes is represented by an arrow line, and each arrow represents the occurrence probability of the association relationship between two nodes.

[0022] Wherein, A←B represents the probability that node B occurs before node A.

[0023] As a preferred scheme of the feature mark method based on the monitoring signal, wherein: the feature analysis further comprises: setting the dimension of the quantum state as: the content of the feature mark and the width of the candidate region growth.

[0024] By determining the quantum state, the feature mark of each candidate region is obtained.

[0025] The process of determining the quantum state is specifically:

[0026] Step one: randomly generate a width of candidate region growth for each seed point;

[0027] The width of the candidate region growth is less than or equal to the preset width threshold; the seed point is located at the center position of the candidate region.

[0028] Step two: calculate the similarity of each candidate region and the feature template using the feature template, and retain the feature mark corresponding to the feature template with a similarity exceeding a preset value φ as the selectable feature mark of each candidate region; in each candidate region, the selectable feature mark is randomly selected to obtain the feature mark of each candidate region.

[0029] The feature template comprises: in historical data, for the same content of the feature mark, the similarity of each two monitoring signals is calculated, and template C is obtained by screening; under the condition that the similarity of template C and other monitoring signals all exceeds a preset value φ, the sum of the similarity of template C and other monitoring signals is minimum.

[0030] Step three: according to the knowledge graph, the fitness of all seed points under the current feature mark is calculated, which is represented as:

[0031] Wherein, n represents the index of the seed; N represents the number of seeds; M n The probability that the nth seed occurs before the n+1 seed.

[0032] Step four: keeping the current width of each candidate region growth, in each candidate region, randomly iteratively replace the selectable feature markers to obtain new feature markers of each candidate region;

[0033] For any seed point, calculate the fitness difference between the new feature markers and the original feature markers, if the difference is less than N·μ, then calculate the matching degree, select the feature marker with the largest matching degree as the result of this iteration; if the difference is not less than N·μ, then directly select the feature marker with the largest fitness as the result of this iteration; iterate in turn until the maximum number of iterations is met or there is no selectable feature marker;

[0034] The matching degree includes the sum of the similarity between the feature markers of each seed point and the corresponding feature template in the current candidate region;

[0035] Wherein, μ represents the unit threshold of fitness, multiplied by the number of seeds to obtain the threshold of fitness;

[0036] Step five: keeping the optimal selection in step four, iteratively replacing the width of the candidate region growth in step one, repeating steps one to four until the maximum number of iterations is met, or there is no selectable feature marker and no replacement region width, complete the iteration, output the label result of each candidate region and the width of the candidate region growth;

[0037] Step six: merging the candidate regions according to the width of the candidate region growth.

[0038] A feature marking system based on monitoring signals, applying a feature marking method based on monitoring signals as described in the application, comprising:

[0039] The acquisition unit collects electromagnetic signals of the monitoring target through the power line signal monitoring device;

[0040] The conversion unit completes analog-to-digital conversion after isolating and filtering the collected electromagnetic signals, and obtains digital spectrum data containing time and amplitude as monitoring signals;

[0041] The analysis unit analyzes the monitoring signals to obtain candidate regions to be marked;

[0042] The marking unit uses a knowledge graph to construct the relationship of the monitoring signals, and performs feature analysis on the candidate regions to obtain the result of feature marking.

[0043] A computer device, comprising a memory and a processor; the memory stores a computer program, wherein the processor implements the steps of the method of any one of the application when executing the computer program.

[0044] A computer readable storage medium having stored thereon a computer program, wherein the computer program, when executed by a processor, implements the steps of the method of any one of the present application.

[0045] The present application provides a feature labeling method based on monitoring signals, which realizes accurate labeling of potential information regions in monitoring signals by constructing a knowledge graph, dividing candidate regions, and introducing a quantum state modeling mechanism. This method not only has clear feature analysis and decision basis, but also enhances the semantic expression and interpretability of the labeling results by introducing feature template matching and probabilistic reasoning. Compared with traditional methods that rely on artificial experience or static thresholds, the present application has higher recognition accuracy and intelligence, especially suitable for leak signal monitoring and graph analysis in complex electromagnetic environments, and has good engineering adaptability and practical application value. BRIEF DESCRIPTION OF DRAWINGS

[0046] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.

[0047] Figure 1 A feature labeling method based on monitoring signals is provided for the first embodiment of the present application.

[0048] Figure 2 A power line signal monitoring device diagram in a feature labeling method based on monitoring signals is provided for the second embodiment of the present application. DETAILED DESCRIPTION

[0049] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings in the specification. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.

[0050] Embodiment 1, refer to Figure 1 An embodiment of the present application provides a feature labeling method based on monitoring signals, comprising:

[0051] S1: Collecting electromagnetic signals of the monitoring target by a power line signal monitoring device.

[0052] Further, the power line signal monitoring device comprises a device interface and a body.

[0053] The body is internally integrated with a coupling circuit, which receives transmission signals on the power line, realizes collection, storage and analysis of signals carried on the power supply network, integrates an isolation module, which isolates transient high-power signals in the power supply network and filters out power frequency signals in the power grid to remove monitoring interference, and continuously monitors the electromagnetic environment in a regional range, alarms signals marked as abnormal.

[0054] The protocol of the device interface supports security authentication, remote management, work order configuration, real-time data and state uploading, alarm log and historical data query.

[0055] In an optional embodiment, the signal analysis process can be completed by a cloud platform. The power line signal monitoring device uploads the collected digitized spectrum data to a cloud server through a network interface, the cloud platform analyzes the feature marking of the candidate region based on a knowledge graph, a feature template and a quantum state modeling algorithm, and returns the marking result to the device end for display or further processing. This method can significantly improve the computing efficiency and realize centralized intelligent identification and multi-terminal shared analysis model.

[0056] S2: After isolating and filtering the collected electromagnetic signals, analog-to-digital conversion is completed to obtain digitized spectrum data containing time and amplitude as monitoring signals.

[0057] The analog-to-digital conversion includes converting a continuous analog electromagnetic signal into a digital time domain signal at a sampling frequency, performing Fourier transform on the digital time domain signal to obtain frequency spectrum data containing frequency and amplitude information, and setting a time stamp at each sampling time.

[0058] Specifically, the continuous analog electromagnetic signal is a voltage signal that changes continuously with time, denoted as s(t), which cannot be directly processed by a computer. An analog-to-digital converter (ADC) is used to sample and quantize s(t) at fixed time intervals: the voltage value is converted to a digital value with a limited number of bits (such as 12 bits or 16 bits). A discrete time sequence is obtained, which is called a digital time domain signal.

[0059] The discrete time sequence signal is converted into a frequency domain representation for analyzing the frequency components it contains. The digital time domain signal x[n] is sent to a fast Fourier transform (FFT) algorithm within a certain window (such as 1024 points); the FFT outputs a complex frequency domain sequence X[k], with each point representing a frequency component (complex amplitude + phase).

[0060] The amplitude spectrum (or power spectrum) is extracted, i.e., A[k] = |X[k]|.

[0061] Each A[k] corresponds to a frequency fk. A set of spectral data points is obtained, which constitutes the "frequency-amplitude" pairs you need, that is, the spectral data.

[0062] S3: analyzing the monitoring signal to obtain a candidate region to be marked.

[0063] Further, the analysis of the monitoring signal includes dividing a two-dimensional time-frequency matrix formed by each spectral data of the monitoring signal and the timestamp of each spectral data at the sampling time into regions, dividing the entire spectral graph into multiple continuous regions as candidate regions for feature marking. Among them, there is allowed to be edge overlap between adjacent regions (each data point can provide basis for the judgment of seed points). The two-dimensional time-frequency matrix formed by the digitized spectral data is divided into regions, and edge overlap is allowed between adjacent regions, aiming to more accurately reflect the continuity and complexity of the monitoring signal in the time and frequency dimensions. Since electromagnetic signals often exhibit characteristics such as fuzzy boundaries, overlapping frequency bands, or time-varying drift in real environments, forcibly performing hard boundary division may result in information loss or incorrect classification.

[0064] By allowing edge overlap, a data point can participate in the judgment process of multiple candidate regions at the same time, thereby retaining its support value for multiple seed point judgments and improving the flexibility and inclusiveness of region division. At the same time, this design provides more complete context information for subsequent feature marking, so that region identification is no longer dependent on isolated points, but has structural correlation and multi-source support, thereby enhancing the stability and robustness of the marking results.

[0065] Based on the signal amplitude threshold and the neighborhood correlation, the region growing algorithm extends from the initial high-energy point to form a signal region with time and frequency continuity;

[0066] The region growing algorithm includes identifying the part with local feature anomaly in the digitized spectrum as a seed point using a binary classification method; setting the seed node to grow on both sides, and constructing a dynamic candidate region through the feature analysis. During the growth process, when the feature marks of two seed points (which can not be adjacent) are the same, if the candidate regions of the two seed points are adjacent or overlapping, the candidate regions of the two adjacent seed points are merged as a candidate region for division. It is worth mentioning that each data point can be the basis for multiple node judgments, so it can be divided into different candidate regions. Therefore, in this method, each data point is subjected to multiple states to support the feature marking of multiple seed points.

[0067] In a preferred embodiment, a binary classification model based on a random forest algorithm is used to judge each time-frequency point in the spectrogram to identify whether it has the structural features of a region growing seed point. The model input includes multi-dimensional features such as spectral amplitude values, time and frequency direction gradients, local region mean and variance, and the training process is based on supervised learning based on a labeled data set. The random forest classifier has good robustness and interpretability, and can adapt to the intelligent screening task of seed points in a complex background.

[0068] S4: Construct the relationship of the monitoring signal by using the knowledge graph, perform feature analysis on the candidate region, and obtain a feature labeling result. The feature analysis includes setting each candidate region as a two-dimensional quantum state, determining the final state of the candidate region through analysis and verification.

[0069] The knowledge graph includes presetting the content of each feature label (which can include combinations of multiple "single label contents"), taking each content as a node, representing the relationship between each two nodes through a connection line with an arrow, and each arrow representing the occurrence probability of an association relationship between two nodes. Wherein, A←B represents the probability that node B occurs before node A.

[0070] By presetting the content of each feature label as a node in the graph and using a connection line with a direction to represent the semantic or temporal association relationship between nodes, the design aims to provide a priori knowledge-based reasoning basis for feature labeling of candidate regions, thereby avoiding relying only on surface matching of spectral features. Considering that some feature events in actual monitoring signals may occur in combination or sequence (for example, multiple signals are associated in space or time), the design allows each node in the graph to not only represent a single label content, but also represent a combination state of multiple labels, thereby improving the expression ability and coverage of the graph.

[0071] In addition, by introducing an arrow to represent the "occurrence probability of an association relationship", for example, B→A represents the probability of the occurrence of feature A after the occurrence of feature B, the graph has the ability to judge the temporal evolution or semantic sequence. This design helps the candidate region to infer a more reasonable and more confident final label result based on the context structure in the graph when multiple potential labels are available, enhancing the explanation ability of the system and the consistency of the reasoning logic.

[0072] Further, the feature analysis further includes setting the dimensions of the quantum state as: the content of the feature label and the width of the candidate region growth (the state of each dimension is a superposition of multiple states, and the state is confirmed through an iteration process). By determining the quantum state, the feature label of each candidate region is obtained.

[0073] The process of determining the quantum state is specifically:

[0074] Step one: randomly generate a candidate region growth width for each seed point.

[0075] The candidate region growth width is less than or equal to a preset width threshold; and the seed point is located at a center position of the candidate region.

[0076] Step two: using a feature template, calculate the similarity of each candidate region to the feature template, and retain the feature markers corresponding to the feature templates with a similarity exceeding a preset value φ as selectable feature markers of each candidate region; in each candidate region, randomly select the selectable feature markers to obtain the feature markers of each candidate region.

[0077] The feature template includes: in historical data, for the content of the same feature marker, calculate the similarity of each two monitoring signals, and screen to obtain a template C; in the case that the similarity of the template C to other monitoring signals all exceeds a preset value φ, the sum of the similarities of the template C to other monitoring signals is the smallest.

[0078] In a preferred embodiment, the similarity calculation method adopts a multi-scale similarity calculation method based on structure spectrum decomposition. Specifically, it includes: performing wavelet or Gaussian multi-scale decomposition on the candidate signal region to extract principal component structure vectors; calculating the cosine similarity of the structure vectors to measure the consistency of the signal profile; and extracting the energy mean and variance to evaluate the consistency of the region amplitude feature. Finally, the structure similarity and the energy similarity are fused in a weighted manner as the matching score between the feature template and the candidate region, enhancing the discriminability and interpretability of the similarity calculation.

[0079] Step three: according to the knowledge graph, calculate the fitness of all seed points under the current feature marker, expressed as:

[0080] Wherein, n represents the index of the seed; N represents the number of seeds; M n represents the probability of the nth seed occurring before the n+1th seed.

[0081] Step four: keep the current width of each candidate region growth, and in each candidate region, randomly replace the selectable feature markers iteratively to obtain new feature markers of each candidate region (the selected new markers are different from the previously selected ones).

[0082] ​For any seed point, the fitness difference |S1-S2| of the new feature mark and the original feature mark is calculated, if the difference is less than N mu, the matching degree is calculated, the feature mark with the largest matching degree is selected as the result of this iteration; if the difference is not less than N mu, the feature mark with the largest fitness is directly selected as the result of this iteration; iteration is performed in turn until the maximum iteration number is reached or there is no selectable feature mark. Wherein, S1 represents the fitness of the original feature mark; S2 represents the fitness of the new feature mark.

[0083] The matching degree includes the sum of the similarity of each seed point feature mark in the current candidate region and the corresponding feature template.

[0084]

[0085] Wherein, mu represents the unit threshold of fitness, multiplied by the number of seeds to obtain the threshold of fitness; j represents the index of the seed, J represents the number of seeds, PP represents the matching degree of the current result, D j represents the similarity of the jth seed.

[0086] Step five: retaining the optimal selection in step four, iteratively replacing the width of the candidate region growth in step one (the width is actually selected within a predetermined interval), repeating steps one to four until the maximum iteration number is reached, or there is no selectable feature mark and no replacement region width, completing the iteration, and outputting the marking result for each candidate region and the width of the candidate region growth.

[0087] Step six: merging the candidate regions according to the width of the candidate region growth.

[0088] In the actual monitoring process, the monitoring signal often has complex shape, obvious time-frequency drift, nonlinear amplitude change and other characteristics. The traditional similarity calculation method based on simple distance or point-by-point comparison is easily disturbed by local noise and is difficult to accurately reflect the similarity of two candidate regions in overall structure and semantic pattern. A multi-scale similarity calculation method based on structure spectrum decomposition is adopted, which aims to extract the core morphological features of the candidate region from a global perspective, obtain stable spectral expression through principal component analysis and other methods, and eliminate local mutation interference by combining multi-scale decomposition to enhance the structural robustness. At the same time, energy features (such as mean and variance) are introduced to evaluate the amplitude level of the signal, forming a dual expression of "shape + value", and then outputting the final similarity score in a fusion form. The purpose of this method is to improve the accuracy and semantic consistency of template screening and matching, and to provide more reliable basis for subsequent quantum state judgment and feature marking.

[0089] On the other hand, the embodiment also provides a feature marking system based on a monitoring signal, which comprises:

[0090] The acquisition unit acquires the electromagnetic signal of the monitoring target through the power line signal monitoring device.

[0091] The conversion unit completes analog-to-digital conversion on the acquired electromagnetic signal after isolation and filtering, and obtains digital spectrum data containing time and amplitude as the monitoring signal.

[0092] The analysis unit analyzes the digital spectrum data to obtain a candidate region to be marked.

[0093] The marking unit uses a knowledge graph to construct the relationship of the monitoring signal, and performs feature analysis on the candidate region to obtain a feature marking result.

[0094] If the above functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the prior art that essentially contributes or the part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.

[0095] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered a list of executable instructions for implementing logic functions, and can be specifically embodied in any computer-readable medium for use by an instruction execution system, device or apparatus, such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute the instructions, or in conjunction with these instruction execution systems, devices or apparatus. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transport programs for use by an instruction execution system, device or apparatus, or in conjunction with these instruction execution systems, devices or apparatus.

[0096] More specific examples (a non-exhaustive list) of the computer readable medium include the following: a portable computer diskette (magnetic device); a random access memory (RAM); a read-only memory (ROM); an erasable programmable read-only memory (EPROM or Flash memory); an optical fiber device; and a portable compact disc read-only memory (CD-ROM). Additionally, the computer readable medium can be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, for instance via an optical scanner, then compiled, interpreted, or otherwise processed, using suitable tools, and then stored in a computer memory.

[0097] It should be understood that aspects of the application can be implemented in hardware, software, firmware or combinations thereof. In the embodiments described above, various steps or methods can be implemented, for example, by software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, and in another embodiment, any of the following technologies, known in the art, or their combinations can be used: discrete logic circuitry having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.

[0098] Example 2, Reference Figure 2 For one embodiment of the application, a feature marking method based on monitoring signals is provided, and in order to verify the beneficial effects of the application, economic benefit calculation and simulation experiments are used for scientific demonstration.

[0099] Through Figure 2 The D101 device includes a body and an interface, and performs data acquisition.

[0100] In order to verify the effectiveness and superiority of the proposed feature marking method based on monitoring signals, a controlled experimental scenario is constructed: three types of typical information equipment signal sources are selected, which are A type computing terminal, B type confidential processing module and C type embedded graphic output device. The above-mentioned devices are connected with the power supply system through the standard power supply line in the typical running state. The experiment is carried out in an electromagnetic isolation environment to exclude environmental radiation interference and ensure the effectiveness and accuracy of the collected signals. The signal acquisition uses the power line signal monitoring device D101 described in the embodiment, which is connected with the power supply line through the body coupling interface, realizes the non-intrusive acquisition of the electromagnetic leakage signals conducted on the device power supply line. The device internally integrates coupling circuit, isolation module and analog-to-digital conversion unit, supports high-resolution monitoring of signals in the frequency band of 1MHz to 1GHz, sets the sampling period to 5ms, and the resolution bandwidth to 100kHz.

[0101] During the experiment, a power line signal monitoring device is used to connect the target device power supply line through the interface; the collected analog electromagnetic signals are sent to the high-precision analog-to-digital conversion module after isolation and filtering; the analog-to-digital converter samples the analog signal at a set sampling period (such as 5 ms) and converts it into a time-amplitude sequence; the sampling data is time-domain framed, and a two-dimensional time-frequency matrix with a time stamp is constructed through Fourier transform as the input for subsequent signal analysis.

[0102] The high feature value points in the time-frequency matrix are identified as "seed points" using a two-classification algorithm based on a spectrum feature map; the constraint conditions for starting the region growing process at each seed point include: the maximum frequency width is 15 frequency points; the time span does not exceed 80 ms; and a candidate region with time-frequency continuity and feature correlation is obtained.

[0103] For each candidate region, its corresponding spectral feature vector is extracted; principal component analysis (PCA) is used for feature dimension reduction; similarity comparison is performed with the historical feature template library to calculate the similarity score; the feature template library is extracted from historical data through the multi-scale spectral shape decomposition + energy evaluation mechanism described in the application to ensure representativeness; the template screening standard is that the similarity with other segments is greater than or equal to 0.75, and the total distance is the smallest.

[0104] A feature label knowledge graph is constructed, where each node represents a feature label type; a directed edge is used to represent the semantic occurrence order and probability relationship between nodes (such as A←B representing the probability of B occurring before A); the matching results of each candidate region are subjected to graph semantic reasoning, and the template similarity and graph path weight are combined to calculate the final label result and confidence score.

[0105] All signal analysis processes are performed on local and cloud platforms respectively; the consistency of the labeled results is compared to verify the migration robustness of the system deployed on different platforms.

[0106] Among them, the traditional method usually adopts fixed threshold judgment and static feature extraction method, and its specific process includes: setting a signal amplitude threshold (such as -80dBm), and directly marking the frequency points exceeding the threshold as "suspicious signals". Based on local mutation or energy density, it is judged whether the signal is "abnormal". The adjacent high-energy points are simply clustered to form a candidate region. The final labeling result depends on manual experience adjustment.

[0107] In the experimental comparison, three types of typical signal sources (A type computing terminal, B type confidential processing module, and C type graphic output device) are tested, and the number of candidate regions obtained by the method of the application is reduced by 46%, 47% and 59% respectively compared with the traditional method, significantly reducing the redundant analysis cost of non-target regions.

[0108] In the number of effective signal identification, the method of the application identifies 46, 53 and 41 effective feature regions respectively, which increases by 39%, 47% and 76% compared with the traditional method. This shows that the application can focus more accurately on the region with abnormal time-frequency behavior and outstanding feature morphology by introducing the high feature point driven region growing mechanism, and cooperate with the feature template for structured comparison, thereby enhancing the consistency of the identified target.

[0109] In the false labeling and misjudgment control, 22, 25 and 21 false labeling regions appear respectively in the traditional method, while the misjudgment control of the method of the application is within 1 to 3 in all tests, and the misjudgment rate is reduced by more than 86%, which verifies the effectiveness of the knowledge graph reasoning mechanism in complex feature judgment.

[0110] Although the method of the application has slightly higher calculation time than the traditional method due to the introduction of feature evolution modeling and graph reasoning, the increase is still within the engineering acceptable range, and the significant judgment accuracy is improved by the calculation resources, realizing the strategy optimization of "calculation for accuracy", which reflects strong engineering practicability and deployment value.

[0111] In summary, the application is significantly superior to the prior art in the aspects of candidate region screening accuracy, effective labeling ability, misjudgment control level and semantic modeling ability, and provides a technical path with high accuracy and high robustness for intelligent identification and labeling of electromagnetic leakage behavior.

[0112] It should be noted that the above embodiments are only used to illustrate the technical solutions of the application and not to limit it. Although the application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the application can be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the application, which should be covered in the scope of the claims of the application.

Claims

1. A feature tagging method based on monitoring a signal, characterized by, The method comprises the following steps: Electromagnetic signals of a monitoring target are collected by a power line signal monitoring device; The collected electromagnetic signals are isolated and filtered, and then subjected to analog-to-digital conversion to obtain digital spectrum data containing time and amplitude as monitoring signals; The monitoring signals are analyzed to obtain candidate regions to be marked; A knowledge graph is used to construct the relationship of the monitoring signals, and the candidate regions are subjected to feature analysis to obtain feature marking results; The feature analysis comprises: regarding each candidate region as a two-dimensional quantum state, and determining the final state of the candidate region through analysis and verification; The knowledge graph comprises: presetting the content of each feature mark, regarding each content as a node, and using an arrowed connection line to represent the relationship between each two nodes, and each arrow represents the probability of occurrence of an association relationship between two nodes; Wherein, A←B represents the probability that node B occurs before node A; The feature analysis further comprises: regarding the dimension of the quantum state as: the content of the feature mark and the width of the candidate region growth; The feature mark of each candidate region is obtained by determining the quantum state; The process of determining the quantum state comprises the following steps: Step one: randomly generating a width of candidate region growth for each seed point; The width of the candidate region growth is less than or equal to a preset width threshold; and the seed point is located at the center position of the candidate region; Step two: calculating the similarity of each candidate region and a feature template, retaining the feature mark corresponding to the feature template with a similarity greater than a preset value φ as the selectable feature mark of each candidate region; and randomly selecting the selectable feature mark in each candidate region to obtain the feature mark of each candidate region; The feature template comprises: calculating the similarity of each two monitoring signals in historical data for the same feature mark content, and screening to obtain a template C; and under the condition that the similarity of template C and other monitoring signals is greater than a preset value φ, the sum of the similarity of template C and other monitoring signals is the smallest; Step three: according to the knowledge graph, the fitness of all seed points under the current feature label is calculated, denoted as: wherein n represents the index of the seed; N represents the number of seeds; M n represents the probability that the nth seed occurs before the n+1th seed. Step four: keeping the current width of each candidate region growth, and randomly replacing the selectable feature mark in each candidate region to obtain a new feature mark of each candidate region; For any seed point, the fitness difference value between the new feature mark and the original feature mark is calculated, if the difference value is less than N·μ, the matching degree is calculated, the feature mark with the largest matching degree is selected as the result of this iteration; if the difference value is not less than N·μ, the feature mark with the largest fitness is directly selected as the result of this iteration; and the iteration is sequentially performed until the maximum iteration number is reached or there is no selectable feature mark. The matching degree comprises: the sum of the similarity of the feature mark of each seed point and the corresponding feature template in the current candidate region; Wherein, μ represents the unit threshold of fitness, and the threshold of fitness is obtained by multiplying the seed number. Step five: keeping the optimal selection in step four, iteratively replacing the width of the candidate region growth in step one, repeating steps one to four until the maximum number of iterations is met, or there is no selectable feature marker and no replacement region width, complete the iteration, output the label result of each candidate region and the width of the candidate region growth; Step six: according to the width of the candidate region growth, the candidate region is merged.

2. The signature method based on monitoring signals as claimed in claim 1, characterized in that: The power line signal monitoring device comprises a device interface and a body; The body is internally integrated with a coupling circuit, which receives transmission signals on the power line, and realizes the collection, storage and analysis of power network signals; An integrated isolation module is used to isolate transient high-power signals in the power network and filter out power frequency signals in the power grid to remove monitoring interference; by continuously monitoring the electromagnetic environment in the region, the signals marked as abnormal are alarmed; The protocol of the device interface supports security authentication, remote management, work order configuration, real-time data and state uploading, alarm log and historical data query.

3. The signature method based on monitoring signals as claimed in claim 2, characterized in that: The analog-to-digital conversion comprises converting continuous analog electromagnetic signals into digital time domain signals at a sampling frequency, and performing Fourier transform on the digital time domain signals to obtain frequency spectrum data containing frequency and amplitude information, while setting a time stamp at each sampling time.

4. The signature method based on monitoring signals as claimed in claim 3, characterized in that: The analysis of the monitoring signal comprises dividing the two-dimensional time-frequency matrix formed by each frequency spectrum data of the monitoring signal and the time stamp of each frequency spectrum data at the sampling time into multiple continuous regions, and dividing the entire frequency spectrum into multiple continuous regions as candidate regions of feature markers; Wherein, the edge overlap between adjacent regions is allowed.

5. The signature method based on monitoring signals as claimed in claim 4, characterized in that: The region division process comprises: based on the region growing algorithm, starting from the initial high-energy point, expanding the signal region with time and frequency continuity; The region growing algorithm comprises: in the digitized frequency spectrum, using a binary classification method to identify the part with local feature anomaly as a seed point; setting the seed point to grow on both sides, and constructing a dynamic candidate region through the feature analysis; During the growth process, when the feature markers of two seed points are the same, if the candidate regions of the two seed points are adjacent or overlap, the candidate regions of the two adjacent seed points are merged as one candidate region for division.

6. A system for tagging features based on a monitored signal, applying a method for tagging features based on a monitored signal according to any one of claims 1-5, characterized in that, It comprises: The acquisition unit collects electromagnetic signals of the monitoring target through the power line signal monitoring device; The conversion unit completes analog-to-digital conversion on the collected electromagnetic signals after isolation and filtering, and obtains digitized frequency spectrum data containing time and amplitude as the monitoring signal; The analysis unit analyzes the monitoring signal to obtain the candidate region to be labeled; The labeling unit uses the knowledge graph to construct the relationship of the monitoring signal, and performs feature analysis on the candidate region to obtain the feature marker result.

7. A computer device comprising: A memory and a processor; The memory stores a computer program, and the processor executes the computer program to realize the steps of the method according to any one of claims 1-5.

8. A computer readable storage medium having stored thereon a computer program, characterized in that: The computer program is executed by the processor to realize the steps of the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Electromagnetic abnormal signal detection method and system

    CN115345198A

  • Communication radiation source threat assessment method based on knowledge graph representation learning

    CN115422404A