A production anomaly early warning method and system based on knowledge graph
By building a knowledge graph-based enterprise management system, obtaining and analyzing task timeliness, process abnormalities and monitoring timeliness information, and generating a comprehensive abnormality rate, the problems of task backlog and process blockage in the enterprise management system are solved, and accurate production abnormality warning is achieved.
Patent Information
- Application Number
- CN202510886579.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-06-30
AI Technical Summary
The existing enterprise management system cannot respond in time when tasks are stacked, resulting in a backlog of multi-task notification window frames and unable to effectively conduct early warnings.
By obtaining the operation knowledge graph data in the enterprise management system, including the time data for to-do tasks, unprocessed notification content and monitoring rules trigger status, a knowledge graph is built, and the task backlog time, process abnormal link information, node association information, monitoring time information and notification time information are generated, and a comprehensive abnormality rate is issued based on this.
A multi-dimensional abnormality assessment of the enterprise management system is realized, which can timely identify task backlogs and process blockages, improve the accuracy and timeliness of early warnings, and ensure that the enterprise can handle production abnormalities in a timely manner.
Smart Images

Figure CN120408455B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of knowledge graph technology, and in particular to a production anomaly early warning method and system based on knowledge graphs. Background Art
[0002] An enterprise management system is a software system that uses information technology to integrate the management of an enterprise's various resources (such as human, material, financial, and information) and business processes. By collecting, processing, storing, and analyzing data, it provides timely and accurate information support to the enterprise's decision-makers and departments, thereby achieving the company's strategic goals and effectively managing daily operations. Knowledge graphs are essential in enterprise management systems. A knowledge graph is a structured data model that represents knowledge through a semantic network. Its core is to abstract real-world entities (such as people, things, and concepts) and the relationships between them into "nodes" and "edges," and to describe the characteristics of entities through attributes. Essentially, it is a semantic network consisting of entities, relationships, and attributes that can store and express knowledge in a machine-understandable manner, supporting complex knowledge reasoning and intelligent applications.
[0003] When dealing with task stacking, existing enterprise management systems usually adopt timely response in advance. This causes a backlog of multiple task notification windows in the process of timely task response, and it is impossible to obtain the backlog status and issue early warnings based on the corresponding backlog status. Therefore, a production anomaly early warning method based on knowledge graph is needed to solve the above problem. Summary of the Invention
[0004] The purpose of the present invention is to provide a production anomaly warning method and system based on knowledge graph to solve the technical problems raised in the above background technology.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A production anomaly early warning method based on knowledge graph, comprising:
[0007] Obtaining operational knowledge graph data from the enterprise management system, where the operational knowledge graph data includes pending task timeliness data, unprocessed notification content, and monitoring rule triggering status;
[0008] Obtaining task backlog time according to the to-do task timeliness data, and obtaining a backlog task rate according to the task backlog time;
[0009] Acquire process abnormality link information and node association information according to the unprocessed notification content, and acquire node abnormality rate according to the process abnormality link information and the node association information;
[0010] Acquire monitoring timeliness information and notification timeliness information according to the triggering status of the monitoring rule, and acquire abnormal delay rate according to the monitoring timeliness information and the notification timeliness information;
[0011] Obtaining a comprehensive abnormality rate based on the backlog task rate, the node abnormality rate, and the abnormal delay rate;
[0012] An early warning is issued for anomalies in the enterprise management system based on the comprehensive anomaly rate.
[0013] Preferably, the step of obtaining the task backlog time according to the to-be-done task aging data, and obtaining the backlog task rate according to the task backlog time, includes:
[0014] Acquire a planned completion time and a plurality of actual completion times of single tasks according to the to-do task timeliness data, and acquire a plurality of backlog times of single tasks according to the planned completion time and the plurality of actual completion times of the single tasks;
[0015] determining in sequence whether the backlog time of a plurality of the single tasks exceeds a preset threshold;
[0016] If it exceeds the preset threshold, the backlog time of multiple single tasks that exceed the preset threshold is accumulated to obtain the total accumulated backlog time;
[0017] Obtaining the corresponding number of tasks according to the actual completion time of the plurality of single tasks, and calculating the standard total completion time according to the number of tasks and the planned completion time;
[0018] The backlog task rate is obtained according to the total standard completion time and the total accumulated backlog duration.
[0019] Preferably, the step of obtaining the node abnormality rate according to the process abnormality link information and the node association information includes:
[0020] Acquire multiple blocked nodes according to the node association information, and acquire multiple previous pass times of corresponding blocked nodes according to the multiple blocked nodes;
[0021] and obtaining a current traffic proportion value based on the plurality of previous traffic times and preset historical node traffic, and using the current traffic proportion value as the node congestion deviation;
[0022] Acquire a stop task identifier according to the process abnormal link information, and acquire a task path identifier according to the stop task identifier;
[0023] Obtaining the historical average number of communications and the current number of communications of the corresponding task identifier according to the task path identifier, and calculating the node communication frequency difference according to the historical average number of node communications, the current number of communications and the preset communication time, and using the node communication frequency difference as the task discrete coefficient;
[0024] The node abnormality rate is obtained according to the node blocking deviation and the task discrete coefficient.
[0025] Preferably, the step of obtaining the abnormal delay rate according to the monitoring timeliness information and the notification timeliness information includes:
[0026] Obtaining an average monitoring delay time according to the monitoring timeliness information;
[0027] Get the historical average delay time and monitoring average delay time within the preset time period and get the monitoring delay ratio;
[0028] Acquire a notification response time according to the notification timeliness information, wherein the notification response time includes a delayed response time and an advanced response time, and acquire a response mean according to the delayed response time and the advanced response time;
[0029] Obtain a historical average response time within a preset time, and obtain a notification delay ratio based on the historical average response time and the response mean;
[0030] The abnormal delay rate is obtained by performing weighted calculation according to the monitoring delay ratio and the notification delay ratio.
[0031] Preferably, the step of obtaining a comprehensive abnormality rate according to the backlog task rate, the node abnormality rate and the abnormal delay rate comprises:
[0032] Obtaining a corresponding backlog task rate weight value according to the backlog task rate;
[0033] Obtaining a corresponding node abnormality rate weight value according to the node abnormality rate;
[0034] The comprehensive abnormality rate is calculated according to the backlog task rate, the node abnormality rate, the abnormal delay rate, the backlog task rate weight value and the node abnormality rate weight value, wherein the calculation formula is:
[0035] ;
[0036] in, represents the comprehensive abnormality rate, represents the backlog rate, represents the node abnormality rate, Table abnormal delay rate, represents the weight value of the backlog task rate, and b represents the weight value of the node abnormality rate.
[0037] Preferably, the step of issuing an early warning for anomalies in the enterprise management system based on the comprehensive anomaly rate includes:
[0038] Obtaining historical abnormality rates of the enterprise management system, and calculating an abnormality rate percentage based on the comprehensive abnormality rate and the historical abnormality rate;
[0039] Determining whether the abnormality rate ratio is greater than a preset abnormality rate ratio;
[0040] If the comprehensive abnormality rate is greater than the preset abnormality rate ratio, it is determined that the current enterprise management system is in an abnormal state, and an early warning is issued for the abnormality in the enterprise management system.
[0041] A production anomaly early warning system based on knowledge graph, including:
[0042] The first acquisition module is used to obtain the operation knowledge graph data in the enterprise management system, wherein the operation knowledge graph data includes the timeliness data of pending tasks, the content of unprocessed notifications, and the trigger status of monitoring rules;
[0043] A second acquisition module is configured to acquire a task backlog time according to the to-be-done task timeliness data, and acquire a backlog task rate according to the task backlog time;
[0044] a third acquisition module, configured to acquire process abnormality link information and node association information according to the unprocessed notification content, and acquire a node abnormality rate according to the process abnormality link information and the node association information;
[0045] a fourth acquisition module, configured to acquire monitoring timeliness information and notification timeliness information according to the monitoring rule triggering status, and acquire an abnormal delay rate according to the monitoring timeliness information and the notification timeliness information;
[0046] a fifth acquisition module, configured to acquire a comprehensive abnormality rate according to the backlog task rate, the node abnormality rate, and the abnormal delay rate;
[0047] The early warning module is used to issue early warnings for abnormalities in the enterprise management system based on the comprehensive abnormality rate.
[0048] Preferably, the second acquisition module includes:
[0049] A first acquiring unit is configured to acquire a planned completion time and a plurality of actual completion times of individual tasks according to the to-be-done task timeliness data, and acquire a plurality of backlog times of individual tasks according to the planned completion time and the plurality of actual completion times of the individual tasks;
[0050] A judging unit, configured to sequentially judge whether the backlog time of a plurality of the single tasks exceeds a preset threshold;
[0051] If it exceeds the preset threshold, the backlog time of multiple single tasks that exceed the preset threshold is accumulated to obtain the total accumulated backlog time;
[0052] A second acquiring unit is configured to acquire the corresponding number of tasks according to the actual completion time of the plurality of single tasks, and calculate the standard total completion time according to the number of tasks and the planned completion time;
[0053] The third acquiring unit is configured to acquire a backlog task rate according to the standard total completion time and the accumulated total backlog duration.
[0054] The present application also provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.
[0055] The present application also provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.
[0056] The beneficial effects of the present application are as follows: the present invention extracts the timeliness of pending tasks, the content of unprocessed notifications and the triggering status of monitoring rules from the enterprise management system, constructs a knowledge graph to realize data integration and semantic association, analyzes the process abnormality links and node associations based on the content of unprocessed notifications, and calculates the node abnormality rate to accurately locate the blocked nodes; obtains the monitoring timeliness and notification timeliness through the triggering status of monitoring rules, calculates the abnormality delay rate to quantify the response delay, and generates a comprehensive abnormality rate by combining the backlog task rate, node abnormality rate and abnormal delay rate. The system status is comprehensively evaluated from three dimensions: task backlog, process blocking and response delay, and finally an early warning is issued based on the comprehensive abnormality rate: by comparing with historical data to identify trend changes, and triggering a personalized early warning mechanism based on a preset threshold interval to ensure early intervention, this method can obtain the backlog status in time, and can solve the problem of multi-task notification window frame backlog, resulting in the inability to obtain the backlog status, and issuing an early warning based on the corresponding backlog status. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 This is a schematic diagram of a method flow chart according to an embodiment of the present application.
[0058] Figure 2 This is a schematic diagram of the system structure of an embodiment of the present application.
[0059] Figure 3 This is a schematic diagram of the internal structure of a computer device according to an embodiment of the present application.
[0060] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0061] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0062] like Figure 1-Figure 3 As shown, this application provides a production anomaly early warning method based on knowledge graph, including:
[0063] S1. Obtaining operational knowledge graph data from the enterprise management system, wherein the operational knowledge graph data includes pending task timeliness data, unprocessed notification content, and monitoring rule triggering status;
[0064] S2. Obtaining a task backlog time based on the to-do task timeliness data, and obtaining a backlog task rate based on the task backlog time;
[0065] S3. Obtaining process abnormality link information and node association information based on the unprocessed notification content, and obtaining a node abnormality rate based on the process abnormality link information and the node association information;
[0066] S4. Acquire monitoring timeliness information and notification timeliness information according to the monitoring rule triggering status, and acquire abnormal delay rate according to the monitoring timeliness information and the notification timeliness information;
[0067] S5. Obtaining a comprehensive abnormality rate based on the backlog task rate, the node abnormality rate, and the abnormal delay rate;
[0068] S6. Issue early warnings for abnormalities in the enterprise management system based on the comprehensive abnormality rate.
[0069] As described in the above steps S1-S6, since the existing enterprise management system usually adopts timely response in advance when processing task stacking, this causes a backlog of multiple task notification windows in the process of timely task response, and it is impossible to obtain the backlog status and issue an early warning based on the corresponding backlog status. The present invention first obtains the operation knowledge graph data in the enterprise management system, wherein the operation knowledge graph data includes the timeliness data of pending tasks, the content of unprocessed notifications and the trigger status of monitoring rules. In this way, the timeliness data of pending tasks, the content of unprocessed notifications and the trigger status of monitoring rules are extracted from the enterprise management system to construct a structured knowledge graph, realize the integration and semantic representation of production data, and provide multi-dimensional data support for subsequent anomaly analysis to ensure the comprehensiveness of information (such as task timeliness, process anomalies, and monitoring status). Secondly, through the "node-edge" structure of the knowledge graph, the association relationship between data is clarified (such as the mapping of tasks and nodes, processes and monitoring);
[0070] The specific acquisition process is: first deploy the data collection interface in the enterprise management system, and extract data from the to-do task module, notification center, and monitoring rule engine through the API interface or real-time database synchronization. For example, obtain the time-sensitive data such as the planned completion time and actual completion time of the to-do task from the task table through SQL query statements, and then map the collected data to nodes and edges in the knowledge graph. To-do tasks, notification content, monitoring rules, etc. are used as entity nodes, and the relationship between tasks and notifications, the triggering relationship between rules and tasks, etc. are used as edges, and attributes such as timeliness, content, and status are added to the nodes. Finally, the collected data is deduplicated, error-corrected, and standardized to ensure data quality. For example, unify the time format, standardize task identifiers, and eliminate the problem of inconsistent data formats in different modules;
[0071] Next, the task backlog time is obtained based on the to-do task timeliness data, and the backlog task rate is obtained based on the task backlog time. In this way, by comparing the planned task completion time with the actual completion time, the task backlog degree can be quantified, reflecting production efficiency anomalies, and the scale (such as the total backlog duration) and proportion (backlog task rate) of task processing delays can be identified to locate efficiency bottlenecks. At the same time, the difference between the actual task completion time and the planned time can be tracked in real time to promptly discover task delay trends and provide data support for resource allocation.
[0072] Then, based on the content of the unprocessed notification, process abnormality link information and node association information are obtained, and the node abnormality rate is obtained based on the process abnormality link information and the node association information. In this way, by analyzing the process abnormality link information and the node association information, the blocked nodes in the process can be accurately identified, avoiding the fuzzy judgment of the abnormal location in the traditional method. Secondly, combined with the node blocking deviation and the task discrete coefficient, the node abnormality is evaluated from the two dimensions of traffic efficiency and communication frequency, which improves the accuracy of abnormality judgment. Based on the node association relationship of the knowledge graph, dynamic association analysis of abnormal nodes and task paths is realized, which facilitates tracing the root cause of the abnormality.
[0073] Secondly, monitoring timeliness information and notification timeliness information are obtained based on the trigger status of the monitoring rule, and the abnormal delay rate is obtained based on the monitoring timeliness information and the notification timeliness information. In this way, by monitoring the average delay time and notification response time, accurate quantification of the timeliness of system monitoring and notification links is achieved, avoiding ambiguous evaluation of response delays;
[0074] At the same time, a comprehensive abnormality rate is obtained based on the backlog task rate, the node abnormality rate, and the abnormal delay rate. By combining the backlog task rate, the node abnormality rate, and the abnormal delay rate, a comprehensive assessment of system abnormalities is conducted from three dimensions: task backlog, process blockage, and response delay. This avoids the one-sidedness of a single indicator and combines multiple dimensional indicators into a single comprehensive abnormality rate, making it easier for management to intuitively understand the overall abnormality level of the system and provide a clear basis for decision-making.
[0075] Finally, an early warning is issued for anomalies in the enterprise management system based on the comprehensive anomaly rate. By comparing the current comprehensive anomaly rate with the historical anomaly rate, the changing trend of the degree of anomaly can be discovered, avoiding misjudgment based only on absolute thresholds, and setting a preset anomaly rate percentage value according to the actual situation of the enterprise, thereby realizing personalized customization of the early warning mechanism and improving the accuracy of the early warning. Secondly, when the anomaly rate percentage exceeds the threshold, an early warning is triggered immediately to ensure that the enterprise can obtain the backlog status in time, and can solve the backlog of multiple task notification windows, resulting in the inability to obtain the backlog status and issue an early warning based on the corresponding backlog status.
[0076] In one embodiment, the step S2 of obtaining the task backlog time according to the to-be-done task aging data and obtaining the backlog task rate according to the task backlog time includes:
[0077] S201, obtaining a planned completion time and actual completion time of multiple single tasks based on the to-do task timeliness data, and obtaining backlog time of multiple single tasks based on the planned completion time and actual completion time of the multiple single tasks;
[0078] S202, sequentially determining whether the backlog time of multiple single tasks exceeds a preset threshold;
[0079] If it exceeds the preset threshold, the backlog time of multiple single tasks that exceed the preset threshold is accumulated to obtain the total accumulated backlog time;
[0080] S203, obtaining the corresponding number of tasks according to the actual completion time of the plurality of single tasks, and calculating the standard total completion time according to the number of tasks and the planned completion time;
[0081] S204: Obtain a backlog task rate based on the total standard completion time and the accumulated total backlog duration.
[0082] As described in steps S201-S204 above, the present invention first obtains the planned completion time and actual completion time of multiple individual tasks based on the pending task timeliness data, and then obtains multiple individual task backlog times based on the planned completion time and the actual completion time of multiple individual tasks. In this way, the planned completion time of the task and the actual completion time of each individual task are extracted from the pending task timeliness data to form a basic data pair of the time dimension. Secondly, establishing a comparison benchmark of "planned completion time - actual completion time" is the primary step in quantifying the degree of task backlog. By structured collection of multi-task time data, the foundation is laid for batch analysis of the overall delay trend of the task queue, ensuring the operability and accuracy of subsequent analysis.
[0083] Next, determining in sequence whether the backlog time of multiple single tasks exceeds a preset threshold;
[0084] If the preset threshold is exceeded, the backlog time of multiple single tasks that exceed the preset threshold is accumulated and calculated to obtain the total accumulated backlog time. This can screen out seriously delayed tasks and calculate their total delay time, and focus on the backlog of tasks that have a greater impact on the production process, avoiding the interference of minor delays, highlighting key issues, and enabling enterprises to give priority to tasks that seriously affect production efficiency. At the same time, the setting of the preset threshold can be determined according to the actual production requirements and historical data of the enterprise. By screening the backlog time that exceeds the threshold, tasks that have a significant impact on the production schedule can be accurately located, providing a clear direction for resource allocation and exception handling, and improving the pertinence of exception warnings;
[0085] Secondly, the corresponding number of tasks is obtained based on the actual completion time of multiple single tasks, and the standard total completion time is calculated based on the number of tasks and the planned completion time. This can establish a task completion time benchmark under normal circumstances and provide a comparison standard for evaluating the actual backlog situation, making the measurement of the backlog level relative and facilitating comparison and analysis between task queues of different sizes. At the same time, taking into account the relationship between the number of tasks and the planned completion time, the standard total completion time is obtained through standardized calculation, which can convert different numbers of tasks into comparable time dimensions, avoid evaluation bias caused by differences in the number of tasks, and ensure the scientific nature of the backlog task rate calculation;
[0086] Finally, the backlog task rate is obtained based on the total standard completion time and the total cumulative backlog time. In this way, the backlog task rate can be used to convert the task backlog situation into a quantitative indicator, which can intuitively reflect the overall task backlog level. At the same time, it can also provide clear quantitative indicators for the company's management, so as to quickly understand the severity of the task backlog in the production system and provide data support for decision-making, such as whether it is necessary to increase manpower, adjust production plans, etc. Secondly, the backlog task rate, as a comprehensive indicator, integrates the two key factors of backlog time and standard completion time, and converts qualitative backlog problems into quantitative values, making the judgment of abnormal situations more objective and accurate, and meeting the needs of refined management of the enterprise.
[0087] In one embodiment, the step S3 of obtaining the node abnormality rate according to the process abnormality link information and the node association information includes:
[0088] S301, obtaining a plurality of blocked nodes according to the node association information, and obtaining a plurality of previous pass times of the corresponding blocked nodes according to the plurality of blocked nodes;
[0089] S302: Obtain a current traffic ratio based on the plurality of previous traffic times and preset historical node traffic, and use the current traffic ratio as a node congestion deviation;
[0090] S303, obtaining a stop task identifier according to the process abnormal link information, and obtaining a task path identifier according to the stop task identifier;
[0091] S304: Obtain the historical average number of communication times and the current number of communication times of the corresponding task identifier according to the task path identifier, calculate the node communication frequency difference according to the historical average number of node communication times, the current number of communication times, and the preset communication time, and use the node communication frequency difference as the task dispersion coefficient;
[0092] S305 : Obtain a node abnormality rate according to the node blocking deviation and the task discrete coefficient.
[0093] As described in steps S301-S305 above, the present invention first obtains multiple blocked nodes based on the node association information, and then obtains multiple previous pass counts of the corresponding blocked nodes based on the multiple blocked nodes. This provides a direct basis for evaluating node anomalies by locating the blocked nodes and their pass data, facilitating the rapid identification of bottlenecks in the production process. Secondly, the node association relationships in the knowledge graph can intuitively reflect the process logic. Obtaining the blocked nodes and pass counts is the basis for quantifying node anomalies. By comparing historical data, it can effectively identify abnormal fluctuations in current pass efficiency, providing data support for subsequent deviation calculations.
[0094] Next, the current traffic ratio is obtained based on the previous traffic times and the preset historical node traffic times, and the current traffic ratio is used as the node congestion deviation. By converting the current traffic ratio into the node congestion deviation, the abnormality of the node traffic efficiency can be quantified. Secondly, the change in the number of traffic times is converted into a quantifiable deviation index, which intuitively reflects the severity of the node congestion and provides a basis for abnormality classification.
[0095] Next, the stop task identifier is obtained based on the process abnormality link information, and the task path identifier is obtained based on the stop task identifier, so that a mapping relationship between the abnormal task and the process path can be established. Secondly, through the association of the task identifier and the path, the process of the abnormal task can be traced, which facilitates the analysis of the propagation path and impact range of the abnormality in the overall process;
[0096] At the same time, the historical average number of communications and the current number of communications of the corresponding task identifier are obtained according to the task path identifier, and the node communication frequency difference is calculated according to the historical average number of node communications, the current number of communications and the preset communication time, and the node communication frequency difference is used as the task discrete coefficient, which can form the task discrete coefficient and quantify the abnormality of the collaboration efficiency between nodes. At the same time, the change of the communication frequency reflects the abnormality of the collaboration between nodes, such as communication delay or frequent communication, which can assist in judging whether the blocked node is abnormal due to collaboration problems;
[0097] Finally, the node anomaly rate is calculated based on the node congestion deviation and the task discrete coefficient. This weighted calculation yields a single quantitative metric reflecting the overall degree of node anomaly. This metric integrates anomalies from the two dimensions of traffic efficiency and collaboration efficiency into a unified indicator, enabling management to quickly assess node health and provide a basis for prioritizing anomaly handling. However, a single metric (such as congestion deviation) may not fully reflect node anomalies. Incorporating the task discrete coefficient from the collaborative dimension can avoid misjudgments caused by a single factor. This weighted calculation allows the weights of each dimension to be adjusted based on the enterprise's actual needs, enhancing the adaptability of the early warning system. The weighting logic for assigning the node congestion deviation and the task discrete coefficient is specific to the node. Node congestion can directly lead to task backlogs and process interruptions, significantly impacting production efficiency. For example, if the system's allocation of material approval nodes results in material flow interruption, the congestion deviation can quickly locate the problematic node. Furthermore, historical production data shows that node congestion anomalies account for a high proportion of total anomalies (e.g., 60%), so they are given a higher weight in prioritizing the task discrete coefficient.
[0098] In one embodiment, the step S4 of obtaining the abnormal delay rate according to the monitoring timeliness information and the notification timeliness information includes:
[0099] S401, obtaining an average monitoring delay time according to the monitoring timeliness information;
[0100] S402, obtaining the historical average delay time and the monitoring average delay within a preset time period to obtain the monitoring delay ratio;
[0101] S403: Acquire a notification response time according to the notification timeliness information, wherein the notification response time includes a delayed response time and an advanced response time, and acquire a response mean according to the delayed response time and the advanced response time;
[0102] S404: Obtain a historical average response time within a preset time period, and obtain a notification delay ratio based on the historical average response time and the response mean;
[0103] S405: Perform weighted calculation according to the monitoring delay ratio and the notification delay ratio to obtain an abnormal delay rate.
[0104] As described in steps S401-S405 above, the present invention first obtains the average monitoring delay time based on the monitoring timeliness information. This extracts the average delay time of the monitoring task from the monitoring timeliness information, quantifies the response lag of the monitoring link, and establishes benchmark data for monitoring timeliness, providing a quantitative basis for determining whether the current monitoring system detects anomalies in a timely manner. Secondly, monitoring serves as the "perception layer" of production anomalies, and its delay directly affects the timeliness of early warnings. The average delay time can quickly locate the efficiency bottleneck of the monitoring module, providing direction for subsequent optimization.
[0105] Next, the historical average delay time and the monitoring average delay time within the preset time period are obtained to obtain the monitoring delay ratio. This monitoring delay ratio reflects the degree of deviation of the current delay from the historical level. By comparing historical data, the time base differences of different monitoring tasks are eliminated, avoiding misjudgments caused by single absolute value judgments and improving the accuracy of anomaly identification.
[0106] Then, the notification response time is obtained based on the notification timeliness information, where the notification response time includes the delayed response time and the advanced response time. The response mean is obtained based on the delayed response time and the advanced response time. The response mean of the two comprehensively evaluates the timeliness performance of the notification link, and avoids focusing only on delayed responses while ignoring abnormalities of early responses (such as misjudgment caused by premature notification triggering). By balancing the two abnormal situations through the mean, a more objective evaluation is achieved, and "too early" or "too late" notification responses may lead to production decision-making errors. For example, early responses may lead to invalid operations, while delayed responses may miss the processing opportunity. Both need to be equally included in the evaluation system;
[0107] Secondly, the historical average response time within a preset timeframe is obtained. Based on this historical average response time and the response mean, the notification delay ratio is calculated. This allows the degree of timeliness anomalies in the notification process to be quantified. The current response efficiency can be calibrated using historical data, identifying whether the notification system is experiencing systematic delays or advances, and providing data support for process optimization. Furthermore, the historical average response time reflects the normal processing capacity of the notification system. The ratio calculation can eliminate differences in processing time between different notification types (e.g., emergency vs. standard notifications), making the indicator more universal.
[0108] Finally, a weighted calculation is performed based on the monitoring delay ratio and the notification delay ratio to generate the anomaly delay rate. This allows for a comprehensive assessment of anomalies across multiple links, transforming the timeliness of anomalies from the two key links of monitoring and notification into a single metric. This allows management to quickly assess the overall system response efficiency. Furthermore, monitoring and notification have different weights in the anomaly warning chain: monitoring is fundamental for problem discovery, while notification is key for problem transmission. This weighted calculation allows the importance of each to be adjusted based on the enterprise's actual needs (e.g., a weight of 0.6 for monitoring and 0.4 for notification), improving the adaptability of the early warning system. The monitoring delay ratio reflects the timeliness of anomaly discovery and is a fundamental link in the early warning chain. If monitoring fails to detect anomalies promptly, no matter how efficient the subsequent notification process is, it cannot compensate. Secondly, the notification delay ratio reflects the efficiency of anomaly transmission and is a key link in the early warning chain. After anomaly detection, delayed notification can lead to delayed responses. Therefore, the matching logic should adhere to the principle of prioritizing foundation over transmission, meaning that the monitoring delay ratio is generally given a higher weight than the notification delay ratio.
[0109] In one embodiment, the step S5 of obtaining a comprehensive abnormality rate based on the backlog task rate, the node abnormality rate, and the abnormal delay rate includes:
[0110] S501. Obtain a corresponding backlog task rate weight value according to the backlog task rate;
[0111] S502: Obtain a corresponding node abnormality rate weight value according to the node abnormality rate;
[0112] S503: Calculate a comprehensive abnormality rate based on the backlog task rate, the node abnormality rate, the abnormal delay rate, the backlog task rate weight value, and the node abnormality rate weight value, wherein the calculation formula is:
[0113] ;
[0114] in, represents the comprehensive abnormality rate, represents the backlog rate, represents the node abnormality rate, Table abnormal delay rate, represents the weight value of the backlog task rate, and b represents the weight value of the node abnormality rate.
[0115] As described in the above steps S501-S503, the present invention first obtains the corresponding backlog task rate weight value according to the backlog task rate, and secondly obtains the corresponding node abnormality rate weight value according to the node abnormality rate. Finally, the comprehensive abnormality rate is calculated according to the backlog task rate, the node abnormality rate, the abnormal delay rate, the backlog task rate weight value and the node abnormality rate weight value. In this way, the backlog task rate, the node abnormality rate, the abnormal delay rate and their weight values are integrated through a formula to output a single comprehensive abnormality rate indicator, which comprehensively reflects the overall abnormality degree of the system and converts multi-dimensional abnormality indicators (task backlog, process blocking, response delay) into a unified quantitative value, which is convenient for management to intuitively grasp the health status of the production system and reduce the complexity of decision-making. Secondly, A single indicator cannot cover all scenarios of production anomalies (for example, task backlogs and process blockages may occur at the same time). The weighted formula can realize the coupled analysis of multi-dimensional anomalies through mathematical modeling. The weight distribution logic of the backlog task rate, the node anomaly rate and the anomaly delay rate is as follows: the backlog task rate directly reflects the production efficiency bottleneck (such as task accumulation leading to delivery delays) and is an "efficiency layer" anomaly; the node anomaly rate reflects the process continuity risk (such as production line node blockage) and is a "process layer" anomaly; the anomaly delay rate reflects the monitoring and response timeliness (such as anomaly discovery / notification lag) and is a "response layer" anomaly. The weight distribution follows the priority of "efficiency layer > process layer > response layer", that is, the backlog task rate usually has the highest weight and the anomaly delay rate has the lowest weight.
[0116] In one embodiment, the step S6 of issuing an early warning for anomalies in the enterprise management system based on the comprehensive anomaly rate includes:
[0117] S601. Obtain historical abnormality rates of the enterprise management system, and calculate an abnormality rate percentage based on the comprehensive abnormality rate and the historical abnormality rate;
[0118] S602, determining whether the abnormality rate ratio is greater than a preset abnormality rate ratio;
[0119] If the comprehensive abnormality rate is greater than the preset abnormality rate ratio, it is determined that the current enterprise management system is in an abnormal state, and an early warning is issued for the abnormality in the enterprise management system.
[0120] As described in the above steps S601-S602, the present invention first obtains the historical abnormality rate of the enterprise management system in history, and calculates the abnormality rate percentage value based on the comprehensive abnormality rate and the historical abnormality rate, and then determines whether the abnormality rate percentage value is greater than the preset abnormality rate percentage value. If the comprehensive abnormality rate is greater than the preset abnormality rate percentage value, the abnormal state in the current enterprise management system is determined, and an early warning is issued for the abnormality in the enterprise management system. In this way, the deviation of the current abnormality level from the historical level can be quantified, and the mechanical defect of judging abnormalities based only on absolute thresholds can be avoided. The abnormality standard is dynamically calibrated through historical data to adapt to the cyclical changes in the enterprise production model (such as the difference between peak and off-seasons), and the production characteristics and management standards of different enterprises are significantly different (such as the abnormality tolerance of semiconductor factories and food processing plants is different). The historical abnormality rate can reflect the enterprise's own "normal fluctuation range". Calculating the percentage value can convert the abnormality assessment into a "relative change", thereby improving the targeted nature of the early warning (for example, if a company's historical abnormality rate is generally high, and the current abnormality rate is high in absolute value but the percentage does not exceed the threshold, then no early warning may be issued). This enables personalized customization of the early warning mechanism and improves the accuracy of the early warning. Secondly, when the abnormality rate percentage exceeds the threshold, an early warning is triggered immediately, ensuring that the company can obtain the backlog status in a timely manner, and can solve the problem of backlogs in multiple task notification windows, resulting in the inability to obtain the backlog status and issue early warnings based on the corresponding backlog status.
[0121] This application also provides a production anomaly early warning system based on a knowledge graph, including:
[0122] The first acquisition module is used to obtain the operation knowledge graph data in the enterprise management system, wherein the operation knowledge graph data includes the timeliness data of pending tasks, the content of unprocessed notifications, and the trigger status of monitoring rules;
[0123] A second acquisition module is configured to acquire a task backlog time according to the to-be-done task timeliness data, and acquire a backlog task rate according to the task backlog time;
[0124] a third acquisition module, configured to acquire process abnormality link information and node association information according to the unprocessed notification content, and acquire a node abnormality rate according to the process abnormality link information and the node association information;
[0125] a fourth acquisition module, configured to acquire monitoring timeliness information and notification timeliness information according to the monitoring rule triggering status, and acquire an abnormal delay rate according to the monitoring timeliness information and the notification timeliness information;
[0126] a fifth acquisition module, configured to acquire a comprehensive abnormality rate according to the backlog task rate, the node abnormality rate, and the abnormal delay rate;
[0127] The early warning module is used to issue early warnings for abnormalities in the enterprise management system based on the comprehensive abnormality rate.
[0128] In one embodiment, the second acquisition module includes:
[0129] A first acquiring unit is configured to acquire a planned completion time and a plurality of actual completion times of individual tasks according to the to-be-done task timeliness data, and acquire a plurality of backlog times of individual tasks according to the planned completion time and the plurality of actual completion times of the individual tasks;
[0130] A judging unit, configured to sequentially judge whether the backlog time of a plurality of the single tasks exceeds a preset threshold;
[0131] If it exceeds the preset threshold, the backlog time of multiple single tasks that exceed the preset threshold is accumulated to obtain the total accumulated backlog time;
[0132] A second acquiring unit is configured to acquire the corresponding number of tasks according to the actual completion time of the plurality of single tasks, and calculate the standard total completion time according to the number of tasks and the planned completion time;
[0133] The third acquiring unit is configured to acquire a backlog task rate according to the standard total completion time and the accumulated total backlog duration.
[0134] The present application also provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.
[0135] The present application also provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.
[0136] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media provided in this application and used in the embodiments may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct RAM bus dynamic RAM (DRDRAM), and RAM bus dynamic RAM (RDRAM).
[0137] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, apparatus, article, or method comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, apparatus, article, or method. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, apparatus, article, or method comprising the element.
[0138] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A production anomaly early warning method based on knowledge graph, characterized in that: include: Obtaining operational knowledge graph data from the enterprise management system, where the operational knowledge graph data includes pending task timeliness data, unprocessed notification content, and monitoring rule triggering status; Obtaining task backlog time according to the to-do task timeliness data, and obtaining a backlog task rate according to the task backlog time; Acquire process abnormality link information and node association information according to the unprocessed notification content, and acquire node abnormality rate according to the process abnormality link information and the node association information; Acquire monitoring timeliness information and notification timeliness information according to the triggering status of the monitoring rule, and acquire abnormal delay rate according to the monitoring timeliness information and the notification timeliness information; Obtaining a comprehensive abnormality rate based on the backlog task rate, the node abnormality rate, and the abnormal delay rate; An early warning is issued for anomalies in the enterprise management system based on the comprehensive anomaly rate.
2. The production anomaly early warning method based on knowledge graph according to claim 1 is characterized in that: The step of obtaining the task backlog time according to the to-be-done task aging data, and obtaining the backlog task rate according to the task backlog time, includes: Acquire a planned completion time and a plurality of actual completion times of single tasks according to the to-do task timeliness data, and acquire a plurality of backlog times of single tasks according to the planned completion time and the plurality of actual completion times of the single tasks; determining in sequence whether the backlog time of a plurality of the single tasks exceeds a preset threshold; If it exceeds the preset threshold, the backlog time of multiple single tasks that exceed the preset threshold is accumulated to obtain the total accumulated backlog time; Obtaining the corresponding number of tasks according to the actual completion time of the plurality of single tasks, and calculating the standard total completion time according to the number of tasks and the planned completion time; The backlog task rate is obtained according to the total standard completion time and the total accumulated backlog duration.
3. The production anomaly early warning method based on knowledge graph according to claim 1 is characterized in that: The step of obtaining the node abnormality rate according to the process abnormality link information and the node association information includes: Acquire multiple blocked nodes according to the node association information, and acquire multiple previous pass times of corresponding blocked nodes according to the multiple blocked nodes; and obtaining a current traffic proportion value based on the plurality of previous traffic times and preset historical node traffic, and using the current traffic proportion value as the node congestion deviation; Acquire a stop task identifier according to the process abnormal link information, and acquire a task path identifier according to the stop task identifier; Obtaining the historical average number of communications and the current number of communications of the corresponding task identifier according to the task path identifier, and calculating the node communication frequency difference according to the historical average number of node communications, the current number of communications and the preset communication time, and using the node communication frequency difference as the task discrete coefficient; The node abnormality rate is obtained according to the node blocking deviation and the task discrete coefficient.
4. The production anomaly early warning method based on knowledge graph according to claim 1 is characterized in that: The step of obtaining the abnormal delay rate according to the monitoring timeliness information and the notification timeliness information includes: Obtaining an average monitoring delay time according to the monitoring timeliness information; Get the historical average delay time and monitoring average delay time within the preset time period and get the monitoring delay ratio; Acquire a notification response time according to the notification timeliness information, wherein the notification response time includes a delayed response time and an advanced response time, and acquire a response mean according to the delayed response time and the advanced response time; Obtain a historical average response time within a preset time, and obtain a notification delay ratio based on the historical average response time and the response mean; The abnormal delay rate is obtained by performing weighted calculation according to the monitoring delay ratio and the notification delay ratio.
5. The production anomaly early warning method based on knowledge graph according to claim 1 is characterized in that: The step of obtaining a comprehensive abnormality rate according to the backlog task rate, the node abnormality rate, and the abnormal delay rate includes: Obtaining a corresponding backlog task rate weight value according to the backlog task rate; Obtaining a corresponding node abnormality rate weight value according to the node abnormality rate; A comprehensive abnormality rate is calculated based on the backlog task rate, the node abnormality rate, the abnormal delay rate, the backlog task rate weight value, and the node abnormality rate weight value.
6. The production anomaly early warning method based on knowledge graph according to claim 1 is characterized in that: The step of providing an early warning of anomalies in the enterprise management system based on the comprehensive anomaly rate includes: Obtaining historical abnormality rates of the enterprise management system, and calculating an abnormality rate percentage based on the comprehensive abnormality rate and the historical abnormality rate; Determining whether the abnormality rate ratio is greater than a preset abnormality rate ratio; If the comprehensive abnormality rate is greater than the preset abnormality rate ratio, it is determined that the current enterprise management system is in an abnormal state, and an early warning is issued for the abnormality in the enterprise management system.
7. A production anomaly warning system based on knowledge graph, characterized in that: include: The first acquisition module is used to obtain the operation knowledge graph data in the enterprise management system, wherein the operation knowledge graph data includes the timeliness data of pending tasks, the content of unprocessed notifications, and the trigger status of monitoring rules; A second acquisition module is configured to acquire a task backlog time according to the to-be-done task timeliness data, and acquire a backlog task rate according to the task backlog time; a third acquisition module, configured to acquire process abnormality link information and node association information according to the unprocessed notification content, and acquire a node abnormality rate according to the process abnormality link information and the node association information; a fourth acquisition module, configured to acquire monitoring timeliness information and notification timeliness information according to the monitoring rule triggering status, and acquire an abnormal delay rate according to the monitoring timeliness information and the notification timeliness information; a fifth acquisition module, configured to acquire a comprehensive abnormality rate according to the backlog task rate, the node abnormality rate, and the abnormal delay rate; The early warning module is used to issue early warnings for abnormalities in the enterprise management system based on the comprehensive abnormality rate.
8. The production anomaly early warning system based on knowledge graph according to claim 7 is characterized in that: The second acquisition module includes: A first acquiring unit is configured to acquire a planned completion time and a plurality of actual completion times of individual tasks according to the to-be-done task timeliness data, and acquire a plurality of backlog times of individual tasks according to the planned completion time and the plurality of actual completion times of the individual tasks; A judging unit, configured to sequentially judge whether the backlog time of a plurality of the single tasks exceeds a preset threshold; If it exceeds the preset threshold, the backlog time of multiple single tasks that exceed the preset threshold is accumulated to obtain the total accumulated backlog time; A second acquiring unit is configured to acquire the corresponding number of tasks according to the actual completion time of the plurality of single tasks, and calculate the standard total completion time according to the number of tasks and the planned completion time; The third acquiring unit is configured to acquire a backlog task rate according to the standard total completion time and the accumulated total backlog duration.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Intelligent factory digital equipment management system and method
CN118502372A
Network security situation early warning method and system based on knowledge graph
CN119603058A