Industrial control all-in-one machine anomaly detection method and system for multi-modal data fusion
Through the multimodal data fusion method, the network equipment, communication and line data of the industrial control all-in-one machine are dynamically collected and analyzed, and the missed detection and false alarm problems in the prior art are solved, achieving higher detection accuracy and real-timeness.
Patent Information
- Application Number
- CN202510962098.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-08-08
AI Technical Summary
The prior art is difficult to fully capture the abnormal behavior of industrial control all-in-one machines, resulting in missed detection and false alarms, and the real-time and accuracy of detection are poor.
Through the multimodal data fusion method, network equipment, network communication and network line data of industrial control all-in-one machine are dynamically collected, multimodal feature indicators of equipment, communication and lines are extracted, real-time feature vectors are constructed and compared with predetermined feature vectors. If the deviation exceeds the limit, a network warning is issued.
It improves the accuracy and timeliness of abnormal detection of industrial control all-in-one machine, reduces the rate of missed reports, and improves the reliability of operation.
Smart Images

Figure CN120455247A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field related to data processing, and specifically to an anomaly detection method and system for an industrial control all-in-one machine for multimodal data fusion. Background Art
[0002] Industrial control computers are the core equipment of industrial control systems, responsible for important tasks such as data processing, equipment control, and task coordination. The stability and reliability of their operating status directly affect the continuity, safety, and efficiency of industrial production. However, with the increasing complexity of industrial environments, industrial control computers face a variety of potential threats such as cyberattacks, hardware failures, and software vulnerabilities. Traditional single-modality data monitoring cannot meet the needs of accurate anomaly detection. For example, monitoring only basic performance indicators such as CPU usage and memory usage of the device, or simply analyzing the packet characteristics of network traffic, cannot fully capture the complex abnormal behavior of the industrial control computer during operation, which can easily lead to missed detections or false alarms. In addition, the industrial field environment contains a large amount of heterogeneous data, including device sensor data, network communication data, and log data, which contains rich equipment operation information. Existing methods cannot effectively integrate and use them for anomaly detection, which in turn affects the accuracy and reliability of industrial control computer anomaly detection.
[0003] Therefore, in the current related technologies, there are technical problems such as difficulty in fully capturing abnormal behaviors, resulting in the risk of missed detection and false alarm in abnormal detection of industrial control all-in-one machines, and poor detection real-time performance and accuracy. Summary of the Invention
[0004] This application solves the technical problems in the existing technology of difficulty in comprehensively capturing abnormal behaviors, resulting in the risk of missed detection and false alarms in abnormal detection of industrial control all-in-one machines, and poor real-time and accuracy of detection, by providing an abnormality detection method and system for industrial control all-in-one machines for multimodal data fusion. It achieves the technical effect of reducing the missed reporting rate of abnormalities of industrial control all-in-one machines, improving the accuracy, timeliness and operational reliability of abnormality detection.
[0005] The present application provides an anomaly detection method for an industrial control all-in-one machine for multimodal data fusion, the method comprising: dynamically collecting multi-source network features of an operating industrial control all-in-one machine to obtain a real-time multimodal network data set; performing feature extraction and analysis on the multimodal network data set according to a feature extraction plan to obtain a real-time network feature set; comparing a real-time feature vector constructed based on the real-time network feature set with a predetermined feature vector to obtain a real-time deviation coefficient; if the real-time deviation coefficient exceeds a predetermined deviation coefficient limit, issuing a network warning signal, and issuing a network anomaly warning for the industrial control all-in-one machine based on the network warning signal.
[0006] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion further performs the following processing: establishing a network modality set of the industrial control all-in-one machine, wherein the network modality set includes network equipment, network communications, and network lines; dynamically collecting the network equipment, the network communications, and the network lines in turn to obtain a device data set, a communication data set, and a line data set, respectively; the device data set, the communication data set, and the line data set constitute the real-time multimodal network data set.
[0007] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion also performs the following processing: extracting multimodal feature indicators stored in the memory of the feature extraction plan, wherein the multimodal feature indicators include device indicators, communication indicators and line indicators; performing feature extraction on the device data set, the communication data set and the line data set based on the device indicators, the communication indicators and the line indicators in sequence to obtain a device feature set, a communication feature set and a line feature set respectively; the device feature set, the communication feature set and the line feature set constitute the real-time network feature set; wherein the device indicators include at least a CPU utilization indicator, a memory occupancy indicator and a network interface status indicator, the communication indicators include at least a data frame content indicator, a data frame format and a data frame transmission protocol, and the line indicators include at least an electrical characteristic indicator, a topology structure indicator and an interference signal indicator.
[0008] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion also performs the following processing: dividing the real-time network feature set to obtain a division result, wherein the division result includes a first-level feature set and a second-level feature set; screening and analyzing the real-time feature vector and the predetermined feature vector with the first-level feature set as a constraint to obtain a real-time first-level vector and a predetermined first-level vector respectively; comparing the real-time first-level vector with the predetermined first-level vector to obtain a first-level deviation coefficient; screening and analyzing the real-time feature vector and the predetermined feature vector with the second-level feature set as a constraint to obtain a real-time second-level vector and a predetermined second-level vector respectively; comparing the real-time second-level vector with the predetermined second-level vector to obtain a second-level deviation coefficient; obtaining a predetermined level weight distribution, and weighting the first-level deviation coefficient and the second-level deviation coefficient according to the predetermined level weight distribution to obtain the real-time deviation coefficient.
[0009] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion also performs the following processing: obtaining any feature in the first-level feature set; matching the real-time first-level vector with the predetermined first-level vector to obtain any real-time feature parameter and any predetermined feature parameter corresponding to the arbitrary feature; taking the difference between the arbitrary real-time feature parameter and the arbitrary predetermined feature parameter, recorded as an arbitrary deviation value; taking the first deviation value in the first-level feature deviation value sequence obtained by taking the descending order of the arbitrary deviation value, and normalizing it as the first-level deviation coefficient.
[0010] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion also performs the following processing: based on the network warning signal, determine whether the arbitrary deviation value exceeds any predetermined threshold of the arbitrary feature; if it exceeds, match the mode corresponding to the arbitrary feature as the abnormal mode, and perform emergency processing on the abnormal mode.
[0011] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion further performs the following processing: if it does not exceed, traverse and analyze the features in the first-level feature set and determine the abnormal mode.
[0012] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion also performs the following processing: matching the abnormal feature set corresponding to the abnormal modality in the real-time network feature set; performing over-limit screening on the abnormal feature set to obtain a target feature set; traversing the target feature set in the abnormal database of the abnormal modality to obtain a historical abnormal data set; matching a preset emergency plan based on the historical abnormal location and historical abnormal type in the historical abnormal data set; and performing network abnormality emergency processing on the industrial control all-in-one machine according to the preset emergency plan.
[0013] In a possible implementation, the industrial control all-in-one machine anomaly detection method for multimodal data fusion also performs the following processing: constructing a three-dimensional model of the industrial control all-in-one machine, and rendering the historical anomaly location and the historical anomaly type to the three-dimensional model to obtain an anomaly visualization model; and performing network anomaly visualization management of the industrial control all-in-one machine based on the anomaly visualization model.
[0014] The present application also provides an industrial control all-in-one machine anomaly detection system for multimodal data fusion, the system comprising: a feature dynamic collection module, for dynamically collecting multi-source network features of the industrial control all-in-one machine in operation to obtain a real-time multimodal network data set; a feature extraction and analysis module, for performing feature extraction and analysis on the multimodal network data set according to a feature extraction plan to obtain a real-time network feature set; a feature vector comparison module, for comparing a real-time feature vector constructed based on the real-time network feature set with a predetermined feature vector to obtain a real-time deviation coefficient; a network anomaly warning module, for issuing a network warning signal if the real-time deviation coefficient exceeds a predetermined deviation coefficient limit, and performing a network anomaly warning on the industrial control all-in-one machine based on the network warning signal.
[0015] The proposed method and system for detecting anomalies in industrial control all-in-one machines for multimodal data fusion in this application aims to dynamically collect multi-source network features of the industrial control all-in-one machines in operation to obtain a real-time multimodal network data set; perform feature extraction and analysis according to the feature extraction plan to obtain a real-time network feature set; compare the real-time feature vector constructed based on the real-time network feature set with the predetermined feature vector; if the real-time deviation coefficient exceeds the predetermined deviation coefficient limit, issue a network warning signal, and issue a network anomaly warning for the industrial control all-in-one machine based on the network warning signal. This solves the technical problems in the prior art of difficulty in fully capturing abnormal behavior, resulting in the risk of missed detection and false alarms in anomaly detection of industrial control all-in-one machines, and poor detection real-time performance and accuracy, thereby achieving the technical effect of reducing the missed detection rate of anomalies in industrial control all-in-one machines, and improving the accuracy, timeliness, and operational reliability of anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings of the embodiments of the present disclosure are briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in precise order. Instead, various steps may be processed in reverse order or simultaneously as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0017] Figure 1 A flow chart of the anomaly detection method for an industrial control all-in-one machine for multimodal data fusion provided in an embodiment of the present application.
[0018] Figure 2 A schematic diagram of the structure of an anomaly detection system for an industrial control all-in-one machine for multimodal data fusion provided in an embodiment of the present application.
[0019] Description of the accompanying drawings: dynamic feature collection module 10, feature extraction and analysis module 20, feature vector comparison module 30, network anomaly warning module 40. DETAILED DESCRIPTION
[0020] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.
[0021] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0022] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict, and the terms “first\second” involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. The terms “including” and “having” and any variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used herein are for the purpose of describing the embodiments of this application only.
[0023] The present application embodiment provides an industrial control machine anomaly detection method for multimodal data fusion, such as Figure 1 As shown, the method includes: Step S100 : Dynamically collect multi-source network features of the operating industrial control all-in-one computer to obtain a real-time multimodal network dataset.
[0024] Step S100 further includes step S110, forming a network modality set of the industrial control all-in-one machine, wherein the network modality set includes network equipment, network communication and network lines; step S120, dynamically collecting the network equipment, the network communication and the network lines in turn to obtain a device data set, a communication data set and a line data set respectively; step S130, the device data set, the communication data set and the line data set constitute the real-time multimodal network data set.
[0025] Preferably, the network modality set of the industrial control all-in-one computer is formed according to network equipment, network communication and network lines, wherein the network equipment is the basic hardware unit of the industrial control all-in-one computer, such as switches, routers, network cards, etc., which are used for tasks such as data reception, processing, and forwarding; network communication focuses on the data transmission process and method in the network, including communication protocols (such as TCP / IP, UDP), data transmission rate, data packet sending and receiving, etc.; network lines are physical channels for data transmission, whether they are wired lines (such as optical fibers, network cables) or wireless lines (such as Wi-Fi, Bluetooth), their status directly affects the stability and integrity of data transmission.
[0026] Preferably, network devices, network communications, and network lines are dynamically collected in sequence. Specifically, for network devices, various operating parameters of the devices are collected in real time through deployed sensors, monitoring software, etc., thereby obtaining a device data set, including the device's CPU usage, memory usage, temperature, fan speed, etc., wherein a high CPU usage indicates that the device is overloaded, and a sustained high temperature may indicate a failure in the cooling system, reflecting the operating status of the network device from multiple dimensions; for network communications, data transmitted in the network is monitored and analyzed in real time through network packet capture tools, traffic monitoring software, etc., thereby obtaining a communication data set. For example, the network traffic size in different time periods is monitored to determine whether there is an abnormal surge in traffic, which may be a signal of a network attack or abnormal data transmission. At the same time, indicators such as data packet transmission delay and packet loss rate are analyzed. Excessive delay or frequent packet loss indicates a problem with network communication; for network lines, line detection instruments, signal monitoring equipment, etc. are used to obtain line physical status information in real time to form a line data set. For example, whether the wired line is broken or short-circuited, and the signal strength and interference of the wireless line are detected, intuitively reflecting whether the line is working properly.
[0027] Preferably, the device data set, communication data set and line data set are combined to form a real-time multimodal network data set. The real-time multimodal network data set can comprehensively and three-dimensionally present the operating status of the industrial control all-in-one machine network system, and thus can more accurately detect network anomalies of the industrial control all-in-one machine, thereby ensuring the stable operation of the industrial control all-in-one machine.
[0028] Step S200 , performing feature extraction and analysis on the multimodal network dataset according to a feature extraction plan to obtain a real-time network feature set.
[0029] Step S200 further includes step S210, extracting the multimodal feature indicators stored in the memory of the feature extraction plan, wherein the multimodal feature indicators include device indicators, communication indicators and line indicators; step S220, performing feature extraction on the device data set, the communication data set and the line data set based on the device indicators, the communication indicators and the line indicators in sequence, to obtain a device feature set, a communication feature set and a line feature set respectively; step S230, the device feature set, the communication feature set and the line feature set constitute the real-time network feature set; wherein the device indicators include at least a CPU utilization indicator, a memory occupancy indicator and a network interface status indicator, the communication indicators include at least a data frame content indicator, a data frame format and a data frame transmission protocol, and the line indicators include at least an electrical characteristic indicator, a topology structure indicator and an interference signal indicator.
[0030] Preferably, memory is a key component for data storage and processing, and its status directly affects the performance and stability of the device. From a multimodal perspective, a feature extraction plan is used to analyze the multimodal feature indicators of the memory to accurately detect memory-related anomalies. The multimodal feature indicators include device indicators (evaluating hardware operating status), communication indicators (evaluating data transmission characteristics), and line indicators (evaluating physical layer and environmental impacts). Specifically, the device indicators include at least CPU utilization indicators, memory occupancy indicators, and network interface status indicators. CPU utilization refers to the proportion of memory call tasks processed by the CPU per unit time. It is obtained through the performance monitoring interface of the industrial control all-in-one computer operating system and reflects the efficiency of the collaborative work between the memory and the CPU. The memory occupancy indicator refers to the proportion of currently used memory capacity to total capacity (such as dynamically monitoring the used space of DRAM / SSD). It is obtained through the memory management unit (MMU) and directly reflects the real-time consumption of memory resources. The network interface status indicator refers to the data interaction status between the memory and the network interface (such as the network card), including the receive / send queue length, buffer hit rate, etc. It is obtained through the network adapter driver log or monitoring tools (such as ethtool) and reflects the memory's caching and processing capabilities for network data.
[0031] Preferably, the communication indicators include at least data frame content indicators, data frame formats, and data frame transmission protocols. Specifically, data frame content indicators refer to the network data frame payload characteristics cached in the memory, such as Modbus protocol register addresses, message body keywords, etc., and the real-time communication data in the memory is parsed through deep packet inspection technology to extract business layer protocol characteristics; data frame format indicators refer to the protocol format compliance of the data frame, such as the MAC address validity of the Ethernet frame, the IP header checksum correctness, etc., which are obtained based on the binary parsing of the original data frame in the memory and compared with the standard protocol format template; data frame transmission protocol indicators refer to the proportion of protocol types processed in the memory (such as the traffic ratio of TCP / UDP / ICMP) and protocol version compatibility (such as TLS 1.2), which are obtained by statistically analyzing the protocol distribution in the memory through the protocol identification engine and connecting to the whitelist strategy of the industrial control system.
[0032] Preferably, the line indicators include at least electrical characteristic indicators, topology indicators, and interference signal indicators. Specifically, the electrical characteristic indicators refer to the electrical parameters of the memory module, such as the power supply voltage (DDR4 standard voltage 1.2V±5%), clock frequency stability, signal-to-noise ratio (SNR), etc., which are read through the motherboard sensor or the memory SPD (serial presence detect) chip to reflect the electrical health status of the memory hardware; the topology indicators refer to the connection path characteristics between the memory and other hardware (such as the CPU, south bridge chip, switch), such as the PCIe bus bandwidth and the number of memory channels (single channel / dual channel), which are obtained through the system hardware configuration file or firmware information (such as the UEFI log), reflecting the data flow efficiency of the memory in the industrial network topology; the interference signal indicators refer to the electromagnetic interference intensity (such as radio frequency interference RF, power ripple) and electrostatic discharge (ESD) event count of the memory area, which are collected through electromagnetic sensors or hardware monitoring chips deployed in the industrial control chassis to reflect the physical impact of the industrial environment on the memory.
[0033] Preferably, feature extraction is performed on the device dataset, communication dataset, and line dataset based on device indicators, communication indicators, and line indicators, respectively, to obtain device feature sets, communication feature sets, and line feature sets, respectively. Specifically, device indicators are used to extract features from memory hardware operating data to identify memory hardware aging (e.g., continuously rising temperatures) or operating system resource scheduling anomalies (e.g., high memory usage due to memory fragmentation). Examples include timing features (10-minute moving averages of CPU utilization and memory usage, and peak frequency), correlation features (Pearson correlation coefficients between memory usage and network interface queue length), and health features (memory module temperature curves, and trends in ECC error corrections). Communication indicators are used to extract features from memory communication data to detect communication attacks (e.g., buffer overflow attacks resulting in abnormal data frame formats) or protocol abuse (e.g., relaying unauthorized protocols through memory). Examples include protocol features (e.g., Modbus TCP frame ratio, number of occurrences of abnormal protocol fields), traffic features (fluctuation of real-time traffic cached in memory, and protocol type distribution of burst traffic), and security features (whether unencrypted sensitive data, such as device authentication keys, is present in memory).
[0034] Preferably, line metrics are used to extract features from the physical environment data associated with the memory to locate physical layer faults (e.g., voltage fluctuations caused by poor line contact) or memory errors caused by environmental interference (e.g., signal distortion caused by high-frequency devices). For example, these features include electrical features (the mean square error of the memory supply voltage, clock signal jitter amplitude), topological features (the number of path hops between the memory and the switch, and the data transmission delay quantile, such as 95th percentile delay > 5ms), and environmental features (daily variations in electromagnetic interference intensity, and the correlation between electrostatic events and production processes, such as a surge in interference during welding operations). Finally, the device feature set, communication feature set, and line feature set are combined to form a real-time network feature set, enabling cross-layer correlation analysis. For example, by combining memory utilization (device metric) with data frame transmission protocol (communication metric), it can be determined whether high memory utilization is caused by abnormal protocol traffic (e.g., DDoS attacks). By aligning electrical characteristic anomalies (line metrics) with memory error logs (device metrics) in time and space, the root cause of hardware failures (e.g., memory slot oxidation) or environmental interference (e.g., poor grounding) can be quickly determined, while ensuring the accuracy of anomaly detection.
[0035] Step S300 : comparing the real-time feature vector constructed based on the real-time network feature set with a predetermined feature vector to obtain a real-time deviation coefficient.
[0036] Step S300 further includes step S310, dividing the real-time network feature set to obtain a division result, wherein the division result includes a first-level feature set and a second-level feature set; step S320, screening and analyzing the real-time feature vector and the predetermined feature vector with the first-level feature set as a constraint, and obtaining a real-time first-level vector and a predetermined first-level vector respectively; step S330, comparing the real-time first-level vector with the predetermined first-level vector to obtain a first-level deviation coefficient; step S340, screening and analyzing the real-time feature vector and the predetermined feature vector with the second-level feature set as a constraint, and obtaining a real-time second-level vector and a predetermined second-level vector respectively; step S350, comparing the real-time second-level vector with the predetermined second-level vector to obtain a second-level deviation coefficient; step S360, obtaining a predetermined level weight distribution, and weighting the first-level deviation coefficient and the second-level deviation coefficient according to the predetermined level weight distribution to obtain the real-time deviation coefficient.
[0037] Preferably, constructing a real-time feature vector based on a real-time network feature set is to extract various features from multimodal network data and express them in a structured vector form for quantitatively describing the current operating status of the device. Each feature value corresponds to a specific indicator in the real-time network feature set, such as CPU utilization, data frame transmission rate, line voltage, etc. Specifically, the extracted features of the network equipment, network communication and network lines in the real-time network feature set are normalized (such as unifying units and scaling numerical ranges) to avoid the influence of dimensional differences on subsequent calculations (for example, CPU utilization is a percentage, and line voltage is volts, which need to be converted into dimensionless standardized values); all feature values are arranged into a vector in a fixed order, where each position corresponds to a feature dimension, which is usually pre-defined according to a feature extraction plan (such as device indicators first, communication indicators second, and line indicators last), thereby obtaining a real-time feature vector that fully reflects the full-link operating status of the industrial control all-in-one machine (from device hardware to communication process to physical lines). By comparing with a predetermined feature vector (a standard vector under normal conditions), a real-time deviation coefficient can be calculated to determine the degree of difference between the current state and the ideal state.
[0038] Preferably, the real-time network feature set is divided according to the importance and correlation of the features to obtain a first-level feature set and a second-level feature set, wherein the first-level feature set contains key features that have a greater impact on the operating status of the industrial control all-in-one machine and can directly reflect whether the core functions of the equipment are normal, such as CPU utilization, memory occupancy, transmission status of key communication protocols, etc.; the second-level feature set contains relatively minor features that also have an impact on the operating status of the equipment, such as traffic fluctuations of non-critical network interfaces, data frame format details of secondary communication protocols, etc., which can assist in judging the potential risks of equipment operation.
[0039] Preferably, the real-time feature vector and the predetermined feature vector are screened and analyzed with the first-level feature set as the constraint condition, wherein the predetermined feature vector is a standard feature vector obtained through a large number of tests and statistics under the normal operating state of the industrial control all-in-one machine, representing the ideal state of the equipment during normal operation. Specifically, the features contained in the first-level feature set are extracted from the real-time feature vector and the predetermined feature vector to form a real-time first-level vector and a predetermined first-level vector, respectively, which are used to compare the key indicators of the current operation of the equipment with the normal state; similarly, with the second-level feature set as the constraint, the features corresponding to the second-level feature set are screened from the real-time feature vector and the predetermined feature vector to form a real-time second-level vector and a predetermined second-level vector, which are used to analyze the deviation of the secondary features of the equipment operation from the normal state.
[0040] Preferably, the real-time first-level vector is compared with the predetermined first-level vector, and the degree of difference is calculated to obtain a first-level deviation coefficient, which reflects the degree of deviation of the key features of the device from the normal state. The larger the coefficient, the higher the possibility of abnormality of the key functions of the device. Similarly, the real-time second-level vector is compared with the predetermined second-level vector to obtain a second-level deviation coefficient, which reflects the deviation of the secondary features of the device. Then, a predetermined level weight distribution is obtained, and the first-level deviation coefficient and the second-level deviation coefficient are weighted according to the predetermined level weight distribution. The first-level feature set and the second-level feature set have different degrees of influence on the operating state of the device, and the predetermined level weight is different. Therefore, the weight ratio is pre-set according to the importance of the feature set as the predetermined level weight. For example, the weight of the first-level feature set may be set to 0.7, and the weight of the second-level feature set may be set to 0.3. Then, according to the predetermined weight distribution, the first-level deviation coefficient and the second-level deviation coefficient are weighted and calculated, and the two are merged according to the weight ratio to finally obtain the real-time deviation coefficient. By comprehensively considering the deviation of the key features and secondary features of the device, it can more comprehensively and accurately reflect the degree of difference between the current operating state of the industrial control all-in-one machine and the normal state, thereby facilitating more accurate network anomaly warning and device status assessment.
[0041] Furthermore, step S330 also includes step S331, obtaining any feature in the first-level feature set; step S332, matching the real-time first-level vector with the predetermined first-level vector to obtain any real-time feature parameter and any predetermined feature parameter corresponding to the arbitrary feature; step S333, taking the difference between the arbitrary real-time feature parameter and the arbitrary predetermined feature parameter, recorded as an arbitrary deviation value; step S334, taking the first deviation value in the first-level feature deviation value sequence obtained by descending the arbitrary deviation value, and normalizing it as the first-level deviation coefficient.
[0042] Preferably, the first-level feature set of the industrial control all-in-one machine includes multiple key features such as CPU utilization and memory occupancy, and one of them is selected as an arbitrary feature. Then, the feature parameters of the real-time first-level vector and the predetermined first-level vector are matched according to the arbitrary feature, and the arbitrary real-time feature parameters and arbitrary predetermined feature parameters corresponding to the arbitrary feature are obtained. Then, the difference between the arbitrary real-time feature parameters and the arbitrary predetermined feature parameters is calculated and recorded as the arbitrary deviation value; then the first deviation value in the first-level feature deviation value sequence obtained by taking the descending arbitrary deviation value is normalized as the first-level deviation coefficient. For example, select a first-level feature (such as memory usage) and match the corresponding parameter values (real-time value 92% and predetermined standard value 70%) from the real-time first-level vector with the predetermined first-level vector. Then, calculate the deviation value = real-time value - predetermined standard value = 92% - 70% = +22%. A positive value indicates that the real-time value is higher than the standard value, and a negative value indicates that it is lower than the standard value. The larger the absolute value of the deviation, the more significant the deviation of the feature from the normal state. Then, calculate the deviation value for each other key features (such as memory and communication latency) to obtain a set of deviation values (for example, CPU deviation +25%, memory deviation +22%, communication delay deviation +5ms, etc.). Arrange the deviation values in descending order from largest to smallest to form a deviation value sequence. The first deviation in the deviation sequence (the one with the largest absolute value) is taken as the most significant abnormal feature deviation. Finally, normalize the deviation value. For example, divide the first deviation value by the warning threshold of the feature (a pre-set safety boundary, such as the warning threshold of CPU utilization is 80%) to obtain the first-level deviation coefficient: 25% ÷ 80% = 0.3125, indicating that the current CPU utilization deviates from the normal state by 31.25%.
[0043] Step S400: If the real-time deviation coefficient exceeds a predetermined deviation coefficient limit, a network warning signal is issued, and a network abnormality warning is issued to the industrial control all-in-one computer according to the network warning signal.
[0044] Preferably, the comprehensive deviation degree of real-time network characteristics (real-time deviation coefficient) is compared with the safety threshold (predetermined deviation coefficient limit). When the deviation exceeds the safety range, an early warning is automatically triggered to remind operation and maintenance personnel to intervene and handle the problem, so as to avoid production interruption or equipment failure due to network abnormalities. The predetermined deviation coefficient limit is a standard value set according to industrial control requirements, which represents the maximum acceptable deviation degree. For example, it may be set to 0.2 to 0.3 (more sensitive to deviation) in precision control scenarios (such as medical equipment and aerospace), and it may be set to 0.5 to 0.7 (allowing a certain degree of fluctuation) in ordinary scenarios (such as assembly line monitoring); then the real-time deviation coefficient is compared with the predetermined deviation coefficient limit. If the real-time deviation coefficient does not exceed the predetermined deviation coefficient limit, it means that the network status is within the safe range, no early warning is issued, and real-time monitoring continues.
[0045] Preferably, if the real-time deviation coefficient exceeds the predetermined deviation coefficient limit, it indicates that the network status has exceeded the safe range, and a network warning signal is issued, such as an alarm through system logs, indicator lights, pop-up windows, etc., and the operation and maintenance personnel are notified or an emergency plan is automatically triggered, such as switching to a backup network and reducing the equipment operating load. The network abnormality warning content includes the warning object (the industrial control all-in-one computer itself and its connected network components, such as switches, sensors, actuators, etc.), the abnormality type (such as "device layer CPU overload", "communication layer data frame format abnormality", "line layer electromagnetic interference exceeds the standard", etc.), the degree of deviation (such as "the current deviation coefficient is 0.72, exceeding the limit of 0.5"), the scope of impact (such as "may cause data transmission delays, affecting production line synchronization") and recommended operations (such as "check the source of CPU load", "check communication line protocol compatibility", "install line anti-interference filters"), thereby ensuring the operational stability and reliability of the industrial control all-in-one computer.
[0046] Furthermore, step S400 also includes step S410, judging whether the arbitrary deviation value exceeds any predetermined threshold of the arbitrary feature based on the network warning signal; step S420, if it exceeds, matching the mode corresponding to the arbitrary feature as an abnormal mode, and performing emergency processing on the abnormal mode.
[0047] Preferably, when the real-time deviation coefficient exceeds a preset limit (indicating that the network status is abnormal), for any feature in the first-level feature set (such as CPU utilization in the device indicator, data frame format in the communication indicator, etc.), compare its real-time feature parameters (current actual measurement values) with predetermined feature parameters (standard values or threshold ranges under normal conditions), and then find out which specific features have exceeded the normal range in actual value, and determine the specific source of the abnormality; then match the mode corresponding to the abnormal feature, that is, when the deviation value of any feature exceeds the predetermined threshold, determine the abnormal mode according to the mode category to which it belongs (device / communication / line), including device mode, communication mode and line mode. For example, if the deviation value of "CPU utilization" exceeds the standard, the abnormal mode is determined to be device; if the "data frame transmission protocol error rate" exceeds the standard, the abnormal mode is determined to be communication; if the "line interference signal strength" exceeds the standard, the abnormal mode is determined to be line.
[0048] Preferably, emergency processing is finally performed on the abnormal mode. If the device mode is abnormal, check the hardware status of the industrial control all-in-one computer (for example, if the CPU load is too high, you may need to restart the device, clean up the process, or upgrade the hardware); monitor the device log to check for software conflicts or program abnormalities. If the communication mode is abnormal, analyze whether the communication protocol matches (for example, if the protocol version is incompatible) and reconfigure the protocol parameters; check whether there are errors in the data frame content (such as verification failures) and check for data interference or transmission errors in the communication link. If the line mode is abnormal, detect the electrical characteristics of the physical line (such as whether the voltage and impedance are normal), repair or replace the faulty cable; check for electromagnetic interference sources around the line (such as high-voltage equipment), adjust the line layout, or add anti-interference measures. By locating the abnormal mode, "precise handling" is achieved, improving the fault handling efficiency of the industrial control all-in-one computer.
[0049] Furthermore, step S410 further includes, if it does not exceed, performing a traversal analysis on the features in the first-level feature set and determining the abnormal mode.
[0050] Preferably, if the real-time deviation coefficient has exceeded the limit, but any deviation value has not exceeded any predetermined threshold, the features in the first-level feature set are traversed and analyzed to check whether there is a cumulative deviation of multiple features. Specifically, all features in the first-level feature set are checked one by one (such as CPU and memory of the device class, transmission rate and packet loss rate of the communication class, etc.), and the deviation value of each feature (the difference between the real-time parameter and the predetermined parameter) is calculated, that is, the deviation value of each feature is recorded, regardless of whether it exceeds the threshold, and the trend of the deviation value (such as continuous small fluctuations, intermittent mutations) and correlation (such as multiple features having the same direction deviation at the same time) are analyzed. Through global This perspective can detect combined deviations or potential anomalies. Deviations between multiple features within a device's modality may not exceed the specified threshold, but may show systematic trends. For example, the deviations for CPU utilization, memory usage, and hard drive read / write rates may not exceed the threshold, but may continue to approach the upper threshold (e.g., reaching 90% of the normal range). This could indicate an impending device overload and represent a device modality anomaly. The deviation of a single feature may not exceed the specified threshold, but may trigger a chain reaction. For example, within the communication mode, the checksum error rate of a secondary protocol may occasionally increase (below the threshold), indirectly increasing the data retransmission rate of the primary protocol. This could be traced to a communication protocol compatibility issue and classified as a communication modality anomaly. Based on the analysis results, the abnormal modality can be precisely located to avoid missed faults due to "indicators not exceeding the specified threshold," ensuring comprehensive and accurate responses to network anomalies.
[0051] Furthermore, step S400 also includes step S430, matching the abnormal feature set corresponding to the abnormal mode in the real-time network feature set; step S440, performing over-limit screening on the abnormal feature set to obtain a target feature set; step S450, traversing the target feature set in the abnormal database of the abnormal mode to obtain a historical abnormal data set; step S460, matching the preset emergency plan based on the historical abnormal location and historical abnormal type in the historical abnormal data set; step S470, performing network abnormality emergency processing on the industrial control all-in-one machine according to the preset emergency plan.
[0052] Preferably, features corresponding to abnormal modalities are matched from the real-time network feature set to form the abnormal feature set. Specifically, if the abnormal modality is equipment, device-related features such as CPU utilization, memory usage, hard disk read / write rates, and sensor data are extracted. If the abnormal modality is communication, communication-related features such as data transmission rate, latency, packet loss rate, and protocol error rate are extracted. If the abnormal modality is line, line-related features such as line impedance, signal attenuation, and physical connection status are extracted. Each feature in the abnormal feature set is then checked again to see if its deviation exceeds a predetermined threshold (which may be an absolute value threshold or a rate of change threshold). Features with exceeding deviation values are retained. For example, exceeding-limit features in the equipment modality may include "CPU utilization exceeding limit" and "memory usage exceeding limit."
[0053] Preferably, the target feature set is traversed in the anomaly database of abnormal modes, wherein the anomaly database pre-stores historical abnormal cases related to abnormal modes (such as equipment, communication, and lines), and each case contains a feature combination that triggers the anomaly (such as "CPU + memory exceeds the limit at the same time"), the specific environment when the anomaly occurs (such as load peak, temperature mutation), the anomaly type (such as hardware failure, software crash, configuration error) and historical positioning results (such as specific faulty components, communication nodes, and line sections). Specifically, the current target feature set is compared with the historical cases in the database, and historical records with highly similar feature combinations are screened to form a historical anomaly data set. For example, if there is a record of "CPU utilization rate > 85% and memory occupancy rate > 90%" in the historical database, which is marked as "device overload", then the case is matched; then the historical anomaly location is extracted from the historical anomaly data set, that is, the specific location where the fault occurred, such as the motherboard of a certain device, the switch of a certain communication link, or a certain physical line; the historical anomaly type, such as hardware failure, software vulnerability, and external interference.
[0054] Preferably, the preset emergency plan includes processing solutions pre-developed for different abnormal locations and types. For example, if the historical case shows "device overload" (software process out of control), the emergency plan may be "terminating the abnormal process, releasing memory, and turning on hardware cooling"; if it shows "communication link congestion" (traffic burst), the emergency plan may be "enabling bandwidth speed limit, switching to backup link, and triggering traffic cleaning"; if it shows "poor line contact" (type: physical failure), the emergency plan may be "automatically reconnecting, switching to redundant lines, and sending manual maintenance work orders"; then, based on the extracted historical abnormal location and historical abnormality type, the preset emergency plan is matched, that is, based on the similarity of historical cases, the plan with the highest matching degree is called first, or multiple plans are combined to handle equipment and communication abnormalities at the same time.
[0055] Preferably, the IPC is finally handled according to a pre-set emergency plan. For example, if the device mode is abnormal, non-critical business processes are shut down to reduce CPU / memory load; the device self-test program is triggered to locate hardware faults (such as fan stalling or hard drive bad sectors); and an alarm message containing the abnormality location is sent to the operation and maintenance personnel (such as "the IPC motherboard temperature sensor is abnormal"). If the communication mode is abnormal, switch to an alternative communication protocol (such as switching from TCP to UDP); enable data compression to reduce transmission traffic; disconnect the abnormal connection and renegotiate communication parameters (such as IP address and port). If the line mode is abnormal, automatically switch to a redundant line (such as activating a backup optical fiber when the main line fails); send a pulse signal to detect the location of the line breakpoint; generate a line maintenance work order and push it to the operation and maintenance personnel. Through automated operations, the spread of abnormalities is quickly handled, ensuring the operational stability and reliability of the IPC.
[0056] Furthermore, step S460 also includes step S461, constructing a three-dimensional model of the industrial control all-in-one machine, and rendering the historical anomaly location and the historical anomaly type to the three-dimensional model to obtain an anomaly visualization model; step S462, performing network anomaly visualization management of the industrial control all-in-one machine according to the anomaly visualization model.
[0057] Preferably, CAD software (such as SolidWorks) and three-dimensional scanning are used to digitally model the industrial control all-in-one machine and its associated network components (such as switches, sensors, communication lines, etc.) to restore their physical form, internal structure and network connection relationship, wherein the external form includes chassis size, interface position, indicator light status, etc., the internal structure shows the installation position of hardware such as the motherboard layout, CPU, memory, and hard disk, and the network topology represents the connection path with other devices (such as connecting to a switch via a network cable and connecting to a remote server via an optical fiber); historical abnormality data (such as the location and type of the abnormality) is bound to specific components or connection nodes in the three-dimensional model, and the abnormality information is intuitively displayed through visual rendering, including highlighting the physical component where the abnormality occurs in the three-dimensional model (such as the CPU module turns red, the fault line flashes), marking the specific location where the abnormality occurs (such as "motherboard memory slot No. 3" and "switch port GE1"), and using different colors or icons to distinguish the abnormality type, and finally obtaining an abnormality visualization model to support users to observe the device status from different perspectives (such as front view, internal perspective, and topology view).
[0058] Preferably, network anomalies of the industrial control all-in-one computer are visualized and managed based on the anomaly visualization model, including anomaly location and troubleshooting. Operation and maintenance personnel can directly locate abnormal components or links through the three-dimensional model. For example, the motherboard memory slot is highlighted in red, and a "memory module failure" can be quickly determined. It also includes historical anomaly trend analysis, counting the frequency of anomalies in different areas in the three-dimensional model (such as using a heat map to display high-temperature hotspots in the equipment chassis), or generating anomaly distribution reports by type (such as "device layer anomalies account for 60%, communication layer accounts for 30%"); the anomaly visualization model can also be accessed through a web browser or mobile APP, supporting remote operation and maintenance teams to view the status of on-site equipment in real time (such as remote engineers using models to guide on-site personnel to replace faulty modules), thereby improving the operation and maintenance efficiency and operational reliability of the industrial control all-in-one computer.
[0059] In the above, refer to Figure 1 The anomaly detection method for an industrial control integrated machine for multimodal data fusion according to an embodiment of the present invention is described in detail. Figure 2 An industrial control machine anomaly detection system for multimodal data fusion according to an embodiment of the present invention is described.
[0060] The industrial control all-in-one machine anomaly detection system for multimodal data fusion according to the embodiment of the present invention is used to solve the technical problems existing in the prior art that it is difficult to fully capture abnormal behaviors, resulting in the risk of missed detection and false alarms in the industrial control all-in-one machine anomaly detection, and poor real-time detection and accuracy. It achieves the technical effect of reducing the missed alarm rate of industrial control all-in-one machine anomalies, improving the accuracy, timeliness and operational reliability of anomaly detection. Figure 2As shown, the industrial control all-in-one machine anomaly detection system for multimodal data fusion includes: a feature dynamic collection module 10, a feature extraction and analysis module 20, a feature vector comparison module 30, and a network anomaly warning module 40.
[0061] The feature dynamic collection module 10 is used to dynamically collect multi-source network features of the industrial control integrated machine in operation to obtain a real-time multimodal network data set; the feature extraction and analysis module 20 is used to perform feature extraction and analysis on the multimodal network data set according to the feature extraction plan to obtain a real-time network feature set; the feature vector comparison module 30 is used to compare the real-time feature vector constructed based on the real-time network feature set with the predetermined feature vector to obtain a real-time deviation coefficient; the network anomaly warning module 40 is used to issue a network warning signal if the real-time deviation coefficient exceeds the predetermined deviation coefficient limit, and to issue a network anomaly warning to the industrial control integrated machine based on the network warning signal.
[0062] The specific configuration of the dynamic feature collection module 10 will be described in detail below. The dynamic feature collection module 10 further includes: establishing a network modality set for the industrial control all-in-one machine, wherein the network modality set includes network devices, network communications, and network lines; dynamically collecting the network devices, network communications, and network lines in sequence to obtain a device dataset, a communication dataset, and a line dataset, respectively; and the device dataset, the communication dataset, and the line dataset constitute the real-time multimodal network dataset.
[0063] The specific configuration of the feature extraction and analysis module 20 will be described in detail below. The feature extraction and analysis module 20 further includes: extracting multimodal feature indicators stored in the feature extraction plan, wherein the multimodal feature indicators include device indicators, communication indicators, and line indicators; performing feature extraction on the device dataset, the communication dataset, and the line dataset based on the device indicators, the communication indicators, and the line indicators, respectively, to obtain a device feature set, a communication feature set, and a line feature set; the device feature set, the communication feature set, and the line feature set constitute the real-time network feature set; wherein the device indicators include at least a CPU utilization indicator, a memory occupancy indicator, and a network interface status indicator; the communication indicators include at least a data frame content indicator, a data frame format, and a data frame transmission protocol; and the line indicators include at least an electrical characteristic indicator, a topology structure indicator, and an interference signal indicator.
[0064] The specific configuration of the feature vector comparison module 30 will be described in detail below. The feature vector comparison module 30 further includes: dividing the real-time network feature set to obtain a division result, wherein the division result includes a primary feature set and a secondary feature set; screening and analyzing the real-time feature vector and the predetermined feature vector with the primary feature set as a constraint to obtain a real-time primary vector and a predetermined primary vector respectively; comparing the real-time primary vector with the predetermined primary vector to obtain a primary deviation coefficient; screening and analyzing the real-time feature vector and the predetermined feature vector with the secondary feature set as a constraint to obtain a real-time secondary vector and a predetermined secondary vector respectively; comparing the real-time secondary vector with the predetermined secondary vector to obtain a secondary deviation coefficient; obtaining a predetermined level weight distribution, and weighting the primary deviation coefficient and the secondary deviation coefficient according to the predetermined level weight distribution to obtain the real-time deviation coefficient.
[0065] The specific configuration of the feature vector comparison module 30 will be described in detail below. The feature vector comparison module 30 further includes: obtaining any feature from the first-level feature set; matching the real-time first-level vector with the predetermined first-level vector to obtain any real-time feature parameter and any predetermined feature parameter corresponding to the arbitrary feature; taking the difference between the arbitrary real-time feature parameter and the arbitrary predetermined feature parameter, recording it as an arbitrary deviation value; and taking the first deviation value in the first-level feature deviation value sequence obtained by descending the arbitrary deviation values, and normalizing it as the first-level deviation coefficient.
[0066] The specific configuration of the network anomaly warning module 40 will be described in detail below. The network anomaly warning module 40 further includes: determining, based on the network warning signal, whether the arbitrary deviation value exceeds any predetermined threshold of the arbitrary feature; if so, matching the mode corresponding to the arbitrary feature as an abnormal mode, and performing emergency processing on the abnormal mode.
[0067] The specific configuration of the network anomaly warning module 40 will be described in detail below. The network anomaly warning module 40 further includes: if it does not exceed, performing traversal analysis on the features in the first-level feature set and determining the abnormal mode.
[0068] The specific configuration of the network anomaly warning module 40 will be described in detail below. The network anomaly warning module 40 further includes: matching the abnormal feature set corresponding to the abnormal modality in the real-time network feature set; performing over-limit screening on the abnormal feature set to obtain a target feature set; traversing the target feature set in the abnormal database of the abnormal modality to obtain a historical anomaly data set; matching a preset emergency plan based on the historical anomaly location and historical anomaly type in the historical anomaly data set; and performing network anomaly emergency processing on the industrial control integrated machine according to the preset emergency plan.
[0069] The specific configuration of the network anomaly warning module 40 will be described in detail below. The network anomaly warning module 40 further includes: constructing a three-dimensional model of the industrial control machine, rendering the historical anomaly locations and types into the three-dimensional model to obtain an anomaly visualization model; and performing network anomaly visualization management of the industrial control machine based on the anomaly visualization model.
[0070] The industrial control all-in-one machine anomaly detection system for multimodal data fusion provided in an embodiment of the present invention can execute the industrial control all-in-one machine anomaly detection method for multimodal data fusion provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0071] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules may be used and run on the user terminal and / or server, and the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other and are not used to limit the scope of protection of the present invention.
[0072] The above specific embodiments do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the scope of protection of this application.
Claims
1. The method for detecting abnormalities of an industrial control integrated machine based on multimodal data fusion is characterized by: include: Dynamically collect multi-source network features of the industrial control integrated machine in operation to obtain a real-time multimodal network dataset; Performing feature extraction and analysis on the multimodal network dataset according to a feature extraction plan to obtain a real-time network feature set; Comparing a real-time feature vector constructed based on the real-time network feature set with a predetermined feature vector to obtain a real-time deviation coefficient; If the real-time deviation coefficient exceeds a predetermined deviation coefficient limit, a network warning signal is issued, and a network abnormality warning is issued to the industrial control all-in-one computer according to the network warning signal.
2. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion according to claim 1, wherein: Dynamically collect multi-source network features of the industrial control integrated machine in operation to obtain a real-time multimodal network dataset, including: Establishing a network modality set of the industrial control all-in-one machine, wherein the network modality set includes network equipment, network communication, and network lines; Dynamically collecting the network devices, the network communications, and the network lines in sequence to obtain a device data set, a communication data set, and a line data set, respectively; The device dataset, the communication dataset and the line dataset constitute the real-time multimodal network dataset.
3. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion as claimed in claim 2, characterized in that: Perform feature extraction and analysis on the multimodal network dataset according to the feature extraction plan to obtain a real-time network feature set, including: Extracting multimodal feature indicators stored in the feature extraction plan, wherein the multimodal feature indicators include device indicators, communication indicators, and line indicators; performing feature extraction on the device dataset, the communication dataset, and the line dataset based on the device index, the communication index, and the line index in sequence to obtain a device feature set, a communication feature set, and a line feature set, respectively; The device feature set, the communication feature set and the line feature set constitute the real-time network feature set; Among them, the equipment indicators include at least CPU utilization indicators, memory occupancy indicators, and network interface status indicators; the communication indicators include at least data frame content indicators, data frame formats, and data frame transmission protocols; and the line indicators include at least electrical characteristics indicators, topology structure indicators, and interference signal indicators.
4. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion according to claim 1, wherein: Comparing a real-time feature vector constructed based on the real-time network feature set with a predetermined feature vector to obtain a real-time deviation coefficient includes: Dividing the real-time network feature set to obtain a division result, wherein the division result includes a primary feature set and a secondary feature set; screening and analyzing the real-time feature vector and the predetermined feature vector using the first-level feature set as a constraint to obtain a real-time first-level vector and a predetermined first-level vector respectively; Comparing the real-time first-order vector with the predetermined first-order vector to obtain a first-order deviation coefficient; The real-time feature vector and the predetermined feature vector are screened and analyzed with the secondary feature set as a constraint to obtain a real-time secondary vector and a predetermined secondary vector respectively; Comparing the real-time secondary vector with the predetermined secondary vector to obtain a secondary deviation coefficient; A predetermined level weight distribution is obtained, and the first-level deviation coefficient and the second-level deviation coefficient are weighted according to the predetermined level weight distribution to obtain the real-time deviation coefficient.
5. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion as claimed in claim 4, characterized in that: Comparing the real-time first-order vector with the predetermined first-order vector to obtain a first-order deviation coefficient includes: Obtaining any feature in the first-level feature set; Matching the real-time first-level vector with the predetermined first-level vector to obtain any real-time feature parameter and any predetermined feature parameter corresponding to the arbitrary feature; Taking the difference between the arbitrary real-time characteristic parameter and the arbitrary predetermined characteristic parameter as an arbitrary deviation value; The first deviation value in the first-level characteristic deviation value sequence obtained by taking any deviation value in descending order is normalized as the first-level deviation coefficient.
6. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion as claimed in claim 5, characterized in that: Also includes: determining, based on the network warning signal, whether the arbitrary deviation value exceeds any predetermined threshold value of the arbitrary feature; If it exceeds, the mode corresponding to the arbitrary feature is matched as an abnormal mode, and emergency processing is performed on the abnormal mode.
7. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion as claimed in claim 6, characterized in that: After determining whether the arbitrary deviation value exceeds any predetermined threshold of the arbitrary feature according to the network warning signal, the method further includes: if not, performing traversal analysis on the features in the primary feature set and determining the abnormal mode.
8. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion as claimed in claim 7, characterized in that: After issuing a network abnormality warning to the industrial control all-in-one computer according to the network warning signal, the method further includes: Matching an abnormal feature set corresponding to the abnormal modality in the real-time network feature set; Performing over-limit screening on the abnormal feature set to obtain a target feature set; Traversing the target feature set in the abnormal database of the abnormal modality to obtain a historical abnormal data set; Matching a preset emergency plan based on the historical anomaly location and historical anomaly type in the historical anomaly data set; Perform network abnormality emergency processing on the industrial control all-in-one computer according to the preset emergency plan.
9. The method for detecting abnormalities in an industrial control integrated machine using multimodal data fusion as claimed in claim 8, characterized in that: Before matching a preset emergency plan based on the historical anomaly location and historical anomaly type in the historical anomaly data set, the method further includes: Constructing a three-dimensional model of the industrial control all-in-one machine, and rendering the historical anomaly locations and the historical anomaly types to the three-dimensional model to obtain an anomaly visualization model; Perform network anomaly visualization management on the industrial control all-in-one machine according to the anomaly visualization model.
10. An industrial control machine anomaly detection system for multimodal data fusion, characterized in that: The system is used to implement the method for detecting anomalies of an industrial control integrated machine for multimodal data fusion according to any one of claims 1 to 9, and the system includes: The dynamic feature collection module is used to dynamically collect multi-source network features of the industrial control integrated machine in operation to obtain a real-time multimodal network dataset; A feature extraction and analysis module, configured to perform feature extraction and analysis on the multimodal network data set according to a feature extraction plan to obtain a real-time network feature set; A feature vector comparison module, configured to compare a real-time feature vector constructed based on the real-time network feature set with a predetermined feature vector to obtain a real-time deviation coefficient; The network anomaly warning module is used to send out a network warning signal if the real-time deviation coefficient exceeds a predetermined deviation coefficient limit, and to provide a network anomaly warning to the industrial control all-in-one machine according to the network warning signal.
Citation Information
Patent Citations
Health degree evaluation method for IT centralized monitoring service system
CN111274087A
Index evaluation method and device, electronic equipment and computer storage medium
CN114444951A
Industrial control host abnormal behavior identification method based on multi-modal data fusion
CN118378196A
Railway data asset safety monitoring and risk early warning method and system
CN119814479A
Equipment state data analysis method and system applied to automated electrical equipment
CN120278705A