Dam anomaly detection method and system based on EMD and isolated forest
Through the combination of EMD decomposition and isolated forest model, the least squares method fits the trend slope and correlation analysis, the problem of ignoring slow trend anomalies and not considering the correlation of environmental loads in dam monitoring is solved, and more accurate and timely abnormal detection is achieved.
Patent Information
- Application Number
- CN202510650177.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-29
AI Technical Summary
The existing dam monitoring methods rely too much on short-term statistical feature analysis, which easily ignores slow trend abnormalities and fails to fully consider the correlation between monitoring signals and environmental loads, resulting in the failure to identify early warning delays and real abnormalities in a timely manner.
Empirical modal decomposition (EMD) is used to decompose the monitoring signal into multiple IMF components and long-term trend components. The trend slope is fitted through the least squares method, combined with the isolated forest model and correlation analysis, a comprehensive anomaly score is formed to identify trend and correlation anomaly.
Effectively identifying slow trend abnormalities improves the accuracy and timeliness of early warnings, ensures timely identification of abnormalities, and avoids misjudgment or misjudgment.
Smart Images

Figure CN120561801A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of dam monitoring, and in particular to a dam anomaly detection method and system based on EMD and isolation forest. Background Art
[0002] With the continued development of large-scale hydraulic structures (such as concrete dams and earth-rock dams), ensuring their structural safety has become increasingly important. Dam stability is directly related to sustainable socioeconomic development and the safety of people's lives and property. To prevent potential dam accidents, engineers have installed various sensors on dams to monitor key physical quantities such as displacement, stress, and seepage pressure. These monitoring signals provide crucial information on the dam's health.
[0003] An existing approach combines empirical mode decomposition (EMD) with isolation forests for anomaly detection in dam monitoring signals. This approach first performs EMD decomposition on the signal to extract features at each scale. Isolation forests are then applied to detect anomalies in each scale component, and finally, the overall signal anomaly is comprehensively determined. Compared to single-scale methods, this multi-scale approach improves the robustness and accuracy of anomaly detection.
[0004] However, existing methods, due to their over-reliance on short-term statistical analysis, tend to overlook slower-moving trend anomalies, leading to delayed warnings. Furthermore, they fail to fully consider the correlation between dam monitoring signals and environmental loads, which can lead to real anomalies not being identified in a timely manner. Summary of the Invention
[0005] In view of the above shortcomings of the existing technologies, the present invention aims to provide a dam anomaly detection method based on EMD and isolation forests. This method addresses the problem that existing methods, due to their over-reliance on short-term statistical feature analysis, tend to overlook slower trending anomalies, leading to delayed warnings. Furthermore, they fail to fully consider the correlation between dam monitoring signals and environmental loads, which can lead to the failure to promptly identify true anomalies.
[0006] A first aspect of an embodiment of the present invention provides a dam anomaly detection method based on EMD and isolation forest, comprising:
[0007] S1: Acquire the original monitoring signal of the dam, wherein the original monitoring signal includes dam detection data and water level signal data;
[0008] S2: Decomposing the original monitoring signal into multiple IMF components and a remaining long-term trend component through empirical mode decomposition;
[0009] S3: performing linear fitting on the long-term trend component using the least squares method to obtain a trend slope;
[0010] S4: normalize the trend slope to a trend abnormality score;
[0011] S5: extracting multiple statistical features of each of the IMF components and the long-term trend component and entropy features of each of the IMF components, and combining the statistical features and the entropy features to form multiple comprehensive feature vectors;
[0012] S6: Outputting a random forest anomaly score of each of the comprehensive feature vectors through an isolation forest model;
[0013] S7: performing correlation coefficient analysis on the dam monitoring data and the water level signal data to determine a correlation anomaly score that measures a change in correlation between the monitoring signals;
[0014] S8: Determine a comprehensive anomaly score based on the trend anomaly score, the random forest anomaly score, and the correlation anomaly score;
[0015] S9: Determine whether the comprehensive abnormality score is greater than a preset abnormality score; if so, determine that an abnormality occurs in the original monitoring signal; otherwise, determine that no abnormality occurs in the original monitoring signal.
[0016] A second aspect of an embodiment of the present invention provides a dam anomaly detection system based on EMD and isolation forest, comprising: a processor and a memory;
[0017] The memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the dam anomaly detection method based on EMD and isolation forests as described in the first aspect are implemented.
[0018] According to a third aspect of an embodiment of the present invention, a readable storage medium is proposed, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the dam anomaly detection method based on EMD and isolation forest as described in the first aspect are implemented.
[0019] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0020] In an embodiment of the present invention, the original monitoring signal is decomposed into multiple IMF components and long-term trend components through empirical mode decomposition, and the least squares method is used to fit the long-term trend and calculate the trend slope, thereby effectively identifying slower trend anomalies, avoiding the problem of traditional methods ignoring slow changes, and improving the accuracy and timeliness of early warnings. Secondly, the solution measures the correlation changes between monitoring signals by performing correlation analysis on dam detection data and water level signal data, and combines trend anomaly scores, random forest anomaly scores, and correlation anomaly scores to form a comprehensive anomaly score, which more comprehensively considers the correlation between signals, thereby avoiding misjudgments or missed judgments caused by insufficient consideration of correlations, and ensuring timely identification of anomalies. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] The accompanying drawings are only for the purpose of illustrating specific embodiments and are not to be considered as limiting the present invention. Throughout the drawings, the same reference symbols represent the same components. Obviously, the drawings described below are only some embodiments of the present invention. It is clear that those skilled in the art can derive other drawings based on these drawings without inventive effort.
[0022] Figure 1 1 is a flow chart of a dam anomaly detection method based on EMD and isolation forests provided by an embodiment of the present invention;
[0023] Figure 2 3 is a structural diagram of a dam anomaly detection system based on EMD and isolation forests provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0024] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described are part of the embodiments of the present invention, rather than all of the embodiments. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work should fall within the scope of protection of the present invention.
[0025] The following describes in detail the dam anomaly detection method based on EMD and isolation forests provided by the embodiment of the present invention through specific embodiments and application scenarios in conjunction with the accompanying drawings.
[0026] Reference Manual Figure 1 , which shows a flow chart of a dam anomaly detection method based on EMD and isolation forest provided by an embodiment of the present invention.
[0027] An embodiment of the present invention provides a dam anomaly detection method based on EMD and isolation forest, which may include the following steps:
[0028] S1: Obtaining the original monitoring signal of the dam, wherein the original monitoring signal includes dam detection data and water level signal data.
[0029] Optionally, the dam monitoring data includes displacement, stress or seepage pressure data.
[0030] S2: Through empirical mode decomposition, the original monitoring signal is decomposed into multiple IMF components and the remaining long-term trend component.
[0031] Empirical Mode Decomposition (EMD) is an adaptive signal processing method used to analyze nonlinear and nonstationary signals. EMD decomposes the original signal into a series of intrinsic mode functions (IMFs), allowing the signal to be analyzed at different time scales.
[0032] Among them, IMF (Intrinsic Mode Function) is the basic component in EMD decomposition, which represents the variation of the original signal at different time scales. Each IMF component is a local oscillation mode extracted from the original signal.
[0033] The long-term trend component is the remaining part of the EMD decomposition process. It represents the low-frequency part of the signal, that is, the long-term trend change of the signal. This trend is usually manifested as a slower changing part and can reflect the gradual change of the signal over a long period of time.
[0034] In a possible implementation, S2 is specifically:
[0035] The original monitoring signal is decomposed into multiple IMF components and the remaining long-term trend component using the following formula:
[0036]
[0037] Among them, x(t) represents the original monitoring signal at time point t, n represents the total number of IMF components, and IMF k represents the kth order intrinsic mode function, and r(t) represents the remaining long-term trend component at time point t.
[0038] Specifically, EMD decomposition breaks down complex signals into different time scales. High-frequency IMFs reflect rapid changes (such as vibration and noise), medium-frequency IMFs reflect cyclical changes or medium-term fluctuations, and low-frequency IMFs and residual terms reflect long-term trends. During preprocessing, IMF components can be denoised or filtered to reduce noise interference.
[0039] In an embodiment of the present invention, by decomposing a signal into multiple IMF components, we can analyze the signal at multiple time scales. Each IMF component corresponds to a different frequency component in the signal, from high frequency to low frequency. This can capture rapid fluctuations and slow changes in the signal. At the same time, the long-term trend component can help us extract long-term change trends from the signal, such as slow changes caused by environmental changes, equipment aging, or structural damage. This is crucial for structural health monitoring (such as dam settlement monitoring) because these changes usually do not cause significant fluctuations in the short term and are easily overlooked.
[0040] S3: Use the least squares method to perform linear fitting on the long-term trend component to obtain the trend slope.
[0041] Among them, Least Squares Fitting is a commonly used mathematical method for data fitting, that is, minimizing the difference between the predicted value and the actual observed value by finding the best fitting curve or straight line.
[0042] It should be noted that the present invention designs a trend anomaly identification method for slowly evolving trend changes in monitoring signals. Using the residual trend term r(t) obtained from the EMD, indicators such as its rate of change are obtained through fitting or differential calculation. For example, a least squares method is used to perform a linear fit on r(t) to obtain the trend slope.
[0043] In a possible implementation, the trend slope is specifically:
[0044]
[0045] Among them, β represents the trend slope, t represents the time point, represents the average value of time, It represents the average value of the long-term trend component within the fitting window, and T represents the length of the time window.
[0046] In this embodiment of the present invention, by fitting the long-term trend component, we can more accurately capture slowly evolving anomalies. For example, a dam may gradually settle over a long period of time. While this change may not be obvious in the short term, trend analysis can detect the problem in a timely manner.
[0047] S4: Normalize the trend slope to a trend anomaly score.
[0048] The Trend Anomaly Score (TAS) is a method used to measure whether a signal's long-term trend is abnormal. It is typically calculated based on the signal's trend slope, which reflects the rate of change of the signal over a period of time. If a signal's long-term trend undergoes an abnormal change, the TAS can help identify this anomaly and provide a quantitative assessment.
[0049] In a possible implementation, S4 is specifically:
[0050] The trend slope was normalized to the trend anomaly score using the following formula:
[0051]
[0052] Among them, I trend represents the trend anomaly score, β norm Indicates the standard value of the trend slope under normal conditions.
[0053] It should be noted that if I trend If >1, the trend is considered abnormal, and the degree of abnormality is evaluated based on its size.
[0054] Optionally, in addition to the linear slope, non-parametric statistics such as the Mann-Kendall test can also be introduced to identify significant trends. The trend identification module ultimately gives a trend anomaly score Strend (for example, directly using I trend Or convert it according to a certain mapping function to obtain a score in the range of 0 to 1).
[0055] The Mann-Kendall test is a nonparametric statistical method used to detect monotonic trends (such as upward or downward trends) in time series data. It does not require a linear assumption for the data and is therefore applicable to nonlinear and non-normally distributed data.
[0056] In the embodiments of the present invention, standardization provides a unified metric for trend anomaly scores, eliminating dimensional differences in signals. This means that regardless of the initial value of the signal, the trend anomaly score can directly reflect the degree of trend change in the signal, making trend changes between different signals more comparable. At the same time, the trend anomaly score provides monitoring personnel with an intuitive quantitative indicator that clearly indicates whether the long-term trend of the signal is abnormal. By setting a threshold, it is possible to quickly determine whether the change in the signal exceeds the expected normal range.
[0057] S5: Extract multiple statistical features of each IMF component and long-term trend component and entropy features of each IMF component, and combine the statistical features and entropy features to form multiple comprehensive feature vectors.
[0058] Entropy is a statistic used to measure signal complexity or uncertainty. In information theory, entropy is used to measure the disorder or information content of a system. In signal processing, time series analysis, and data mining, entropy is widely used to describe signal characteristics such as complexity, randomness, and uncertainty.
[0059] In a possible implementation, the calculation formula of the entropy value feature is specifically:
[0060]
[0061] Among them, H k represents the entropy value of the kth IMF component, p i (k) represents the probability of the kth IMF component in the i-th amplitude interval, ln represents the natural logarithm, and i represents the amplitude interval.
[0062] Specifically, for each IMF component and residual trend term, multiple feature quantities that can characterize their statistical characteristics are calculated. Based on traditional features, the present invention introduces entropy features to quantify signal complexity. The higher the entropy value, the richer the information of the modal function and the higher the degree of disorder, and vice versa. For time series signals, indicators such as sample entropy (Sample Entropy) that measure sequence complexity can also be calculated. Through entropy features, abnormal signs such as enhanced random noise and complex vibration patterns can be captured. In addition to entropy, each IMF also calculates the energy mean and standard deviation to comprehensively characterize the amplitude and fluctuation characteristics of the scale component.
[0063] In a possible implementation, the comprehensive feature vector is specifically:
[0064] F k =[μ k ,σ k ,E k ,H k ,…]
[0065] Among them, F k represents the comprehensive eigenvector corresponding to the kth IMF component, μ k represents the mean characteristic corresponding to the kth IMF component, σ k represents the standard deviation characteristic corresponding to the kth IMF component, E k represents the energy characteristics corresponding to the kth IMF component, H k Represents the entropy value characteristics corresponding to the kth IMF component.
[0066] In the embodiments of the present invention, the entropy feature can capture subtle changes in the signal, especially when the signal has complex or non-periodic fluctuations, so entropy can serve as an effective indicator. Furthermore, combining multiple features (such as mean, standard deviation, energy, entropy, etc.) not only improves the efficiency of feature extraction but also makes data analysis more comprehensive, better capturing signal details and potential anomalies.
[0067] S6: Output the random forest anomaly score of each comprehensive feature vector through the isolation forest model.
[0068] Isolation Forest (iForest) is an unsupervised learning algorithm specifically designed for anomaly detection. This algorithm uses the concept of random forests to isolate outliers, offering advantages such as high efficiency, ease of implementation, and applicability to high-dimensional data. The Isolation Forest model is particularly well-suited for processing large datasets and high-dimensional data, and can effectively identify anomalous data points that deviate significantly from normal patterns.
[0069] In a possible implementation, S6 specifically includes:
[0070] S601: Calculate the anomaly score of each IMF component using the isolation forest model:
[0071]
[0072] Among them, s k represents the anomaly score of the kth IMF component, c(n) represents the normalization constant, and E[h(x)] represents the average path length of the sample in the isolation forest.
[0073] Optionally, c(n) is a constant used for normalization. When the amount of data is n Where H is the harmonic series. This formula converts the path length into an anomaly score between 0 and 1.
[0074] S602: Perform weighted fusion on the anomaly scores of each IMF component to obtain the random forest anomaly score:
[0075]
[0076] Among them, S total represents the random forest anomaly score, n represents the total number of IMF components, and w k represents the weight of the kth IMF component.
[0077] In an embodiment of the present invention, each IMF component captures a different frequency component of the signal (e.g., a high-frequency component or a low-frequency component). By weighted fusion of the anomaly scores of each IMF component, the anomaly of the signal at multiple time scales can be comprehensively reflected, thereby improving the comprehensiveness and accuracy of anomaly detection. At the same time, by weighted averaging, the excessive impact of the anomaly score of a single IMF component on the overall result can be avoided, thereby reducing false positives and false negatives. In particular, when some IMF components may be affected by noise, the IMF components with smaller weights will have less impact on the final result, improving the robustness of the comprehensive score.
[0078] S7: Perform correlation coefficient analysis on the dam monitoring data and water level signal data to determine a correlation anomaly score that measures the change in correlation between the monitoring signals.
[0079] In a possible implementation, S7 specifically includes:
[0080] S701: Setting a preset time window, and calculating the mean of the dam monitoring data and the water level signal data within the preset time window to obtain the mean of the dam monitoring data and the mean of the water level signal data.
[0081] In the embodiment of the present invention, by calculating the mean, the offset of the signal can be removed, the analysis focus can be concentrated on the relative change of the signal, and the deviation caused by the passage of time can be eliminated.
[0082] S702: Based on the mean value of the dam monitoring data and the mean value of the water level signal data, the Pearson correlation coefficient value between the dam monitoring data and the water level signal data is calculated using the Pearson correlation coefficient formula.
[0083] The Pearson Correlation Coefficient is a statistic used to measure the linear relationship between two variables. Its value ranges from -1 to 1, indicating the degree of correlation between the two variables. A Pearson Correlation Coefficient closer to 1 indicates a stronger linear relationship between the two variables, while a value closer to -1 indicates a strong negative correlation between the two variables. A value closer to 0 indicates almost no linear relationship between the two variables.
[0084] For example, when the dam monitoring data is displacement signal data, the Pearson correlation coefficient within a time window is calculated:
[0085]
[0086] Among them, r XY represents the Pearson correlation coefficient value, T represents the time window length, X(t) represents the displacement signal at time point t, and Y(t) represents the water level signal at time point t. Represents the mean value of the displacement signal within the preset time window, Indicates the mean value of the water level signal within the preset time window.
[0087] Under normal circumstances, dam displacement and water level should show a high correlation; if the correlation coefficient decreases significantly over a period of time, it may indicate abnormal displacement (e.g., structural damage leading to abnormal response). Similarly, correlation analysis can be performed for seepage pressure and water level, stress and temperature, and other parameters. If no additional environmental variables are available, correlation between multi-point monitoring data can be used. For example, if displacement at different measuring points on the dam is usually synchronized, if the correlation between the displacement at one measuring point and that at other points decreases, an anomaly may be occurring at that measuring point.
[0088] S703: Determine the correlation anomaly score based on the Pearson correlation coefficient value:
[0089] S corr =1-r XY
[0090] Among them, S corr Represents the correlation anomaly score.
[0091] In this embodiment of the present invention, in dam monitoring, the dam's displacement signal and water level signal typically exhibit a long-term linear correlation. By calculating the Pearson correlation coefficient, we can quantify changes in this relationship and determine whether there are any anomalies that deviate from the expected pattern. Furthermore, by calculating the correlation anomaly score, we can quantify the degree of abnormality in the correlation change. A larger value indicates a more abnormal correlation change. This provides a quantitative basis for subsequent decision-making.
[0092] S8: Determine a comprehensive anomaly score based on the trend anomaly score, the random forest anomaly score, and the correlation anomaly score.
[0093] In one possible implementation, the comprehensive abnormality score is specifically:
[0094] S final =w total S total +w corr s corr +w trend s trend
[0095] Among them, S final represents the comprehensive abnormality score, w total represents the weight of the random forest anomaly score, S total represents the random forest anomaly score, w corr represents the weight of the correlation anomaly score, s corr represents the correlation anomaly score, w trend represents the weight of the trend anomaly score, s trend Indicates the trend anomaly score.
[0096] Optionally, w total +w corr +w trend =1.
[0097] It should be noted that the weight setting reflects the importance of each part to the overall abnormality judgment: for example, for displacement monitoring, water level correlation is very critical, and the related abnormality score can be given a higher weight; for vibration signals, the entropy feature of high-frequency IMF is more important, which can improve the corresponding s k The weight of .
[0098] In an embodiment of the present invention, by combining different anomaly detection methods (such as trend analysis, random forest model, correlation analysis, etc.), the comprehensive anomaly score can analyze the abnormality of the signal from multiple angles. This means that not only can the long-term trend changes of the signal be captured, but also local fluctuations and correlation changes can be identified, providing more comprehensive anomaly detection. At the same time, the combined anomaly score provides a quantitative anomaly assessment indicator that can provide monitoring personnel with a clear basis for judgment. This helps to automatically determine whether an anomaly has occurred in the real-time monitoring system, respond in a timely manner, and take appropriate measures.
[0099] S9: Determine whether the comprehensive anomaly score is greater than a preset anomaly score. If so, determine that the original monitoring signal is abnormal. Otherwise, determine that the original monitoring signal is not abnormal.
[0100] Specifically, a preset anomaly score threshold, based on historical data or expert experience, is used to distinguish between normal and abnormal signals. When the combined anomaly score exceeds this threshold, it indicates that the signal is abnormal; when the combined anomaly score falls below this threshold, the signal change is within the normal range.
[0101] In this embodiment of the present invention, by setting a preset anomaly scoring threshold and comparing it with the comprehensive anomaly score, an automated, quantitative, and standardized determination of whether a monitoring signal is abnormal can be achieved. This approach not only improves monitoring efficiency and reduces human intervention, but also ensures the accuracy and consistency of anomaly detection and provides a reliable basis for decision-making.
[0102] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0103] In an embodiment of the present invention, the original monitoring signal is decomposed into multiple IMF components and long-term trend components through empirical mode decomposition, and the least squares method is used to fit the long-term trend and calculate the trend slope, thereby effectively identifying slower trend anomalies, avoiding the problem of traditional methods ignoring slow changes, and improving the accuracy and timeliness of early warnings. Secondly, the solution measures the correlation changes between monitoring signals by performing correlation analysis on dam detection data and water level signal data, and combines trend anomaly scores, random forest anomaly scores, and correlation anomaly scores to form a comprehensive anomaly score, which more comprehensively considers the correlation between signals, thereby avoiding misjudgments or missed judgments caused by insufficient consideration of correlations, and ensuring timely identification of anomalies.
[0104] Reference Manual Figure 2 , shows a structural diagram of a dam anomaly detection system based on EMD and isolation forest provided by an embodiment of the present invention.
[0105] The embodiment of the present invention provides a dam anomaly detection system 20 based on EMD and isolation forest, comprising: a processor 201 and a memory 202;
[0106] The memory 202 stores programs or instructions that can be run on the processor 201. When the programs or instructions are executed by the processor 201, the steps of the above-mentioned dam anomaly detection method based on EMD and isolation forests are implemented, and the same technical effects can be achieved. To avoid repetition, the present invention will not be described in detail.
[0107] It should be understood that the processor 201 in the embodiment of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0108] It should also be understood that the memory 202 in the embodiment of the present invention can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0109] The above embodiments can be implemented in whole or in part through software, hardware (such as circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired method (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0110] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0111] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0112] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0113] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of the device or unit, which can be electrical, mechanical or other forms.
[0114] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0115] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0116] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0117] An embodiment of the present invention provides a readable storage medium including: a program or instruction is stored on the readable storage medium, and when the program or instruction is executed by the processor, the steps of the above-mentioned dam anomaly detection method based on EMD and isolation forest are implemented, and the same technical effect can be achieved. To avoid repetition, the present invention will not be repeated.
[0118] Finally, it should be noted that the above embodiments are merely illustrative of the technical solutions of the embodiments of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they may still modify the technical solutions described in the aforementioned embodiments, or replace some of the technical features therein with equivalents; and such modifications or replacements do not deviate from the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention. Any changes or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be covered by the scope of protection of the present invention.
Claims
1. A dam anomaly detection method based on EMD and isolation forest, characterized in that: include: S1: Acquire the original monitoring signal of the dam, wherein the original monitoring signal includes dam monitoring data and water level signal data; S2: Decomposing the original monitoring signal into multiple IMF components and a remaining long-term trend component through empirical mode decomposition; S3: performing linear fitting on the long-term trend component using the least squares method to obtain a trend slope; S4: normalize the trend slope to a trend abnormality score; S5: extracting multiple statistical features of each of the IMF components and the long-term trend component and entropy features of each of the IMF components, and combining the statistical features and the entropy features to form multiple comprehensive feature vectors; S6: Outputting a random forest anomaly score of each of the comprehensive feature vectors through an isolation forest model; S7: performing correlation coefficient analysis on the dam monitoring data and the water level signal data to determine a correlation anomaly score that measures a change in correlation between the monitoring signals; S8: Determine a comprehensive anomaly score based on the trend anomaly score, the random forest anomaly score, and the correlation anomaly score; S9: Determine whether the comprehensive abnormality score is greater than a preset abnormality score; if so, determine that an abnormality occurs in the original monitoring signal; otherwise, determine that no abnormality occurs in the original monitoring signal.
2. The dam anomaly detection method based on EMD and isolation forest according to claim 1 is characterized in that: The S2 is specifically: The original monitoring signal is decomposed into multiple IMF components and the remaining long-term trend component using the following formula: Among them, x(t) represents the original monitoring signal at time point t, n represents the total number of IMF components, and IMF k represents the kth order intrinsic mode function, and r(t) represents the remaining long-term trend component at time point t.
3. The dam anomaly detection method based on EMD and isolation forest according to claim 1 is characterized in that: The trend slope is specifically: Among them, β represents the trend slope, t represents the time point, represents the average value of time, It represents the average value of the long-term trend component within the fitting window, and T represents the length of the time window.
4. The dam anomaly detection method based on EMD and isolation forest according to claim 3 is characterized in that: The S4 is specifically: The trend slope was normalized to a trend anomaly score using the following formula: Among them, I trend represents the trend anomaly score, β norm Indicates the standard value of the trend slope under normal conditions.
5. The dam anomaly detection method based on EMD and isolation forest according to claim 1 is characterized in that: The statistical characteristics specifically include: energy, mean and standard deviation; The calculation formula of the entropy value feature is specifically: Among them, H k represents the entropy value of the kth IMF component, p i (k) represents the probability of the kth IMF component in the i-th amplitude interval, ln represents the natural logarithm, and i represents the amplitude interval.
6. The dam anomaly detection method based on EMD and isolation forest according to claim 5 is characterized in that: The comprehensive feature vector is specifically: F k =[μ k ,s k ,E k ,H k ,…] Among them, F k represents the comprehensive eigenvector corresponding to the kth IMF component, μ k represents the mean characteristic corresponding to the kth IMF component, σ k represents the standard deviation characteristic corresponding to the kth IMF component, E k represents the energy characteristics corresponding to the kth IMF component, H k Represents the entropy value characteristics corresponding to the kth IMF component.
7. The dam anomaly detection method based on EMD and isolation forest according to claim 1 is characterized in that: The S6 specifically includes: S601: Calculate the abnormality score of each IMF component using the isolation forest model: Among them, s k represents the anomaly score of the kth IMF component, c(n) represents the normalization constant, represents, E[h(x)] represents the average path length of the sample in the isolation forest; S602: Perform weighted fusion on the anomaly scores of the IMF components to obtain the random forest anomaly score: Among them, S total represents the random forest anomaly score, n represents the total number of IMF components, and w k represents the weight of the kth IMF component.
8. The dam anomaly detection method based on EMD and isolation forest according to claim 1 is characterized in that: The S7 specifically includes: S701: Setting a preset time window, and calculating the mean of the dam monitoring data and the water level signal data within the preset time window to obtain the mean of the dam monitoring data and the mean of the water level signal data; S702: Calculating a Pearson correlation coefficient between the dam monitoring data and the water level signal data using a Pearson correlation coefficient formula based on the mean value of the dam monitoring data and the mean value of the water level signal data; S703: Determine the correlation anomaly score based on the Pearson correlation coefficient value: S corr =1-r XY Among them, S corr represents the correlation anomaly score, r XY Represents the Pearson correlation coefficient value.
9. The dam anomaly detection method based on EMD and isolation forest according to claim 1, characterized in that: The comprehensive abnormality score is specifically: S final =w total S total +w corr s corr +w trend s trend Among them, S final represents the comprehensive abnormality score, w total represents the weight of the random forest anomaly score, S total represents the random forest anomaly score, w corr represents the weight of the correlation anomaly score, s corr represents the correlation anomaly score, w trend represents the weight of the trend anomaly score, s trend Indicates the trend anomaly score.
10. A dam anomaly detection system based on EMD and isolation forest, characterized by: include: processor and memory; The memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the dam anomaly detection method based on EMD and isolation forests as described in any one of claims 1 to 9 are implemented.
Citation Information
Cited By
Fault early warning method and system for express logistics sorting equipment
CN121660666A
A fault early warning method and system for express logistics sorting equipment
CN121660666B
An engineering quality detection data tamper-proofing and abnormality early warning method and system
CN122529576A
An engineering quality detection data tamper-proofing and abnormality early warning method and system
CN122529576B