Iot data anomaly detection method based on directed graph spatiotemporal feature fusion

By employing a directed graph spatiotemporal feature fusion method, the challenge of modeling sensor dependencies in IoT sensor networks was solved, enabling high-precision and robust anomaly detection that adapts to environmental changes.

CN120597173BActive Publication Date: 2025-11-07XIAMEN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510952572.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-11-07
Estimated Expiration
2045-07-10

AI Technical Summary

Technical Problem

Existing IoT data anomaly detection methods struggle to effectively model the complex interdependencies between sensors, especially in large-scale sensor networks where computational burden is heavy and they are sensitive to sudden environmental changes, resulting in poor identification accuracy.

Method used

A method based on directed graph spatiotemporal feature fusion is adopted. The directed causal relationship of the sensor network is learned through Bayesian variational inference. Combined with graph attention mechanism and gated recurrent unit, the adjacency matrix weights are dynamically adjusted to generate anomaly scores and dynamic thresholds for detection.

Benefits of technology

It significantly improves the accuracy of anomaly propagation path identification, enhances the robustness and adaptability of the model, and can provide high-precision anomaly detection in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597173B_ABST
    Figure CN120597173B_ABST
Patent Text Reader

Abstract

The application discloses a directed graph space-time feature fusion-based Internet of Things data anomaly detection method, which comprises the following steps: S1, collecting data of a plurality of sensor nodes in the Internet of Things, and constructing a sensor network data set; S2, cleaning and preprocessing the sensor network data in the region; S3, learning the directed graph adjacency matrix of the sensor network through Bayesian variational inference on the processed data, and modeling the directed causal relationship between the sensor nodes; S4, processing the sensor of the predicted target location by using a space feature extraction module, and extracting the multi-hop neighborhood space feature by using a directed graph guided graph attention mechanism; S5, processing the space feature of the predicted target location sensor network data and the directed graph by using a space-time feature fusion module, dynamically adjusting the directed graph structure and performing data prediction; S6, generating an anomaly score and a dynamic threshold value and performing anomaly detection; the method can improve the Internet of Things data anomaly detection performance.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of Internet of Things data anomaly detection, and particularly relates to an Internet of Things data anomaly detection method based on directed graph spatiotemporal feature fusion. BACKGROUND

[0002] Internet of Things systems can continuously generate large amounts of data sets, such as temperature, humidity, and air pollutant monitoring data of large-scale intelligent environment monitoring systems. In intelligent Internet of Things applications, accurate and reliable data collection is crucial for decision-making, especially in industrial environments that rely on seamless collaboration between different entities. However, due to resource constraints, Internet of Things sensors are vulnerable to attacks, leading to data anomalies within Internet of Things systems. As the complexity and dimensionality of sensor data continue to increase, manual monitoring tasks become increasingly difficult. Therefore, for intelligent applications based on the Internet of Things, an efficient and accurate anomaly detection system is crucial.

[0003] Due to the difficulty of obtaining real anomaly labels, unsupervised anomaly detection has received extensive attention, and the development of its methods has evolved from traditional statistical models to deep learning methods. Early methods mainly relied on statistical models or distance-based algorithms, detecting anomalies through temporal features or distance thresholds. With the development of deep learning, long short-term memory networks (LSTM) have become a core tool for anomaly detection due to their time modeling capabilities. For example, multi-scale recurrent encoder-decoder algorithms construct multi-scale feature matrices and locate anomalies through residual matrices. Generative adversarial networks (GAN) and convolutional neural networks (CNN) are combined with long short-term memory networks (LSTM) to capture temporal features, and multi-modal observation reconstruction distribution and stochastic recurrent networks are proposed to enhance the robustness of detection. However, these methods usually cannot explicitly model the complex interdependence between sensors, limiting their ability to detect relationship deviations during abnormal events.

[0004] Sensor networks can be modeled as a graph structure, where nodes represent sensors and edges represent dependencies. Since device interactions in the Internet of Things are often asymmetric, directed graphs can more accurately reflect causal relationships. Graph neural networks (GNNs) have become a powerful tool for processing graph data. Graph convolutional networks (GCNs) update the embedding representation of the target node by assigning fixed weights to the embeddings from neighboring nodes. Graph attention networks (GATs) learn the weights of neighboring nodes, perform weighted aggregation to update the node representation. Most graph neural network (GNN)-based methods assume that the relationship between sensors or general node connections is predefined, which can lead to a significant increase in computational overhead as the dimension increases. In order to process sensor data without a predefined graph structure, graph learning-based anomaly detection methods have been developed. Graph deviation networks (GDNs) dynamically construct graphs by selecting Top-k nodes based on node embeddings. Nodes are functionally classified based on similarity and recursively encoded. But like the graph deviation network (GDN), methods based on attention mechanisms and fully connected graphs require frequent computation of node similarity, which can lead to computational burden in practical applications, especially in large-scale sensor networks. In addition, the physical interpretability of the learned graph structure is still unclear, and similarity-based graphs are also sensitive to data noise.

[0005] These methods and challenges highlight the need for the development of lightweight, robust, and interpretable mechanisms to learn graph structures in future research. Although the strength of spatial correlation between sensor nodes directly determines the effectiveness of anomaly detection, the spatial dependence in real-world deployments exhibits dynamic nonlinear characteristics, which poses challenges for robust modeling. Sensor data itself contains complex spatiotemporal dependencies, so a unified architecture is needed to capture nonlinear interaction mechanisms. However, the coupling between temporal evolution and spatial propagation dynamically exacerbates the complexity of modeling through dimensional entanglement. In addition, in the absence of real labeled data, the design of anomaly scoring functions and thresholds relies heavily on assumptions about the data distribution, such as Gaussian or Poisson distribution, making the system vulnerable to sudden environmental changes and less accurate in recognition. SUMMARY

[0006] To solve the above problems, the present application proposes an Internet of Things data anomaly detection method based on directed graph spatiotemporal feature fusion, which effectively utilizes the spatiotemporal coupling features and causal characteristics between Internet of Things data to improve the performance of Internet of Things data anomaly detection.

[0007] To achieve the above purpose, the present application adopts the following technical solutions:

[0008] The Internet of Things data anomaly detection method based on directed graph spatiotemporal feature fusion comprises the following steps:

[0009] S1, collect data of multiple sensor nodes in the Internet of Things, and construct a sensor network data set;

[0010] S2, cleaning and preprocessing the sensor network data in the region;

[0011] S3, learning the directed graph adjacency matrix of the sensor network through Bayesian variational inference on the processed data, and modeling the directed causal relationship between sensor nodes;

[0012] S4, processing the sensor at the predicted target location using a spatial feature extraction module, and extracting multi-hop neighborhood spatial features using a directed graph guided graph attention mechanism;

[0013] S5, processing the spatial features of the sensor network data and the directed graph at the predicted target location using a spatio-temporal feature fusion module, dynamically adjusting the directed graph structure and performing data prediction;

[0014] S6, generating an anomaly score and a dynamic threshold and performing anomaly detection.

[0015] Preferably, the specific process of step S1 is: 50 PM 2.5 sensor nodes deployed in the target area collect continuous environmental monitoring data for one year at a minute level, construct a time series data set containing 8640 time points; each sensor node synchronously records the geographic position, time stamp and PM 2.5 concentration value, forming a multi-dimensional space-time matrix.

[0016] Preferably, the specific process of step S2 is:

[0017] S21, normalize the data of the sensor nodes using the min-max value algorithm to eliminate the dimensional difference of the sensors, and the calculation formula is: wherein, is the normalized single training set data; is the original single training set data; is the training set data; is the minimum value in the training set data; is the maximum value in the training set data;

[0018] S22, introduce a decay factor to the sliding window time series data to suppress noise interference, and the calculation formula is: wherein, is the time series data of all sensors; is the decay factor; is the data of all sensor nodes under the sliding window; ​​​​​​

[0019] S23, missing values are repaired by interpolation, and abnormal fluctuations are removed in combination with median filtering.

[0020] Preferably, the specific process of step S3 is:

[0021] S31, modeling the sensor network as a directed graph , wherein, is a set of sensor nodes, is an adjacency matrix;

[0022] S32, decomposing the adjacency matrix into an orthogonal matrix and a lower triangular matrix , combining Gumbel-Sinkhorn distribution to optimize sensor node ordering;

[0023] S33, introducing variational inference maximum evidence lower bound to learn sparse directed adjacency matrix , and eliminating self-loop paths by physical prior constraint.

[0024] Preferably, the specific process of step S4 is:

[0025] S41, defining sensor node embedding vectors, calculating the similarity between sensor nodes, and the calculation formula is: , wherein, is a sensor node and cosine similarity, used to quantify the correlation strength between nodes; is a sensor node ; is a sensor node ; is a learnable embedding vector of sensor node , representing its inherent characteristics; is a learnable embedding vector of sensor node , representing its inherent characteristics; is the transpose of vector ; is the L2 norm of vector ; is the L2 norm of vector ;

[0026] S42, generating an aggregated adjacency matrix based on multi-hop adjacency matrix weighted fusion, and the calculation formula is: , wherein, is an aggregated adjacency matrix; is a learnable attenuation coefficient; is a multi-hop adjacency matrix; is the number of hops,k =1 indicates a direct neighbor. k =2 indicates a second-order neighbor;

[0027] S43. The spatial features of sensor network data are calculated using a directed graph-guided graph attention mechanism. The attention coefficients are jointly determined by the adjacency weights and feature interaction terms, and the calculation formula is as follows: , , , ,in, Spatial characteristics of sensor network data; To correct the linear unit, a nonlinear activation is introduced; For sensor nodes The weight of one's own attention; For sensor nodes i For sensor nodes Attention weights; To share the linear transformation matrix for feature mapping; For sensor nodes In time t Input features; For sensor nodes In time t Input features; For sensor nodes The set of neighbors; For sensor nodes splicing characteristics; For sensor nodes Learnable embedding vectors; This involves concatenating vectors. For sensor nodes With sensor nodes Feature interaction score; For activation functions; This is a learnable parameter vector used to calculate the attention coefficients; For sensor nodes splicing characteristics; Adjacency weight; For sensor nodes With sensor nodes m Feature interaction score; For sensor nodes m ; For sensor nodes of k Jump to neighbor set.

[0028] Preferably, the specific process of step S5 is as follows:

[0029] S51, the spatial features of the sensor nodes in the sensor network are spliced into a joint input i i

[0030] S52, embedding the adjacency weight in the gated recurrent unit , realizing spatio-temporal feature fusion through the update gate and reset gate of topological awareness;

[0031] S53, dynamically adjusting the adjacency matrix weight through the multi-layer perception , forming a closed-loop time series driving graph structure evolution mechanism;

[0032] S54, multi-step data prediction based on fused spatio-temporal features, generating a prediction value through a fully connected layer , the generation method of the prediction value is: , wherein, is a fully connected layer; is an embedding vector of the first N sensor nodes; is the hidden state output by the first N gated recurrent units; is a Hadamard product; Huber loss function is used to optimize the prediction accuracy: , wherein, is a Huber loss function, used to balance the prediction accuracy and robustness; is the time length of the training set; is the size of the sliding window; is the prediction value; is the Huber loss threshold.

[0033] Preferably, the specific process of step S6 is:

[0034] S61, calculate the local prediction bias, and generate a normalized error based on the median-IQR standardization, the calculation formula is: , , wherein, is the local prediction bias; is the actual observation value of the sensor node at time t ; is the prediction value of the sensor node at time t ; is the normalized error; is the median on the training set ; is the interquartile range on the training set .​​​​​

[0035] S62, quantize the neighbor consistency error, the calculation formula is: Wherein, is the neighbor consistency error; is the local prediction bias of the sensor node j .

[0036] S63, weighted fusion of normalized error and neighbor consistency error, generate the final anomaly score: Wherein, is the anomaly score; is the balance coefficient, determined by grid search of validation set;

[0037] S64, calculate the dynamic threshold based on the sliding window quantile, the calculation formula is: Wherein, is the dynamic threshold; is the third quartile of the anomaly score in the sliding window; is the dynamic threshold coefficient, used to control the sensitivity of anomaly judgment; is the interquartile range, IQR= - , is the first quartile;

[0038] determine as an abnormal data.

[0039] After adopting the above technical scheme, the present application has the following beneficial effects:

[0040] 1. The present application accurately captures the asymmetric spatiotemporal dependence relationship between Internet of Things data: through Bayesian variational inference and sparse constraint to generate a directed graph, the directional dependence between sensor data is explicitly modeled (such as one-way pollution propagation), overcoming the defect that traditional symmetric graph structure cannot represent real physical causal influence, significantly improving the recognition accuracy of abnormal propagation path.

[0041] 2. The present application enhances the long-range key node sensing ability: a multi-hop adjacency matrix guided attention mechanism is proposed, which dynamically fuses the neighborhood features of different hop paths through a learnable attenuation coefficient, suppressing high-hop noise interference while preserving key causal relationship information, effectively improving the sensitivity of abnormal data under complex topology.

[0042] 3. The present application embeds the graph weight into the GRU gate unit, dynamically adjusts the adjacency matrix weight combining the node hidden state and real-time data, forms a closed-loop system of "spatiotemporal feature driven graph update-graph structure guided feature fusion", adapts to non-steady-state scenarios such as node failure or environmental mutation, and enhances the model robustness.

[0043] 4、The multi-granularity score and adaptive threshold calibration of the application: combine local sensor prediction bias and neighborhood joint bias to construct a composite anomaly score, and adjust the dynamic threshold in real time based on the sliding window quantile, eliminate the scale difference of sensor data and the interference of non-Gaussian distribution, accurately distinguish normal fluctuations and real anomalies, and effectively improve the performance of Internet of Things data anomaly detection.

[0044] 5、The application uses publicly available data that is easy to collect, combines spatio-temporal features, solves the problem of missing detection caused by ignoring the causal dependence between sensor data in the prior art and the lack of adaptability of static threshold to time-varying data, and provides a high-precision and high-robustness anomaly detection scheme for Internet of Things data in complex environments. BRIEF DESCRIPTION OF DRAWINGS

[0045] Figure 1 The flowchart of the application;

[0046] Figure 2 The flowchart of the application;

[0047] Figure 3 The causal relationship learning diagram between Internet of Things data of the application;

[0048] Figure 4 The spatio-temporal feature extraction and fusion based on directed graph and Internet of Things data reconstruction diagram of the application;

[0049] Figure 5 The schematic diagram of adaptive updating of anomaly detection dynamic threshold of the application;

[0050] Figure 6 The directed relationship diagram between sensor nodes of the application;

[0051] Figure 7 The anomaly detection effect comparison diagram of different anomaly detection methods of the application. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical scheme and advantages of the application clearer and more apparent, the application will be further described in detail below with examples. It should be understood that the specific examples described herein are only used to explain the application and not to limit the application.

[0053] As shown in Figures 1 to 7 The Internet of Things data anomaly detection method based on directed graph spatio-temporal feature fusion comprises the following steps:

[0054] S1, collect data of multiple sensor nodes in the Internet of Things, and construct a sensor network data set;

[0055] The specific process of step S1 is: 50 PM2.5 sensors are deployed in the target area to collect data of multiple sensor nodes, and a sensor network data set is constructed. 2.5The sensor nodes collect environmental monitoring data continuously for one year at a frequency of minutes, and build a time series data set containing 8640 time points; each sensor node synchronously records the geographical position, timestamp and PM 2.5 concentration value, forming a multi-dimensional space-time matrix;

[0056] S2, cleaning and preprocessing the sensor network data in the region;

[0057] The specific process of step S2 is:

[0058] S21, normalizing the data of the sensor nodes using the minimum-maximum value algorithm to eliminate the dimensional differences of the sensors, and the calculation formula is: wherein, is the normalized single training set data; is the original single training set data; is the training set data; is the minimum value in the training set data; is the maximum value in the training set data;

[0059] S22, introducing a decay factor to the sliding window time series data to suppress noise interference, and the calculation formula is: wherein, is the time series data of all sensors; , , , is the decay factor; , , , is the data of all sensor nodes under the sliding window;

[0060] S23, repairing missing values by interpolation and removing abnormal fluctuations combined with median filtering;

[0061] S3, learning the adjacency matrix of the directed graph of the sensor network through Bayesian variational inference on the processed data, and modeling the directed causal relationship between the sensor nodes;

[0062] The specific process of step S3 is:

[0063] S31, modeling the sensor network as a directed graph wherein, is the set of sensor nodes, is the adjacency matrix;

[0064] S32, decomposing the adjacency matrix into an orthogonal matrix and a lower triangular matrix , combined with Gumbel-Sinkhorn distribution optimization sensor node ranking;

[0065] S33, introduce variational inference maximum evidence lower bound, learn sparse adjacency matrix , and eliminate self-loop path by physical prior constraint;

[0066] S4, the sensor node of the predicted target location is processed by a spatial feature extraction module, and a directed graph guided graph attention mechanism is used to extract multi-hop neighborhood spatial features;

[0067] The specific process of step S4 is:

[0068] S41, define the sensor node embedding vector, calculate the similarity between sensor nodes, and the calculation formula is: , is the cosine similarity of sensor nodes and , used to quantify the correlation strength between nodes; is the sensor node ; is the sensor node ; is the learnable embedding vector of sensor node , representing its inherent characteristics; is the learnable embedding vector of sensor node , representing its inherent characteristics; is the transpose of vector ; is the L2 norm of vector ; is the L2 norm of vector ;

[0069] S42, generate an aggregated adjacency matrix based on the weighted fusion of multi-hop adjacency matrices, and the calculation formula is: , is the aggregated adjacency matrix; is the learnable attenuation coefficient; is the multi-hop adjacency matrix; is the hop number, k =1 represents a direct neighbor, k =2 represents a second-order neighbor;

[0070] S43, calculate the spatial features of sensor network data by a directed graph guided graph attention mechanism, and the attention coefficient is determined by the adjacency weight and the feature interaction term, and the calculation formula is: , , , , Spatial characteristics of sensor network data; To correct the linear unit, a nonlinear activation is introduced; For sensor nodes The weight of one's own attention; For sensor nodes i For sensor nodes Attention weights; To share the linear transformation matrix for feature mapping; For sensor nodes In time t Input features; For sensor nodes In time t Input features; For sensor nodes The set of neighbors; For sensor nodes splicing characteristics; For sensor nodes Learnable embedding vectors; This involves concatenating vectors. For sensor nodes With sensor nodes Feature interaction score; For activation functions; This is a learnable parameter vector used to calculate the attention coefficients; For sensor nodes splicing characteristics; Adjacency weight; For sensor nodes With sensor nodes m Feature interaction score; For sensor nodes m ; For sensor nodes of k Jump to neighbor set;

[0071] S5. The spatial characteristics and directed graph of the sensor network data of the predicted target location are processed by the spatiotemporal feature fusion module, the structure of the directed graph is dynamically adjusted and data prediction is performed.

[0072] The specific process of step S5 is as follows:

[0073] S51, Add sensor nodes to the sensor network i Spatial features With sensor nodes i Sliding window timing data splicing into joint input ;

[0074] S52. Embed adjacency weights in the gated loop unit. Spatiotemporal feature fusion is achieved through update gates and reset gates based on topology awareness;

[0075] S53. Dynamically adjust the adjacency matrix weights using a multilayer perceptron. This forms a closed-loop time-driven graph structure evolution mechanism;

[0076] S54. Perform multi-step data prediction based on the fused spatiotemporal features, and generate predicted values ​​through a fully connected layer. Predicted value The generation method is as follows: ,in, It is a fully connected layer; Embed the vectors for the first N sensor nodes; The hidden state output by the first N gated loop units; The prediction accuracy is optimized using the Hadamard product and the Huber loss function. ,in, The Huber loss function is used to balance prediction accuracy and robustness. The length of the training set; To adjust the sliding window size; This is a predicted value; The Huber loss threshold;

[0077] S6. Generate anomaly scores and dynamic thresholds and perform anomaly detection;

[0078] The specific process of step S6 is as follows:

[0079] S61. Calculate the local prediction bias and generate the normalized error based on median-IQR standardization. The calculation formula is as follows: , ,in, This represents a local prediction bias; For sensor nodes In time t The actual observed values; For sensor nodes In time t The predicted value; This is the normalization error; For the training set the median; For the training set Interquartile range;

[0080] S62. Quantify the neighbor consistency error, the calculation formula is as follows: ,in, This is the neighbor consistency error; local prediction bias of the sensor node j ;

[0081] S63, weighted fusion of normalized error and neighbor consistency error to generate final anomaly score: wherein, is the anomaly score; is the balance coefficient, determined by grid search on validation set;

[0082] S64, dynamic threshold based on sliding window quantile, the calculation formula is: wherein, is the dynamic threshold; is the third quartile of anomaly score in the sliding window; is the dynamic threshold coefficient, used to control the sensitivity of anomaly determination; is the interquartile range, IQR = Q3-Q1 - , is the first quartile;

[0083] determine as an abnormal data.

[0084] The above description is only the preferred specific implementation of the present application, but the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for detecting abnormal data of Internet of Things based on directed graph spatiotemporal feature fusion, characterized in that, The method comprises the following steps: S1, collecting data of a plurality of sensor nodes in an Internet of Things, and constructing a sensor network data set; S2, cleaning and preprocessing the sensor network data in the region; S3, learning the adjacency matrix of the directed graph of the sensor network through Bayesian variational inference on the processed data, and modeling the directed causal relationship between the sensor nodes; S4, processing the sensor network data of the target location using a spatial feature extraction module, and extracting multi-hop neighborhood spatial features using a directed graph guided graph attention mechanism; S5, processing the spatial features of the sensor network data of the target location and the directed graph using a spatiotemporal feature fusion module, dynamically adjusting the directed graph structure, and performing data prediction; The specific process of step S5 is: S51, Add sensor nodes to the sensor network i Spatial features With sensor nodes i Sliding window timing data splicing into joint input ; S52, embedding an adjacency weight in a gated recurrent unit The spatio-temporal feature fusion is realized by a topology-aware update gate and a reset gate. S53, dynamically adjusting the adjacency matrix weight through a multi-layer perception , a closed-loop timing driving graph structure evolution mechanism is formed; S54, based on the fused spatiotemporal features, multi-step data prediction is performed to generate a prediction value through a full connection layer , the generation method of the prediction value is: , wherein is a full connection layer; is an embedding vector of the first N sensor nodes; is a hidden state output by the first N gated recurrent units; is a Hadamard product; the prediction accuracy is optimized by using a Huber loss function: , wherein is a Huber loss function, used to balance the prediction accuracy and robustness; is the time length of the training set; is the size of the sliding window; is the prediction value; is a Huber loss threshold value; S6, generating an anomaly score and a dynamic threshold and performing anomaly detection.

2. The directed graph-based spatio-temporal feature fusion Internet of Things data anomaly detection method of claim 1, wherein, The specific process of step S1 is: through 50 PM 2.5 sensor nodes deployed in the target area, collect environmental monitoring data for a continuous year at a minute-level frequency, construct a time series data set containing 8640 time points; each sensor node synchronously records the geographic position, timestamp and PM 2.5 concentration value, forming a multi-dimensional space-time matrix. 3.The IoT data anomaly detection method based on directed graph spatio-temporal feature fusion of claim 1, wherein, The specific process of step S2 is: S21, the data of the sensor node is normalized by using the minimum-maximum value algorithm, and the dimension difference of the sensor is eliminated, and the calculation formula is: wherein, is the normalized single training set data; is the original single training set data; is the training set data; is the minimum value in the training set data; is the maximum value in the training set data; S22, introduce a damping factor to the sliding window time series data, suppress noise interference, the calculation formula is: Wherein, is the time series data of all sensors; , , , is the damping factor; , , , is the data of all sensor nodes under the sliding window; S23, repairing missing values by interpolation, and removing abnormal fluctuations by combining median filtering.

4. The Internet of Things data anomaly detection method based on directed graph spatio-temporal feature fusion of claim 1, wherein, The specific process of step S3 is: S31, model the sensor network as a directed graph wherein, is a set of sensor nodes, is an adjacency matrix; S32, decompose the adjacency matrix by Schur decomposition into an orthogonal matrix and a lower triangular matrix and a lower triangular matrix , combine the Gumbel-Sinkhorn distribution to optimize the sensor node ordering; S33, introduce variational inference maximum evidence lower bound to learn sparse adjacency matrix and eliminate self-loop paths by physical prior constraints.

5. The method of claim 1, wherein, The specific process of step S4 is: S41, define the sensor node embedding vector, calculate the similarity between sensor nodes, the calculation formula is: wherein, is the cosine similarity of the sensor node and , used to quantify the association strength between nodes; is the sensor node ; is the sensor node ; is the learnable embedding vector of the sensor node , representing its inherent characteristics; is the learnable embedding vector of the sensor node , representing its inherent characteristics; is the transpose of the vector ; is the L2 norm of the vector ; is the L2 norm of the vector ; S42, based on the multi-hop adjacency matrix weighted fusion to generate an aggregated adjacency matrix, the calculation formula is: Wherein, is the aggregated adjacency matrix; is a learnable decay coefficient; is a multi-hop adjacency matrix; is the hop number, k =1 represents a direct neighbor, k =2 represents a second-order neighbor; S43, the graph attention mechanism guided by the directed graph calculates the sensor network data space features, and the attention coefficient is determined by the joint of the adjacency weight and the feature interaction term, and the calculation formula is: , , , wherein, is the sensor network data space feature; is the rectified linear unit, introducing the nonlinear activation; is the attention weight of the sensor node to itself; is the attention weight of the sensor node i to the sensor node ; is the shared linear transformation matrix, used for feature mapping; is the input feature of the sensor node at time t ; is the input feature of the sensor node at time t ; is the neighbor set of the sensor node ; is the concatenation feature of the sensor node ; is the learnable embedding vector of the sensor node ; is the vector concatenation; is the feature interaction score of the sensor node and the sensor node ; is the activation function; is the learnable parameter vector, used for calculating the attention coefficient; is the concatenation feature of the sensor node ; is the adjacency weight; is the feature interaction score of the sensor node and the sensor node m ; is the sensor node m ; is the hop neighbor set of the sensor node k .

6. The directed graph spatiotemporal feature fusion-based IoT data anomaly detection method of claim 1, wherein, The specific process of step S6 is: S61, calculate the local prediction bias, and generate the normalized error based on the median-IQR standardization, the calculation formula is: , where, is the local prediction bias; is the actual observation value of the sensor node at time t ; is the predicted value of the sensor node at time t ; is the normalized error; is the median of the training set ; is the interquartile range of the training set ; S62, quantize the neighbor consistency error, the calculation formula is: wherein, is the neighbor consistency error; is the local prediction bias of the sensor node j ; S63, weighted fusion of normalized error and neighbor consistency error to generate final anomaly score: wherein, is the anomaly score; is the balance coefficient, determined by grid search on validation set; S64, calculating a dynamic threshold based on the sliding window quantile, the calculation formula is: wherein, is a dynamic threshold; is the third quartile of the abnormal score in the sliding window; is a dynamic threshold coefficient, used to control the sensitivity of the abnormality determination; is the interquartile range, IQR = Q3 - Q1; , is the first quartile;​ determination is abnormal data.

Citation Information

Patent Citations

  • Equipment health state assessment method based on fast graph transformation network

    CN116861330A

  • Time series data anomaly detection method combining graph learning and double attention mechanism

    CN118779804A