Internet of Things data anomaly detection method and system and electronic equipment
By performing matrix transformation on the recursive formula of the EWMA algorithm and using parallel processors for parallel computing, the problem of low efficiency of the traditional EWMA algorithm in large-scale IoT data processing is solved, and real-time fault detection and equipment safety and stability are achieved.
Patent Information
- Application Number
- CN202510540451.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-09-12
AI Technical Summary
The traditional EWMA algorithm is inefficient when processing large-scale IoT sensor data, has difficulty meeting the real-time requirements of fault detection, and has high resource usage, making it impossible to deploy in edge devices or embedded systems.
By performing matrix transformation on the recursive formula of the exponentially weighted moving average method, constructing a transformation matrix and using a processor with parallel processing capabilities such as a GPU for parallel computing, the output sequence is calculated directly through the input sequence and the preset initial matrix, eliminating the mutual dependence of the data in the result sequence.
It improves computing efficiency, meets the real-time processing needs of IoT sensor data, promptly detects equipment anomalies, ensures safe and stable operation of equipment, and reduces resource consumption, enabling it to be deployed on edge devices or embedded systems.
Smart Images

Figure CN120632274A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of parallel computing, and in particular to a method, system, and electronic device for detecting anomalies in Internet of Things data. Background Art
[0002] The Exponentially Weighted Moving Average (EWMA) is a statistical method that assigns different weights to data at different time points to calculate the average, which can better reflect recent changes. Therefore, EWMA is generally used to process physical network sensor data. However, the popularity of IoT devices and the development of edge computing have put higher demands on real-time data processing and fault detection.
[0003] Traditional EWMA methods typically obtain a sequence of outputs from a given input sequence. This implementation requires loop iteration, resulting in an algorithmic time complexity of O(N). This overhead increases with larger data volumes. Furthermore, due to the serial correlation, traditional weighted moving average methods cannot be parallelized. Consequently, traditional EWMA algorithms typically run on CPUs, making them inefficient when processing large-scale IoT sensor data and unable to meet the real-time requirements of fault detection. Furthermore, CPUs consume a lot of resources when processing large amounts of data, making them difficult to deploy on edge devices or embedded systems. Summary of the Invention
[0004] The embodiments of the present application provide a method, system, and electronic device for detecting anomalies in IoT data to at least address the problem in the related art that the traditional EWMA algorithm is inefficient when processing large-scale IoT sensor data.
[0005] In a first aspect, an embodiment of the present application provides a method for detecting anomalies in IoT data, the method being applied to a processor having a parallel processing function, the method comprising:
[0006] Acquire sensor monitoring data at different times, and acquire an input sequence based on the monitoring data, wherein the input sequence includes a transformation matrix, and the transformation matrix is acquired based on a recursive model of an exponentially weighted moving average method and a preset smoothing factor;
[0007] An output sequence is obtained by multiplying the input sequence and a preset initial matrix, wherein the elements in the output sequence represent the calculation results of the monitoring data at the corresponding moment;
[0008] In response to any element in the output sequence not meeting a preset threshold range, the monitoring data is determined to be abnormal data.
[0009] In one embodiment, the transformation matrix is obtained according to a recursive model of an exponentially weighted moving average method and a preset smoothing factor, including:
[0010] A recursive model of the exponentially weighted moving average method is obtained, and the recursive model is as follows:
[0011] y i =a i *y i-1 +b i *x i
[0012] The recursive model is subjected to matrix transformation based on a preset smoothing factor. The model after matrix transformation includes the transformation matrix:
[0013]
[0014] Among them, i represents the i moment, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i-1 represents the calculation result at time i-1, A represents the transformation matrix, A i Represents the input data at time i.
[0015] In one embodiment, the derivation process of obtaining an output sequence by multiplying the input sequence and a preset initial matrix includes:
[0016] The process of deducing the model after matrix transformation is as follows:
[0017]
[0018]
[0019] Among them, i represents the i-th moment, n represents the n-th data, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i Represents the calculation result at time i, A represents the transformation matrix, A i and A n represents the input sequence, C i represents the cumulative multiplication result of the input sequence, and y0 represents the preset initial matrix.
[0020] In one embodiment, the processor with parallel processing capabilities includes a GPU, and the processor is used to calculate the sensor detection data, the input sequence, and the initial matrix.
[0021] In one embodiment, the method further comprises:
[0022] In response to the monitoring data being abnormal data, an early warning message is issued, wherein the early warning message includes at least one of sound, light and text forms.
[0023] In a second aspect, an embodiment of the present application provides an anomaly detection system for IoT data, the system being applied to a processor having parallel processing capabilities, the system comprising:
[0024] Acquisition module: used to acquire sensor monitoring data at different times, and obtain an input sequence based on the monitoring data, wherein the input sequence includes a transformation matrix, and the transformation matrix is obtained based on a recursive model of an exponentially weighted moving average method and a preset smoothing factor;
[0025] Operation module: used for performing cumulative multiplication of the input sequence and a preset initial matrix to obtain an output sequence, wherein the elements in the output sequence represent the operation results of the monitoring data at the corresponding moment;
[0026] A judgment module is configured to judge that the monitoring data is abnormal data in response to any element in the output sequence not meeting a preset threshold range.
[0027] In one embodiment, the acquisition module includes:
[0028] The recursive model used to obtain the exponentially weighted moving average method is as follows:
[0029] y i =a i *y i-1 +b i *x i The recursive model is subjected to matrix transformation based on a preset smoothing factor. The model after matrix transformation includes the transformation matrix:
[0030]
[0031] Among them, i represents the i moment, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i-1 represents the calculation result at time i-1, A represents the transformation matrix, A i Represents the input data at time i.
[0032] In one embodiment, the acquisition operation module includes:
[0033] The process of deducing the model after matrix transformation is as follows:
[0034]
[0035] Among them, i represents the i-th moment, n represents the n-th data, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i Represents the calculation result at time i, A represents the transformation matrix, A i and A n represents the input sequence, C i represents the cumulative multiplication result of the input sequence, and y0 represents the preset initial matrix.
[0036] In a third aspect, an embodiment of the present application provides a computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for detecting anomalies in IoT data as described in the first aspect above is implemented.
[0037] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a method for detecting anomalies in IoT data as described in the first aspect above.
[0038] The embodiments of the present application provide a method, system, and electronic device for detecting anomalies in IoT data, which have at least the following technical effects.
[0039] This application transforms the original recursive formula to directly calculate the output sequence from the input sequence and a preset initial matrix. This eliminates the interdependence of data in the result sequence of the original recursive formula, so that elements in the result sequence do not have to wait for the previous calculation to complete, facilitating parallel computing. Furthermore, it utilizes processors with parallel computing capabilities to perform parallel computing to solve computing tasks, improving computing efficiency, meeting the real-time processing needs of IoT sensor data, and promptly detecting device anomalies, thereby ensuring safe and stable device operation.
[0040] The details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0042] Figure 1 This is a flow chart of a method for detecting anomalies in IoT data according to an embodiment of the present application;
[0043] Figure 2This is a structural block diagram of an anomaly detection system for IoT data according to an embodiment of the present application;
[0044] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0045] In order to make the purpose, technical solutions and advantages of this application more clearly understood, the present application is described and illustrated below in conjunction with the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely used to explain this application and are not intended to limit this application. Based on the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without making any creative efforts are within the scope of protection of this application.
[0046] Obviously, the drawings described below are merely examples or embodiments of the present application. Those skilled in the art can, without inventive effort, apply the present application to other similar scenarios based on these drawings. Furthermore, it is also understood that, although the effort involved in such a development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, changes in design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as an insufficiency of the content disclosed in this application.
[0047] References to "embodiments" in this application mean that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it refer to independent or alternative embodiments that are mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described in this application may be combined with other embodiments unless there is a conflict.
[0048] Unless otherwise defined, the technical or scientific terms used in this application should have the ordinary meaning understood by a person of ordinary skill in the technical field to which this application belongs. The words "one", "a", "the" and the like used in this application do not indicate a limit on quantity and may indicate the singular or plural. The terms "include", "comprise", "have" and any variations thereof used in this application are intended to cover non-exclusive inclusions; for example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units that are not listed, or may also include other steps or units that are inherent to these processes, methods, products or devices. The words "connect", "connected", "coupled" and the like used in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The word "multiple" used in this application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the objects before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.
[0049] In a first aspect, embodiments of the present application provide a method for detecting anomalies in IoT data, the method being used in conjunction with a processor having parallel processing capabilities. Optionally, the processor having parallel processing capabilities includes, but is not limited to, a graphics processing unit (GPU), a multi-core CPU, and a field programmable gate array (FPGA).
[0050] Figure 1 This is a flow chart of a method for detecting anomalies in IoT data according to an embodiment of the present application. Figure 1 As shown, the method includes:
[0051] Step S101 , acquiring sensor monitoring data at different times, and acquiring an input sequence according to the monitoring data, wherein the input sequence includes a transformation matrix, and the transformation matrix is acquired according to a recursive model of an exponentially weighted moving average method and a preset smoothing factor.
[0052] Optionally, the sensor monitoring data includes vibration, temperature, pressure, etc. The recursive formula of the exponentially weighted moving average can be expressed as y i =a i ×y i-1 +b i ×x i Among them, ai and b i Represents the smoothing factor, which is used to control the weight of each item, a i and b i Set based on experience and actual application scenarios. i Represents the input data at time i, y i-1 Indicates the result of the operation at time i-1. Exponentially weighted moving average usually represents a general problem, such as given an input sequence {x n 、x n-1 ,...,x0}, find the result sequence {y n 、y n-1 ,...,y0}.
[0053] The recursive formula for the original exponentially weighted moving average is typically implemented through loop iteration, resulting in an algorithmic time complexity of O(N), where N is the length of the input sequence. When the data scale is very large, the time overhead also increases with the data size. Furthermore, because the recursive formula is serially correlated, the interdependence of y in it prevents parallel computation, resulting in low computational efficiency.
[0054] In one example, step S101 includes:
[0055] A recursive model of the exponentially weighted moving average method is obtained, and the recursive model is as follows:
[0056] y i =a i *y i-1 +b i *x i
[0057] The recursive model is transformed into a matrix based on a preset smoothing factor. The transformed model includes the transformation matrix:
[0058]
[0059] Among them, i represents the i moment, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i-1 represents the calculation result at time i-1, A represents the transformation matrix, A i Represents the input sequence data at time i.
[0060] Optionally, a transformation matrix is constructed based on the characteristics of the recursive formula to weaken the connection between the current calculation and the previous calculation results, making it easier to decompose and block the calculation process for parallel computing and improve computational efficiency. The smoothing factor is used to control the weight of each data item. The value of the smoothing factor is (0,1]. The larger the smoothing factor, the higher the weight of the latest data point, indicating that the data prediction at this time will pay more attention to the recent trend changes and is more suitable for short-term predictions; the smaller the smoothing factor, the higher the weight of the corresponding historical data, which is suitable for long-term stable predictions. The smoothing factor is set based on experience and actual application scenarios.
[0061] Step S102 : performing cumulative multiplication on the input sequence and the preset initial matrix to obtain an output sequence, where the elements in the output sequence represent the calculation results at the time corresponding to the monitoring data.
[0062] Optionally, the output sequence is calculated directly using the input sequence and a preset initial matrix without waiting for the completion of the previous calculation, so that the intermediate results of the elements in the result sequence can be divided into blocks and calculated independently within the blocks, which is conducive to the parallel calculation of the exponentially weighted moving average method and improves the calculation efficiency.
[0063] In one example, the derivation process of obtaining the output sequence by multiplying the input sequence and the preset initial matrix in step S102 includes:
[0064] The process of deducing the model after matrix transformation is as follows:
[0065]
[0066] Among them, i represents the i-th moment, n represents the n-th data, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i Represents the calculation result at time i, A represents the transformation matrix, A i and A n represents the input sequence, C i Represents the cumulative multiplication result of the input sequence, and y0 represents the preset initial matrix.
[0067] Optionally, a smoothing factor is used to control the weight of each data point. The value of the smoothing factor is (0, 1). A larger smoothing factor gives a higher weight to the latest data point, indicating that the data forecast at this time will pay more attention to the recent trend changes and is more suitable for short-term forecasts. A smaller smoothing factor gives a higher weight to historical data and is suitable for long-term stable forecasts. The smoothing factor is set based on experience and actual application scenarios.
[0068] After the above steps, for a given input sequence {x n 、x n-1,...,x0}, find the result sequence {y n 、y n-1 , ..., y0}, through the recursive formula of exponentially weighted moving average y i =a i ×y i-1 +b i ×x i Implementation. It can be converted to: Given an input sequence {A n 、A n-1 , ..., A0}, output a sequence of equal rows {R n 、R n-1 , ..., R0}, where each element in the data sequence in, represents any binary operation, A n is the input sequence data determined according to the transformation matrix and monitoring data, and A0 and R0 are the preset initial matrices.
[0069] Step S103 : In response to any element in the output sequence not meeting a preset threshold range, the monitoring data is determined to be abnormal data.
[0070] Optionally, the sensor monitoring data includes vibration, temperature, pressure, etc. The preset threshold range can be determined based on prior data or other calculation methods. When performing anomaly detection, it is possible to judge in real time whether the detection data at the current moment is abnormal based on the sensor monitoring data obtained at different moments. It is also possible to judge whether the monitoring data at all moments input are abnormal based on the sensor detection data obtained at different moments. In addition, the sensor monitoring data is processed by a parallel processor such as a GPU, and the processing process is divided into two reduction stages and a scanning stage during parallel processing. Among them, each thread in the reduction stage processes a part of the data, and gradually merges the data in each step. For example, the monitoring data is processed in the reduction stage to obtain the input sequence, and the time complexity of the reduction stage is O(logN). The scanning stage propagates the local prefix product to the global based on the reduction result, and the time complexity of the scanning stage is O(logN).
[0071] This approach directly calculates the output sequence from the input sequence and a preset initial matrix, eliminating interdependencies in the resulting sequence. This allows for independent computation of intermediate results within each element of the resulting sequence, without having to wait for the previous calculation to complete. This facilitates parallel computing. By utilizing processors with parallel computing capabilities to solve computational tasks in parallel, this approach fully leverages hardware acceleration capabilities, improves computational efficiency, and meets the real-time processing needs of IoT sensor data, enabling timely detection of device anomalies and ensuring safe and stable operation.
[0072] In one example, a processor with parallel processing capabilities includes a GPU, and the processor performs calculations on sensor detection data, an input sequence, and an initial matrix.
[0073] Alternatively, GPUs, as specialized coprocessors, have a large number of computing units and naturally support large-scale thread concurrency. Transforming the original recursive formula into a general formula and directly calculating the output sequence from the input sequence and a preset initial matrix fully leverages the GPU's parallel computing capabilities, speeding up the algorithm and enabling real-time fault detection and timely identification of device anomalies. This also reduces resource consumption, making it suitable for deployment and operation on edge devices or embedded systems.
[0074] In one example, the method further includes: in response to the monitoring data being abnormal data, issuing an early warning message, the early warning message including at least one of sound, light, and text. Optionally, the fault early warning message can be presented in the form of sound, light, or text.
[0075] In some embodiments, the general model of the exponentially weighted moving average method in this application can also be used to make weather forecasts based on historical weather, and to calculate the volatility of financial assets, etc.
[0076] As an example, taking the analysis of bearing vibration data as an example, the computational efficiency of the traditional exponentially weighted moving average method and the anomaly detection method for IoT data provided by this application is compared. Bearings are key components in rotating equipment, and vibration signals are important indicators of the health status of bearings. Their failures can cause equipment downtime or even safety accidents. However, bearing vibration data usually contains noise, and it may be difficult to detect early faults directly through analysis methods such as thresholds. Table 1 shows the computational efficiency comparison of the anomaly detection method for IoT data provided by this application and the traditional method when analyzing the vibration trend of sensor data using a moving weighted average algorithm with a window size of 100. Among them, the window size represents the number of historical data involved in the calculation of each data point.
[0077] Table 1
[0078] Unit: s (seconds) 10^5 10^6 10^7 10^8 Abnormal detection method of this application 0.023s 0.023s 0.2s 0.4s Traditional methods 0.1s 3s 22s 296s
[0079] As shown in Table 1, when the data scale is large, as the data volume grows exponentially, the time complexity of the anomaly detection method for IoT data provided by this application grows slowly, which is much lower than the time complexity of traditional methods, and the computational efficiency is greatly improved compared with traditional methods.
[0080] In summary, this application transforms the original recursive formula and replaces it with a general formula. It directly calculates the output sequence through the input sequence and the preset initial matrix, eliminating the mutual dependence of the data in the result sequence. The intermediate results of the elements in the result sequence can be divided into blocks and calculated independently within the block without having to wait for the calculation of the previous item to be completed, which facilitates parallel computing. Processors with parallel computing capabilities are used to perform parallel computing to solve computing tasks, making full use of hardware acceleration capabilities, improving computing efficiency, meeting the real-time processing needs of IoT sensor data, and timely detecting device anomalies, thereby ensuring the safe and stable operation of the equipment. It can also reduce resource consumption, enabling it to be deployed and run on edge devices or embedded systems.
[0081] In a second aspect, an embodiment of the present application provides an anomaly detection system for IoT data, which is used to cooperate with a processor with parallel processing capabilities. Figure 2 This is a structural block diagram of an anomaly detection system for IoT data according to an embodiment of the present application. Figure 2 As shown, the system includes:
[0082] Acquisition module 100: used to acquire sensor monitoring data at different times, and obtain an input sequence based on the monitoring data. The input sequence includes a transformation matrix, which is obtained based on a recursive model of an exponentially weighted moving average method and a preset smoothing factor.
[0083] Operation module 200: used to obtain an output sequence by performing cumulative multiplication on the input sequence and a preset initial matrix, where the elements in the output sequence represent the operation results at the time corresponding to the monitoring data.
[0084] The judgment module 300 is configured to determine that the monitoring data is abnormal data in response to any element in the output sequence not meeting a preset threshold range.
[0085] In one example, the acquisition module 100 includes:
[0086] Get the recursive model of the exponentially weighted moving average method. The recursive model is as follows:
[0087] y i =a i *y i-1 +b i *x i
[0088] The recursive model is transformed into a matrix based on a preset smoothing factor. The transformed model includes the transformation matrix:
[0089]
[0090] Among them, i represents the i moment, a i and bi is the preset smoothing factor, x i represents the monitoring data at time i, y i-1 represents the calculation result at time i-1, A represents the transformation matrix, A i Represents the input data at time i.
[0091] In one example, the acquisition operation module 200 includes:
[0092] The process of deducing the model after matrix transformation is as follows:
[0093]
[0094] Among them, i represents the i-th moment, n represents the n-th data, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i Represents the calculation result at time i, A represents the transformation matrix, A i and A n represents the input sequence, C i Represents the cumulative multiplication result of the input sequence, and y0 represents the preset initial matrix.
[0095] In one example, a processor with parallel processing capabilities includes a GPU, and the processor performs calculations on sensor detection data, an input sequence, and an initial matrix.
[0096] In one example, the system further includes: a device for issuing an early warning message in response to the monitoring data being abnormal data, wherein the early warning message includes at least one of sound, light, and text.
[0097] In summary, this application transforms the original recursive formula and replaces it with a general formula. It directly calculates the output sequence through the input sequence and the preset initial matrix, eliminating the mutual dependence of the data in the result sequence. The intermediate results of the elements in the result sequence can be divided into blocks and calculated independently within the block without having to wait for the calculation of the previous item to be completed, which facilitates parallel computing. Processors with parallel computing capabilities are used to perform parallel computing to solve computing tasks, making full use of hardware acceleration capabilities, improving computing efficiency, meeting the real-time processing needs of IoT sensor data, and timely detecting device anomalies, thereby ensuring the safe and stable operation of the equipment. It can also reduce resource consumption, enabling it to be deployed and run on edge devices or embedded systems.
[0098] In a third aspect, an embodiment of the present application provides an electronic device, Figure 3This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements an anomaly detection method for IoT data provided in the first aspect. Figure 3 The electronic device 60 shown is only an example and should not limit the functions and scope of use of the embodiments of the present application.
[0099] The electronic device 60 may be a general-purpose computing device, such as a server device. Components of the electronic device 60 may include, but are not limited to, the at least one processor 61, the at least one memory 62, and a bus 63 connecting different system components (including the memory 62 and the processor 61).
[0100] The bus 63 includes a data bus, an address bus, and a control bus.
[0101] The memory 62 may include a volatile memory, such as a random access memory (RAM) 621 and / or a cache memory 622 , and may further include a read-only memory (ROM) 623 .
[0102] The memory 62 may also include a program / utility 625 having a set (at least one) of program modules 624, such program modules 624 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0103] The processor 61 executes various functional applications and data processing by running computer programs stored in the memory 62, such as an anomaly detection method for IoT data provided in the first aspect of the present application.
[0104] The electronic device 60 can also communicate with one or more external devices 64 (e.g., a keyboard, pointing device, etc.). This communication can occur via an input / output (I / O) interface 65. Furthermore, the model-generating device 60 can also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 66. As shown, the network adapter 66 communicates with other modules of the model-generating device 60 via a bus 63. It should be understood that, although not shown, other hardware and / or software modules can be used in conjunction with the model-generating device 60, including but not limited to microcode, device drivers, redundant processors, external disk drive arrays, RAID (RAID) systems, tape drives, and data backup storage systems.
[0105] It should be noted that although several units / modules or sub-units / modules of the electronic device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more units / modules described above may be embodied in a single unit / module. Conversely, the features and functions of a single unit / module described above may be further divided and embodied by multiple units / modules.
[0106] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having a program stored thereon. When the program is executed by a processor, the method for detecting anomalies in IoT data provided in the first aspect is implemented.
[0107] The readable storage medium may include, but is not limited to, a portable disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0108] In a possible implementation, the present invention can also be implemented in the form of a program product, which includes program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps of an anomaly detection method for Internet of Things data provided by the first aspect.
[0109] The program code for executing the present invention may be written in any combination of one or more programming languages, and may be executed entirely on the user device, partially on the user device, as an independent software package, partially on the user device and partially on a remote device, or entirely on the remote device.
[0110] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0111] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A method for detecting anomalies in IoT data, characterized in that: The method is applied to a processor with a parallel processing function, and the method includes: Acquire sensor monitoring data at different times, and acquire an input sequence based on the monitoring data, wherein the input sequence includes a transformation matrix, and the transformation matrix is acquired based on a recursive model of an exponentially weighted moving average method and a preset smoothing factor; An output sequence is obtained by multiplying the input sequence and a preset initial matrix, wherein the elements in the output sequence represent the calculation results of the monitoring data at the corresponding moment; In response to any element in the output sequence not meeting a preset threshold range, the monitoring data is determined to be abnormal data.
2. The method for detecting anomalies in IoT data according to claim 1, wherein: The transformation matrix is obtained according to the recursive model of the exponentially weighted moving average method and a preset smoothing factor, including: A recursive model of the exponentially weighted moving average method is obtained, and the recursive model is as follows: and i =a i *and i-1 +b i *x i The recursive model is subjected to matrix transformation based on a preset smoothing factor. The model after matrix transformation includes the transformation matrix: Among them, i represents the i moment, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i-1 represents the calculation result at time i-1, A represents the transformation matrix, A i Represents the input data at time i.
3. The method for detecting anomalies in IoT data according to claim 2, wherein: The derivation process of obtaining an output sequence by multiplying the input sequence and a preset initial matrix includes: The process of deducing the model after matrix transformation is as follows: Among them, i represents the i-th moment, n represents the n-th data, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i Represents the calculation result at time i, A represents the transformation matrix, A i and A n represents the input sequence, C i represents the cumulative multiplication result of the input sequence, and y0 represents the preset initial matrix.
4. The method for detecting anomalies in IoT data according to claim 1, wherein: The processor with parallel processing capabilities includes a GPU, and the processor is used to calculate the sensor detection data, the input sequence, and the initial matrix.
5. The method for detecting anomalies in IoT data according to claim 1, wherein: The method further comprises: In response to the monitoring data being abnormal data, an early warning message is issued, wherein the early warning message includes at least one of sound, light and text forms.
6. An anomaly detection system for Internet of Things data, characterized in that: The system is applied to a processor with a parallel processing function, and the system includes: Acquisition module: used to acquire sensor monitoring data at different times, and obtain an input sequence based on the monitoring data, wherein the input sequence includes a transformation matrix, and the transformation matrix is obtained based on a recursive model of an exponentially weighted moving average method and a preset smoothing factor; Operation module: used for performing cumulative multiplication of the input sequence and a preset initial matrix to obtain an output sequence, wherein the elements in the output sequence represent the operation results of the monitoring data at the corresponding moment; A judgment module is configured to judge that the monitoring data is abnormal data in response to any element in the output sequence not meeting a preset threshold range.
7. The anomaly detection system for Internet of Things data according to claim 6, characterized in that: The acquisition module includes: The recursive model used to obtain the exponentially weighted moving average method is as follows: and i =a i *and i-1 +b i *x i The recursive model is subjected to matrix transformation based on a preset smoothing factor. The model after matrix transformation includes the transformation matrix: Among them, i represents the i moment, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i-1 represents the calculation result at time i-1, A represents the transformation matrix, A i Represents the input data at time i.
8. The anomaly detection system for Internet of Things data according to claim 6, characterized in that: The acquisition operation module includes: The process of deducing the model after matrix transformation is as follows: Among them, i represents the i-th moment, n represents the n-th data, a i and b i is the preset smoothing factor, x i represents the monitoring data at time i, y i Represents the calculation result at time i, A represents the transformation matrix, A i and A n represents the input sequence, C i represents the cumulative multiplication result of the input sequence, and y0 represents the preset initial matrix.
9. An electronic device, characterized in that: The invention comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method for detecting anomalies in Internet of Things data according to any one of claims 1 to 5 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, an anomaly detection method for Internet of Things data according to any one of claims 1 to 5 is implemented.