Distributed detection method and system for trusted data of Internet of Things equipment

By performing distributed collaborative filtering with structured embedded coding and deep learning on edge servers, the problem of unreliable data of IoT devices in complex network environments is solved, and efficient and accurate anomaly detection is achieved.

CN120639796APending Publication Date: 2025-09-12SHANGHAI TEGAO INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510758180.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

IoT devices are susceptible to failures, interference, or malicious attacks in complex network environments, resulting in unreliable data. Traditional centralized and distributed detection methods are difficult to meet the requirements of high real-time performance and high accuracy, especially in utilizing the correlation between devices for collaborative credibility judgment.

Method used

By receiving real-time data from IoT devices at the edge server and performing structured embedding coding, and using the distributed collaborative filtering idea of ​​deep learning, the credibility of device data is evaluated and a collaborative credibility gain factor is generated for anomaly detection.

Benefits of technology

It achieves more accurate and robust distributed anomaly detection, improves the credibility and detection accuracy of IoT device data, adapts to dynamic network environments, and reduces latency and communication overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639796A_ABST
    Figure CN120639796A_ABST
Patent Text Reader

Abstract

The invention provides a distributed detection method and system for trusted data of Internet of Things equipment, and relates to the field of intelligent detection, and the method comprises the steps: firstly obtaining real-time data of first to Nth Internet of Things equipment, and carrying out the structural embedded coding; then, through a distributed collaborative filtering thought based on deep learning, namely, the behavior pattern of one device data can be evaluated by referring to the behavior pattern of a neighbor or similar device group, and the credibility of the single device data is judged by utilizing the potential relevance between the devices of the Internet of Things; and thus, complex association and consistency between the real-time data of the target Internet of Things equipment and group data distribution are mined and learned. And finally, more accurate and more robust distributed anomaly detection is realized by judging whether the real-time data of the target Internet of Things equipment deviates from the normal behavior mode of the group and generating a collaborative credible gain factor.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of intelligent detection, and more particularly, in an embodiment of the present application, to a method and system for distributed detection of trusted data of IoT devices. Background Art

[0002] With the rapid development and widespread application of the Internet of Things (IoT) technology, massive numbers of IoT devices are being deployed in various environments, from smart homes and smart cities to industrial automation and environmental monitoring, continuously generating large amounts of real-time data. This data forms the foundation for decision-making, control, and optimization for many upper-layer applications and services, making its reliability crucial. However, IoT devices are often deployed in complex physical environments, with volatile network conditions and even a lack of security protection. They are vulnerable to failures, interference, or malicious attacks (such as data forgery and tampering), resulting in the generation of abnormal or unreliable data. Once adopted by application systems, this unreliable data can lead to erroneous decisions, resulting in economic losses and even safety incidents. Furthermore, the distributed nature of IoT systems, the large number of devices, and the real-time requirements for data generation pose significant challenges to traditional centralized data detection methods, such as single-point computing bottlenecks, high latency, and high communication overhead.

[0003] To address data credibility issues in the IoT environment, some existing detection methods attempt to identify anomalous data locally on devices or central servers. For example, some solutions deploy simple rules or statistical models on devices for initial filtering, but this often struggles to capture complex anomalous patterns and is limited by the device's computing power. While transferring all data to the cloud for centralized analysis and processing can leverage more powerful computing resources and complex algorithms, these approaches face significant bandwidth pressure and high processing latency, making them difficult to meet the real-time requirements of many IoT applications (such as industrial control and autonomous driving). Furthermore, some distributed anomaly detection attempts may focus on independent analysis at each node or simple information aggregation, failing to fully leverage collaborative information across groups of devices to improve detection accuracy and robustness. Furthermore, these approaches may struggle to handle heterogeneous data, cope with dynamically changing network environments, and balance computational overhead with detection performance. These existing solutions often struggle to effectively address the challenges of IoT data's diverse sources, complex internal correlations, and high real-time requirements. They are particularly deficient in leveraging inter-device correlations for collaborative credibility assessment.

[0004] Therefore, an optimized distributed detection scheme for trusted data of IoT devices is desired. Summary of the Invention

[0005] In order to solve the above technical problems, the present application is proposed. The embodiment of the present application provides a distributed detection method and system for trusted data of IoT devices, which first obtains the real-time data of the first to Nth IoT devices and performs structured embedded coding. Then, through the distributed collaborative filtering idea based on deep learning, that is, the behavior pattern of a device data can be evaluated by referring to the behavior pattern of its "neighbors" or similar device groups, the potential correlation between IoT devices is used to judge the credibility of a single device data, thereby mining and learning the complex correlation and consistency between the real-time data of the target IoT device and the group data distribution. Finally, by judging whether the real-time data of the target IoT device deviates from the "normal" behavior pattern of the group and generating a collaborative trust gain factor, more accurate and robust distributed anomaly detection is achieved.

[0006] According to one aspect of the present application, a method for distributed detection of trusted data of an Internet of Things device is provided, which includes:

[0007] receiving, at the edge server, real-time data from first to Nth IoT devices;

[0008] Performing structured embedded coding on the real-time data of the first to Nth IoT devices to obtain structured embedded coding features of the real-time data of the first to Nth IoT devices, and extracting the structured embedded coding features of the real-time data of the i-th IoT device;

[0009] Performing distributed collaborative filtering on the real-time data structured embedded coding features of the i-th IoT device and the real-time data structured embedded coding features of the first to N-th IoT devices to obtain a device data collaborative trust gain factor;

[0010] Based on the comparison between the device data collaborative trustworthy gain factor and the preset threshold, it is determined whether the real-time data of the i-th Internet of Things device is abnormal.

[0011] According to another aspect of the present application, a distributed detection system for trusted data of IoT devices is provided, comprising:

[0012] An IoT device data acquisition module, configured to receive real-time data from the first to Nth IoT devices at the edge server;

[0013] a structured embedded coding extraction module, configured to perform structured embedded coding on the real-time data of the first to Nth IoT devices to obtain structured embedded coding features of the real-time data of the first to Nth IoT devices, and to extract the structured embedded coding features of the real-time data of the i-th IoT device;

[0014] a distributed collaborative filtering processing module, configured to perform distributed collaborative filtering on the structured embedded coding features of the real-time data of the i-th IoT device and the structured embedded coding features of the real-time data of the first to N-th IoT devices to obtain a device data collaborative trust gain factor;

[0015] The IoT device anomaly judgment module is used to determine whether the real-time data of the i-th IoT device is abnormal based on the comparison between the device data collaborative trust gain factor and the preset threshold.

[0016] Compared with the existing technology, the present application provides a distributed detection method and system for trusted data of IoT devices, which first obtains the real-time data of the first to Nth IoT devices and performs structured embedded coding. Then, through the distributed collaborative filtering concept based on deep learning, that is, the behavior pattern of a device data can be evaluated by referring to the behavior pattern of its "neighbors" or similar device groups, the potential correlation between IoT devices is used to judge the credibility of individual device data, thereby mining and learning the complex correlation and consistency between the real-time data of the target IoT device and the group data distribution. Finally, by judging whether the real-time data of the target IoT device deviates from the "normal" behavior pattern of the group and generating a collaborative trust gain factor, more accurate and robust distributed anomaly detection is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0018] Figure 1 The present invention is a flowchart of a method for distributed detection of trusted data of IoT devices according to an embodiment of the present application.

[0019] Figure 2 Schematic diagram of data flow of a method for distributed detection of trusted data of IoT devices according to an embodiment of the present application.

[0020] Figure 3 A flowchart for performing structured embedded coding on the real-time data of the first to Nth IoT devices in the distributed detection method for trusted data of IoT devices according to an embodiment of the present application to obtain structured embedded coding features of the real-time data of the first to Nth IoT devices, and extracting structured embedded coding features of the real-time data of the i-th IoT device.

[0021] Figure 4A flowchart of a method for distributed detection of trusted data of IoT devices according to an embodiment of the present application, in which the real-time data structured embedded coding vector of the i-th IoT device is used as a device data query vector, and the device data query vector and a set of the real-time data structured embedded coding vectors of the first to N-th IoT devices are input into a distributed collaborative filtering network based on deep learning to obtain the device data collaborative trust gain factor.

[0022] Figure 5 This is a system block diagram of a distributed detection system for trusted data of IoT devices according to an embodiment of the present application. DETAILED DESCRIPTION

[0023] Various exemplary embodiments, features, and aspects of the present application will be described in detail below with reference to the accompanying drawings. The same reference numerals in the accompanying drawings represent elements with the same or similar functions. Although various aspects of the embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.

[0024] The word “exemplary” is used exclusively herein to mean “serving as an example, example, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments.

[0025] In addition, numerous specific details are provided in the following detailed description to better illustrate the present application. Those skilled in the art will appreciate that the present application can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art are not described in detail in order to highlight the main purpose of the present application.

[0026] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. Throughout the description of this application, "plurality" means two or more, unless otherwise specifically defined.

[0027] With the rapid development and widespread adoption of the Internet of Things (IoT) technology, the number of IoT devices in various environments has skyrocketed. From smart homes and smart cities to industrial automation and environmental monitoring, these devices continuously generate vast amounts of real-time data. Numerous high-level applications and services rely on this data for decision-making, control operations, and system optimization, making data reliability paramount. However, IoT devices are often deployed in locations with complex physical conditions, volatile network environments, and even weak security protections. This makes them vulnerable to failures, interference, and even malicious attacks (such as data forgery or tampering), generating unreliable data. Once this untrustworthy data is incorporated into application systems, it can lead to erroneous decisions, resulting in financial losses or security incidents. Furthermore, given the distributed nature of IoT systems, the large number of devices, and the high real-time requirements, traditional centralized data verification approaches face significant challenges, such as single-point computing bottlenecks, long latency, and high communication costs. Existing solutions to address data reliability challenges in IoT environments include attempts to identify abnormal data locally on devices or on central servers. Some solutions choose to use basic rules or statistical models on the device to initially screen data. However, this approach often struggles to identify complex anomaly patterns and is limited by the device's own computing power. Transmitting all data to the cloud for processing using more powerful computing resources and advanced algorithms, while effective, also requires significant bandwidth and high latency, making it unsuitable for fast-response IoT applications such as industrial control and autonomous driving. Meanwhile, some distributed anomaly detection solutions attempt to address the problem through independent node analysis or simple information aggregation. However, these approaches fail to fully leverage the synergy between devices to improve detection accuracy and stability, and they also struggle to process heterogeneous data, adapt to dynamically changing network environments, and balance computational cost with detection performance. Current solutions struggle to cope with the wide range of IoT data sources, complex internal connections, and high real-time requirements. In particular, there is significant room for improvement in leveraging relationships between devices for collaborative trust assessment.

[0028] To address the above technical issues, the technical solution of this application proposes a distributed detection method for trusted data from IoT devices. Considering that the raw data generated by IoT devices is often heterogeneous and unstructured, direct processing is inefficient and difficult to capture deep features. Therefore, a structured embedded coding approach is used to process the real-time data from the first to Nth IoT devices. This method can transform diverse real-time data from different devices into a unified, low-dimensional structured vector representation rich in semantic information. Secondly, to fully leverage the potential correlations between IoT devices to determine the trustworthiness of individual device data, a distributed collaborative filtering approach based on deep learning is employed. Specifically, the behavioral pattern of a device's data can be evaluated by referencing the behavioral patterns of its "neighbors" or groups of similar devices. This allows for in-depth exploration and learning of the complex correlations and consistency between the target IoT device's real-time data and the group data distribution. This helps determine whether the target IoT device's real-time data deviates from the group's "normal" behavior pattern, generating a collaborative trust gain factor based on this information, enabling more accurate and robust distributed anomaly detection.

[0029] This application proposes a distributed detection method for trusted data of IoT devices. Figure 1 The present invention is a flowchart of a method for distributed detection of trusted data of IoT devices according to an embodiment of the present application. Figure 2 Schematic diagram of data flow of the method for distributed detection of trusted data of IoT devices according to an embodiment of the present application. Figure 1 and Figure 2 As shown, according to the embodiment of the present application, the distributed detection method for trusted data of IoT devices includes: S110, receiving real-time data from the first to N-th IoT devices at the edge server; S120, performing structured embedded coding on the real-time data of the first to N-th IoT devices to obtain structured embedded coding features of the real-time data of the first to N-th IoT devices, and extracting the structured embedded coding features of the real-time data of the i-th IoT device; S130, performing distributed collaborative filtering processing on the structured embedded coding features of the real-time data of the i-th IoT device and the structured embedded coding features of the real-time data of the first to N-th IoT devices to obtain a device data collaborative trusted gain factor; S140, determining whether there is an abnormality in the real-time data of the i-th IoT device based on a comparison between the device data collaborative trusted gain factor and a preset threshold.

[0030] In the above-mentioned distributed detection method for trusted data on IoT devices, step S110 involves receiving real-time data from first to Nth IoT devices at the edge server. It should be understood that with the development of Internet of Things (IoT) technology, a vast number of IoT devices have been deployed in various environments, continuously generating large amounts of real-time data. However, because IoT devices are often deployed in complex physical environments, with volatile network conditions, and even in scenarios lacking security protection, they are vulnerable to failures, interference, or malicious attacks, resulting in the generation of abnormal or unreliable data. Facing this challenge, receiving and initially processing real-time data from IoT devices on edge servers has become an effective solution. First, as data processing nodes close to IoT devices, edge servers can effectively reduce the time delay and communication overhead of data transmission to the cloud. Since many IoT applications (such as industrial control and autonomous driving) have high requirements for real-time data processing, directly sending all data to a remote data center for processing can result in significant latency, potentially leading to missed critical decision moments. Performing initial data reception and processing on edge servers can significantly shorten response times and improve overall system efficiency. Edge computing architectures can also employ encryption technologies to further enhance data security, ensuring that only authorized entities can access processed data. Furthermore, receiving real-time data from IoT devices on edge servers is crucial for improving robustness and adapting to dynamic changes. IoT environments feature numerous and widely distributed devices, and network conditions and device status can change at any time. In this context, relying on a single central server to manage data for all devices is neither practical nor efficient. Edge servers, on the other hand, can flexibly adapt to the specific conditions within their coverage area, quickly responding to local changes and collaborating with other edge nodes when necessary to complete complex tasks. This approach not only improves the system's fault tolerance but also enhances its flexibility to respond to emergencies. Specifically, IoT devices transmit collected real-time data using their respective communication protocols (such as Wi-Fi, ZigBee, and LoRa), while edge servers require the corresponding interfaces and technical capabilities to receive this data. This often means that edge servers must support multiple communication protocols to effectively connect and interact with different types of IoT devices. Furthermore, receiving real-time data at the edge server helps protect user privacy and data security. Since data collected by IoT devices may contain sensitive information, directly transmitting this data to the cloud can pose a risk of leakage. By processing data locally or close to the data source (i.e., edge servers), the spread of sensitive information can be greatly limited, reducing the risk of data leakage. After receiving data transmitted by IoT devices, the edge server will then perform preliminary analysis and organization of the received information.Because the raw, real-time data generated by IoT devices is often heterogeneous and unstructured, direct processing is inefficient and difficult to capture deep features. Therefore, preliminary data cleaning and formatting on edge servers is essential. Edge servers preprocess this raw data, including but not limited to removing noise, filling in missing values, and converting the data into a unified format for subsequent processing. This step not only improves data quality but also lays the foundation for subsequent data encoding and feature extraction.

[0031] Figure 3 This is a flowchart of performing structured embedding coding on the real-time data of the first to Nth IoT devices in the distributed detection method for trusted data of IoT devices according to an embodiment of the present application to obtain structured embedding coding features of the real-time data of the first to Nth IoT devices, and extracting structured embedding coding features of the real-time data of the i-th IoT device. Figure 3 As shown, in an embodiment of the present application, the step S120 includes: S121, performing structured embedded coding on the real-time data of the first to N-th Internet of Things devices to obtain a set of structured embedded coding vectors of the real-time data of the first to N-th Internet of Things devices as the structured embedded coding features of the real-time data of the first to N-th Internet of Things devices; S122, extracting the structured embedded coding vector of the real-time data of the i-th Internet of Things device from the set of structured embedded coding vectors of the real-time data of the first to N-th Internet of Things devices as the structured embedded coding features of the real-time data of the i-th Internet of Things device.

[0032] Specifically, in step S121, the real-time data of the first to Nth IoT devices are subjected to structured embedded coding to obtain a set of structured embedded coding vectors of the real-time data of the first to Nth IoT devices as the structured embedded coding features of the real-time data of the first to Nth IoT devices. It should be understood that the original real-time data generated by IoT devices usually has significant heterogeneity and unstructured characteristics. These data come from a wide range of sources and have various formats. Direct processing is not only inefficient, but also difficult to effectively capture the deep features and complex patterns contained therein, which brings challenges to subsequent precise analysis and credibility judgment. Therefore, in the technical solution of the present application, the real-time data of the first to Nth IoT devices are further subjected to structured embedded coding to obtain a set of structured embedded coding vectors of the real-time data of the first to Nth IoT devices. Through structured embedded coding, real-time data of various forms from different devices can be uniformly mapped into a normalized, low-dimensional vector space, generating a set of structured real-time data structured embedded coding vectors related to the first to Nth IoT devices. These vectors are not only in a unified format, which is convenient for subsequent model processing, but more importantly, they can condense and carry rich semantic information and potential association features in the original data, providing high-quality, information-intensive input for the subsequent use of deep learning networks for individual-group distribution learning and collaborative credibility assessment, thereby effectively improving the ability of the entire distributed detection solution to process heterogeneous data and mine deep associations, laying the foundation for more accurate and robust IoT device data credibility detection.

[0033] Specifically, step S122 extracts the real-time data structured embedding coding vector of the i-th IoT device from the set of real-time data structured embedding coding vectors of the first to N-th IoT devices as the real-time data structured embedding coding feature of the i-th IoT device. It should be understood that this allows us to shift from a macroscopic analysis of the semantic distribution of real-time data embedding across the IoT group to a microscopic analysis of individual IoT devices, treating the real-time data of a specific IoT device as a device data query vector to be evaluated, and analyzing the set of real-time data structured embedding coding vectors of the first to N-th IoT devices within the group.

[0034] In an embodiment of the present application, step S130 includes: using the structured embedded coding vector of the real-time data of the i-th IoT device as a device data query vector, and inputting the device data query vector and the set of structured embedded coding vectors of the real-time data of the first to N-th IoT devices into a deep learning-based distributed collaborative filtering network to obtain the device data collaborative trust gain factor. It should be understood that this essentially utilizes the powerful learning capabilities of deep networks to capture and integrate the complex, high-order correlations and dependencies between the individual device data and the data distribution of the entire device group. This process aims to deeply explore the behavioral patterns and consistency or differences of the real-time data of individual IoT devices in the context of group device data. The ultimate goal is to generate a quantitative indicator that reflects this collaborative relationship—the device data collaborative trust gain factor—to quantify the contribution or deviation of the device data query features to the semantics of the real-time data group of the first to N-th IoT devices. Specifically, the network can evaluate the trustworthiness of the i-th device data based on the interaction between the embedded semantics of the real-time data of individual IoT devices and the group, rather than relying solely on the isolated individual IoT device data. By processing the device data query vector within the context of a set of structured embedding encoding vectors for the real-time data of the first to Nth IoT devices, the network learns a more robust and discriminative representation because it incorporates global structural information and feature association information from the semantic graph of the real-time data population distribution. This enables the final output device data collaborative trust gain factor to more accurately reflect the degree of conformity or abnormality of the i-th device data relative to the "normal" behavior pattern of the population. This effectively overcomes the deficiency of traditional methods that fail to fully utilize collaborative information between devices, improving the accuracy of IoT data credibility detection and the ability to identify complex abnormal patterns.

[0035] Figure 4 A flowchart of a method for distributed detection of trusted data of IoT devices according to an embodiment of the present application, wherein the real-time data structured embedded coding vector of the i-th IoT device is used as a device data query vector, and the device data query vector and the set of the real-time data structured embedded coding vectors of the first to N-th IoT devices are input into a distributed collaborative filtering network based on deep learning to obtain the device data collaborative trust gain factor. Figure 4 As shown, in an embodiment of the present application, the step S130 includes: S131, calculating the real-time data group distribution semantic graph of the set of real-time data structured embedded coding vectors of the first to Nth Internet of Things devices; S132, mapping the device data query vector into the real-time data group distribution semantic graph to obtain the cluster distribution modulated device data query vector; S133, determining the device data collaborative trust gain factor based on the cluster distribution modulated device data query vector and the set of real-time data structured embedded coding vectors.

[0036] Specifically, step S131 calculates a real-time data group distribution semantic graph of a set of real-time data structured embedded coding vectors of the first to Nth IoT devices, which is expressed as a real-time data group distribution semantic calculation formula:

[0037] X={x1,x2,...,x i ,...,x N}

[0038]

[0039] Where X represents the set of real-time data structured embedding coding vectors of the first to Nth IoT devices, x1, x2, x j 、x N They represent the first, second, jth, and Nth real-time data structured embedded coding vectors in the set of real-time data structured embedded coding vectors, respectively. i The real-time data structured embedding coding vector of the i-th IoT device is used as the device data query vector, R(x1, x1), R(x N ,x1), R(x1,x N )、R(x N ,x N ) and R(x i ,x j ) represent the feature values ​​of (1,1), (N,1), (1,n), (N,N) and (i,j) positions in the real-time data group distribution semantic graph, [x i ;x j ] indicates x i and x j Cascade, W r represents the trainable weight matrix, b represents the trainable bias vector, r i,j Represents x i and x j The real-time data structured features between the interactive modulation coding vector, sigmoid represents the S-type activation function, r i,j,h Represents r i,j The eigenvalue of the hth position in , T represents r i,jThe length of M represents the real-time data group distribution semantic graph. It should be understood that computing the real-time data group distribution semantic graph, which is a collection of structured embedding code vectors for the real-time data of the first to Nth IoT devices, is intended to address the challenge of credibility assessment in distributed IoT device data due to the complex correlations and unstructured features. This step expands the feature relationships of device data from local linear associations to global high-order dependency modeling by constructing a graph-structured implicit semantic space. This takes into account the strong coupling between device data features—each feature does not exist independently but forms a dynamic association network through multi-level interactions. The real-time data group distribution semantic graph integrates feature distribution patterns, co-occurrence patterns, and spatial topology to map discrete features into a high-dimensional association space, breaking through the reliance of traditional analysis methods on local linear relationships. Essentially, this method leverages the unsupervised learning mechanism of graph neural networks to adaptively mine nonlinear dependencies and synergistic patterns between features, including implicit functional complementarity and semantic synergy, while maintaining the original data distribution characteristics. This graph-structured representation not only reconstructs the topological order between features, but also forms discriminative group contextual features through hierarchical aggregation, visualizing the semantic association paths of high-dimensional heterogeneous data. It provides a priori knowledge framework that includes feature importance weights and group coordination rules for subsequent trustworthy evaluation, effectively solving the problem of feature decoupling caused by the heterogeneity of device data in distributed environments.

[0040] In an embodiment of the present application, step S132 includes mapping the device data query vector to the device data group semantic feature space of the real-time data group distribution semantic graph to obtain a cluster distribution modulated device data query vector, where the cluster distribution modulated device data query formula is expressed as:

[0041]

[0042] in, represents matrix multiplication, v i represents the device data query vector after cluster distribution modulation. It should be understood that after completing the global distribution feature analysis of the set of real-time data structured embedded coding vectors of the first to Nth IoT devices, the micro-feature deconstruction phase begins. By decoupling the individual feature responses from the group distribution, the real-time data structured embedded coding vector corresponding to the i-th device is extracted as the device data query vector. This phase establishes an analysis paradigm based on the "individual-group" dual perspective. While preserving the statistical characteristics of the group distribution, it treats the device data query vector as an entity with independent semantic expression, emphasizing its heterogeneous contribution to group collaboration. This analytical framework transcends the limitations of traditional global modeling. By introducing a distinguishability measure for device-level features, it reveals the functional positioning differences of different device data query vectors in the group topology, providing theoretical support for the subsequent implementation of differentiated evaluation based on device characteristics.

[0043] To achieve a deep coupling of individual features with group context, the device data query vector is further embedded in the semantic association space constructed from the semantic graph of the real-time data group distribution, generating a cluster-distributed modulated device data query vector with group memory characteristics. This process essentially uses a graph-structured semantic space mapping mechanism to dynamically match the device data query vector with potential high-order association patterns in the group distribution. This process leverages the device synergy relationships and feature complementarity inherent in the semantic graph to perform context-aware enhancement on the original features. This modulation process not only involves a nonlinear transformation of the feature space but also adaptively incorporates group distribution information through the attention mechanism of a graph neural network. This modulated cluster-distributed modulated device data query vector carries the dual semantic components of both device-specific and group distribution features. The spatially reconstructed cluster-distributed modulated device data query vector not only enhances the representational power of the device data query vector but also significantly improves the accuracy of subsequent feature selection in discriminating between device synergies and anomalies by incorporating the topological constraints and co-occurrence patterns of the group distribution.

[0044] In an embodiment of the present application, the step S133 includes: S1331, performing global adaptive optimization on the cluster distribution modulated device data query vector to obtain an optimized cluster distribution modulated device data query vector; S1332, calculating the device data collaborative trust gain factor of the optimized cluster distribution modulated device data query vector relative to the set of real-time data structured embedded coding vectors.

[0045] In an embodiment of the present application, the step S1331 includes: S1331-1, based on the cluster distribution modulated device data query vector and the device data query vector, performing scale-invariant correction on the real-time data group distribution semantic graph to obtain the real-time data group distribution semantic fixed association matrix; S1331-2, based on the cluster distribution modulated device data query vector and the device data query vector, performing global correlation abnormal dimension correction on the device data query vector to obtain the cluster distribution modulated device data query vector; S1331-3, based on the real-time data group distribution semantic fixed association matrix and the cluster distribution modulated device data query vector, optimizing the expression of the cluster distribution modulated device data query vector to obtain the optimized cluster distribution modulated device data query vector.

[0046] Specifically, step S1331-1 performs a scale-invariant correction on the real-time data group distribution semantic graph based on the cluster distribution modulated device data query vector and the device data query vector to obtain a real-time data group distribution semantic invariant association matrix, which is expressed as a scale-invariant correction formula:

[0047]

[0048] Among them, ⊙-1 represents the inverse of the eigenvalue of each position in the vector, M i ' is x i The corresponding real-time data group distribution semantic immobile association matrix.

[0049] Specifically, in step S1331-2, based on the cluster distribution modulated device data query vector and the device data query vector, a global correlation abnormal dimension correction is performed on the device data query vector to obtain a cluster distribution modulated device data query vector, which is expressed as a global correlation abnormal dimension correction formula:

[0050] x' i =ln(v i )⊙[ln(x i ) ⊙-1 ]

[0051] Among them, ⊙ is the point multiplication by position, ln represents the logarithmic function value with the natural constant e as the base, x' i is x i Modified cluster distribution modulation device data query vector.

[0052] Specifically, in step S1331-3, based on the real-time data group distribution semantic fixed association matrix and the cluster distribution modulated device data query vector, the cluster distribution modulated device data query vector is optimized to obtain an optimized cluster distribution modulated device data query vector, which is expressed as the optimized expression formula:

[0053]

[0054] Among them, v' i is x' i The corresponding optimized cluster distribution modulated device data query vector.

[0055] Specifically, in step S1331, the inherent limitation of the semantic graph M of real-time data group distribution in capturing local correlation features through feature vector pair calculation is the global consistency misalignment phenomenon caused by local correlation constraints. The essence of this phenomenon is that the topological transmission process of the feature near-field energy distribution will produce coding distortion due to the non-uniformity of the semantic field, which in turn affects the global applicability of the device data group difference significance measurement. To this end, a scale-invariant correlation matrix needs to be constructed as a correction mechanism, that is, This process is done by characterizing the individual characteristics x i Set as the stable mapping point under the action of the semantic graph M of the real-time data group distribution, expand its beta function global conjugate distribution relative to the modulation result, and analyze the global critical dimension (i.e., abnormal dimension) that characterizes the local correlation defect, that is, x' i =ln(vi )⊙[ln(x i ) ⊙-1 ]. Then, through M i '-M to establish a nonlinear propagation channel in the energy scale dimension. This channel is achieved by By anchoring the abnormal dimension to the fixed point topology, the global reconstruction of the near-field energy fluctuations of local correlated defects in the scale-invariant space is achieved, thereby eliminating the universal deviation in the feature expression. This reconstruction method based on dynamical system theory effectively improves the device data query vector v by mapping the local abnormal energy disturbance into the invariant feature of the global scale transformation. i The discriminant accuracy in the embedding process of the semantic graph M of real-time data group distribution enables the difference significance measure to obtain the stability of global topological constraints while maintaining local sensitivity.

[0056] Specifically, step S1332 calculates the device data collaborative trust gain factor of the optimized cluster distribution modulated device data query vector relative to the set of real-time data structured embedded coding vectors, and the device data collaborative trust gain factor calculation formula is expressed as:

[0057]

[0058] Among them, v' i,k Indicates v' i The eigenvalue at the kth position in i,k represents the eigenvalue of the kth position in the device data query vector, L represents the length of the device data query vector, and λ i Indicates that v' i The corresponding real-time data suppression factor, π represents the circumference of a circle, arctan represents the inverse tangent function, Represents the device data collaboration trust gain factor. It should be understood that in order to evaluate the contribution of a single feature to the overall data distribution, the importance of individual features is quantified by calculating the device data collaboration trust gain factor. The device data collaboration trust gain factor measures the potential impact of a specific device data query vector on the group semantic expression ability by assuming its removal or retention. In essence, it is a feature importance assessment mechanism based on counterfactual reasoning. By simulating feature missing scenarios and evaluating the degree of attenuation of overall semantic representation ability, the device data collaboration trust gain factor reveals the causal effect of features in group collaboration and provides a quantifiable decision-making basis for feature selection. A high value of the device data collaboration trust gain factor indicates that the feature plays a key role in maintaining the semantic integrity of the group. Conversely, a low value indicates that it has high redundancy and can be used as a priority indicator for dynamic feature screening, thereby constructing an adaptive feature selection framework based on feature importance ranking.

[0059] In the above-mentioned distributed detection method for trusted data of IoT devices, step S140 determines whether the real-time data of the i-th IoT device contains anomalies based on a comparison between the device data collaborative trust gain factor and a preset threshold. It should be understood that comparing the device data collaborative trust gain factor with the preset threshold is essentially a statistically based decision-making process, designed to distinguish normal from abnormal data based on pre-set criteria. An ideal threshold should effectively identify true anomalies while minimizing false positives to ensure stable operation. In this process, the device data collaborative trust gain factor serves as a measurement indicator, the value of which directly reflects the degree of deviation of the target IoT device's real-time data from the group's behavior pattern. If the value of the device data collaborative trust gain factor is lower than the preset threshold, it indicates that the target IoT device's real-time data differs significantly from the group's behavior pattern, potentially indicating an anomaly. Conversely, if the device data collaborative trust gain factor is higher than or equal to the preset threshold, the target IoT device's real-time data is considered to conform to the group's "normal" behavior pattern and can be considered trusted data. Specifically, considering the importance of historical data, the distribution of the device data collaborative trust gain factor in past records can be analyzed to preliminarily set the threshold. By statistically analyzing a large amount of data under known normal operations, it is possible to identify the typical range of these data in the collaborative trust gain factor. This historical data-based approach helps understand the fluctuation range of the factor under normal conditions and, based on this, sets an initial threshold that covers most normal situations while effectively screening out anomalies. Secondly, domain knowledge is also an important basis for determining preset thresholds. When setting thresholds, full consideration should be given to the expertise and actual needs of a specific field. This includes, but is not limited to, understanding the common types of anomalies and their characteristics within the field, and the ability to tolerate different types of errors. Incorporating the opinions and experience of domain experts can help adjust the threshold more accurately, making it more in line with actual conditions.

[0060] In summary, a distributed detection method for trusted data of IoT devices based on an embodiment of the present application is illustrated, which first obtains the real-time data of the first to Nth IoT devices and performs structured embedding coding. Then, through the distributed collaborative filtering idea based on deep learning, that is, the behavior pattern of a device data can be evaluated by referring to the behavior pattern of its "neighbors" or similar device groups, the potential correlation between IoT devices is used to judge the credibility of a single device data, thereby mining and learning the complex correlation and consistency between the real-time data of the target IoT device and the group data distribution. Finally, by judging whether the real-time data of the target IoT device deviates from the "normal" behavior pattern of the group and generating a collaborative trust gain factor, more accurate and robust distributed anomaly detection is achieved.

[0061] Figure 5FIG is a system block diagram of a distributed detection system for trusted data of IoT devices according to an embodiment of the present application. Figure 5 As shown, according to an embodiment of the present application, a distributed detection system 100 for trusted data of an IoT device includes: an IoT device data acquisition module 110, which is used to receive real-time data from the first to N IoT devices at an edge server; a structured embedded coding extraction module 120, which is used to perform structured embedded coding on the real-time data of the first to N IoT devices to obtain structured embedded coding features of the real-time data of the first to N IoT devices, and extract the structured embedded coding features of the real-time data of the i-th IoT device; a distributed collaborative filtering processing module 130, which is used to perform distributed collaborative filtering processing on the structured embedded coding features of the real-time data of the i-th IoT device and the structured embedded coding features of the real-time data of the first to N-th IoT devices to obtain a device data collaborative trusted gain factor; an IoT device anomaly judgment module 140, which is used to determine whether there is an anomaly in the real-time data of the i-th IoT device based on a comparison between the device data collaborative trusted gain factor and a preset threshold.

[0062] Here, those skilled in the art will understand that the specific operations of each step in the above-mentioned IoT device trusted data distributed detection system have been referenced above. Figures 1 to 4 The invention has been introduced in detail in the description of the distributed detection method of trusted data of IoT devices, and therefore, its repeated description will be omitted.

[0063] As described above, the IoT device trusted data distributed detection system 100 according to the embodiment of the present application can be implemented in various terminal devices. In one example, the IoT device trusted data distributed detection system 100 can be integrated into the terminal device as a software module and / or hardware module. For example, the IoT device trusted data distributed detection system 100 can be a software module in the operating system of the terminal device, or can be an application developed for the terminal device; of course, the IoT device trusted data distributed detection system 100 can also be one of the many hardware modules of the terminal device.

[0064] Alternatively, in another example, the IoT device trusted data distributed detection system 100 and the terminal device may also be separate devices, and the IoT device trusted data distributed detection system 100 may be connected to the terminal device via a wired and / or wireless network and transmit interactive information in accordance with an agreed data format.

[0065] In summary, a distributed detection system for trusted data of IoT devices based on an embodiment of the present application is illustrated, which first obtains the real-time data of the first to Nth IoT devices and performs structured embedding coding. Then, through the distributed collaborative filtering idea based on deep learning, that is, the behavior pattern of a device data can be evaluated by referring to the behavior pattern of its "neighbors" or similar device groups, the potential correlation between IoT devices is used to judge the credibility of a single device data, thereby mining and learning the complex correlation and consistency between the real-time data of the target IoT device and the group data distribution. Finally, by judging whether the real-time data of the target IoT device deviates from the "normal" behavior pattern of the group and generating a collaborative trust gain factor, more accurate and robust distributed anomaly detection is achieved.

[0066] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the module division is merely a logical function division, and other division methods may be used in actual implementation.

[0067] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed across multiple network elements. Some or all of the modules may be selected to achieve the purpose of the solution of this embodiment according to actual needs.

[0068] In addition, the functional modules in various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or hardware plus software functional modules.

[0069] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0070] Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims rather than the foregoing description, and all changes that come within the meaning and range of equivalents of the claims are intended to be embraced therein. Any reference to a figure in a claim should not be construed as limiting the claim to which it relates.

[0071] Furthermore, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices recited in a system claim may also be implemented by a single unit or device through software or hardware. Second-order terms are used to indicate names and do not imply any particular order.

[0072] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit of the technical solutions of the present invention.

Claims

1. A distributed detection method for trusted data of IoT devices, characterized in that: include: receiving, at the edge server, real-time data from first to Nth IoT devices; Performing structured embedded coding on the real-time data of the first to Nth IoT devices to obtain structured embedded coding features of the real-time data of the first to Nth IoT devices, and extracting the structured embedded coding features of the real-time data of the i-th IoT device; Performing distributed collaborative filtering on the real-time data structured embedded coding features of the i-th IoT device and the real-time data structured embedded coding features of the first to N-th IoT devices to obtain a device data collaborative trust gain factor; Based on the comparison between the device data collaborative trustworthy gain factor and the preset threshold, it is determined whether the real-time data of the i-th Internet of Things device is abnormal.

2. The method for distributed detection of trusted data of IoT devices according to claim 1, characterized in that: Performing structured embedded coding on the real-time data of the first to N-th IoT devices to obtain structured embedded coding features of the real-time data of the first to N-th IoT devices, and extracting the structured embedded coding features of the real-time data of the i-th IoT device, including: Performing structured embedded coding on the real-time data of the first to Nth IoT devices to obtain a set of structured embedded coding vectors of the real-time data of the first to Nth IoT devices as structured embedded coding features of the real-time data of the first to Nth IoT devices; The real-time data structured embedding coding vector of the i-th Internet of Things device is extracted from the set of real-time data structured embedding coding vectors of the first to N-th Internet of Things devices as the real-time data structured embedding coding feature of the i-th Internet of Things device.

3. The method for distributed detection of trusted data of IoT devices according to claim 2, characterized in that: The real-time data structured embedded coding features of the i-th Internet of Things device and the real-time data structured embedded coding features of the first to N-th Internet of Things devices are subjected to distributed collaborative filtering processing to obtain a device data collaborative trust gain factor, including: using the real-time data structured embedded coding vector of the i-th Internet of Things device as a device data query vector, and inputting the device data query vector and the set of the real-time data structured embedded coding vectors of the first to N-th Internet of Things devices into a distributed collaborative filtering network based on deep learning to obtain the device data collaborative trust gain factor.

4. The method for distributed detection of trusted data of IoT devices according to claim 3, characterized in that: The method comprises: using the real-time data structured embedded coding vector of the i-th IoT device as a device data query vector, inputting the device data query vector and a set of the real-time data structured embedded coding vectors of the first to N-th IoT devices into a distributed collaborative filtering network based on deep learning to obtain the device data collaborative trust gain factor, including: Calculating a real-time data group distribution semantic graph of a set of real-time data structured embedding coding vectors of the first to Nth IoT devices; Mapping the device data query vector into a real-time data group distribution semantic graph to obtain a cluster distribution modulated device data query vector; The device data collaborative trust gain factor is determined based on a set of cluster distribution modulated device data query vectors and real-time data structured embedded coding vectors.

5. The method for distributed detection of trusted data of IoT devices according to claim 4, characterized in that: Mapping the device data query vector to a real-time data group distribution semantic graph to obtain a cluster distribution modulated device data query vector includes: mapping the device data query vector to a device data group semantic feature space of the real-time data group distribution semantic graph to obtain a cluster distribution modulated device data query vector.

6. The method for distributed detection of trusted data of IoT devices according to claim 5, characterized in that: Determining the device data collaborative trust gain factor based on a set of cluster distribution modulated device data query vectors and real-time data structured embedded coding vectors includes: Performing global adaptive optimization on the cluster distribution modulated device data query vector to obtain an optimized cluster distribution modulated device data query vector; Calculate the device data collaborative trust gain factor of the optimized cluster distribution modulated device data query vector relative to the set of real-time data structured embedding coding vectors.

7. The method for distributed detection of trusted data of IoT devices according to claim 6, characterized in that: Performing global adaptive optimization on the cluster distribution modulated device data query vector to obtain an optimized cluster distribution modulated device data query vector, including: Based on the cluster distribution modulated device data query vector and the device data query vector, the real-time data group distribution semantic graph is scale-invariantly modified to obtain the real-time data group distribution semantic invariant association matrix; Based on the cluster distribution modulated device data query vector and the device data query vector, performing global correlation abnormal dimension correction on the device data query vector to obtain the cluster distribution modulated device data query vector; Based on the real-time data group distribution semantic fixed association matrix and the cluster distribution modulated device data query vector, the cluster distribution modulated device data query vector is optimized to obtain the optimized cluster distribution modulated device data query vector.

8. A distributed detection system for trusted data of IoT devices, characterized in that: include: An IoT device data acquisition module, configured to receive real-time data from the first to Nth IoT devices at the edge server; a structured embedded coding extraction module, configured to perform structured embedded coding on the real-time data of the first to Nth IoT devices to obtain structured embedded coding features of the real-time data of the first to Nth IoT devices, and to extract the structured embedded coding features of the real-time data of the i-th IoT device; a distributed collaborative filtering processing module, configured to perform distributed collaborative filtering on the structured embedded coding features of the real-time data of the i-th IoT device and the structured embedded coding features of the real-time data of the first to N-th IoT devices to obtain a device data collaborative trust gain factor; The IoT device anomaly judgment module is used to determine whether the real-time data of the i-th IoT device is abnormal based on the comparison between the device data collaborative trust gain factor and the preset threshold.

9. The distributed detection system for trusted data of IoT devices according to claim 8, characterized in that: The structured embedded code extraction module is used to: Performing structured embedded coding on the real-time data of the first to Nth IoT devices to obtain a set of structured embedded coding vectors of the real-time data of the first to Nth IoT devices as structured embedded coding features of the real-time data of the first to Nth IoT devices; The real-time data structured embedding coding vector of the i-th Internet of Things device is extracted from the set of real-time data structured embedding coding vectors of the first to N-th Internet of Things devices as the real-time data structured embedding coding feature of the i-th Internet of Things device.