Abnormal behavior detection method of intelligent terminal remote management platform

By collecting multi-dimensional data streams in real time and performing regression analysis, dynamically generating anomaly detection thresholds and multi-dimensional correlation analysis, we can solve the problems of false detection and missed detection caused by hardware aging, environmental changes and user behavior differences in traditional methods, and realize efficient abnormal behavior detection and processing of the smart terminal remote management platform.

CN120654150AInactive Publication Date: 2025-09-16GUANGZHOU ZHIHUI NEW TERRITORIES SOFTWARE TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510744563.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-09-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional smart terminal remote management platforms are unable to accurately identify abnormal behaviors when faced with hardware aging, environmental changes, and differences in user behavior, resulting in false detections and missed detections. Existing methods also lack flexibility and cannot dynamically adjust processing strategies.

Method used

By collecting multi-dimensional data streams in real time, performing regression analysis to calculate the impact coefficient, dynamically generating anomaly detection thresholds, and combining multi-dimensional data analysis and processing models, dynamic adjustment and multi-dimensional correlation analysis are achieved to generate comprehensive anomaly scores and processing strategies.

Benefits of technology

It improves the accuracy of abnormal behavior detection, reduces the false alarm rate and missed alarm rate, enhances the system's adaptability and stability, and improves operation and maintenance efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120654150A_ABST
    Figure CN120654150A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal behavior detection method for a smart terminal remote management platform, which comprises the following steps: collecting multi-dimensional data streams of hardware state, software behavior, network communication and user operation in real time, dividing dynamic factors into three layers and nine classes, generating multiplicative / additive dynamic thresholds by utilizing regression analysis, and realizing abnormal association detection in combination with a multi-dimensional model. And a threshold value and a strategy are optimized in a closed-loop manner through historical data. According to the method, the limitation of a traditional fixed threshold is broken through, the problems of false detection and missing detection in dynamic scenes such as hardware aging and environment change are solved through dynamic factor modeling, the complex anomaly positioning capability is improved by utilizing multi-dimensional feature fusion, and intelligent operation and maintenance are realized by virtue of confidence classification and a strategy self-optimization mechanism. The method is suitable for intelligent terminal equipment in education, medical treatment and other scenes, and the anomaly detection accuracy and the system adaptability of a remote management platform are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of smart terminal remote management technology, and in particular to a method for detecting abnormal behavior of a smart terminal remote management platform, which is suitable for real-time monitoring of the hardware, software, network and user operation behavior of terminal devices, and realizes dynamic threshold adjustment and multi-dimensional anomaly detection. Background Art

[0002] With the widespread adoption of smart terminal devices, the importance of smart terminal remote management platforms has become increasingly prominent. However, in actual use, smart terminal devices face complex and changing operating environments, where abnormal behavior can occur across multiple dimensions, including hardware status, software behavior, network communications, and user operations. Traditional abnormal behavior detection methods typically use fixed thresholds, which are difficult to adapt to the varying operating states and environments of smart terminal devices. For example, hardware aging can cause device performance parameters to change, and fixed thresholds cannot accurately reflect the device's actual status, making false detections or missed detections likely.

[0003] Existing detection methods based on static thresholds have significant limitations. For one thing, static thresholds cannot adapt to the impact of dynamic factors such as hardware aging and ambient temperature fluctuations, resulting in detection results that are inconsistent with actual operating conditions. Furthermore, single-dimensional data analysis struggles to capture correlations between multi-dimensional data and cannot accurately identify complex abnormal behaviors caused by the combined effects of multiple factors. Furthermore, existing exception handling mechanisms lack flexibility and are unable to dynamically adjust handling strategies based on the severity and confidence level of abnormal behavior.

[0004] Although the technical solution disclosed in Chinese Patent Publication No. CN115080290A uses an intelligent algorithm for anomaly detection, it still has the following shortcomings: First, the solution mainly relies on static thresholds or single-dimensional data analysis, and cannot achieve collaborative analysis of multi-dimensional data; second, the solution lacks the ability to respond in real time to dynamic factors such as hardware status, environmental factors, and user behavior; finally, the solution's exception handling mechanism is relatively rigid and cannot dynamically adjust the processing strategy based on the actual situation of abnormal behavior.

[0005] Smart terminal remote management platforms face even more complex challenges in actual operation. At the hardware level, parameters such as touchscreen impedance drift and motherboard temperature fluctuations change over time. Environmental factors such as temperature, humidity, and electromagnetic interference can affect device performance. Furthermore, user behavior can vary depending on usage habits and load patterns. The interplay of these dynamic factors makes it difficult for traditional anomaly detection methods to accurately identify truly abnormal behavior.

[0006] Therefore, developing a method that can collect, dynamically analyze and accurately detect abnormal behaviors in the smart terminal remote management platform in real time is of great significance to improving the stability and security of the system. Summary of the Invention

[0007] The purpose of this application is to provide an abnormal behavior detection method and system for a smart terminal remote management platform, which has the advantages of dynamically adjusting the abnormal detection threshold, realizing multi-dimensional data collaborative analysis, and improving the accuracy of abnormal behavior detection.

[0008] The present application provides a method for detecting abnormal behavior of a smart terminal remote management platform, and the technical solution is as follows: real-time collection of multi-dimensional data streams of the platform, packaging the data streams of each dimension into data packets and integrating them into a multi-dimensional data set, the multi-dimensional data streams including at least hardware status data, software behavior logs, network communication indicators, and user operation characteristics; extracting dynamic factor data affecting the abnormal behavior detection standard from the multi-dimensional data set as independent variables, calculating the influence coefficient of each independent variable on the abnormal threshold through regression analysis, and correcting the preset abnormal behavior detection benchmark threshold based on the influence coefficient to dynamically generate the final abnormal detection threshold; inputting the parameters required for abnormal behavior detection of the multi-dimensional data set collected in real time into a multi-dimensional abnormal behavior detection model, and comparing the multi-dimensional data features with the dynamically generated abnormal detection threshold through the model, and outputting abnormal behavior detection results combined with one or more dimensional analysis; substituting the output abnormal behavior detection results into the abnormal behavior processing model, dynamically adjusting the parameters of each dimension of the platform based on the preset strategy or triggering the corresponding level of abnormal reminder operation to resolve the detected abnormal behavior. Preferably, the present application also proposes that the parameters required for abnormal behavior detection in hardware status data include: touch pressure value, motherboard temperature and power supply fluctuation parameters; the parameters required for abnormal behavior detection in software behavior logs include process resource occupancy rate, handwriting trajectory data packet integrity and driver abnormal event records; the parameters required for abnormal behavior detection in network communication indicators include screen mirroring delay, video stream encoding abnormality rate and conference connection handshake success rate; the parameters required for abnormal behavior detection in user operation characteristics include writing speed mean, pressure standard deviation, and daily usage time. Preferably, the present application also proposes extracting dynamic factor data affecting the anomaly detection standard from a multidimensional data set as an independent variable, calculating the influence coefficient of each variable on the anomaly threshold through regression analysis, and correcting the preset abnormal behavior detection benchmark threshold based on the influence coefficient to generate a dynamic anomaly detection threshold; including: defining the dynamic factors affecting the anomaly detection standard and dividing them into hardware layer dynamic factors, environment layer dynamic factors and user behavior layer dynamic factors; obtaining quantitative data of the dynamic factors of each layer from the multidimensional data set through real-time sensor collection or log file parsing; using the quantitative data of the dynamic factors as independent variables and the threshold deviation corresponding to the historical abnormal events as the dependent variable, using linear regression or nonlinear regression algorithm to calculate the influence coefficient of each independent variable on the anomaly threshold; using the preset benchmark threshold as the initial value, standardizing the quantitative data of each dynamic factor, and converting its original value into a dimensionless standardized value F i to eliminate the dimensional difference; assigning a corresponding influence coefficient ki to each dynamic factor, indicating the sensitivity of the factor to the threshold adjustment; based on the type of the dynamic factor, the standardized value F of the relevant parameters that jointly affect the same type of dynamic factors in the hardware layer, environment layer, and user behavior layer is converted into i and the corresponding influence coefficient ki are substituted into the multiplicative dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold; based on the type of dynamic factor, the standardized value Fi of the relevant parameters that independently affect a certain type of dynamic factor in the hardware layer, environment layer, and user behavior layer and the corresponding influence coefficient ki are substituted into the additive dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold. Preferably, the present application also proposes that the quantitative data of the dynamic factors of the hardware layer include at least: hardware aging-related parameters, including capacitor capacity attenuation rate, chip leakage rate, and solder joint oxidation degree; hardware operation status-related parameters, including touch screen impedance drift rate, motherboard temperature change, and power supply ripple fluctuation; hardware loss-related parameters, including touch screen wear degree and button contact oxidation rate; the quantitative data of the dynamic factors of the environment layer include at least: environmental physics-related parameters, including ambient temperature, humidity, and electromagnetic radiation intensity; power supply quality-related parameters, including grid voltage fluctuation percentage and frequency offset; mechanical environment-related parameters, including vibration amplitude and impact intensity; the quantitative data of the dynamic factors of the user behavior layer include at least: load mode-related parameters, including CPU occupancy, memory usage, and software operation type (gaming / office / rendering); operation interaction-related parameters, including touch frequency, button press strength, and the number of peripheral connections. Preferably, the present application also proposes that, based on the type of dynamic factors, the standardized values ​​Fi of the relevant parameters that jointly affect the same type of dynamic factors in the hardware layer, environment layer, and user behavior layer and the corresponding influence coefficient ki are substituted into the multiplicative dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold, including: real-time collection of quantitative data of the relevant parameters that jointly affect the same type of dynamic factors in the hardware layer, environment layer, and user behavior layer to obtain their standardized values ​​Fi; multiplying the standardized value Fi by the corresponding influence coefficient ki and adding the value obtained to 1 to calculate the adjustment item of each factor; multiplying the adjustment items of all dynamic factors and multiplying them by the benchmark threshold to obtain the corresponding dynamic anomaly detection threshold Td.

[0009] Preferably, the present application also proposes that, based on the type of dynamic factors, the standardized values ​​Fi of the relevant parameters that independently affect a certain type of dynamic factors in the hardware layer, environment layer, and user behavior layer and the corresponding influence coefficient ki are substituted into the additive dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold, including: real-time collection of quantitative data of the relevant parameters that independently affect a certain type of dynamic factors in the hardware layer, environment layer, and user behavior layer to obtain their standardized values ​​Fi; multiplying the standardized value Fi by the corresponding influence coefficient ki to obtain the value to calculate the adjustment item of each factor; adding the value obtained by adding the adjustment items of all dynamic factors to the baseline threshold to obtain the corresponding dynamic anomaly detection threshold Td. Preferably, the present application also proposes that the parameters required for abnormal behavior detection of the multidimensional data set collected in real time are input into a multidimensional abnormal behavior detection model, and the multidimensional data features are compared with the dynamically generated abnormal detection threshold through the model, and the abnormal behavior detection results combined with one or more dimensional analysis are output, including: normalizing the multidimensional data features to eliminate the dimensional differences between different dimensions; using a weighted fusion algorithm to assign weights according to the real-time confidence of each dimensional data to generate a comprehensive anomaly score; when the comprehensive anomaly score exceeds the dynamic anomaly detection threshold, triggering multidimensional correlation analysis to identify the main cause dimension and associated dimension combination of the abnormal behavior; outputting a structured detection result including an anomaly type label, an impact dimension list and a confidence score. Preferably, the present application also proposes to substitute the output abnormal behavior detection results into the abnormal behavior processing model, dynamically adjust the various dimensional parameters of the platform based on the preset strategy or trigger the corresponding level of abnormal reminder operation to solve the detected abnormal behavior, including: matching the predefined response policy library according to the abnormal type label, and selecting at least one repair operation of hardware reset, software process restart, and network connection switching; dividing the abnormal level based on the confidence score, automatically executing the repair operation when the confidence is higher than the first threshold, and generating a manual review request when it is lower than the first threshold but higher than the second threshold; recording the historical data of the abnormal handling process for optimizing the operation priority in the response policy library. Preferably, the present application also proposes that the switching logic between the multiplicative dynamic threshold calculation formula model and the additive dynamic threshold calculation formula model includes: when the dynamic factor belongs to hardware aging, ambient temperature or user load mode, the multiplicative dynamic threshold calculation formula model is preferentially used; when the dynamic factor belongs to hardware transient state, mechanical vibration or user single operation characteristics, the additive dynamic threshold calculation formula model is preferentially used; if the same type of dynamic factor has both multiplicative and additive model applicable conditions, a mixed dynamic threshold is generated by weighted average; the multiplicative dynamic threshold calculation formula model or the additive dynamic threshold calculation formula model sets an upper limit for the adjustment item to avoid a single factor from excessively affecting the threshold, and the formula is Td=T0+(T0*α); wherein α is the upper limit coefficient, with a value range of 0.2-0.5, and is dynamically adjusted according to the type of abnormality; α can also represent a preset proportional factor, which is used to limit the upper limit of the dynamic adjustment to prevent the threshold from being adjusted too large.

[0010] Preferably, the present application also proposes a feedback optimization mechanism for the anomaly detection threshold: regularly count the false alarm rate and missed alarm rate of the anomaly detection results, and calculate the threshold adjustment compensation value ΔT; when the false alarm rate exceeds the preset range, increase the baseline threshold by ΔT; when the missed alarm rate exceeds the preset range, lower the baseline threshold by ΔT; use the adjusted baseline threshold as the initial value for a new round of dynamic threshold calculation, and update the historical data set in the regression analysis. From the above, it can be seen that the abnormal behavior detection method and system for a smart terminal remote management platform provided in this application effectively solves the problem that the traditional fixed threshold method cannot adapt to hardware aging, environmental changes and user behavior differences by dynamically adjusting the abnormal detection threshold and combining multi-dimensional data analysis, significantly improving the accuracy of abnormal behavior detection and reducing the false alarm rate and missed alarm rate.

[0011] Compared with the prior art, the present invention has the following beneficial effects: 1. This case divides dynamic factors into hardware, environmental, and user behavior layers, and combines them with regression analysis to generate multiplicative and additive dynamic thresholds. This allows the system to adapt in real time to hardware aging (such as capacitor degradation), environmental changes (such as high temperatures), and user load fluctuations (such as high CPU usage). For example, the anomaly threshold is automatically lowered in response to hardware aging to avoid missed detections due to performance degradation; in high-temperature environments, the temperature threshold is dynamically tightened to prevent misinterpretation of normal temperature increases as anomalies. This fundamentally addresses the problem of traditional fixed thresholds being unable to adapt to dynamic device changes. This results in improved detection adaptability through a dynamic threshold mechanism.

[0012] 2. This case uses a weighted fusion algorithm to integrate multi-dimensional data such as hardware status, software logs, and network metrics to generate a comprehensive anomaly score and trigger correlation analysis, accurately identifying multi-factor coupled anomalies (such as a combined failure caused by hardware aging, high temperature, and high load). Compared to single-dimensional detection, this mechanism can capture the interaction between touch impedance drift and abnormal motherboard temperature, avoiding misjudgment of a single indicator, improving anomaly location accuracy, and significantly reducing troubleshooting time for operations and maintenance personnel; thus, multi-dimensional correlation analysis enhances anomaly location capabilities. 3. This case dynamically adjusts baseline thresholds by regularly analyzing false alarm and missed alarm rates, and updates the historical dataset for the regression model, enabling continuous optimization of the detection strategy over the device lifecycle. For example, after two years of use, the system automatically adjusts the capacitance attenuation coefficient based on aging data to maintain detection accuracy. In vibrating environments, historical data is used to optimize the weighting of vibration factors, reducing false alarm rates. This achieves a closed-loop evolution of "detection-assessment-correction," reducing reliance on manual maintenance. This closed-loop optimization mechanism enables self-evolution of the system.

[0013] 4. This case classifies anomalies based on confidence scores. High-confidence anomalies automatically trigger repair actions such as hardware downtime and process restarts, while medium-confidence anomalies generate manual review tickets to prevent low-confidence anomalies from falsely triggering actions. Furthermore, historical processing data optimizes policy priorities (for example, frequently failing repair actions are automatically downgraded), improving anomaly handling efficiency, shortening response time for critical faults, and balancing detection sensitivity with system stability. This intelligent hierarchical processing improves operational efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 It is a flow chart of the abnormal behavior detection method of the smart terminal remote management platform in this case. DETAILED DESCRIPTION

[0015] The technical solutions of this application will be described clearly and completely below, in conjunction with the accompanying drawings. It should be understood that the described embodiments represent only a portion of the embodiments of this application, and not all of them. The components of this application, generally described and illustrated in the drawings herein, may be arranged and designed in a variety of different configurations. Therefore, the following detailed description of the embodiments of this application provided in the drawings is not intended to limit the scope of the claimed application, but rather merely represents selected embodiments of this application. All other embodiments derived by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. Furthermore, in the description of this application, the terms "first," "second," etc., are used solely to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0016] In the traditional anomaly detection mechanism of existing smart terminal remote management platforms, fixed threshold strategies are unable to adapt to the interference of hardware performance degradation, environmental parameter fluctuations, and changes in user operation modes on anomaly judgment. Hardware operating status parameters and network communication indicators are dynamically coupled, and single-dimensional static detection models are unable to accurately capture the anomaly characteristics of multi-factor linkage, resulting in an increased false positive rate. For example, when the touch screen impedance drift and the motherboard temperature change in conjunction, the fixed threshold cannot distinguish between normal aging and signal offsets caused by abnormal short circuits, resulting in a decrease in the confidence level of anomaly detection. Furthermore, user operation frequency is dynamically correlated with software process resource utilization, and static detection rules are prone to misidentifying legitimate operations in high-load scenarios as abnormal processes. For example, in the management of industrial tablet devices equipped with touch interaction functions, long-term operation of the devices causes the capacitor capacity decay rate and the degree of solder joint oxidation to continuously increase, and the touch pressure value and the change in the motherboard temperature show a nonlinear correlation. When the ambient humidity exceeds the critical value and causes power ripple fluctuations, traditional detection models cannot accurately distinguish between normal power consumption fluctuations and power module failures because they lack an analysis mechanism for the correlation between hardware-layer dynamic factors and environmental-layer parameters. In this case, the coordinated changes in screen mirroring delay and video stream encoding anomaly rate are not included in the multi-dimensional feature fusion analysis, resulting in an increased rate of missed detection of network communication anomalies. If these issues are not addressed, anomaly detection models will be unable to adapt to the dynamic feature shifts of device groups at different stages of their lifecycles. False positives can trigger unnecessary hardware resets, accelerating device physical wear and tear. Undetected anomalous network connection behavior can lead to unauthorized data transmission, compromising the platform's security perimeter. In multi-user concurrent operation scenarios, unmodified detection thresholds can incorrectly suppress legitimate high-load processes, reducing platform service response efficiency and ultimately significantly decreasing device group availability and the robustness of the management platform.

[0017] When faced with the above problems, the present application first realized the interference of the coupling effect of dynamic factors on the anomaly detection threshold. For example, hardware aging and environmental parameters synergistically affect the impedance drift of the touch screen, and the traditional method has not established a multi-dimensional parameter correlation analysis mechanism. In this regard, the present application attempts to solve the defect that the fixed threshold cannot adapt to the performance degradation of hardware by introducing a multi-dimensional data stream to dynamically correct the baseline threshold. It was further discovered that the dynamic correlation between user operation mode and software resource occupancy rate has not been effectively modeled, resulting in misjudgment of high-load scenarios, so it is necessary to construct a multi-dimensional data fusion analysis framework. By performing regression analysis on environmental layer parameters and hardware status data, dynamically calculating the influence coefficient, and combining user behavior characteristics to achieve adaptive adjustment of the threshold, a multi-dimensional dynamic detection mechanism is formed. In this regard, the present application proposes an abnormal behavior detection method for a smart terminal remote management platform, which is applied to the smart terminal remote management platform and includes the following steps: real-time collection of multi-dimensional data streams of the platform, packaging the data streams of each dimension into data packets and integrating them into a multi-dimensional data set, the multi-dimensional data streams including at least hardware status data, software behavior logs, network communication indicators, and user operation characteristics; extracting dynamic factor data affecting the abnormal behavior detection standard from the multi-dimensional data set as independent variables, calculating the influence coefficient of each independent variable on the abnormal threshold through regression analysis, and correcting the preset abnormal behavior detection benchmark threshold based on the influence coefficient to dynamically generate the final abnormal detection threshold; inputting the parameters required for abnormal behavior detection of the multi-dimensional data set collected in real time into a multi-dimensional abnormal behavior detection model, and comparing the multi-dimensional data features with the dynamically generated abnormal detection threshold through the model, and outputting abnormal behavior detection results combined with one or more dimensional analysis; substituting the output abnormal behavior detection results into the abnormal behavior processing model, dynamically adjusting the various dimensional parameters of the platform based on the preset strategy or triggering the corresponding level of abnormal reminder operation to resolve the detected abnormal behavior.

[0018] The multidimensional data stream of the real-time acquisition platform refers to the simultaneous acquisition of operational data from the smart terminal remote management platform, including hardware status, software behavior, network communications, and user operations. This can be achieved through embedded sensors, log capture tools, or network traffic monitoring interfaces. By integrating real-time data from different dimensions, a comprehensive monitoring foundation is established. Extracting dynamic factor data that influences abnormal behavior detection criteria from multidimensional datasets as independent variables involves identifying time-varying parameters such as hardware aging, ambient temperature, and user load patterns. This can be achieved through principal component analysis or feature importance ranking algorithms, improving the efficiency of regression analysis by screening key variables. Calculating the influence coefficient of each independent variable on the anomaly threshold through regression analysis involves using statistical methods to quantify the strength of the association between different dynamic factors and abnormal events. This can be achieved through linear regression, ridge regression, or random forest regression algorithms. The weight parameters for each variable are obtained by training a model with historical data. Modifying the preset abnormal behavior detection baseline threshold based on the influence coefficient refers to adjusting the initial threshold based on the actual impact of the dynamic factors. This can be achieved through multiplicative or additive models. After standardization to eliminate dimensional differences, the coefficients are combined to dynamically calculate the threshold. A multi-dimensional abnormal behavior detection model is a comprehensive analysis model that integrates hardware, software, network, and user behavior data. It can be implemented using a weighted fusion algorithm or a deep learning model. Normalization eliminates dimensional differences and outputs a multi-dimensional anomaly score. An abnormal behavior processing model is an automated decision-making module with predefined response strategies. It can be implemented using a rules engine or reinforcement learning model. It triggers hardware resets, process restarts, or graded alerts based on the anomaly type and confidence score. The core innovation of this application lies in generating real-time adjusted anomaly detection thresholds through dynamic factor extraction and regression analysis, combining multi-dimensional data fusion and multi-model collaborative mechanism to solve the false alarm and missed alarm problems caused by fixed thresholds and single-dimensional analysis in traditional methods, and improve the accuracy and adaptability of abnormal behavior detection in complex environments.

[0019] The working process and principle of this application are as follows: the smart terminal remote management platform collects multidimensional data streams in real time, including hardware status data, software behavior logs, network communication indicators, and user operation characteristics. This data is packaged and integrated into a multidimensional dataset. Dynamic factors affecting the abnormal behavior detection standard are extracted from the multidimensional dataset as independent variables. Regression analysis is used to calculate the influence coefficient of each independent variable on the abnormality threshold. Based on these influence coefficients, the preset abnormal behavior detection baseline threshold is modified to dynamically generate the final abnormality detection threshold.

[0020] The parameters required for anomaly detection in multidimensional datasets collected in real time are fed into a multidimensional anomaly detection model. This model compares the multidimensional data features with dynamically generated anomaly detection thresholds and outputs anomaly detection results that combine analysis from one or more dimensions. This multidimensional analysis can capture complex anomaly patterns and improve detection accuracy.

[0021] The detection results are then fed into the abnormal behavior processing model. Based on pre-set policies, the model dynamically adjusts various platform parameters or triggers corresponding abnormality alerts to address the detected abnormal behavior. This dynamic adjustment mechanism enables the most appropriate response based on the actual situation, improving the system's adaptability and stability.

[0022] As a preferred embodiment, the solution of this application is specifically implemented as follows: In the smart terminal remote management platform, a data collection module is deployed to collect multi-dimensional data streams in real time. Hardware status data includes CPU temperature, memory usage, and hard drive read and write speeds; software behavior logs include process startup time, abnormal crash records, and resource usage; network communication indicators include network latency, packet loss rate, and bandwidth utilization; and user operation characteristics include click frequency, operation sequence, and session duration.

[0023] The data preprocessing module cleans and standardizes the collected data to form a unified multidimensional dataset. The dynamic factor extraction module identifies and extracts key factors that affect anomaly detection from the multidimensional dataset, such as hardware aging, ambient temperature changes, and user operation patterns.

[0024] The regression analysis module uses algorithms such as multivariate linear regression or support vector regression, taking the extracted dynamic factors as independent variables and the threshold deviation of historical anomaly events as the dependent variable, to calculate the coefficient of influence of each factor on the anomaly threshold. The threshold correction module dynamically adjusts the preset baseline threshold based on the calculated influence coefficient to generate an anomaly detection threshold that adapts to the current state.

[0025] The multi-dimensional abnormal behavior detection model receives real-time data and dynamic thresholds and uses machine learning algorithms (such as random forests or deep neural networks) to identify abnormal patterns. The model outputs the abnormal behavior type, impact dimension, and confidence score.

[0026] Based on the detection results and the pre-set policy library, the abnormal behavior processing module selects actions such as resetting hardware parameters, restarting software processes, or switching network connections. The processing results are recorded and used to continuously optimize the policy library and detection model.

[0027] Through the above solution, this application achieves dynamic adaptability and multi-dimensional analysis capabilities for abnormal behavior detection in the smart terminal remote management platform. The dynamic threshold adjustment mechanism effectively reduces false positives and missed positives due to hardware aging, environmental changes, or differences in user behavior. Multi-dimensional data fusion analysis improves the accuracy of identifying complex abnormal patterns. The dynamic selection and execution of abnormality handling strategies enhances the platform's self-healing capabilities. These improvements collectively enhance the stability, reliability, and security of the smart terminal remote management platform, providing more accurate and efficient remote management services for smart terminal device groups.

[0028] In some of the above-mentioned solutions in this application, when collecting the multi-dimensional data stream of the platform in real time, the specific parameters of hardware status data, software behavior logs, network communication indicators, and user operation characteristics are not clearly defined, resulting in a lack of specificity in the parameters required for abnormal behavior detection, and an inability to accurately capture changes in key indicators, affecting detection accuracy.

[0029] This application further proposes that the parameters required for abnormal behavior detection in hardware status data include touch pressure value, motherboard temperature and power fluctuation parameters; the parameters required for abnormal behavior detection in software behavior logs include process resource occupancy rate, handwriting trajectory data packet integrity and driver abnormal event records; the parameters required for abnormal behavior detection in network communication indicators include screen mirroring delay, video stream encoding abnormality rate and conference connection handshake success rate; the parameters required for abnormal behavior detection in user operation characteristics include writing speed mean, pressure standard deviation and daily usage time.

[0030] Touch pressure values ​​are collected in real time by pressure sensors, reflecting the physical state of the touchscreen. Mainboard temperature is periodically measured by temperature sensors to indicate hardware operational stability. Power supply fluctuation parameters are continuously monitored by voltage detection circuits to record the output stability of the power module. Process resource utilization is obtained through the operating system interface to monitor the computing resource consumption of software processes. The integrity of handwriting trace packets is verified by a verification algorithm to ensure that data transmission is not lost or tampered with. Driver abnormality event records are extracted using log analysis tools to identify underlying driver anomalies. Screen mirroring latency is measured using a network probe to assess real-time communication quality. Video stream encoding anomaly rate is calculated based on decoder feedback to detect encoding errors. Conference connection handshake success rate is calculated through protocol analysis to reflect network connection reliability. Mean writing speed is calculated using touch sampling data to capture user operating habits. Pressure standard deviation is calculated using pressure sensor data to measure touch operation stability. Daily usage time is accumulated using a timer to analyze user behavior patterns.

[0031] Specifically, touch pressure values ​​are analyzed in conjunction with motherboard temperature. When pressure values ​​increase abnormally and the temperature exceeds a threshold, a touchscreen hardware failure warning is triggered. Process resource utilization is correlated with driver abnormality event records. If resource utilization increases suddenly and the number of driver abnormality events increases simultaneously, abnormal software process behavior is identified. Screen mirroring latency and video stream encoding abnormality rates are monitored jointly. When latency exceeds a dynamic threshold and the encoding abnormality rate continues to rise, insufficient network bandwidth or an encoder failure is identified. The mean writing speed and pressure standard deviation are monitored in tandem. A sudden drop in the mean speed and abnormal fluctuations in the pressure standard deviation indicate abnormal user operation or touch device failure. Daily usage time data is used to establish a user behavior baseline. When actual usage time deviates from the baseline range, other parameters are combined to analyze whether it constitutes abnormal operation. For example, if the power fluctuation parameter exceeds the normal range and an abnormal increase in the motherboard temperature is detected, a hardware power module failure warning is triggered. If the handwriting trajectory packet integrity check fails and the conference connection handshake success rate (network communication indicator) decreases simultaneously, a network transmission link abnormality is identified.

[0032] As a preferred embodiment, the solution of this application is specifically implemented as follows: Parameters required for detecting abnormal behavior in hardware status data include touch pressure, motherboard temperature, and power fluctuation parameters. Touch pressure is collected in real time by a pressure sensor, motherboard temperature is monitored by a temperature sensor, and power fluctuation parameters are recorded by the power management chip.

[0033] Parameters required for detecting abnormal behavior in software behavior logs include process resource usage, handwriting trace packet integrity, and driver abnormal event records. Process resource usage is provided by the operating system task manager, handwriting trace packet integrity is achieved by checking packet header and tail identifiers, and driver abnormal event records are extracted from system log files.

[0034] Parameters required for abnormal behavior detection in network communication metrics include screen mirroring latency, video stream encoding anomaly rate, and conference connection handshake success rate. Screen mirroring latency is calculated by measuring the time difference between the sender and receiver. The video stream encoding anomaly rate is reported by the codec. The conference connection handshake success rate is calculated as the ratio of connection attempts to successful ones.

[0035] Parameters required for detecting abnormal behavior in user operation characteristics include mean writing speed, pressure standard deviation, and daily usage duration. Mean writing speed is calculated based on the time interval between handwriting sampling points, pressure standard deviation is based on statistical analysis of pressure sensor data, and daily usage duration is obtained by recording the time the device is turned on and off.

[0036] Through the above technical solution, this application realizes the comprehensive collection and analysis of multi-dimensional data of the smart terminal remote management platform. As a result, the system can comprehensively evaluate the device status from multiple angles such as hardware, software, network and user operation, thereby improving the accuracy and reliability of abnormal behavior detection. Furthermore, by collecting specific parameter indicators such as touch pressure value, motherboard temperature, process resource utilization, etc., the system can accurately locate potential problems, which helps to quickly diagnose and resolve abnormal situations, thereby improving the operation and maintenance efficiency and user experience of the smart terminal remote management platform.

[0037] In some of the above-mentioned schemes in this application, it is proposed to calculate the influence coefficient of dynamic factors on the abnormal threshold through regression analysis and correct the baseline threshold. However, when the types and interactive relationships of dynamic factors are complex, a single adjustment method cannot accurately reflect the differential impacts of hardware aging, environmental changes and user behavior, resulting in insufficient accuracy and adaptability of dynamic adjustment of the threshold.

[0038] This application further proposes a technical solution for extracting dynamic factor data from a multidimensional data set, dividing it into dynamic factors at the hardware layer, environmental layer, and user behavior layer, obtaining quantitative data through sensor or log analysis, and using linear or nonlinear regression algorithms to calculate the influence coefficient and perform multiplicative or additive dynamic adjustment on the benchmark threshold.

[0039] The dynamic factor classification includes hardware aging parameters, hardware operating status parameters, and hardware loss parameters. The environmental layer covers parameters such as temperature, humidity, and voltage fluctuations. The user behavior layer includes load patterns and operational interaction parameters. Normalization uses the Z-score method to eliminate dimensional differences. The multiplicative model is suitable for factors with long-term cumulative effects, while the additive model is suitable for factors with instantaneous fluctuations. The impact coefficient is obtained by training on a historical abnormal event dataset, and the regression model parameters are optimized using gradient descent.

[0040] Specifically, the capacitance decay rate is collected as a percentage by an electrochemical sensor, normalized, and multiplied by a baseline threshold to achieve aging compensation. Ambient temperature data is acquired in degrees Celsius by a temperature sensor, normalized, and combined with the grid voltage fluctuation parameter for additive adjustment. The CPU utilization rate in the user load mode is exponentially smoothed using real-time sampling, and its normalized value is input into the multiplicative model along with the memory utilization parameter. When both hardware and environmental factors affect the same detection metric, the multiplicative model is prioritized to account for the combined effects of aging and temperature, while instantaneous vibration data is additively added to the baseline threshold. The normalized value is calculated using a sliding window statistical method, with the window length set to 1 / 240 of the average device lifespan to ensure data trend stability. The regression model updates the impact coefficient every 24 hours and is trained using 30 days of historical abnormal event data.

[0041] As a preferred embodiment, the solution of this application is specifically implemented as follows: Dynamic factors that influence anomaly detection criteria are defined and categorized into hardware-layer dynamic factors, environmental-layer dynamic factors, and user-behavior-layer dynamic factors. Hardware-layer dynamic factors include capacitor capacity decay rate, chip leakage rate, and solder joint oxidation degree; environmental-layer dynamic factors include ambient temperature, humidity, and electromagnetic radiation intensity; and user-behavior-layer dynamic factors include CPU utilization, memory usage, and software type.

[0042] From multidimensional datasets, quantitative data on dynamic factors at each layer can be obtained through real-time sensor data collection or log file parsing. For example, a capacitance tester can be used to measure capacitance decay rate, a temperature and humidity sensor can be used to collect ambient temperature and humidity data, and CPU and memory usage can be obtained from system logs.

[0043] Using the quantitative data of dynamic factors as independent variables and the threshold deviations corresponding to historical abnormal events as dependent variables, a linear regression algorithm is used to calculate the influence coefficient of each independent variable on the abnormal threshold. Specifically, the least squares method is used to fit the regression equation to obtain the influence coefficient of each dynamic factor.

[0044] Using a preset baseline threshold as the initial value, the quantitative data for each dynamic factor is normalized, converting its raw value into a dimensionless standardized value, Fi. This normalization process uses the Z-score method, calculated as follows: Fi = (Xi - μ) / σ, where Xi is the raw value, μ is the mean, and σ is the standard deviation.

[0045] Each dynamic factor is assigned a corresponding influence coefficient ki, which indicates the sensitivity of the factor to threshold adjustment. The influence coefficient ki ranges from 0 to 1, with larger values ​​indicating greater sensitivity.

[0046] Based on the type of dynamic factors, the standardized values ​​Fi of the relevant parameters that affect the same type of dynamic factors in the hardware layer, environment layer, and user behavior layer, as well as the corresponding influence coefficients ki, are substituted into the multiplicative dynamic threshold calculation formula model to calculate the corresponding dynamic anomaly detection threshold. The multiplicative dynamic threshold calculation formula is: Td = T0* Π(1 + ki* Fi)* SF, where T0 is the reference threshold and π represents the multiplication.

[0047] Based on the type of dynamic factor, the standardized values ​​Fi of the relevant parameters that independently influence a specific type of dynamic factor at the hardware, environment, and user behavior layers, as well as the corresponding influence coefficients ki, are substituted into the additive dynamic threshold calculation model to generate the corresponding dynamic anomaly detection threshold. The additive dynamic threshold calculation formula is: Td = T0 + Σ(ki *Fi), where T0 is the base threshold and Σ represents the sum.

[0048] Through the above technical solution, the present application realizes the dynamic adjustment of the anomaly detection threshold and improves the accuracy of abnormal behavior detection. Since dynamic factors in multiple dimensions such as hardware, environment and user behavior are taken into account, the anomaly detection threshold can adapt to different operating states and environmental changes. By calculating the impact coefficient through regression analysis, the degree of influence of each dynamic factor on the threshold is accurately quantified, avoiding the errors caused by subjective settings. The use of multiplicative and additive dynamic threshold calculation models can flexibly handle different types of dynamic factors, making the threshold adjustment more accurate. In addition, the standardization process eliminates the influence of different dimensions, so that multi-dimensional data can be uniformly compared and calculated.

[0049] In some of the above-mentioned solutions in this application, dynamic factor data collection only focuses on parameters at a single level. The hardware layer may ignore the continuous impact of aging status on operational stability. The environmental layer fails to cover the combined effects of power supply quality and mechanical vibration on the physical structure of the equipment. The user behavior layer lacks coordinated monitoring of load patterns and interactive operations, resulting in missing data dimensions in dynamic threshold calculations, affecting the accuracy of anomaly detection.

[0050] This application further proposes that the quantitative data of dynamic factors at the hardware layer include at least hardware aging-related parameters, hardware operating status-related parameters, and hardware loss-related parameters; the quantitative data of dynamic factors at the environment layer include at least environmental physics-related parameters, power supply quality-related parameters, and mechanical environment-related parameters; the quantitative data of dynamic factors at the user behavior layer include at least load mode-related parameters and operation interaction-related parameters.

[0051] Hardware aging parameters monitor electrolyte depletion through capacitor capacity decay, chip leakage rate reflects semiconductor device aging, and solder joint oxidation measures metal connection reliability. Hardware operational status parameters identify contact performance degradation through touchscreen impedance drift, motherboard temperature variation captures fluctuations in cooling system efficiency, and power supply ripple fluctuation reflects the attenuation capability of the filter circuit. Hardware loss parameters quantify surface material loss through touchscreen wear, and key contact oxidation rate assesses contact impedance trends. Environmental physical parameters compensate for sensor measurement errors through ambient temperature and humidity data, while electromagnetic radiation intensity monitors signal interference source strength. Power quality parameters assess power adapter input stability through grid voltage fluctuation percentage, while frequency offset measures AC waveform distortion. Mechanical environmental parameters measure device structural stress distribution through vibration amplitude, while shock intensity records instantaneous mechanical load peaks. User behavior parameters, including CPU utilization and memory usage, reflect computing resource demand patterns, while software runtime type distinguishes workload characteristics. Touch frequency and press force are correlated to analyze interaction intensity, while the number of peripheral connections monitors interface resource utilization.

[0052] Specifically, the capacitance decay rate is calculated using the slope of the voltage-time curve. A hardware aging warning is triggered when the slope exceeds a threshold. The touchscreen impedance drift rate is measured using a four-wire method to measure surface resistance, combined with a temperature compensation algorithm to eliminate environmental interference. The grid voltage fluctuation percentage is sampled over a one-minute period, and the standard deviation of the effective value is calculated. Any fluctuation exceeding 5% of the baseline is considered abnormal. Vibration amplitude is collected using a three-axis accelerometer, and frequency domain feature extraction windows are set along the X, Y, and Z axes to identify resonant frequency offsets. Software runtime type classification uses a fuzzy matching algorithm for process names to establish a GPU call signature library for gaming processes and an I / O operation pattern library for office processes. Touch frequency counts the number of active touch points per unit time, and the peak-to-valley difference in pressure intensity is measured using a piezoelectric film sensor. These two factors are combined to generate a user operation intensity index. After all parameters are standardized, hardware aging parameters are used in multiplicative threshold adjustment, environmental vibration parameters in additive threshold adjustment, and user load parameters are incorporated into both models. This creates a multidimensional compensation mechanism that improves anomaly detection accuracy under complex operating conditions.

[0053] As a preferred embodiment, the solution of this application is specifically implemented as follows: Quantitative data of hardware layer dynamic factors include the following parameters: Hardware aging-related parameters: The capacitance attenuation rate is obtained by measuring the ratio of the actual capacitance of the capacitor to the rated capacitance; the chip leakage rate is calculated by measuring the static power consumption of the chip in standby mode; the degree of solder joint oxidation is quantified by detecting the rate of change of the solder joint resistance value.

[0054] Parameters related to hardware operating status: The touch screen impedance drift rate is obtained by periodically measuring the rate of change of the touch screen resistance value; the motherboard temperature change is obtained by using a temperature sensor to collect the motherboard temperature in real time and calculate the temperature difference between adjacent time points; the power supply ripple fluctuation is quantified by measuring the peak-to-peak value of the power supply output voltage.

[0055] Hardware wear-related parameters: The degree of touch screen wear is quantified by detecting changes in the reflectivity of the screen surface using an optical sensor; the oxidation rate of the key contacts is calculated by measuring the increase in the key contact resistance.

[0056] Quantitative data of dynamic factors of the environmental layer include the following parameters: Environmental physical parameters: Ambient temperature and humidity are collected in real time by temperature and humidity sensors; electromagnetic radiation intensity is measured by an electromagnetic field intensity meter.

[0057] Power supply quality related parameters: The grid voltage fluctuation percentage is calculated by measuring the ratio of the maximum deviation of the grid voltage to the rated voltage; the frequency offset is obtained by measuring the difference between the actual frequency and the standard frequency.

[0058] Mechanical environment related parameters: Vibration amplitude is measured by an accelerometer to measure the acceleration change of the equipment; shock intensity is quantified by recording the instantaneous acceleration peak value through a shock sensor.

[0059] Quantitative data on dynamic factors at the user behavior layer include the following parameters: Load mode-related parameters: CPU usage and memory usage are collected in real time through system monitoring tools; the software running type is determined by analyzing the process name and resource usage characteristics.

[0060] Operation interaction related parameters: touch frequency is obtained by counting the number of touch events per unit time; button pressing force is measured by a pressure sensor to measure the pressure value when the button is pressed; the number of peripheral connections is counted by detecting the number of connected USB devices and Bluetooth devices.

[0061] Through the above technical solution, this application can comprehensively collect dynamic factor data related to the hardware, environment and user behavior of smart terminal devices. The quantitative data of the dynamic factors at the hardware layer reflects the aging degree and real-time operating status of the device, the quantitative data of the dynamic factors at the environment layer captures the impact of the external environment on the performance of the device, and the quantitative data of the dynamic factors at the user behavior layer reflects the load characteristics of the device under different usage modes. These multi-dimensional dynamic factor data provide comprehensive and accurate input for subsequent abnormal behavior detection, which helps to improve the accuracy and sensitivity of anomaly detection. By collecting and analyzing these dynamic factors in real time, the system can adjust the anomaly detection threshold in a timely manner to adapt to the performance changes of the device in different usage scenarios and environments, thereby reducing false positives and missed positives and improving the reliability of abnormal behavior detection.

[0062] In some of the above-mentioned schemes of this application, the dynamic threshold adjustment process needs to deal with the situation where multiple dynamic factors jointly affect the same type of anomaly detection, but the traditional additive adjustment method is difficult to accurately reflect the synergistic effect of multiple factors, resulting in insufficient sensitivity of the threshold adjustment, affecting the accuracy of anomaly detection.

[0063] This application further proposes real-time collection of quantitative data on relevant parameters that jointly affect the same type of dynamic factors at the hardware layer, environment layer, and user behavior layer to obtain their standardized value Fi; the value obtained by multiplying the standardized value Fi by the corresponding influence coefficient ki is then added to the value 1 to calculate the adjustment item for each factor; the adjustment items of all dynamic factors are multiplied and multiplied by the baseline threshold to obtain the corresponding dynamic anomaly detection threshold Td. The specific formula is: Normalization uses the Z-score method to eliminate dimensional differences and ensure comparability across parameters. Adjustment terms are constructed using the (1 + ki × Fi) formula to maintain product stability and prevent zero values ​​from causing overall failure. Multiplication and superposition can amplify synergistic effects. For example, when the motherboard temperature and ambient temperature increase simultaneously, the multiplication relationship can amplify the temperature's impact on the threshold. The baseline threshold uses the device's factory calibration value as the initial benchmark and is dynamically updated using the formula Td = T0 × Π(1 + ki × Fi).

[0064] Specifically, taking the combined effects of touchscreen aging and rising ambient temperature as an example, a capacitance decay rate F1 = 0.3 corresponds to k1 = 0.15, and an ambient temperature change F2 = 2.5 corresponds to k2 = 0.08. The adjustment factors are 1 + 0.15 × 0.3 = 1.045 and 1 + 0.08 × 2.5 = 1.2, respectively. Multiplying these two factors yields a comprehensive adjustment coefficient of 1.045 × 1.2 = 1.254. If the baseline threshold T0 = 500, the dynamic threshold becomes 500 × 1.254 = 627. This calculation method exponentially reflects the combined effects of hardware aging and environmental changes. Compared to the additive model, which only produces a linear increment of 0.15 × 0.3 + 0.08 × 2.5 = 0.245, the multiplicative model better reflects the nonlinear coupling relationship of actual physical parameters. When multiple factors deviate from the normal range simultaneously, this model can quickly improve anomaly detection sensitivity and effectively prevent the missed detection of complex anomalies.

[0065] As a preferred embodiment, the solution of this application is specifically implemented as follows: Real-time quantitative data is collected for relevant parameters that jointly influence the same type of dynamic factors at the hardware, environmental, and user behavior layers, obtaining their standardized values, Fi. For example, for the hardware-level dynamic factor of touch screen impedance drift, data is collected every 10 minutes using the built-in impedance measurement circuit. The raw data is then converted to standardized values ​​between 0 and 1 using a maximum-minimum normalization method.

[0066] To calculate the adjustment term for each factor, multiply the normalized value Fi by the corresponding influence coefficient ki and add the value 1. Specifically, assuming the normalized value of the touch screen impedance drift rate is 0.8 and its corresponding influence coefficient is 0.5, the adjustment term for this factor is 1 + (0.8 * 0.5) = 1.4.

[0067] Multiply the adjustment items of all dynamic factors and multiply them by the baseline threshold to obtain the corresponding dynamic anomaly detection threshold Td. Further, assuming there are 3 dynamic factors, their adjustment items are 1.4, 1.2 and 1.3 respectively, and the baseline threshold is 100, then the dynamic anomaly detection threshold Td = 100 * 1.4 1.2 * 1.3 = 218.4.

[0068] Through the above technical solution, the present application can adaptively adjust the anomaly detection threshold according to the real-time status of multiple dynamic factors, thereby improving the accuracy and sensitivity of anomaly detection. As a result, the system can better adapt to dynamic influences such as hardware aging, environmental changes, and differences in user behavior, reducing the occurrence of false alarms and missed reports. Specifically, when the device is in a high temperature environment or high load state, the dynamic threshold will be increased accordingly to avoid normal performance fluctuations being misjudged as anomalies; and in the case of device aging or low load, the dynamic threshold will be appropriately lowered to capture potential abnormal conditions in a timely manner. This dynamic adjustment mechanism makes anomaly detection more in line with the actual operating status of the device, improving the reliability and stability of the smart terminal remote management platform.

[0069] In some of the above-mentioned solutions of this application, when extracting dynamic factor data from a multidimensional data set, if a multiplicative model is used for relevant parameters that independently affect a certain type of dynamic factor, it may not be able to accurately reflect the independent impact of a single factor on the threshold, resulting in deviations in the dynamic threshold adjustment. This application further proposes to substitute the standardized values ​​of relevant parameters that independently affect a certain type of dynamic factors in the hardware layer, environment layer, and user behavior layer and the corresponding influence coefficients into the additive dynamic threshold calculation formula model to generate a dynamic anomaly detection threshold. Normalized values ​​eliminate dimensional differences, making different parameters comparable. The influence coefficient quantifies the sensitivity of each factor to threshold adjustments. The additive model linearly superimposes the adjustment terms for each factor, achieving a direct cumulative effect of independent factors on the threshold. For example, the touchscreen impedance drift rate and ambient temperature can be considered independent factors at the hardware and environmental levels, respectively, with their adjustment terms additively affecting the baseline threshold. Specifically, after collecting quantitative data on the touch screen's impedance drift rate in real time, the raw values ​​are normalized and converted to a dimensionless, standardized value, F1. Assuming the influence coefficient k1 of this factor is 0.2, the adjustment term is F1 × k1. Simultaneously, the standardized value F2 corresponding to the ambient temperature and the influence coefficient k2 (for example, 0.15) are combined to calculate the adjustment term, F2 × k2. If the baseline threshold is T0, the dynamic anomaly detection threshold, Td, is generated using the formula Td = T0 + (F1 × k1) + (F2 × k2). When the touch screen's impedance drifts due to hardware aging, the F1 value increases. When added to the baseline threshold, Td also increases, thereby more accurately matching the current hardware state and avoiding false negatives caused by fixed thresholds. This additive model is applicable to transient states or single-time operation characteristics, such as sudden changes in motherboard temperature or abnormal single touch pressure by a user. It can quickly adjust the threshold based on independent factors, improving the real-time and accuracy of anomaly detection.

[0070] As a preferred embodiment, the solution of this application is specifically implemented as follows: Real-time quantitative data is collected for parameters independently influencing a specific type of dynamic factor at the hardware, environment, and user behavior layers to obtain a standardized value, Fi. For example, for the touch screen impedance drift rate at the hardware layer, the raw data collected is 5%, and after normalization, Fi = 0.5. For the ambient temperature at the environment layer, the raw data collected is 30°C, and after normalization, Fi = 0.6. For the CPU utilization at the user behavior layer, the raw data collected is 80%, and after normalization, Fi = 0.8.

[0071] Multiply the normalized value Fi by the corresponding influence coefficient ki to calculate the adjustment factor for each factor. Assume that the influence coefficient ki for the touch screen impedance drift rate is 0.2, the influence coefficient ki for the ambient temperature is 0.3, and the influence coefficient ki for the CPU usage is 0.5. The calculated adjustment factors are: 0.5 × 0.2 = 0.1, 0.6 × 0.3 = 0.18, and 0.8 × 0.5 = 0.4, respectively.

[0072] Add up the adjustment items of all dynamic factors and then add them to the baseline threshold to get the corresponding dynamic anomaly detection threshold Td. Assuming the baseline threshold is 100, the calculation formula for the dynamic anomaly detection threshold Td is: Td = 100 + (0.1 + 0.18 + 0.4) = 100.68 Through the above technical solution, this application achieves adaptive adjustment of anomaly detection thresholds based on multi-dimensional dynamic factors. As a result, the anomaly detection threshold can be dynamically adjusted based on real-time changes in hardware status, environmental conditions, and user behavior, improving the accuracy and flexibility of anomaly detection. Furthermore, by adopting an additive model, this solution can independently consider the impact of each dynamic factor on the threshold, avoiding mutual interference between factors and making threshold adjustment more precise and controllable.

[0073] In addition, the multiplicative dynamic threshold calculation formula model or the additive dynamic threshold calculation formula model sets an upper limit for the adjustment item to prevent a single factor from excessively affecting the threshold. In this case, the formula is Td=T0+(T0*α); where α is the upper limit coefficient, ranging from 0.2 to 0.5, and is dynamically adjusted according to the type of anomaly; α can also represent a preset proportional factor, which is used to limit the upper limit of the dynamic adjustment to prevent the threshold from being adjusted too much. Since each factor may have measurement errors (such as the touch impedance drift rate measurement error of ±15%), the weight coefficient ki has sample bias (limited training data coverage), and in extreme cases, a factor coupling amplification effect may occur (such as aging + high temperature + high load). Therefore, a hard upper limit must be set through T0×α to prevent mathematical calculations from breaking the physical safety boundary. The logic of introducing the upper limit constraint is to prevent the adjustment item from being amplified without limit in extreme cases, and the constraint conditions need to be introduced: When the calculated adjustment term is ≤ T0×α, the actual calculated value is used. When the calculated adjustment term is greater than T0×α, T0×α is mandatory.

[0074] In some of the above-mentioned solutions of this application, the multidimensional data set collected in real time contains data of different dimensions such as hardware status data, software behavior logs, network communication indicators, and user operation characteristics. Due to the differences in the dimensions and numerical ranges of the data of each dimension, a direct comprehensive comparison will cause the contribution of some dimensional data to the anomaly score to be magnified or reduced. In addition, the anomaly indicator of a single dimension may not accurately reflect the complex anomaly scenario of multiple factors coupling, and it is difficult to locate the main cause of the abnormal behavior.

[0075] This application further proposes a specific implementation plan of the multi-dimensional abnormal behavior detection model, including: normalizing multi-dimensional data features to eliminate dimensional differences between different dimensions; using a weighted fusion algorithm to assign weights based on the real-time confidence of each dimensional data to generate a comprehensive anomaly score; when the comprehensive anomaly score exceeds the dynamic anomaly detection threshold, triggering multi-dimensional correlation analysis to identify the main cause dimension and associated dimension combination of abnormal behavior; and outputting structured detection results including anomaly type labels, a list of impact dimensions, and a confidence score.

[0076] Normalization converts raw data of different dimensions into numerical values ​​in the range [0, 1] using extreme value or standardization methods. A weighted fusion algorithm assigns weights to each dimension based on real-time confidence. For example, the confidence weight for hardware status data is set to 0.3, and the weight for network communication metrics is set to 0.25. Multidimensional association analysis uses an association rule mining algorithm to calculate the correlation coefficient matrix between dimensions and select dimension combinations with correlation coefficients exceeding 0.7 as the primary contributing dimensions. Structured detection results are encapsulated in JSON format, including fields for anomaly type, dimension list, and confidence.

[0077] Specifically, the original value of the motherboard temperature in the hardware status data is 45°C, which is normalized to 0.45 using the extreme value method. The original value of the screen mirroring delay in the network communication metric is 200ms, which is normalized to 0.8. During weighted fusion, the motherboard temperature is assigned a weight of 0.3 and the delay is assigned a weight of 0.25, resulting in a composite anomaly score of 0.45 × 0.3 + 0.8 × 0.25 = 0.335. When this score exceeds the dynamic threshold of 0.3, the correlation analysis module identifies that the correlation coefficient between the motherboard temperature and the screen mirroring delay reaches 0.85, indicating a coupled fault caused by hardware cooling anomaly and insufficient network bandwidth. The output results are labeled "Hardware-Network Combined Anomaly" with the impact dimension list including motherboard temperature and screen mirroring delay, and a confidence score of 0.88. This structured data can be directly input into the anomaly handling module to trigger cooling optimization and network bandwidth switching.

[0078] As a preferred embodiment, the solution of this application is specifically implemented as follows: Normalize multidimensional data features to eliminate dimensional differences between different dimensions. Specifically, we use the min-max normalization method to map each dimension's data to the range [0, 1]. For example, for CPU utilization, we divide the original value by 100% to obtain the normalized result; for network latency, we divide the original value by the preset maximum acceptable latency to obtain the normalized result.

[0079] Furthermore, a weighted fusion algorithm is used to assign weights based on the real-time confidence of each dimension's data to generate a comprehensive anomaly score. The confidence level is determined by calculating the variance of the data in each dimension. A smaller variance indicates more stable data and a higher confidence level. The weights are assigned using the softmax function to ensure that the sum of all weights is 1. The comprehensive anomaly score is obtained through weighted summation.

[0080] Therefore, when the combined anomaly score exceeds the dynamic anomaly detection threshold, multi-dimensional correlation analysis is triggered to identify the primary contributing dimension and associated dimension combinations of the abnormal behavior. Specifically, the dimension with the greatest contribution is first identified as the primary contributing dimension. The correlation coefficients between the other dimensions and the primary contributing dimension are then calculated. Dimensions with correlation coefficients exceeding a preset threshold are considered associated dimensions.

[0081] Finally, the output is a structured detection result consisting of anomaly type labels, a list of impact dimensions, and a confidence score. The anomaly type labels are determined using a decision tree model based on the primary and associated dimensions. The impact dimension list includes the primary and all associated dimensions. The confidence score is calculated based on the difference between the comprehensive anomaly score and the dynamic threshold.

[0082] Through the above technical solution, this application achieves comprehensive analysis and anomaly detection of multidimensional data. Through normalization and weighted fusion, the dimensional differences of data of different dimensions are effectively eliminated, improving the accuracy of anomaly detection. Multidimensional correlation analysis can identify the main causes and related factors of abnormal behavior, providing more comprehensive information support for subsequent anomaly handling. Structured detection results facilitate system automation and manual analysis, improving the efficiency and accuracy of anomaly handling.

[0083] In some of the above-mentioned solutions of this application, exception handling relies on fixed rules and cannot dynamically adjust repair measures according to the confidence of the exception detection results, resulting in high-confidence exceptions not being handled in a timely manner or low-confidence exceptions being repaired incorrectly.

[0084] This application further proposes to substitute the abnormal behavior detection results into the abnormal behavior processing model, dynamically adjust the platform parameters or trigger abnormal reminder operations based on preset strategies, including matching the predefined response strategy library according to the abnormal type label, and selecting at least one repair operation among hardware reset, software process restart, and network connection switching; dividing the abnormality level based on the confidence score, automatically executing the repair operation when the confidence is higher than the first threshold, and generating a manual review request when it is lower than the first threshold but higher than the second threshold; recording historical data of the abnormality handling process for optimizing the operation priority in the response strategy library.

[0085] Among them, the response policy library contains the mapping relationship between anomaly types and repair operations. Hardware reset corresponds to motherboard temperature anomaly, software process restart corresponds to process resource usage anomaly, and network connection switching corresponds to screen mirroring delay anomaly; the confidence score is calculated by the degree of deviation between the comprehensive anomaly score output by the multi-dimensional abnormal behavior detection model and the dynamic threshold; the manual review request contains a list of abnormal dimensions and confidence distribution data; operation priority optimization adjusts the strategy execution order by statistically analyzing the success rate of historical operations.

[0086] Specifically, when a screen mirroring delay anomaly is detected, the anomaly type label matches the response policy library, triggering a network connection switching operation. At this time, the confidence score is 0.85, which is higher than the preset first threshold of 0.8, and the network port switching is performed directly. If the confidence score of the detected motherboard temperature anomaly is 0.75, which is between the first threshold of 0.8 and the second threshold of 0.7, a manual review work order is generated, and the hardware restart is performed after confirmation by the administrator. The results of each repair operation are recorded in the historical database. When statistics show that the success rate of the software process restart is less than 60%, the priority of the operation in the policy library is lowered, and the driver reload operation is performed first. Through the confidence grading mechanism, low-credibility anomalies triggering erroneous operations are avoided. At the same time, the operation success rate data is used to continuously optimize the response strategy and improve the efficiency of exception handling.

[0087] As a preferred embodiment, the solution of the present application is specifically implemented as follows: when the anomaly detection result is an abnormal software process resource usage, the anomaly type label is marked as "process overflow" and the confidence score is 0.87. The predefined matching strategies in the response strategy library include terminating the abnormal process, restarting the associated service, and clearing the memory cache. According to the confidence score threshold setting, the first threshold is 0.85 and the second threshold is 0.75. The system automatically performs process termination and memory cleanup operations, and generates a repair log containing the abnormal process ID and resource usage curve. If the confidence score is between 0.75 and 0.85, a manual review work order is generated and sent to the operation and maintenance terminal. The work order is accompanied by a process behavior timing diagram and associated network connection status data. All repair operation records are stored in the policy optimization database, including operation type, execution time and repair result verification indicators, which are used to count high-frequency repair actions and optimize the priority ranking of response strategies. Through the above technical solution, this application realizes the dynamic adaptation of the exception handling mechanism and the detection confidence, solving the problem that fixed rules cannot distinguish the severity of exceptions. By triggering automatic repair or manual intervention through confidence grading, the risk of misoperation in low-confidence scenarios is avoided, while ensuring the rapid closure of high-confidence exceptions. The continuous accumulation of historical operation data provides an empirical basis for strategy optimization, so that the priority of repair actions can be dynamically adjusted according to the actual operation and maintenance results, improving the efficiency and accuracy of exception handling.

[0088] In some of the above-mentioned solutions in this application, there are problems such as insufficient matching between repair measures and exception types during exception handling, lack of dynamic grading mechanism for exception responses, and lack of data support for policy optimization, which may lead to the repair operation deviating from actual needs, excessive reliance on manual processing for low-confidence exceptions, and lagging behind changes in device status in policy library updates.

[0089] This application further proposes a method for executing repair operations using an abnormal behavior processing model, including matching a response strategy library based on abnormal type labels, dividing abnormal levels based on confidence scores and triggering corresponding operations, while recording processing process data for strategy optimization.

[0090] The response policy library predefines mappings between various repair operations and anomaly types, such as hardware resets corresponding to hardware status anomalies, software process restarts corresponding to software behavior anomalies, and network connection switching corresponding to network communication anomalies. Confidence scoring uses a dual-threshold mechanism: the first threshold is set at 85% to trigger automatic repairs, and the second threshold is set at 60% as the manual review boundary. Historical data records include fields such as anomaly type, executed operation, repair time, and success rate. Data mining is used to optimize the operation priority ranking of the policy library.

[0091] Specifically, when an abnormal software process resource usage is detected, the exception type label is marked as "Abnormal Software Behavior," and a process restart is automatically triggered if the confidence score reaches 90%. If an abnormal touch pressure value is detected but the confidence score is 70%, the system generates a work order and submits it to the operations and maintenance personnel for review. After each exception is handled, the operation response time and repair success rate data are recorded. When the success rate of a certain type of operation falls below the set standard, its priority in the policy library is lowered. Through a confidence-driven hierarchical processing mechanism, while ensuring that high-confidence exceptions are handled promptly, low-confidence misjudgments that cause incorrect operations are avoided. The accumulation of historical data forms a closed-loop policy optimization, allowing repair strategies to dynamically adapt to the evolution of device operating status, improving the effectiveness and timeliness of exception handling.

[0092] As a preferred embodiment, the solution of the present application is specifically implemented as follows: in the process of generating anomaly detection thresholds of the remote management platform of the smart terminal, when dynamic factors related to hardware aging are monitored, such as the capacitance decay rate reaches 0.05% per hour and lasts for more than 72 hours, the multiplicative dynamic threshold calculation formula model is preferentially used. This model multiplies the standardized value corresponding to the capacitance decay rate by its influence coefficient and adds it to the baseline threshold, thereby reflecting the cumulative impact of the progressive degradation of hardware performance on the anomaly detection threshold. When an instantaneous hardware state change is detected, such as the motherboard temperature rises by more than 15 degrees Celsius within 5 minutes, the additive dynamic threshold calculation formula model is switched to, and the product of the standardized value of the temperature change and the influence coefficient is directly added to the baseline threshold to quickly respond to sudden anomalies. If the same abnormal event involves both hardware aging and ambient temperature fluctuations, such as capacitor aging causing the power ripple to increase instantaneously in a high temperature environment, the multiplicative model calculation result is distributed with a weight of 0.6, and the additive model calculation result is distributed with a weight of 0.4, and a mixed dynamic threshold is generated by weighted averaging.

[0093] Through the above technical solution, this application effectively solves the problem of insufficient threshold adaptability caused by differences in dynamic factor types. By distinguishing the impact of long-term cumulative effects and instantaneous state changes on the threshold, precise regulation of the detection threshold is achieved. The hybrid threshold generation method takes into account the gradual impact of slow variables such as hardware aging and the need for immediate response to emergencies, enabling the anomaly detection system to maintain stable detection sensitivity under complex working conditions and reducing the risk of misjudgment due to improper model selection.

[0094] In some of the above-mentioned schemes of this application, although the dynamically generated anomaly detection threshold can be adjusted in real time through regression analysis, the initial value of the benchmark threshold itself may be biased, resulting in the accumulation of false alarms or missed alarms over time, affecting the detection accuracy.

[0095] The present application further proposes to regularly count the false alarm rate and missed alarm rate of the abnormality detection results, and calculate the threshold adjustment compensation value ΔT; when the false alarm rate exceeds the preset range, the baseline threshold is increased by ΔT; when the missed alarm rate exceeds the preset range, the baseline threshold is lowered by ΔT; the adjusted baseline threshold is used as the initial value for a new round of dynamic threshold calculation, and the historical data set in the regression analysis is updated.

[0096] Among them, the false alarm rate and the missed alarm rate are counted every 24 hours, and the anomaly detection results generated by the platform during the statistical period are all marked as true positive or false positive; the calculation of ΔT is based on the weighted sum of the false alarm rate and the missed alarm rate, and the weight coefficient is set to 0.6 to 0.8 according to the anomaly type; the adjustment range of the baseline threshold is linearly related to ΔT, and the proportional factor is 1.2 to 1.5; the update of the historical data set adopts a sliding window mechanism with a window length of 30 days. Each update retains the data of the last 30 days and deletes the old data outside the window.

[0097] Specifically, when the system detects a false alarm rate exceeding 5% for three consecutive statistical periods, it triggers an increase in the baseline threshold. For example, if the current baseline threshold is 80 and the calculated ΔT is 3, the increased baseline threshold is 80 + 3 × 1.2 = 83.6. The adjusted threshold serves as the initial value for subsequent dynamic threshold calculations, and the detection data before and after the adjustment is stored in the historical dataset. When the false alarm rate exceeds 3%, the baseline threshold is adjusted downward using the same mechanism, with a scaling factor of 1.5. When updating the sliding window, a timestamp filtering mechanism is used to retain only the latest 30 days of data for each dynamic factor, ensuring the timeliness of the sample for regression analysis. This forms a closed-loop feedback loop, gradually optimizing the accuracy of the threshold baseline value.

[0098] As a preferred embodiment, the solution of the present application is specifically implemented as follows: After the anomaly detection system is deployed on the remote management platform of the smart terminal, the system starts the threshold feedback optimization process at the end of each quarter. The anomaly detection module retrieves the detection records of the past three months, and calculates the ratio of the number of false alarm events to the total number of normal events as the false alarm rate, and the ratio of the number of missed events to the total number of true abnormal events as the missed alarm rate. When the false alarm rate exceeds the preset upper limit of 5%, the deviation value between the current benchmark threshold and the historical optimal threshold is calculated as ΔT, and the benchmark threshold is increased by 0.3 times ΔT; when the missed alarm rate exceeds the preset upper limit of 2%, the benchmark threshold is lowered by 0.5 times ΔT. The adjusted benchmark threshold is immediately applied to the dynamic threshold calculation of the next cycle. At the same time, all hardware aging parameters, ambient temperature changes and user operation mode data in this cycle are added to the regression analysis training set, and the influence coefficient calculation model is retrained. This process adopts an automated closed-loop mechanism and does not require manual intervention.

[0099] The following are the specific methods of this case method in different scenarios: 1. Detect abnormal motherboard temperature Scenario Description: In a smart terminal remote management platform, the system continuously collects motherboard temperature data in real time. Assume that the preset baseline threshold is T0 = 70°C. The system also monitors dynamic factors affecting motherboard temperature, including ambient temperature (environmental layer) and CPU load (user behavior layer).

[0100] Dynamic factor quantitative data: ambient temperature: 30°C (assuming real-time data collection via environmental sensors), CPU load: 80% (assuming data collection via system monitoring tools); Dynamic factor influence coefficients (assuming they are derived through regression analysis): The influence coefficient of ambient temperature on the motherboard temperature threshold is k1 = 0.1, and the influence coefficient of CPU load on the motherboard temperature threshold is K2 = 0.2; Normalization (assuming the original values ​​of ambient temperature and CPU load have been normalized, the example values ​​are used directly here): ambient temperature normalization value F1 = 0.5 (assuming the normalization result of an ambient temperature of 30°C relative to the baseline ambient temperature of 25°C), CPU load normalization value F2 = 0.8 (assuming the normalization result of 80% load relative to the baseline load of 50%) Dynamic anomaly detection threshold calculation (using the multiplicative dynamic threshold calculation formula model, because the ambient temperature and CPU load jointly affect the motherboard temperature): Td = T0 *(1 + k1*F1)*(1 + k2*F2)= 70 *(1 + 0.1 *0.5) (1+ 0.2* 0.8)= 70 *1.05*1.16=85.26℃ Abnormal detection and processing: When the real-time collected motherboard temperature rises sharply to 90°C in a short period of time, exceeding the dynamically generated threshold of 85.26°C, the system automatically triggers the hardware protection mechanism, such as reducing the CPU frequency to 60% and starting the cooling fan at the highest speed to prevent hardware overheating and damage.

[0101] Anomaly detection of smart whiteboards in remote teaching scenarios Scenario description: During remote teaching, a certain model of smart whiteboard experiences touch delay and video freeze. The ambient temperature is 35°C and the device is three years old.

[0102] (1) Multidimensional data collection and standardized calculation Data Dimensions Original parameters Historical mean / standard deviation Normalized value (Fi) calculation Hardware Status Touch screen impedance drift rate 12% Mean 5%, standard deviation 2% F1 = (12%-5%) / 2% = 3.5 Motherboard temperature 78℃ Mean 65℃, standard deviation 5℃ F2 = (78-65) / 5 = 2.6 Dynamic factors in the environmental layer Ambient temperature 35℃ Mean 25℃, standard deviation 5℃ F3 = (35-25) / 5 = 2.0 Hardware aging parameters Capacitance decay rate 18% Mean 10%, standard deviation 3% F4 = (18%-10%) / 3% = 2.67 User behavior layer CPU usage 85% Mean 45%, standard deviation 15% F5 = (85%-45%) / 15% =2.67 (2) Dynamic threshold calculation (hybrid model) (2-1) Multiplicative model (synergistic effects of hardware aging + ambient temperature + load mode) Influence coefficient allocation: Capacitance attenuation rate k4 = 0.6; ambient temperature k3 = 0.3; CPU usage k5 = 0.5 Product of adjustment items: (1+0.6×2.67)×(1+0.3×2.0)×(1+0.5×2.67) = 2.602×1.6×2.335 ≈ 9.75 Reference threshold T0 = 70°C (mainboard temperature reference) (2-2) Additive model (independent influence of touch impedance) Influence coefficient k1 = 0.4 Adjustment: 0.4 × 3.5 = 1.4 (2-3) Hybrid threshold generation (multiplicative weight 0.7, additive weight 0.3), for dynamic factor data with both synergistic and independent effects, the hybrid model formula Td = β*(T0 Π(1 + ki* Fi))+(1-β)*(T0 + Σ(ki* Fi)) Td = 70×9.75×0.7 + (70+1.4)×0.3=499.17°C. The motherboard's upper temperature limit is typically 100°C, so 499.17°C is clearly unreasonable. Therefore, the adjustment item upper limit correction mechanism is enabled. The adjustment item upper limit is set to T0×α=70×0.2=14°C to ensure that the threshold correction does not exceed 20% of the baseline value to prevent mathematical calculations from exceeding the hardware safety boundary.

[0103] After correction (enabling the upper limit coefficient α = 0.2): Total of multiplicative adjustment terms = 70 + 14 = 84°C (3) Multi-dimensional abnormal correlation analysis Comprehensive anomaly score (weight distribution: hardware 0.4, environment 0.2, load 0.4): 0.4 × (3.5 + 2.6) + 0.2 × 2.0 + 0.4 × 2.67 = 0.4 × 6.1 + 0.4 + 0.4 × 2.67 = 2.44 + 0.4 + 1.068 = 3.908 (greater than the preset score threshold of 3, triggering multi-dimensional correlation analysis) Main factors: Touch resistance (F1=3.5) + Motherboard temperature (F2=2.6) Abnormality type label: "Hardware aging - high temperature - high load combined abnormality" (4) Intelligent response and threshold optimization Automatic execution: Hardware layer: Fan speed increased to 1800rpm (originally 1200rpm) Software layer: Close 3 non-teaching processes (free up 30% of memory) Touch layer: Enable impedance compensation algorithm (reduce drift rate by 20%) Threshold feedback optimization: False alarm rate statistics: currently 5% (preset 10%, within the limit) Capacitance attenuation coefficient (k4 from 0.6 to 0.65 (aging increased) (5) Quantification of effects index Before optimization After optimization Improvement Touch delay 200ms 80ms 60% Video freeze rate 15% 3% 80% Abnormal motherboard temperature false alarm 8 times / day 2 times / day 75% As described in the preceding embodiments, this application systematically divides the dynamic factors affecting anomaly detection into the hardware layer (aging / operating status / loss), the environmental layer (physical / power supply / mechanical), and the user behavior layer (load / interaction). Quantitative data is acquired through sensor and log analysis, and Z-score normalization is used to eliminate dimensional differences. A multiplicative model is used for common influencing factors (such as the synergistic effect of hardware aging and high temperature), while an additive model is used for independent influencing factors (such as mechanical vibration). Regression analysis is used to calculate the influence coefficient, enabling nonlinear dynamic adjustment of the threshold, addressing the problem that fixed thresholds cannot adapt to the coupling of multiple factors.

[0104] Through the above technical solution, this application effectively solves the problem of misjudgment caused by static thresholds in traditional methods that cannot adapt to device performance degradation and environmental changes. By periodically quantifying and evaluating detection accuracy and reversing the baseline threshold, the anomaly detection model remains robust to hardware aging and environmental parameter drift. Combined with a dynamic expansion mechanism for historical data sets, the parameter sensitivity of the regression analysis model is further optimized, forming a self-iterating anomaly detection system that significantly reduces the frequency of manual maintenance.

[0105] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, various modifications and variations of the present application are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. An abnormal behavior detection method for a smart terminal remote management platform, applied to a smart terminal remote management platform, is characterized in that: The following steps are involved: Real-time acquisition of the platform's multi-dimensional data streams, packaging each dimension's data stream into a data packet and integrating it into a multi-dimensional data set, the multi-dimensional data streams including at least hardware status data, software behavior logs, network communication indicators, and user operation characteristics; Extracting dynamic factor data that affects the abnormal behavior detection standard from the multidimensional data set as independent variables, calculating the influence coefficient of each independent variable on the abnormal threshold through regression analysis, and modifying the preset abnormal behavior detection benchmark threshold based on the influence coefficient to dynamically generate a final abnormal behavior detection threshold; Inputting the parameters required for abnormal behavior detection of the multidimensional data set collected in real time into a multidimensional abnormal behavior detection model, and using the model to compare the multidimensional data features with the dynamically generated abnormality detection threshold, and outputting abnormal behavior detection results combined with one or more dimensional analysis; The output abnormal behavior detection results are substituted into the abnormal behavior processing model, and the various dimensional parameters of the platform are dynamically adjusted based on the preset strategy or the corresponding level of abnormal reminder operations are triggered to resolve the detected abnormal behavior.

2. The method according to claim 1, characterized in that The parameters required for abnormal behavior detection in the hardware status data include: touch pressure value, motherboard temperature and power supply fluctuation parameters; the parameters required for abnormal behavior detection in the software behavior log include process resource occupancy rate, handwriting trajectory data packet integrity and driver abnormal event records; the parameters required for abnormal behavior detection in the network communication indicators include screen mirroring delay, video stream encoding abnormality rate and conference connection handshake success rate; the parameters required for abnormal behavior detection in the user operation characteristics include writing speed mean, pressure standard deviation, and daily usage time.

3. The method according to claim 1, characterized in that The method of "extracting dynamic factor data affecting anomaly detection criteria from the multidimensional dataset as independent variables, calculating the influence coefficient of each variable on the anomaly threshold through regression analysis, and modifying a preset abnormal behavior detection benchmark threshold based on the influence coefficient to generate a dynamic anomaly detection threshold" includes: Define the dynamic factors that affect anomaly detection standards and divide them into hardware layer dynamic factors, environment layer dynamic factors, and user behavior layer dynamic factors; From the multidimensional dataset, quantitative data of dynamic factors at each layer is obtained through real-time sensor collection or log file analysis; Using the quantitative data of the dynamic factors as independent variables and the threshold deviation corresponding to historical abnormal events as dependent variables, a linear regression or nonlinear regression algorithm is used to calculate the influence coefficient of each independent variable on the abnormal threshold; Using the preset benchmark threshold as the initial value, the quantitative data of each dynamic factor is standardized and its original value is converted into a dimensionless standardized value F i to eliminate the dimension difference; Assigning a corresponding influence coefficient ki to each dynamic factor, indicating the sensitivity of the factor to the threshold adjustment; Based on the type of dynamic factors, the standardized values ​​Fi of the relevant parameters that jointly affect the same type of dynamic factors in the hardware layer, environment layer, and user behavior layer, as well as the corresponding influence coefficients ki, are substituted into the multiplicative dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold; Based on the type of dynamic factors, the standardized values ​​Fi of the relevant parameters that independently affect a certain type of dynamic factors in the hardware layer, environment layer, and user behavior layer, as well as the corresponding influence coefficient ki, are substituted into the additive dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold.

4. The method according to claim 3, characterized in that The quantitative data of the hardware layer dynamic factors at least include: Hardware aging-related parameters, including capacitor capacity decay rate, chip leakage rate, and solder joint oxidation degree; Parameters related to hardware operating status, including touch screen impedance drift rate, motherboard temperature change, and power supply ripple fluctuation; Hardware wear-related parameters, including touch screen wear and key contact oxidation rate; The quantitative data of the dynamic factors of the environmental layer include at least: Environmental physical parameters, including ambient temperature, humidity, and electromagnetic radiation intensity; Power supply quality related parameters, including grid voltage fluctuation percentage and frequency offset; Mechanical environment related parameters, including vibration amplitude and impact intensity; The quantitative data of the dynamic factors of the user behavior layer includes at least: Load mode related parameters, including CPU usage, memory usage, and software running type; Operation interaction related parameters, including touch frequency, button pressing force, and the number of peripheral connections.

5. The method according to claim 3, characterized in that "Based on the type of dynamic factor, the standardized values ​​Fi of the relevant parameters that jointly influence the same type of dynamic factor in the hardware layer, environment layer, and user behavior layer, as well as the corresponding influence coefficients ki, are substituted into the multiplicative dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold" includes: Collect quantitative data of relevant parameters that affect the same type of dynamic factors in the hardware layer, environment layer, and user behavior layer in real time, and obtain their standardized values ​​Fi; The adjustment term for each factor is calculated by multiplying the normalized value F i by the corresponding influence coefficient ki and adding the value 1; Multiply the adjustment items of all dynamic factors and multiply them by the benchmark threshold to obtain the corresponding dynamic anomaly detection threshold Td.

6. The method according to claim 3 or 5, characterized in that "Based on the type of dynamic factor, the standardized values ​​Fi of the relevant parameters that independently affect a certain type of dynamic factor in the hardware layer, environment layer, and user behavior layer, as well as the corresponding influence coefficients ki, are substituted into the additive dynamic threshold calculation formula model to calculate and generate the corresponding dynamic anomaly detection threshold" includes: Collect quantitative data of relevant parameters that independently affect a certain type of dynamic factors in the hardware layer, environment layer, and user behavior layer in real time, and obtain their standardized values ​​Fi; The value obtained by multiplying the normalized value F i by the corresponding influence coefficient ki is used to calculate the adjustment term for each factor; The value obtained by adding the adjustment items of all dynamic factors is added to the reference threshold to obtain the corresponding dynamic anomaly detection threshold Td.

7. The method according to claim 1, characterized in that The "inputting the parameters required for abnormal behavior detection of the multidimensional data set collected in real time into a multidimensional abnormal behavior detection model, and using the model to compare the multidimensional data features with the dynamically generated abnormality detection threshold, and outputting abnormal behavior detection results combined with one or more dimensional analysis" includes: Normalizing the multidimensional data features to eliminate dimensional differences between different dimensions; A weighted fusion algorithm is used to assign weights based on the real-time confidence of each dimension of data to generate a comprehensive anomaly score; When the comprehensive anomaly score exceeds the dynamic anomaly detection threshold, multi-dimensional correlation analysis is triggered to identify the main cause dimension and related dimension combination of abnormal behavior; The output includes structured detection results including anomaly type labels, impact dimension lists, and confidence scores.

8. The method according to claim 1 or 7, characterized in that The "substituting the output abnormal behavior detection results into the abnormal behavior processing model, dynamically adjusting various dimensional parameters of the platform based on preset strategies or triggering abnormal reminder operations of corresponding levels to resolve the detected abnormal behavior" includes: Match the predefined response policy library based on the exception type label and select at least one repair action from hardware reset, software process restart, or network connection switching; The anomaly level is divided based on the confidence score. When the confidence score is higher than a first threshold, the repair action is automatically performed. When the confidence score is lower than the first threshold but higher than a second threshold, a manual review request is generated. The historical data of the exception handling process is recorded to optimize the operation priority in the response strategy library.

9. The method according to claim 6, characterized in that The switching logic between the multiplicative dynamic threshold calculation formula model and the additive dynamic threshold calculation formula model includes: When the dynamic factors are hardware aging, ambient temperature, or user load patterns, the multiplicative dynamic threshold calculation formula model is preferred; When the dynamic factors are the transient state of hardware, mechanical vibration, or the characteristics of a single user operation, the additive dynamic threshold calculation formula model is preferred; If the same type of dynamic factor has both multiplicative and additive model applicable conditions, the mixed dynamic threshold is generated by weighted average; The multiplicative dynamic threshold calculation formula model or the additive dynamic threshold calculation formula model sets an upper limit for the adjustment item to prevent a single factor from excessively affecting the threshold, and the upper limit is Td=T0+(T0*α); wherein α is the upper limit coefficient, and the value range is 0.2-0.

5.

10. The method according to claim 1, characterized in that It also includes a feedback optimization mechanism for anomaly detection thresholds: Regularly calculate the false alarm rate and missed alarm rate of anomaly detection results, and calculate the threshold adjustment compensation value ΔT; When the false alarm rate exceeds the preset range, the baseline threshold is adjusted upward by ΔT; when the missed alarm rate exceeds the preset range, the baseline threshold is adjusted downward by ΔT; The adjusted baseline threshold is used as the initial value for a new round of dynamic threshold calculation, and the historical data set in the regression analysis is updated.

Citation Information

Patent Citations

  • Abnormal data detection method and system based on intelligent algorithm

    CN115080290A

Cited By

  • Touch screen park smart lighting decision and optimization method based on big data

    CN121334938A

  • Host security early warning method, device and equipment in data center and readable medium

    CN121543088A