LLM-based multi-machine cooperative abnormal data detection system

By utilizing an LLM-based multi-drone collaborative anomaly data detection system, and employing a distributed architecture of airborne terminals, edge servers, and the cloud, efficient information sharing and collaborative decision-making among drone clusters are achieved. This optimizes data processing and utilization, enhances the ability to respond to complex and emerging threats, and solves the multi-drone collaborative security issues in existing technologies.

CN120675827BActive Publication Date: 2025-12-09BEIJING INST OF TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511187346.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-12-09
Estimated Expiration
2045-08-22

AI Technical Summary

Technical Problem

Existing drone swarms suffer from issues such as missing mechanisms, data processing bottlenecks, insufficient threat response, and poor system scalability in terms of multi-drone collaborative security. They struggle to achieve real-time status sharing, heterogeneous data fusion, and collaborative decision-making among drones, and cannot meet the needs of swarm tasks and distributed threat response.

Method used

A multi-machine collaborative anomaly data detection system based on LLM is adopted. Through a distributed architecture of airborne terminal, edge server and cloud, the system uses generation module, processing module and prediction and analysis module to perform anomaly detection and data processing. Combined with the hybrid expert model mechanism for decision fusion, it achieves efficient multi-machine collaboration.

Benefits of technology

It enables efficient information sharing and collaborative decision-making among drone swarms, optimizes data processing and utilization, enhances the ability to respond to complex and emerging threats, and solves the problems of decision optimization difficulties and insufficient system scalability under resource constraints.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675827B_ABST
    Figure CN120675827B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of unmanned aerial vehicle cluster safety and cooperation, in particular to a multi-machine cooperative abnormal data detection system based on LLM, which comprises a generation module, which is used for generating at least one abnormality detection score by using an airborne end; a processing module is used for extracting features from a first historical database in an edge server, obtaining first historical features, obtaining a binary classification abnormality detection label, calculating a performance index vector, and uploading the binary classification abnormality detection label and the performance index vector to a cloud end; a prediction and analysis module is used for performing long-time sequence prediction by using the cloud end to obtain a long-time sequence prediction result, and performing safety analysis by using the cloud end to obtain a safety analysis result. Therefore, the problems of mechanism loss, data processing bottleneck, insufficient threat response and poor system expansibility of the existing unmanned aerial vehicle cluster in the aspect of multi-machine cooperative safety are solved, efficient multi-machine cooperation is realized, and data processing and utilization are optimized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of UAV cluster security and cooperation, and in particular to a multi-UAV cooperative anomaly data detection system based on LLM. BACKGROUND

[0002] With the wide application of UAVs (Unmanned Aerial Vehicles) in key fields such as military reconnaissance, emergency communication, environmental monitoring, and logistics transportation, the clusterization and intelligentization of UAVs have become an important development trend. UAV clusters can perform more complex and larger-scale tasks, but also put higher requirements on system security, communication efficiency, and cooperative decision-making capability.

[0003] However, as the application of UAVs evolves from single-UAV intelligence to multi-UAV cooperation, the existing technology still has significant deficiencies in supporting complex, dynamic, and distributed UAV cluster security and cooperation. On the one hand, the existing technology lacks multi-UAV cooperation mechanisms, making it difficult to achieve real-time state sharing, heterogeneous data fusion, and cooperative decision-making among UAVs, and unable to meet the needs of cluster tasks and distributed threat response. On the other hand, the centralized data processing mode is difficult to adapt to the massive, high-speed, and heterogeneous data streams generated by UAV clusters, and the on-board and edge resources are limited, resulting in information delay and decision lag. In addition, the existing technology has limited ability to identify complex and variable threats, making it difficult to achieve resource-aware intelligent decision-making. Moreover, due to the fixed existing architecture, it is difficult to adapt to changes in task requirements, adjustments in cluster size, and the emergence of new threats, lacking modular design and dynamic expansion capabilities. These deficiencies limit the application effect of UAV clusters in complex task environments and need to be addressed urgently. SUMMARY

[0004] The present application provides a multi-UAV cooperative anomaly data detection system based on LLM to solve the problems of mechanism deficiency, data processing bottleneck, threat response deficiency, and poor system scalability of existing UAV clusters in multi-UAV cooperative security, achieving efficient multi-UAV cooperation and optimizing data processing and utilization.

[0005] The first aspect embodiment of the present application provides a multi-UAV cooperative anomaly data detection system based on LLM, which comprises:

[0006] A generation module for generating at least one anomaly detection score using the on-board end;

[0007] A processing module for extracting features from a first historical database in the edge server to obtain first historical features, obtaining a binary classification anomaly detection label according to the first historical features and the at least one anomaly detection score, calculating a performance index vector, and uploading the binary classification anomaly detection label and the performance index vector to the cloud end;

[0008] a prediction and analysis module configured to perform long-time sequence prediction using the cloud to obtain a long-time sequence prediction result and perform security analysis using the cloud to obtain a security analysis result.

[0009] According to an embodiment of the present application, the LLM-based multi-machine cooperative anomaly data detection system is further configured to:

[0010] obtain second historical features from a second historical database of the cloud;

[0011] upload the at least one anomaly detection score, the binary classification anomaly detection label, the performance index vector, the first historical features, the second historical features, the long-time sequence prediction result, and the security analysis result to a decision Agent body in the edge server;

[0012] based on a preset hybrid expert model mechanism, perform fusion calculation on the at least one anomaly detection score, the binary classification anomaly detection label, the performance index vector, the first historical features, the second historical features, the long-time sequence prediction result, and the security analysis result using the decision Agent body to obtain an optimal cooperative decision vector;

[0013] based on the optimal cooperative decision vector, control the at least one target UAV to perform a multi-machine cooperative task.

[0014] According to an embodiment of the present application, the prediction and analysis module is configured to:

[0015] convert the optimal cooperative decision vector into a target behavior instruction;

[0016] send the target behavior instruction to at least one target UAV through the edge server to control the at least one target UAV to perform a multi-machine cooperative task.

[0017] According to an embodiment of the present application, the generation module is configured to:

[0018] obtain local data and sampling data of a UAV sensor, and construct a local data set according to the local data and the sampling data;

[0019] perform anomaly detection processing and / or time sequence prediction processing on the local data set to generate the at least one anomaly detection score.

[0020] According to an embodiment of the present application, after performing long-time sequence prediction using the cloud to obtain a long-time sequence prediction result and performing security analysis using the cloud to obtain a security analysis result, the prediction and analysis module is further configured to:

[0021] offline training and fine-tuning the model in the cloud to obtain updated model parameters;

[0022] updating the model in the edge server and / or the model in the on-board end based on the updated model parameters.

[0023] According to an embodiment of the present application, the LLM-based multi-machine cooperative abnormal data detection system is embedded with an intelligent agent.

[0024] According to the LLM-based multi-machine cooperative abnormal data detection system according to the embodiments of the present application, the on-board end is used to generate an abnormal detection score; the first historical features are extracted from the first historical database in the edge server, and a binary classification abnormal detection label is obtained according to the first historical features and the abnormal detection score, and a performance index vector is calculated, and the binary classification abnormal detection label and the performance index vector are uploaded to the cloud; the cloud is used to perform long-time sequence prediction to obtain a long-time sequence prediction result, and safety analysis is performed to obtain a safety analysis result. In this way, the problems of mechanism missing, data processing bottleneck, threat response deficiency and poor system scalability of the existing unmanned aerial vehicle cluster in multi-machine cooperative safety are solved, efficient multi-machine cooperation is achieved, and data processing and utilization are optimized.

[0025] The second aspect embodiment of the present application provides an LLM-based multi-machine cooperative abnormal data detection method, which uses an LLM architecture and an embedded intelligent agent system, and the LLM architecture and the embedded intelligent agent system include an on-board end, an edge server and a cloud. The method includes the following steps:

[0026] at least one abnormal detection score is generated by using the on-board end;

[0027] features are extracted from a first historical database in the edge server to obtain first historical features, a binary classification abnormal detection label is obtained according to the first historical features and the at least one abnormal detection score, a performance index vector is calculated, and the binary classification abnormal detection label and the performance index vector are uploaded to the cloud;

[0028] long-time sequence prediction is performed by using the cloud to obtain a long-time sequence prediction result, and safety analysis is performed by using the cloud to obtain a safety analysis result.

[0029] According to an embodiment of the present application, the LLM-based multi-machine cooperative abnormal data detection method further includes:

[0030] second historical features are obtained from a second historical database of the cloud;

[0031] uploading the at least one anomaly detection score, the binary classification anomaly detection label, the performance indicator vector, the first historical feature, the second historical feature, the long time series prediction result and the security analysis result to a decision Agent body in the edge server;

[0032] based on a preset hybrid expert model mechanism, fusing and calculating the at least one anomaly detection score, the binary classification anomaly detection label, the performance indicator vector, the first historical feature, the second historical feature, the long time series prediction result and the security analysis result by using the decision Agent body to obtain an optimal collaborative decision vector;

[0033] based on the optimal collaborative decision vector, controlling the at least one target unmanned aerial vehicle to perform a multi-machine collaborative task.

[0034] According to an embodiment of the present application, based on the optimal collaborative decision vector, controlling the at least one target unmanned aerial vehicle to perform a multi-machine collaborative task, comprising:

[0035] converting the optimal collaborative decision vector into a target behavior instruction;

[0036] sending the target behavior instruction to at least one target unmanned aerial vehicle through the edge server to control the at least one target unmanned aerial vehicle to perform a multi-machine collaborative task.

[0037] According to an embodiment of the present application, the at least one anomaly detection score is generated by using the on-board end, comprising:

[0038] obtaining local data and sampling data of an unmanned aerial vehicle sensor, and constructing a local data set according to the local data and the sampling data;

[0039] performing anomaly detection processing and / or time series prediction processing on the local data set to generate the at least one anomaly detection score.

[0040] According to an embodiment of the present application, after the long time series prediction result is obtained by using the cloud end and the security analysis result is obtained by using the cloud end, further comprising:

[0041] offline training and fine-tuning the model in the cloud end to obtain updated model parameters;

[0042] updating the model in the edge server and / or the model in the on-board end based on the updated model parameters.

[0043] According to the LLM-based multi-machine cooperative abnormal data detection method provided in the embodiments of the present application, the on-board end is used to generate an abnormal detection score; the first historical features are extracted from the first historical database in the edge server, and a binary classification abnormal detection label is obtained according to the first historical features and the abnormal detection score, and a performance index vector is calculated, and the binary classification abnormal detection label and the performance index vector are uploaded to the cloud end; the cloud end is used to perform long-time sequence prediction to obtain a long-time sequence prediction result, and safety analysis is performed to obtain a safety analysis result. In this way, the problems of mechanism loss, data processing bottleneck, insufficient threat response and poor system scalability of the existing unmanned aerial vehicle cluster in multi-machine cooperative safety are solved, efficient multi-machine cooperation is realized, and data processing and utilization are optimized.

[0044] The third aspect of the embodiments of the present application provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor executes the program to implement the LLM-based multi-machine cooperative abnormal data detection method as described in the above embodiments.

[0045] The fourth aspect of the embodiments of the present application provides a computer readable storage medium having a computer program stored thereon, which is executed by a processor to implement the LLM-based multi-machine cooperative abnormal data detection method as described in the above embodiments.

[0046] The additional aspects and advantages of the present application will be partially given in the following description, partially will become obvious from the following description, or will be understood by the practice of the present application. BRIEF DESCRIPTION OF DRAWINGS

[0047] The above and / or additional aspects and advantages of the present application will become apparent and more readily appreciated from the following description of the embodiments, with reference to the following drawings, in which:

[0048] Figure 1 A block schematic diagram of an LLM-based multi-machine cooperative abnormal data detection system according to an embodiment of the present application;

[0049] Figure 2 A schematic diagram of the architecture of an LLM-based multi-machine cooperative abnormal data detection system according to an embodiment of the present application;

[0050] Figure 3 A schematic diagram of the internal architecture of an Agent according to an embodiment of the present application;

[0051] Figure 4 A flowchart of an LLM-based multi-machine cooperative abnormal data detection method according to an embodiment of the present application;

[0052] Figure 5 A schematic diagram of the structure of an electronic device according to an embodiment of the present application.

[0053] Label: 10 - a multi-machine collaborative abnormal data detection system based on LLM, 100 - generation module, 200 - processing module, 300 - prediction and analysis module; 501 - memory, 502 - processor, 503 - communication interface. DETAILED DESCRIPTION

[0054] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary and are intended to explain the present application, and cannot be understood as a limitation of the present application.

[0055] Those skilled in the art can appreciate that in the related art, in order to cope with the challenges of system security, communication efficiency and collaborative decision-making ability in the process of unmanned aerial vehicle clustering and intelligent operation, artificial intelligence, especially large-scale language model, is introduced into unmanned aerial vehicle system to improve its autonomous perception, understanding and decision-making ability, which has become a research hotspot in recent years.

[0056] However, the existing unmanned aerial vehicle system and the preliminary LLM application architecture face the following key pain points when coping with multi-machine collaborative security scenarios:

[0057] (1) Lack of effective multi-machine collaboration mechanism: existing systems focus more on single-machine intelligence, and lack efficient mechanisms to handle real-time state sharing, heterogeneous data fusion and collaborative decision-making among multiple unmanned aerial vehicles, making it difficult to cope with cluster tasks and distributed threats that require close coordination.

[0058] (2) Data processing and storage bottleneck: traditional centralized data storage and processing mode is difficult to adapt to the massive, high-speed, heterogeneous distributed data flow generated by unmanned aerial vehicle clusters. The computing and storage resources on board and at the edge are limited, and cannot effectively process and utilize real-time local and nearby data, resulting in information delay and decision lag.

[0059] (3) Insufficient static threat response and knowledge utilization: the system has limited ability to identify complex and variable threats (such as GPS spoofing, network attacks, and sensor interference combinations), and lacks a mechanism to dynamically and real-time integrate domain expert knowledge (such as specific countermeasures) into the decision-making process.

[0060] (4) Decision optimization difficulty under resource constraints: in the resource-constrained environment of on-board and edge, how to ensure the timeliness and accuracy of decision-making while taking into account the consumption of computing and communication resources, and to realize resource-aware intelligent decision-making, is a major challenge.

[0061] (5) Poor system scalability and adaptability: Existing architectures are often fixed and difficult to adapt to changes in task requirements, adjustments in cluster size, and the emergence of new threats, lacking good modular design and dynamic expansion capabilities.

[0062] To overcome the above-mentioned pain points in the prior art, the present application proposes a multi-machine cooperative abnormal data detection system based on LLM.

[0063] Specifically, Figure 1 is a block diagram of a multi-machine cooperative abnormal data detection system based on LLM according to an embodiment of the present application.

[0064] As Figure 1 shown, the multi-machine cooperative abnormal data detection system based on LLM 10 includes a generation module 100, a processing module 200, and a prediction and analysis module 300.

[0065] Among them, the generation module 100 is configured to generate at least one abnormality detection score using an on-board terminal; the processing module 200 is configured to extract features from a first historical database in an edge server to obtain first historical features, and obtain a binary classification abnormality detection label according to the first historical features and the at least one abnormality detection score, and calculate a performance index vector, and upload the binary classification abnormality detection label and the performance index vector to a cloud terminal; and the prediction and analysis module 300 is configured to perform long-time sequence prediction using a cloud terminal to obtain a long-time sequence prediction result, and perform security analysis using the cloud terminal to obtain a security analysis result.

[0066] It should be noted that the multi-machine cooperative abnormal data detection system based on LLM according to an embodiment of the present application is embedded with an intelligent agent.

[0067] For example, as Figure 2 shown, Figure 2 is an architecture diagram of the multi-machine cooperative abnormal data detection system based on LLM according to an embodiment of the present application. The architecture integrates distributed data storage, multi-level model cooperation, and Agent-based intelligent decision-making mechanisms, and deploys small models (such as OPT-350m, OPT-125m), medium models (such as OPT-1.3B, OPT-6.7B), and large models (such as Llama2-7B, Llama2-13B, TimesNet, Time-LLM) on the on-board terminal, the medium-sized edge server, and the cloud terminal, respectively, to realize data acquisition, real-time processing and long-time sequence prediction, and security pattern analysis.

[0068] In the application embodiment, the LLM-based multi-machine cooperative abnormal data detection system adopts a distributed data storage architecture. An edge server sets up a short-term history database (Short-Term History Database), that is, a first history database, for storing real-time data segments. A cloud sets up a long-term history database (Long-Term History Database), that is, a second history database, for storing global trend and pattern data. The architecture introduces innovative time window sliding aggregation and data validity scoring mechanisms, effectively solving the synchronization and fusion problems of multi-source asynchronous data.

[0069] Further, the application embodiment adds an intelligent Agent at the edge server, which is based on the MOE (Mixture of Experts) internal algorithm, integrates task decomposition, distribution, decision fusion functions, and introduces domain experts (such as GPS anomaly defense experts, network recovery experts, and model self-update experts).

[0070] The working principle of the LLM-based multi-machine cooperative abnormal data detection system proposed in the application will be described in detail below.

[0071] Specifically, the generation module 100 is configured to: acquire local data and sampling data of a UAV sensor, and construct a local data set according to the local data and the sampling data; perform abnormal detection processing and / or time series prediction processing on the local data set to generate at least one abnormal detection score.

[0072] The abnormal detection score refers to a score of the degree of abnormality of sensor and network data detected by the airborne small model in real time.

[0073] Specifically, data acquisition and preliminary processing are performed by the airborne end. The UAV sensor collects real-time data, and forms a local data set in combination with the local data. The local data is subjected to real-time abnormal detection and time series prediction by the small model at the airborne end to generate at least one preliminary abnormal detection score φ. The at least one preliminary abnormal detection score φ is sent to the edge server.

[0074] Further, features are extracted from the first history database in the edge server to obtain first history features. A binary classification abnormal detection label is obtained according to the first history features and the at least one abnormal detection score. A performance index vector is calculated, and the binary classification abnormal detection label and the performance index vector are uploaded to the cloud.

[0075] The first history database is a short-term history database, which can store data within a few minutes to tens of minutes. The binary classification abnormal detection label refers to the “normal / abnormal” judgment of the airborne end or the aggregated data by the medium model of the edge server, which is a binary label.

[0076] Specifically, data aggregation and middle-level analysis are performed by the edge server. The edge server aggregates the anomaly detection scores from one or more UAVs and extracts short-term historical data, i.e., first historical features S, from a short-term historical database. The first historical features S can be a vector composed of statistical features such as anomaly frequency, mean, variance, etc. within the last few minutes to tens of minutes. A middle model deployed in the edge server combines at least one anomaly detection score and the first historical features S extracted from the short-term historical database to perform analysis, output a more accurate binary classification anomaly detection label, and calculate its own performance indicators M, i.e., a performance indicator vector M = [A, P, R, F1]: Accuracy, Precision, Recall, and F1-score. The first historical database of the embodiment of the present application is used to store recent data segments for Agent queries.

[0077] Further, the edge server uploads the processed data to the cloud.

[0078] Further, through the prediction and analysis module 300, the cloud is used for long-time sequence prediction to obtain a long-time sequence prediction result, and the cloud is used for security analysis to obtain a security analysis result.

[0079] Further, in some embodiments, the LLM-based multi-UAV cooperative anomaly data detection system 10 is also used to: obtain second historical features from a second historical database in the cloud; upload at least one anomaly detection score, a binary classification anomaly detection label, a performance indicator vector, first historical features, second historical features, a long-time sequence prediction result, and a security analysis result to a decision Agent body in the edge server; based on a pre-set hybrid expert model mechanism, use the decision Agent body to perform fusion calculation on at least one anomaly detection score, a binary classification anomaly detection label, a performance indicator vector, first historical features, second historical features, a long-time sequence prediction result, and a security analysis result to obtain an optimal cooperative decision vector; and based on the optimal cooperative decision vector, control at least one target UAV to perform a multi-UAV cooperative task.

[0080] The second historical database is a long-term historical database that can store data for several hours, several days, or longer. The second historical features L refer to a vector extracted from the second historical database, which includes macro features such as periodic trends and historical anomaly pattern statistics. The long-time sequence prediction result T is a trend prediction vector of future sensor data for several minutes or longer by a large model in the cloud. The security analysis result K is a recognition digital label of an attack pattern extracted by global data analysis.

[0081] Specifically, cloud global analysis and model maintenance are utilized. The cloud's second historical database stores global historical data, i.e., the second historical features L, including long-term regularities / patterns, which are uploaded to the decision Agent body through the second historical database in the cloud, and large-scale model in the cloud is used for long-time sequence prediction to obtain long-time sequence prediction results T, and large-scale security pattern analysis is performed to obtain security analysis results K.

[0082] Further, the decision Agent body located at the edge server is the core of the LLM architecture and the embedded agent system, which aggregates information from each layer, including: the anomaly detection score φ of the on-board end (possibly obtained indirectly through edge model labels or directly transmitted), the binary classification anomaly detection labels and performance indicator vector M of the edge model, the first historical features S, the second historical features L (obtained through data requests from the second historical database), the long-time sequence prediction results T of the cloud, and the security analysis results K of the cloud.

[0083] Further, the Agent fuses multi-source information through the internal MoE mechanism to calculate the optimal collaborative decision vector x*. In addition, the Agent initiates data requests to the first historical database and the second historical database to obtain the context required for decision-making.

[0084] Further, in some embodiments, the prediction and analysis module 300 is configured to: convert the optimal collaborative decision vector into target behavior instructions; and send the target behavior instructions to at least one target UAV through the edge server to control the at least one target UAV to perform the multi-UAV collaborative task.

[0085] Specifically, the decision Agent body is used for instruction issuance and closed-loop feedback. The decision Agent body converts the optimal decision vector x* into specific behavior instructions, which are issued to relevant UAVs through the edge server to perform the multi-UAV collaborative task. In addition, the decision Agent body updates the weights of the medium-sized model on the edge server according to the decision results and the current state. The decision Agent body also feeds back the system state and decision information to the ground station GCS in real time. The execution results and new state of the UAVs will enter the system again through the sensor data stream to form a closed loop, and the large model in the cloud will also be continuously iteratively optimized according to the long-term data.

[0086] Further, in some embodiments, after the cloud is used for long-time sequence prediction to obtain long-time sequence prediction results, and the cloud is used for security analysis to obtain security analysis results, the prediction and analysis module 300 is further configured to: perform offline training and fine-tuning on the model in the cloud to obtain updated model parameters; and update the model in the edge server and / or the model in the on-board end based on the updated model parameters.

[0087] Specifically, the cloud is responsible for offline training and fine-tuning of large models in the cloud, and the updated model parameters are distributed to the edge server and / or the on-board end, i.e., the fine-tuned medium model parameters of the cloud are distributed to the edge or on-board end, the model weight in the edge server is updated, or the model weight in the on-board end is updated, or the model weight in the edge server and the model weight in the on-board end are updated at the same time.

[0088] The internal algorithm of the decision Agent body proposed in the embodiments of the application is described in detail below.

[0089] Specifically, the internal data flow and processing process of the intelligent agent is as shown in Figure 3 , including a data aggregation and preprocessing module containing a multi-source asynchronous data synchronization mechanism , a weight distribution and control module containing a threat identification and expert weight adjustment mechanism , an expert reasoning module containing an expert system dynamic expansion mechanism , a decision fusion module containing a resource-aware decision mechanism , a feedback and cyclic adjustment module containing a confidence evaluation synthesis mechanism , and a collaborative enhancement module for optimal collaborative decision-making . The algorithm processes of each module are described in detail below.

[0090] First, the data aggregation and preprocessing module is introduced.

[0091] Specifically, a unified feature vector is constructed:

[0092] ;

[0093] wherein, is a feature vector, which is used to mathematically model the features of multi-source (on-board end, edge server, cloud) data for intelligent agent calculation, is an anomaly detection score, is a performance index vector, is a first historical feature, is a second historical feature, is a long-time series prediction result, is a security analysis result.

[0094] To ensure the timeliness of the data, when aggregating data from various sources, the decision Agent body uses time stamp alignment or uses the latest available data within a specified time window, and can include data freshness as part of the feature in the vector .

[0095] Further, to solve the problem of multi-source asynchronous data, the system uses the following multi-source asynchronous data synchronization mechanism algorithm for data aggregation and synchronization.

[0096] (1) Time window sliding aggregation: for time series data (such as the first historical feature ), the exponentially weighted moving average (EWMA, Exponentially Weighted Moving-Average) method is used to give higher weight to recent data:

[0097] ;

[0098] where, is the first historical feature, is the sliding window size, is the decay factor, is the data at time .

[0099] (2) Data validity score: define a timeliness function for each data source:

[0100] ;

[0101] where, is the timeliness function, represents a specific data item or data point, is the local timestamp of the agent, controls the decay rate, is the timestamp of data, i.e. the time when the data is generated or recorded, is the data "half-life" (which can be adjusted according to the data type).

[0102] (3) Data missing processing: when a data source is temporarily unavailable, use historical data prediction filling (short-term missing) or degradation strategy (long-term missing):

[0103] ;

[0104] where, is the incomplete feature vector caused by data missing, is the predicted value of the feature vector obtained by the time series prediction method; is the pre-set safe degradation value, is the timestamp of the last complete feature vector, is the artificially set time threshold, which is the selection standard for filling strategy and long-term strategy.

[0105] (4) Data fusion quality evaluation: define the fusion data quality metric :

[0106] ;

[0107] wherein, is the fusion data quality metric, is the human-set weight of each specific data item, which can be adjusted according to the task type, is each specific data item or data point received by the agent.

[0108] If , an additional data request is triggered or the decision confidence threshold is raised .

[0109] Secondly, the weight allocation and control module is introduced.

[0110] Specifically, the importance weight of each expert is calculated by the control module :

[0111] ;

[0112] wherein, is the relevance evaluation function of the i-th expert, is the relevance evaluation function of the j-th expert, is the input vector, is the total number of experts.

[0113] Further, the design aims to evaluate the relevance and reliability of each expert under the current scenario according to the input vector . For example, if the input vector contains features indicating a specific network attack mode (from security analysis results or the first historical features ), the weight of the network recovery expert may be increased, which enables the Agent to dynamically focus on the most relevant expert opinions.

[0114] The weight allocation and control module involves the threat identification and expert weight adjustment mechanism.

[0115] Through the following design, the present application establishes a dynamic association between threat features and expert knowledge:

[0116] (1) Threat-Expert Association Matrix: A matrix is maintained, wherein, is the number of possible threat types, is the number of experts. representing threat types with experts .

[0117] (2) Threat feature extraction function: extract threat feature vector from input vector :

[0118] ;

[0119] where can be implemented as a specialized feature extraction network or a rule-based mapping function.

[0120] (3) Threat probability distribution calculation: calculate the probability distribution of various threat types based on threat features:

[0121] ;

[0122] where is a vector representing the probability of each threat type, is a dimensional weight matrix, each row corresponds to a threat type, and each column corresponds to a feature in , obtained by training and learning, is a dimensional bias vector, allowing each threat type to have a baseline offset, and each element corresponds to a threat type, obtained by training and learning.

[0123] (4) Threat-based expert weight adjustment: multiply threat probability and correlation matrix to correct control module output:

[0124] ;

[0125] where is the corrected i-th expert relevance evaluation function, is the adjustment intensity hyperparameter.

[0126] The final expert weight calculation is:

[0127] .

[0128] (5) Correlation matrix adaptive update: based on decision effect feedback, update correlation matrix periodically:

[0129] ;

[0130] where is the value of the updated correlation matrix j row i column, to update the value of the jth row i th column of the previous association matrix, to the learning rate, to the quantitative score of the decision effect, to the value of the jth item.

[0131] Further, the expert reasoning module is introduced .

[0132] Specifically, the decision variable is defined as a decision vector , each component corresponding to a different control parameter (such as evacuation intensity , link switching , anti-jamming , etc.).

[0133] Each expert (such as GPS defense, network recovery, anti-jamming, model updating, etc.) outputs its recommended decision vector according to the input .

[0134] Experts can give non-zero recommended values to one or more decision components according to their field expertise. For example: the GPS defense expert may recommend . The network expert may recommend . The anti-jamming expert may recommend .

[0135] The architecture supports dynamic expansion of the expert system, and new expert models or updates to existing expert logic can be registered through predefined interfaces. The control module and decision fusion mechanism of the Agent can adapt to changes in the expert set, embodying the modularity and scalability of the system.

[0136] The expert system dynamic expansion mechanism of the embodiments of the present application is described in detail below, and the embodiments of the present application adopt the following strategies to realize the dynamics and scalability of the expert system:

[0137] (1) Standardized expert interface: uniformly define the specification method for all expert models to receive input features, output decisions and confidence, report support dimensions, and update themselves according to feedback.

[0138] (2) Expert registration and unloading mechanism: provide an interface for dynamically adding and removing expert modules, so as to flexibly manage the expert list at runtime.

[0139] (3) Expert capability evaluation function: define a capability evaluation function for newly added experts:

[0140] ;

[0141] wherein, For testing scenario set, For similarity score of expert suggestion and reference decision, For suggestion of expert to be evaluated, For reference decision.

[0142] (4) Expert cold start strategy: when a new expert registers, the system adopts a conservative strategy to gradually increase its influence:

[0143] ;

[0144] Where, is the weight of the newly added expert t, is the growth factor, is the upper limit of the weight of the expert, which gradually increases with the ability evaluation score.

[0145] (5) Expert competition mechanism: among experts with similar functions, dynamically adjust resource allocation according to historical performance:

[0146] ;

[0147] Where, is the proportion of computing resources obtained by expert , is the historical performance measure of expert i, controls the competition intensity.

[0148] Further, the decision fusion module is introduced.

[0149] Specifically, the decision fusion module includes decision vector and cost function.

[0150] Define the cost function of expert , measure the weighted deviation of decision vector and its suggestion :

[0151] ;

[0152] Where, is the sensitivity weight of expert to decision component (irrelevant component ).

[0153] Construct the overall cost function as the weighted sum of the cost of each expert:

[0154] ;

[0155] Further, the optimization solution is carried out.

[0156] The goal of optimization is to find the optimal solution under the constraints. (e.g., the range of values ​​for each component) Minimize the overall cost function Decision vector :

[0157] ;

[0158] Constraints In addition to physical constraints, it can also include current resource state constraints (such as available bandwidth and computing load), making the decision biased towards resource-efficient solutions.

[0159] This optimization problem can be solved using appropriate nonlinear programming (such as interior point method, sequential quadratic programming) or numerical optimization algorithms (such as variants of gradient descent).

[0160] Furthermore, the decision fusion module is introduced. Resource perception and decision-making mechanism.

[0161] In system design, resource efficiency is just as important as decision-making effectiveness. This application's embodiments implement resource-aware decision-making through the following algorithm:

[0162] (1) Resource consumption model: Define a resource consumption function for each decision component. , indicating the implementation of decisions The required resource overhead is modeled using piecewise functions:

[0163] ;

[0164] (2) Total resource constraints: Define the system's available resource vector ,in, Indicates the first The availability of each resource. Then, construct the resource constraint function:

[0165] ;

[0166] in, For resource constraint functions, For decision weight Resources The consumption function.

[0167] (3) Multi-objective optimization: Introducing the resource efficiency objective into the optimization problem, transforming it into multi-objective optimization:

[0168] ;

[0169] in, The weight factor of resource efficiency can be dynamically adjusted according to the current load of the system.

[0170] (4) Constraint relaxation mechanism: when there is no solution under strict resource constraints, the system can automatically apply a relaxation strategy:

[0171] ;

[0172] satisfies:

[0173] ;

[0174] wherein, is the relaxation variable of the i-th constraint, is a penalty factor. (5) Resource dynamic scheduling: based on the urgency, the system can dynamically reallocate resource limits:

[0175]

[0176] ; wherein,

[0177] is the updated available amount of the i-th resource, is the regular available amount of the i-th resource set by the system under normal circumstances, is the urgency measure of the current situation, is the elasticity coefficient of the resource .

[0178] (6) Solution algorithm selection: according to the problem complexity and computing resources, the system adaptively selects among the following algorithms:

[0179] a) In emergency situations: fast approximate solution (such as gradient descent limited iteration);

[0180] b) In normal situations: exact solution (such as sequential quadratic programming);

[0181] c) In idle periods: global search (such as genetic algorithm).

[0182] Further, the feedback and cyclic adjustment module of the embodiments of the present application is introduced .

[0183] The feedback and cyclic adjustment module of the embodiments of the present application includes a feedback cycle and adaptive adjustment and confidence evaluation comprehensive mechanism.

[0184] Wherein, the feedback cycle and adaptive adjustment includes the following steps:

[0185] Evaluate the confidence of the optimal decision . Confidence evaluation can integrate multiple methods, for example:​

[0186] a) Expert consensus: measuring the consensus of expert recommendations The degree of divergence between them (e.g., weighted variance).

[0187] b) Historical performance: Refer to similar decisions made in similar scenarios. The historical success rate.

[0188] c) Simulation verification: Rapid evaluation in a simplified simulation environment The possible effects.

[0189] d) Specific metrics: Monitor whether certain key performance indicators (KPIs) are within the target range. The implementation achieved the expected results.

[0190] like (Based on a preset threshold), the latest data (S, L, T, K) is updated from the short-term / long-term database and the cloud, and the feature vector is reconstructed. Furthermore, the steps of weight calculation, expert reasoning, cost function construction, and optimization solution are repeatedly executed.

[0191] This process continues until the decision confidence level meets the requirements, thus achieving closed-loop adaptive behavior.

[0192] Furthermore, the confidence assessment mechanism in this application adopts a multi-dimensional confidence assessment system to achieve a comprehensive assessment of decision quality:

[0193] Expert consensus score Assess the degree of agreement among the experts:

[0194] ;

[0195] The higher the consistency, the closer the score is to 1.

[0196] Historical similarity score By comparing the decision-making effects in similar historical scenarios:

[0197] ;

[0198] in, Historical decision records, including feature vectors ,decision making and effects ; () Calculate the similarity between the current feature vector and the historical data; () Assess the success of historical decisions.

[0199] Simulation verification score Rapidly validate decision-making effectiveness in a lightweight simulation environment:

[0200] ;

[0201] where, is the decision made in the simulation environment causing the th KPI value, is the pre-set optimal value, is the pre-set worst value.

[0202] Uncertainty assessment : assess the uncertainty of the current input data:

[0203] ;

[0204] where, is the estimated variance of each component of the input vector , and is the scaling factor.

[0205] Confidence synthesis calculation: multi-dimensional weighted integration:

[0206] ;

[0207] where the weight can be dynamically adjusted through reinforcement learning and other methods to optimize long-term decision-making quality.

[0208] Adaptive threshold: dynamically adjust the threshold according to the urgency of the situation :

[0209] ;

[0210] where, is the basic threshold, controls the degree of threshold reduction in emergency situations, is the urgency assessment of the current scenario.

[0211] Finally, the cooperative enhancement module of the embodiments of the present application is introduced .

[0212] Specifically, when the system involves a large number of unmanned aerial vehicles, the cooperative enhancement module is introduced to achieve more efficient decision-making and execution.

[0213] Hierarchical decision-making architecture: group unmanned aerial vehicles into multiple clusters, and set edge servers and agents within each cluster:

[0214] ;

[0215] Cross-cluster coordination: clusters share summary information through high-level coordination mechanisms:

[0216] ;

[0217] wherein, is the cluster shared information summary, containing key state, decision intention and uncertainty assessment.

[0218] Differential decision negotiation: when there is conflict between adjacent cluster decisions, trigger negotiation mechanism:

[0219] ;

[0220] The specific negotiation process of the embodiment of the application can utilize the game theory framework to seek Nash equilibrium or Pareto optimal solution.

[0221] Therefore, the agent will finally obtain the optimal decision vector and issue it to each relevant UAV, and each UAV executes the corresponding operation (evacuation, communication switching, anti-jamming, etc.) according to each component of and feeds back the execution result to the system.

[0222] The multi-machine cooperative abnormal data detection system 10 based on LLM proposed by the application has the following remarkable effects:

[0223] Efficient multi-machine cooperation is realized: by introducing intelligent agents at the edge end, combining distributed data architecture and multi-level models, efficient information sharing, state synchronization and cooperative decision-making between UAV clusters are realized, effectively solving the problem of lack of effective multi-machine cooperation mechanism in related technologies. The cooperative enhancement module further supports hierarchical management and conflict negotiation of large-scale clusters.

[0224] Optimize data processing and utilization: the innovative distributed short-term / long-term history database design, combined with time window sliding aggregation, data effectiveness scoring mechanism, effectively processes multi-source asynchronous data, fully utilizes the advantages of real-time data on board and at the edge, and alleviates the data processing and storage bottleneck in related technologies.

[0225] Enhance dynamic threat adaptability: the MoE (Mixture of Experts) structure embedded in the agent, combined with threat recognition and expert weight dynamic adjustment mechanism, can intelligently call the most relevant expert knowledge for decision-making according to the real-time threat situation, significantly improving the response capability to complex and new threats, overcoming the limitations of insufficient static threat response and knowledge utilization in related technologies.

[0226] Achieving resource-aware intelligent decision-making: The decision fusion module explicitly considers resource consumption models and constraints, optimizing resource use efficiency while meeting task requirements. Through adaptive solving algorithms, the balance between decision effectiveness and resource overhead is achieved, solving the problem of decision optimization under resource constraints in related technologies.

[0227] Excellent modularity and scalability: Based on standardized expert interfaces and dynamic registration / unloading mechanisms, the system can easily integrate new sensor data, models, expert knowledge or decision logic, with good scalability, adapting to future technological development and changes in task requirements, alleviating the problems of insufficient system scalability and adaptability in related technologies.

[0228] Enhanced system robustness and adaptability: The multi-dimensional confidence evaluation mechanism combined with the feedback loop adjustment module ensures the reliability of the decision. The system can adaptively adjust according to the decision confidence and environmental changes, and continuously optimize performance through closed-loop feedback, improving the overall robustness in complex dynamic environments.

[0229] Complete end-to-end solution: The present application provides a complete architecture and algorithm process from data acquisition, multi-layer model analysis, distributed storage, agent decision fusion to collaborative instruction issuance, providing a systematic solution for safe, efficient and intelligent multi-vehicle cooperation of unmanned aerial vehicles.

[0230] According to the LLM-based multi-vehicle cooperation abnormal data detection system 10 provided by the embodiment of the present application, the airborne end generates an anomaly detection score; the first historical features are extracted from the first historical database in the edge server, and a binary classification anomaly detection label is obtained according to the first historical features and the anomaly detection score, and a performance index vector is calculated, and the binary classification anomaly detection label and the performance index vector are uploaded to the cloud end; the cloud end is used for long-time sequence prediction to obtain a long-time sequence prediction result, and safety analysis is performed to obtain a safety analysis result. Thus, the problems of mechanism missing, data processing bottleneck, threat response deficiency and poor system scalability in the existing unmanned aerial vehicle cluster in multi-vehicle cooperation safety are solved, efficient multi-vehicle cooperation is realized, and data processing and utilization are optimized.

[0231] The LLM-based multi-vehicle cooperation abnormal data detection method applied to the LLM-based multi-vehicle cooperation abnormal data detection system 10 described above is described below with reference to the accompanying drawings.

[0232] Specifically, Figure 4 A flowchart of an LLM-based multi-vehicle cooperation abnormal data detection method provided by an embodiment of the present application.

[0233] As Figure 4 shown, the LLM-based multi-vehicle cooperation abnormal data detection method comprises the following steps:

[0234] In step S401, at least one anomaly detection score is generated by the on-board end.

[0235] In step S402, features are extracted from the first historical database in the edge server to obtain first historical features, and a binary classification anomaly detection label is obtained according to the first historical features and the at least one anomaly detection score, and a performance index vector is calculated, and the binary classification anomaly detection label and the performance index vector are uploaded to the cloud end.

[0236] In step S403, long-time sequence prediction is performed by the cloud end to obtain a long-time sequence prediction result, and security analysis is performed by the cloud end to obtain a security analysis result.

[0237] Further, in some embodiments, generating at least one anomaly detection score by the on-board end comprises: obtaining local data and sampling data of the unmanned aerial vehicle sensor, and constructing a local data set according to the local data and the sampling data; performing anomaly detection processing and / or time series prediction processing on the local data set to generate at least one anomaly detection score.

[0238] Further, in some embodiments, the LLM-based multi-machine cooperative anomaly data detection method further comprises: obtaining second historical features from a second historical database in the cloud end; uploading the at least one anomaly detection score, the binary classification anomaly detection label, the performance index vector, the first historical features, the second historical features, the long-time sequence prediction result, and the security analysis result to a decision Agent body in the edge server; based on a pre-set hybrid expert model mechanism, the decision Agent body is used to perform fusion calculation on the at least one anomaly detection score, the binary classification anomaly detection label, the performance index vector, the first historical features, the second historical features, the long-time sequence prediction result, and the security analysis result to obtain an optimal cooperative decision vector; based on the optimal cooperative decision vector, at least one target unmanned aerial vehicle is controlled to perform a multi-machine cooperative task.

[0239] Further, in some embodiments, based on the optimal cooperative decision vector, at least one target unmanned aerial vehicle is controlled to perform a multi-machine cooperative task, comprising: converting the optimal cooperative decision vector into a target behavior instruction; sending the target behavior instruction to at least one target unmanned aerial vehicle through the edge server to control at least one target unmanned aerial vehicle to perform a multi-machine cooperative task.

[0240] Further, in some embodiments, after performing long-time sequence prediction by the cloud end to obtain a long-time sequence prediction result, and performing security analysis by the cloud end to obtain a security analysis result, the method further comprises: performing offline training and fine-tuning on the model in the cloud end to obtain updated model parameters; based on the updated model parameters, updating the model in the edge server and / or the model in the on-board end.

[0241] It should be noted that the foregoing explanation and description of the LLM-based multi-machine cooperative abnormal data detection system embodiment also applies to the LLM-based multi-machine cooperative abnormal data detection method of this embodiment, which will not be described here.

[0242] According to the LLM-based multi-machine cooperative abnormal data detection method of the embodiment of the present application, the on-board end generates an anomaly detection score; the first historical features are extracted from the first historical database in the edge server, and a binary classification anomaly detection label is obtained according to the first historical features and the anomaly detection score, and a performance index vector is calculated, and the binary classification anomaly detection label and the performance index vector are uploaded to the cloud end; the cloud end is used for long-time sequence prediction to obtain a long-time sequence prediction result, and security analysis is performed to obtain a security analysis result. Thus, the problems of mechanism loss, data processing bottleneck, insufficient threat response, and poor system scalability of the existing unmanned aerial vehicle cluster in multi-machine cooperative security are solved, efficient multi-machine cooperation is achieved, and data processing and utilization are optimized.

[0243] Secondly, the LLM-based multi-machine cooperative abnormal data detection system according to the embodiment of the present application is described with reference to the accompanying drawings.

[0244] Figure 5 The structure schematic diagram of the electronic device provided by the embodiment of the present application is provided. The electronic device can include:

[0245] The memory 501, the processor 502, and the computer program stored in the memory 501 and executable on the processor 502.

[0246] The processor 502 implements the LLM-based multi-machine cooperative abnormal data detection method provided in the above embodiments when executing the program.

[0247] Further, the electronic device further includes:

[0248] The communication interface 503 is used for communication between the memory 501 and the processor 502.

[0249] The memory 501 is used to store the computer program executable on the processor 502.

[0250] The memory 501 can include a high-speed RAM memory, and can also include a non-volatile memory, such as at least one disk memory.

[0251] If the memory 501, the processor 502 and the communication interface 503 are implemented independently, the communication interface 503, the memory 501 and the processor 502 can be connected with each other through a bus and complete communication between each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, Figure 5 Only one thick line is used to represent the bus in the figure, but it does not mean that there is only one bus or only one type of bus.

[0252] Optionally, in a specific implementation, if the memory 501, the processor 502 and the communication interface 503 are integrated on a chip, the memory 501, the processor 502 and the communication interface 503 can complete communication between each other through an internal interface.

[0253] The processor 502 can be a Central Processing Unit (CPU), or an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement one or more embodiments of the present application.

[0254] The embodiment of the present application also provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the LLM-based multi-machine cooperative abnormal data detection method.

[0255] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example" or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples without contradiction.

[0256] In addition, the terms "first", "second", etc. are used only for the purpose of description, and should not be understood as indicating or implying relative importance or a specific number of the technical features indicated. Therefore, the features defined as "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, such as two, three, etc., unless otherwise specifically limited.

[0257] Although the embodiments of the present application have been shown and described above, it is understood that the above-described embodiments are exemplary and should not be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above-described embodiments within the scope of the present application.

Claims

1. A multi-machine collaborative anomaly data detection system based on LLM, characterized in that, The system includes: The generation module is used to generate at least one anomaly detection score using the airborne terminal; The processing module is used to extract features from the first historical database in the edge server to obtain the first historical features, and to obtain a binary anomaly detection label based on the first historical features and the at least one anomaly detection score, and to calculate the performance index vector, and to upload the binary anomaly detection label and the performance index vector to the cloud. The prediction and analysis module is used to perform long-term series prediction using the cloud to obtain long-term series prediction results, and to perform security analysis using the cloud to obtain security analysis results. The LLM-based multi-machine collaborative anomaly data detection system is further configured to: obtain a second historical feature from the second historical database in the cloud; upload the at least one anomaly detection score, the binary anomaly detection label, the performance index vector, the first historical feature, the second historical feature, the long-term series prediction result, and the security analysis result to a decision agent in the edge server; based on a preset hybrid expert model mechanism, use the decision agent to perform fusion calculations on the at least one anomaly detection score, the binary anomaly detection label, the performance index vector, the first historical feature, the second historical feature, the long-term series prediction result, and the security analysis result to obtain an optimal collaborative decision vector; and based on the optimal collaborative decision vector, control at least one target UAV to perform a multi-machine collaborative task.

2. The multi-machine collaborative anomaly data detection system based on LLM according to claim 1, characterized in that, The prediction and analysis module is used for: Transform the optimal collaborative decision vector into target behavior instructions; The target behavior command is sent to at least one target drone through the edge server to control the at least one target drone to perform a multi-drone collaborative task.

3. The multi-machine collaborative anomaly data detection system based on LLM according to claim 1, characterized in that, The generation module is used for: Acquire local data and sampling data from the drone's sensors, and construct a local dataset based on the local data and the sampling data; Anomaly detection processing and / or time-series prediction processing are performed on the local dataset to generate at least one anomaly detection score.

4. The multi-machine collaborative anomaly data detection system based on LLM according to claim 1, characterized in that, After performing long-term series prediction using the cloud and obtaining the long-term series prediction results, and performing security analysis using the cloud and obtaining the security analysis results, the prediction and analysis module is further used for: The model in the cloud is trained and fine-tuned offline to obtain updated model parameters; Based on the updated model parameters, the model in the edge server and / or the model in the airborne terminal are updated.

5. The multi-machine collaborative anomaly data detection system based on LLM according to claim 1, characterized in that, The LLM-based multi-machine collaborative anomaly data detection system embeds an intelligent agent.

6. A multi-machine collaborative anomaly data detection method based on LLM, characterized in that, The method includes the following steps: At least one anomaly detection score is generated using the airborne terminal; Features are extracted from the first historical database in the edge server to obtain the first historical features. A binary anomaly detection label is obtained based on the first historical features and the at least one anomaly detection score. A performance index vector is calculated, and the binary anomaly detection label and the performance index vector are uploaded to the cloud. Long-term series prediction is performed using the cloud to obtain long-term series prediction results, and security analysis is performed using the cloud to obtain security analysis results. The LLM-based multi-machine collaborative anomaly data detection method further includes: obtaining a second historical feature from the second historical database in the cloud; uploading the at least one anomaly detection score, the binary anomaly detection label, the performance index vector, the first historical feature, the second historical feature, the long-term series prediction result, and the security analysis result to a decision agent in the edge server; based on a preset hybrid expert model mechanism, using the decision agent to perform fusion calculations on the at least one anomaly detection score, the binary anomaly detection label, the performance index vector, the first historical feature, the second historical feature, the long-term series prediction result, and the security analysis result to obtain an optimal collaborative decision vector; and controlling at least one target UAV to perform a multi-machine collaborative task based on the optimal collaborative decision vector.

7. An electronic device, characterized in that, include: The system includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the LLM-based multi-machine collaborative anomaly data detection method as described in claim 6.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer program is executed by a processor to implement the LLM-based multi-machine collaborative anomaly data detection method as described in claim 6.

Citation Information

Patent Citations

  • Equipment anomaly detection system and method based on cloud edge cooperation mode

    CN115098330A