Iot device behavior analysis method and system based on adaptive feature extraction

By using an adaptive feature extraction method and combining communication quality, resource load, environmental state, and protocol feature parameters, an anomaly detection model is constructed, which solves the problem of accuracy in behavioral analysis of IoT devices in multi-dimensional environments and improves the sensitivity and accuracy of anomaly detection.

CN120825422BActive Publication Date: 2025-11-18ELIDA (FUJIAN) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511332106.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-11-18
Estimated Expiration
2045-09-18

AI Technical Summary

Technical Problem

Existing IoT device behavior analysis methods are difficult to fully reflect the dynamic characteristics of devices in a multi-dimensional environment, and traditional anomaly detection models have poor adaptability in the case of protocol switching or sudden environmental changes, which can easily lead to misjudgment or missed judgment.

Method used

By using an adaptive feature extraction method, the original time-series signals of IoT devices are obtained. Combined with communication quality, resource load, environmental status and protocol characteristic parameters, the perturbation curvature, time delay coupling potential, residual inertia factor and protocol stability function are calculated to construct an anomaly detection model and determine the abnormal state of device behavior in real time.

Benefits of technology

It achieves a comprehensive characterization of device operation behavior based on multi-dimensional information fusion, reduces energy consumption, and improves the sensitivity and accuracy of anomaly detection, making it suitable for resource-constrained IoT terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120825422B_ABST
    Figure CN120825422B_ABST
Patent Text Reader

Abstract

The application discloses an Internet of Things device behavior analysis method and system based on adaptive feature extraction, and relates to the technical field of Internet of Things.The method comprises the following steps: S1: obtaining original time sequence signals, communication quality parameters, resource load parameters, environment state parameters and protocol feature parameters of a target device; S2: calculating a disturbance curvature quantity based on the original time sequence signals and the communication quality parameters; S3: calculating a time delay coupling potential according to the disturbance curvature quantity and the resource load parameters; S4: calculating a residual inertia factor according to the time delay coupling potential and the environment state parameters; S5: constructing a protocol stability function according to the residual inertia factor and the protocol feature parameters; S6: outputting an abnormal sensitization degree according to the residual inertia factor and the protocol stability function; and S7: determining a device behavior abnormal state according to a comparison between the abnormal sensitization degree and a preset abnormal threshold value.Through multi-dimensional parameter fusion modeling and dynamic anomaly detection based on an effective data set, the behavior of an Internet of Things device is described and abnormality is recognized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) technology, specifically to a method and system for analyzing the behavior of IoT devices based on adaptive feature extraction. Background Technology

[0002] With the widespread application of IoT devices in industrial control, smart homes, and intelligent transportation, the operating status and communication behavior of these devices are becoming increasingly complex. Due to fluctuations in communication quality, changes in resource load, and environmental interference, devices are prone to abnormal behavior, affecting system stability and reliability. Existing device behavior analysis methods typically rely on single-dimensional features, such as judging solely based on communication quality or resource consumption, which fails to comprehensively reflect the dynamic characteristics of devices in multi-dimensional environments. Furthermore, traditional anomaly detection models exhibit poor adaptability under protocol switching or sudden environmental changes, easily leading to misjudgments or missed detections. Therefore, there is an urgent need for a multi-dimensional feature extraction method that integrates communication quality, resource load, environmental status, and protocol characteristics, combined with an adaptive modeling mechanism, to achieve accurate detection and real-time anomaly judgment of IoT device behavior. Summary of the Invention

[0003] In view of the shortcomings of the prior art described above, the purpose of this invention is to provide a method and system for analyzing the behavior of Internet of Things devices based on adaptive feature extraction, so as to solve the above-mentioned technical problems.

[0004] To achieve the above objectives, the present invention provides the following technical solution: a method for analyzing the behavior of IoT devices based on adaptive feature extraction, comprising:

[0005] S1: Acquire the raw timing signal of the target device, and synchronously collect communication quality parameters, resource load parameters, environmental status parameters and protocol characteristic parameters according to the preset sampling frequency;

[0006] S2: Calculate the perturbation curvature of the communication quality modulation based on the original timing signal and communication quality parameters;

[0007] S3: Based on the perturbation curvature, combined with the original timing signal and resource load parameters, calculate the time-delay coupling potential of resource load modulation;

[0008] S4: Calculate the residual inertia factor of environmental abrupt modulation based on the time-delay coupling potential and environmental state parameters;

[0009] S5: Based on the residual inertia factor and combined with protocol characteristic parameters, construct a protocol-aware protocol stability function;

[0010] S6: Based on the residual inertia factor and protocol stability function, construct an anomaly detection model for equipment behavior and output the real-time anomaly sensitivity.

[0011] S7: Based on the comparison between the abnormal sensitivity and the preset abnormal threshold, determine the abnormal state of the device behavior in real time.

[0012] The present invention is further configured such that S2 includes:

[0013] The original time series signal is normalized to obtain the normalized original time series signal;

[0014] Based on the normalized original time series signal, a third-order difference accumulation operation is performed within a preset local time window to obtain the bending intensity of the signal.

[0015] Based on communication quality parameters, a curvature suppression function for communication degradation response is constructed, wherein the communication quality parameters include latency jitter and packet loss rate;

[0016] The bending strength quantity is modulated by the communication state response using the curvature suppression function, and the perturbation curvature quantity is output.

[0017] The latency jitter is calculated by the standard deviation of transmission latency within a preset time window, and the packet loss rate is calculated by the proportion of packet loss events within the same time window.

[0018] The present invention is further configured such that S3 includes:

[0019] Based on the perturbation curvature, combined with the normalized original time-series signal and its time delay differential components, a time-domain integral operation of the historical coupling contribution is performed to generate a preliminary coupling potential.

[0020] Based on resource load parameters, a multi-dimensional load-coupled resource decay function is constructed, wherein the resource load parameters include processor utilization, memory occupancy, and battery discharge curve curvature.

[0021] The initial coupling potential is modulated by the resource load response using the resource decay function, and the time-delay coupling potential is output.

[0022] The present invention is further configured such that S4 includes:

[0023] The time-delayed coupling potential is integrated with a time-weighted quadratic weight to generate the fundamental inertial quantity.

[0024] Based on environmental state parameters, an inertial suppression function for environmental gradient response is constructed, wherein the environmental state parameters include temperature change gradient, humidity change gradient, and vibration intensity integral.

[0025] The residual inertia factor is output by modulating the fundamental inertia quantity in response to environmental abrupt changes through an inertial suppression function.

[0026] The present invention is further configured such that S5 includes:

[0027] A fourth-order difference integral is performed on the residual inertia factor to generate the intensity of inertial change.

[0028] Based on protocol characteristic parameters, a stability modulation function for the protocol state response is constructed, wherein the protocol characteristic parameters include protocol type and protocol switching acceleration;

[0029] A protocol stability function is constructed by dynamically modulating the intensity of inertial change using a stability modulation function that is adaptive to the protocol.

[0030] The present invention is further configured such that the stability modulation function performs differentiated modulation according to the protocol type:

[0031] When the protocol type is an unreliable transmission protocol, an exponential amplification mechanism based on protocol switching acceleration is adopted;

[0032] When the protocol type is a reliable transmission protocol, a quadratic polynomial weighting mechanism based on protocol switching acceleration is adopted;

[0033] When the protocol is in a switching state, the cubic term of the protocol switching change intensity is used to enhance the modulation sensitivity.

[0034] The protocol switching acceleration is calculated using the second derivative of the protocol state change rate, and the protocol switching mutation intensity is calculated using the frequency and amplitude of protocol type switching events per unit time.

[0035] The present invention is further configured such that S6 includes:

[0036] Construct an effective dataset based on three-dimensional constraints, and extract a subset of residual inertia factor data from the sampling times corresponding to the effective dataset;

[0037] Based on a subset of residual inertia factor data, protocol-related aggregation operations are performed to generate a device-specific reference inertia center.

[0038] The deviation of the historical residual inertia factor from the reference inertia center is accumulated in the time domain to generate the deviation accumulation.

[0039] Based on the cumulative deviation and the stability function, an anomaly detection model for device behavior is constructed, and the real-time anomaly sensitivity of the device is output.

[0040] The present invention is further configured such that the construction step of the effective dataset includes:

[0041] Iterate through all sampling times of the target device within the preset total observation time, and perform three-dimensional constraint condition judgment for each sampling time:

[0042] The communication quality index calculated based on the communication quality parameters is greater than or equal to the preset communication quality threshold.

[0043] The Euclidean norm of the resource load index calculated based on the resource load parameters is less than or equal to the preset resource load threshold.

[0044] The Euclidean norm of the environmental response index calculated based on environmental state parameters is less than or equal to the preset environmental gradient threshold.

[0045] A sampling time is included in the valid dataset only if it simultaneously satisfies the above three-dimensional constraints. The valid dataset consists of sampling times that satisfy all constraints.

[0046] The present invention is further configured such that S7 includes:

[0047] When the abnormal sensitivity exceeds the preset abnormal threshold, the device behavior is determined to be in an abnormal state.

[0048] When the abnormal sensitivity is less than or equal to the preset abnormal threshold, the device behavior is determined to be in a normal state.

[0049] This invention also provides an IoT device behavior analysis system based on adaptive feature extraction, the system comprising:

[0050] Signal acquisition module: used to acquire the raw timing signals of the target device, and synchronously acquire real-time communication quality parameters, resource load parameters, environmental status parameters and protocol characteristic parameters through a preset sampling frequency;

[0051] Perturbation calculation module: used to calculate the perturbation curvature of communication quality modulation based on the original timing signal and communication quality parameters;

[0052] Delay Coupling Potential Calculation Module: Used to calculate the delay coupling potential of resource load modulation based on the perturbation curvature, combined with the original timing signal and resource load parameters;

[0053] Residual inertia factor calculation module: used to calculate the residual inertia factor of environmental abrupt modulation based on the time delay coupling potential and environmental state parameters;

[0054] Protocol stability construction module: used to construct a protocol-aware protocol stability function based on the residual inertia factor and protocol characteristic parameters;

[0055] Anomaly detection modeling module: used to construct anomaly detection models of equipment behavior based on residual inertia factor and protocol stability function, and output real-time anomaly sensitivity.

[0056] Abnormal state determination module: used to determine the abnormal state of device behavior in real time based on the comparison result of abnormal sensitivity and preset abnormal threshold.

[0057] This invention provides a method and system for analyzing the behavior of IoT devices based on adaptive feature extraction. The method comprises: S1: acquiring the original time-series signal of the target device and synchronously collecting communication quality parameters, resource load parameters, environmental state parameters, and protocol feature parameters according to a preset sampling frequency; S2: calculating the perturbation curvature of communication quality modulation based on the original time-series signal and communication quality parameters; S3: calculating the time-delay coupling potential of resource load modulation based on the perturbation curvature, combined with the original time-series signal and resource load parameters; S4: calculating the residual inertia factor of environmental abrupt modulation based on the time-delay coupling potential and environmental state parameters; S5: constructing a protocol-aware protocol stability function based on the residual inertia factor and protocol feature parameters; S6: constructing an anomaly detection model of device behavior based on the residual inertia factor and protocol stability function, and outputting a real-time anomaly sensitivity; S7: determining the abnormal state of device behavior in real time based on the comparison result of the anomaly sensitivity and a preset anomaly threshold. The beneficial effects include:

[0058] 1. By acquiring the original timing signals of the target device and combining them with communication quality parameters, resource load parameters, environmental status parameters, and protocol characteristic parameters, a complete analysis framework can be established based on multi-dimensional information fusion, thereby achieving a comprehensive characterization of the device's operating behavior;

[0059] 2. In the time-delay coupling potential calculation stage, the initial coupling potential is dynamically modulated by the resource decay function. Considering multi-dimensional load factors such as processor utilization, memory usage and battery discharge curve curvature, the calculation intensity can be adaptively adjusted according to the device operating status, thereby reducing energy consumption while ensuring detection effect. It is suitable for IoT terminals with limited resources.

[0060] 3. In the anomaly detection stage, an effective dataset is constructed based on three-dimensional constraints, and the deviation between the reference inertia center and the residual inertia factor is dynamically accumulated. Combined with the protocol stability function, an anomaly detection model is generated, which can accurately identify the deviation trend of equipment behavior and improve the sensitivity and accuracy of anomaly detection.

[0061] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0062] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:

[0063] Figure 1 A flowchart illustrating an exemplary embodiment of the present invention of an IoT device behavior analysis method based on adaptive feature extraction;

[0064] Figure 2 This is a schematic diagram illustrating the structure of an IoT device behavior analysis system based on adaptive feature extraction, as an exemplary embodiment of the present invention. Detailed Implementation

[0065] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.

[0066] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0067] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the invention. However, it will be apparent to those skilled in the art that embodiments of the invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the invention.

[0068] Example 1

[0069] IoT device behavior analysis methods based on adaptive feature extraction, such as Figure 1 As shown, it includes:

[0070] S1: Acquire the raw timing signal of the target device, and synchronously collect communication quality parameters, resource load parameters, environmental status parameters and protocol characteristic parameters according to the preset sampling frequency;

[0071] S2: Calculate the perturbation curvature of the communication quality modulation based on the original timing signal and communication quality parameters;

[0072] S3: Based on the perturbation curvature, combined with the original timing signal and resource load parameters, calculate the time-delay coupling potential of resource load modulation;

[0073] S4: Calculate the residual inertia factor of environmental abrupt modulation based on the time-delay coupling potential and environmental state parameters;

[0074] S5: Based on the residual inertia factor and combined with protocol characteristic parameters, construct a protocol-aware protocol stability function;

[0075] S6: Based on the residual inertia factor and protocol stability function, construct an anomaly detection model for equipment behavior and output the real-time anomaly sensitivity.

[0076] S7: Based on the comparison between the abnormal sensitivity and the preset abnormal threshold, determine the abnormal state of the device behavior in real time.

[0077] The present invention is further configured such that S2 includes:

[0078] The original time series signal is normalized to obtain the normalized original time series signal;

[0079] Based on the normalized original time series signal, a third-order difference accumulation operation is performed within a preset local time window to obtain the bending intensity of the signal.

[0080] Based on communication quality parameters, a curvature suppression function for communication degradation response is constructed, wherein the communication quality parameters include latency jitter and packet loss rate;

[0081] The bending strength quantity is modulated by the communication state response using the curvature suppression function, and the perturbation curvature quantity is output.

[0082] The latency jitter is calculated using the standard deviation of transmission latency within a preset time window, and the packet loss rate is calculated using the proportion of packet loss events within the same time window. Specifically, this embodiment is used to calculate the perturbation curvature based on the original timing signal of the target device and its communication quality parameters to reflect the bending characteristics of the signal under the device's communication state. In this embodiment, the original timing signal is acquired by a multi-modal sensor system, and the signal includes device status signal, energy consumption signal, communication signal, and interaction event signal. The device status signal is used to characterize the device's operating state, including power-on, standby, and power-off states. This signal is acquired by a binary switch status sensor and transmitted through a digital input interface to achieve real-time recording of the device's operating state. The energy consumption signal is used to reflect the energy consumption characteristics of the device during operation, specifically including parameters such as current, voltage, and power. It is acquired in real time by current and voltage sensors and transmitted to the data processing module in the form of analog signals for subsequent power analysis and energy consumption pattern modeling. The communication signal is used to characterize the device's interaction with other devices. The system collects communication status data between devices or networks, including data packet timing, data packet size, and packet loss rate. This signal is acquired through network traffic monitoring and is applicable to data capture for Wi-Fi, Bluetooth, and ZigBee protocols, providing basic data for communication behavior analysis. Interactive event signals record interactions between devices and users, including touch, click, and swipe events. These are collected by sensors on input devices such as touchscreens, buttons, or remote controls, recording the operation time and type, providing a basis for user behavior pattern analysis. The acquired raw time-series signal from the target device is normalized to eliminate the impact of differences in dimensions and amplitudes on subsequent calculations, ensuring the comparability of the third-order differential accumulation operation. Within a preset local time window, a third-order differential accumulation operation is performed on the normalized raw time-series signal to calculate the signal's bending intensity. The bending intensity is used to quantify the signal's fluctuation intensity and abrupt change characteristics over a short period. The third-order differential accumulation operation captures higher-order fluctuation information and can clearly reflect the signal's local non-stationarity. The calculation logic for the bending intensity is as follows: ,in, For equipment At any moment The bending strength quantity, quantized signal within a preset local time window The degree of curvature or bending within; , and respectively equipment At any moment , and The normalized original time-series signal; The preset local time window length is used to control the coverage of the third-order difference accumulation, i.e., the number of consecutive time points involved in the calculation. In a local time window Step index within; A unique identifier for the device; Sampling time; This is used to amplify the impact of local anomalies or spikes, enhancing the response to abnormal signal fluctuations; it synchronously acquires the device's communication quality parameters, including latency jitter and packet loss rate. Latency jitter is calculated using the standard deviation of transmission latency within a preset time window, and packet loss rate is calculated using the proportion of packet loss events within the same time window. A curvature suppression function is constructed based on latency jitter and packet loss rate to dynamically adjust the signal bending intensity according to communication quality. The construction logic of the curvature suppression function is as follows: , This is a curvature suppression function used to modulate the bending strength based on communication quality, controlling its attenuation during communication degradation. For equipment At any moment The communication quality indicators reflect the reliability of the equipment's communication link; is the modulation sensitivity coefficient, used to determine the intensity of the influence of communication quality on curvature suppression, with a value range of [1, 5]. This is used to perform a fourth-order nonlinear amplification of the degree of communication quality loss, making the attenuation response of bending strength steeper when communication deteriorates, thus enhancing the modulation effect on low communication quality states; the calculation logic of the communication quality index is as follows: ,in, For a moment The latency jitter reflects the instability of the communication link delay; For a moment The packet loss rate reflects the reliability of data packet transmission; and These are communication quality attenuation coefficients, used to control the weighting of delay jitter and packet loss rate on communication quality indicators. The value range is [0.01, 1]. The value range is [0.01, 2]; after the bending intensity of the signal is modulated by the curvature suppression function, the disturbance curvature is obtained. This processing is used to dynamically adjust the signal bending intensity according to the communication quality of the equipment, so as to realize the controllable response of communication quality changes to signal disturbances. The calculation logic of the disturbance curvature is as follows: ,in, For equipment At any moment The perturbation curvature is the local signal bending intensity after fusion communication quality modulation, used to quantify device behavior perturbations; The modulation coefficient is used to control the degree of amplification or suppression of the bending intensity by the modulation of the communication state, and its value ranges from [0, 6].

[0083] The present invention is further configured such that S3 includes:

[0084] Based on the perturbation curvature, combined with the normalized original time-series signal and its time delay differential components, a time-domain integral operation of the historical coupling contribution is performed to generate a preliminary coupling potential.

[0085] Based on resource load parameters, a multi-dimensional load-coupled resource decay function is constructed, wherein the resource load parameters include processor utilization, memory occupancy, and battery discharge curve curvature.

[0086] Resource load response modulation is applied to the initial coupling potential using a resource attenuation function to output a time-delay coupling potential. Specifically, based on the normalized original time-series signal and a fixed time delay difference, the signal variation at consecutive moments is calculated to characterize the short-term dynamics of the device behavior. By integrating the disturbance curvature and signal variation in the time domain, historical coupling contributions are accumulated to generate a preliminary coupling potential. This integral reflects the coupling strength between the device signal variation and the disturbance curvature from the initial time to the current time period. The calculation logic of the preliminary coupling potential is as follows: ,in, For equipment At any moment The initial coupling potential is used to measure the coupling strength between historical disturbances and equipment status. Through historical integration, long-term coupling patterns of signals can be identified, and potential abnormal trends in equipment behavior can be captured. The preset delay step size; For equipment At any moment The amount of perturbation curvature; Let be the integral variable; by comprehensively considering the device's processor utilization, memory usage, and battery discharge curve curvature, a resource decay function is calculated. This resource decay function represents the degree of degradation of the device's resources. Combined with the influence of the device's current load state on historical behavior patterns, the calculation logic of the resource decay function is as follows: ,in, This is a resource decay function used to represent the strength of the influence of device resource load on the time-delay coupling potential; The Euclidean norm of the resource load index represents the device's performance at time [time]. The overall resource load status, and the calculation logic of the Euclidean norm of the resource load index is as follows: , Processor utilization rate reflects the degree of processor resource usage. This is the memory utilization rate, used to reflect the degree of memory resource usage. The curvature of the battery discharge curve is given. The initial coupling potential is modulated by the resource decay function to obtain the time-delay coupling potential. This modulation process reflects the influence of the equipment load state on the equipment's behavioral history and demonstrates the modulating role of this influence in time-delay coupling. The calculation logic of the time-delay coupling potential is as follows: ,in, For equipment At any moment The time-delay coupling potential is used to describe the time delay variation of the device during signal transmission and processing under different resource load conditions, and the impact of this time delay variation on the device behavior. This is the attenuation adjustment coefficient, used to adjust the sensitivity to load attenuation. The value range is [0, 1]. In the dynamic evolution of device load status, when the device is under high load, especially when the processor utilization or memory occupancy is close to saturation, the resource decay function increases, resulting in a decrease in the time delay coupling potential. This reflects the operating state of the system under resource bottleneck, that is, the coupling contribution of historical signals is effectively suppressed. At this time, the device behavior is more dominated by real-time load, the influence of historical data on system behavior weakens, and the effective coupling strength of signal transmission and processing weakens, which may lead to a relatively lagging response of the system to sudden load or changes. Under low load, when the processor utilization and memory occupancy are far from saturation, the resource decay function decreases, thereby increasing the time delay coupling potential. This indicates that the coupling contribution of historical signals is preserved, and the device can efficiently coordinate real-time behavior and historical behavior.

[0087] The present invention is further configured such that S4 includes:

[0088] The time-delayed coupling potential is integrated with a time-weighted quadratic weight to generate the fundamental inertial quantity.

[0089] Based on environmental state parameters, an inertial suppression function for environmental gradient response is constructed, wherein the environmental state parameters include temperature change gradient, humidity change gradient, and vibration intensity integral.

[0090] The basic inertia quantity is modulated by an environmental abrupt response using an inertial suppression function, outputting a residual inertia factor. Specifically, the basic inertia quantity is obtained by performing a time-weighted integral operation on the time-delay coupling potential. The purpose of this step is to consider the influence of historical time-delay coupling potential on the current state of the equipment. The calculation logic of the basic inertia quantity is as follows: ,in, For equipment At any moment The basic inertia represents the degree to which the resource load and behavior coupling of the device over a historical period affects the current state of the device. For equipment At any moment The time-delay coupling potential; The weighting function represents the square of the time difference. This weighting function is used to weight the relationship between historical behavior and the current moment based on the time difference, thus amplifying the influence of longer time spans on the current moment. The calculation logic of the inertia suppression function is as follows: ,in, This is the inertia suppression function, used to adjust the response of equipment to residual inertia factors when the environment changes drastically. When the equipment is in a state of sudden environmental change, the inertia suppression function... The value increases, thereby suppressing the growth of residual inertia factor, ensuring that the system can respond to sudden environmental changes in a timely manner, and avoiding excessive reliance of equipment on historical states; The Euclidean norm of the environmental response index is used to measure the intensity of environmental change. The calculation logic for the Euclidean norm of the environmental response index is as follows: , The temperature gradient represents the rate of temperature change per unit time. The humidity gradient represents the rate of change of humidity per unit time. The vibration intensity integral is used to describe the intensity of vibration disturbances in the environment. The residual inertia factor is calculated by modulating the basic inertia quantity according to the inertial suppression function. This residual inertia factor is used to capture the adaptive process of the equipment between historical behavior and current environmental changes. The calculation logic of the residual inertia factor is as follows: ,in, For equipment At any moment The residual inertia factor is used to reflect the equipment's ability to adapt to changes in the external environment or the load on internal resources. This is the environmental adjustment coefficient, used to control the intensity of the impact of environmental changes on the residual inertia factor, with a value range of [0, 5]. When the residual inertia factor... A smaller residual inertia factor indicates that the equipment has adapted to changes in the external environment or internal load relatively quickly, and the equipment can quickly transition from its historical state to its current state, reflecting the equipment's strong adaptability. Conversely, when the residual inertia factor is large, it indicates that the equipment is still in the inertial stage of the adaptation process and has not yet fully adapted to the new environmental changes.

[0091] The present invention further specifies that step S5 includes: performing a fourth-order differential integral operation on the residual inertia factor to generate an inertia change intensity quantity; constructing a stability modulation function for the protocol state response based on protocol characteristic parameters, wherein the protocol characteristic parameters include protocol type and protocol switching acceleration; and performing protocol-adaptive dynamic modulation on the inertia change intensity quantity through the stability modulation function to construct a protocol stability function. The present invention further specifies that the stability modulation function performs differentiated modulation according to protocol type classification: when the protocol type belongs to an unreliable transmission protocol, an exponential amplification mechanism based on protocol switching acceleration is used; when the protocol type belongs to a reliable transmission protocol, an exponential amplification mechanism based on protocol switching acceleration is used. A quadratic polynomial weighting mechanism for speed is used; when the protocol is in a switching state, the cube term of the protocol switching mutation intensity is used to enhance modulation sensitivity; the protocol switching acceleration is calculated using the second derivative of the protocol state change rate, and the protocol switching mutation intensity is calculated using the frequency and amplitude of protocol type switching events per unit time; specifically, by performing a fourth-order differential integral on the residual inertia factor, an inertial change intensity quantity is generated. This inertial change intensity quantity is used to quantify the inertial change intensity of the device in the time dimension. The fourth-order differential integral can effectively capture the high-order dynamic characteristics of device state changes, helping the system to accurately identify and analyze inertial fluctuations in device behavior; the calculation logic of the inertial change intensity quantity is as follows: , For equipment At any moment The inertial change intensity represents the intensity of the change in the inertial characteristics of the equipment over time; and Representing the equipment At any moment and The residual inertia factor; the introduction of the inertia change intensity quantity enables the system to accurately capture the change amplitude of the inertia factor over time, thereby effectively quantifying the inertial fluctuations in the device behavior and identifying the adaptive changes of the device between historical and current states; the stability modulation function performs differentiated modulation according to the protocol type and protocol state to adapt to the characteristics of the protocol and the protocol switching frequency; when the protocol type is an unreliable protocol, such as UDP and CoAP, an exponential amplification mechanism based on protocol switching acceleration is adopted to enhance the dynamic adjustment capability, because unreliable protocols exhibit poor stability during switching and require stronger modulation to ensure the stability of the device; when the protocol type is a reliable protocol, such as TCP and MQTT QoS2, a quadratic polynomial weighting mechanism based on protocol switching acceleration is adopted, considering that reliable protocols have strong inherent stability and the modulation process is relatively smooth; when the protocol is in a switching state, a cubic term of the protocol switching mutation intensity is used to enhance the modulation sensitivity, thereby more effectively dealing with the system disturbances brought about by protocol switching; the calculation logic of the stability modulation function is as follows: ,in, This is a stability modulation function used to control the system stability during protocol switching. Indicates protocol characteristic parameters; and These are modulation coefficients, used to control the modulation effects of unreliable and reliable protocols, respectively. The value range is [1, 5]. The value range is [0.1, 1]; For protocol type, discrete encoding identifier, such as MQTTQoS1, CoAP, and HTTP / 2, etc.; The acceleration of protocol switching is calculated using the second derivative of the protocol state change rate, i.e., the acceleration of indicators such as the number of connections and retransmission rate. For protocol switching acceleration modulus; A set of unreliable protocol types; A set of reliable protocol types; This indicates a protocol switching state, signifying that the protocol is in the process of switching from one type to another. The magnitude of the protocol type gradient represents the intensity of protocol type abrupt changes. It is calculated from the protocol type switching frequency and amplitude. The frequency represents the number of times the protocol type switches per unit time, while the amplitude is determined by the protocol type... The numerical mapping is used for calculation, and the protocol type is converted into a vector representation using One-Hot encoding. For example, MQTTQoS1 can be mapped to [1, 0, 0], and HTTP / 2 can be mapped to [0, 0, 1]. Therefore, the magnitude of the protocol type switching from MQTTQoS1 to HTTP / 2 can be represented as the difference between the vectors, i.e., [1, 0, 0]. [0, 0, 1] = [1, 0, -1] = The protocol stability function measures the stability and adaptability of a device during protocol switching and load changes. It calculates the device's protocol adaptability by weighting historical inertia changes and combining this with a dynamically adjusted stability modulation function. The calculation logic of the protocol stability function is as follows: ,in, This is the protocol stability function; The attenuation coefficient is used to control the degree to which the device depends on historical behavior, and its value ranges from [0, 1]. This is a stability modulation function.

[0092] The present invention further specifies that step S6 includes: constructing an effective dataset based on three-dimensional constraints; extracting a subset of residual inertia factor data from the sampling times corresponding to the effective dataset; performing protocol-related aggregation operations based on the subset of residual inertia factor data to generate a device-specific reference inertia center; performing time-domain accumulation operations on the deviations between historical residual inertia factors and the reference inertia center to generate a deviation accumulation amount; constructing an anomaly detection model of device behavior based on the deviation accumulation amount and a stability function, and outputting the device's real-time anomaly sensitivity; the present invention further specifies that the construction step of the effective dataset includes: traversing all sampling times of the target device within a preset total observation period, and performing a three-dimensional constraint condition judgment for each sampling time: based on the communication quality parameters calculated... The communication quality index is greater than or equal to a preset communication quality threshold; the Euclidean norm of the resource load index calculated based on resource load parameters is less than or equal to a preset resource load threshold; the Euclidean norm of the environmental response index calculated based on environmental state parameters is less than or equal to a preset environmental gradient threshold; only when the above three-dimensional constraints are met simultaneously at the sampling time are they included in the valid dataset, which consists of sampling times that meet all constraints; specifically, the construction of the valid dataset is to filter out low-quality sampling times and retain only data that meets the above three-dimensional constraints, which can effectively represent the actual behavior of the device; the three-dimensional constraints include: the communication quality index calculated based on communication quality parameters is greater than or equal to a preset communication quality threshold, that is: ,in, For communication quality indicators, The preset communication quality threshold is defined as follows: the Euclidean norm of the resource load index calculated based on the resource load parameters is less than or equal to the preset resource load threshold, i.e.: ,in, The Euclidean norm of the resource load index. The preset resource load threshold is used; the Euclidean norm of the environmental response index calculated based on environmental state parameters is less than or equal to the preset environmental gradient threshold, i.e.: ,in, The Euclidean norm of the environmental response indicator. A preset environmental gradient threshold is used; when the device's communication quality, resource load, and environmental status simultaneously meet the above three-dimensional constraints, the data sampling moment is included in the valid dataset. This valid dataset contains all sampling times that satisfy the above three-dimensional constraints; the calculation logic for the reference inertial center is as follows: ,in, For equipment The reference inertia center represents the expected inertia value of the device behavior, which is the standard behavior state of the device calculated based on the sampling time in the effective dataset; The sampling time in the valid dataset; The time decay weighting function is used to assign higher weights to recent data and reduce the influence of historical data. The calculation logic of the time decay weighting function is as follows: ,in, is the decay coefficient, used to control the rate of time decay, and its value ranges from [0, 1]. The current moment; For a valid dataset The cardinality, i.e., the sampling time in the effective dataset that satisfies the three-dimensional constraints. The total number; based on the equipment's residual inertia factor and reference inertia center, the deviation is calculated, and the deviation is subjected to a three-fold weighted accumulation operation in the time domain to obtain the cumulative deviation. By accumulating the continuous deviation of the equipment's behavior, possible abnormal behaviors are amplified, thereby improving detection sensitivity; the calculation logic of the cumulative deviation is as follows: ,in, For equipment At any moment Cumulative deviation; The deviation is weighted three times, which enhances the impact when the deviation is large, especially when the equipment experiences significant anomalies, amplifying the anomaly signal more strongly. Based on the cumulative deviation and the stability function, an anomaly detection model for equipment behavior is constructed. The construction logic of the anomaly detection model is as follows: ,in, For equipment At any moment The abnormal sensitivity is used to assess the degree of abnormality in device behavior. A higher value indicates a more severe abnormal behavior of the device. It is a constant used to prevent the denominator from being zero, and its value range is [0.0000001, 0.0001].

[0093] The present invention is further configured such that S7 includes:

[0094] When the abnormal sensitivity exceeds the preset abnormal threshold, the device behavior is determined to be in an abnormal state.

[0095] When the abnormal sensitivity is less than or equal to a preset abnormal threshold, the device behavior is determined to be in a normal state. Specifically, the abnormal sensitivity is judged in real time based on the preset abnormal threshold to determine whether the device is in an abnormal state. When the abnormal sensitivity is greater than the preset abnormal threshold, that is: The device is determined to be in an abnormal state, among which... A preset anomaly threshold is set; when the anomaly sensitivity is less than or equal to the preset anomaly threshold, i.e.: Determine that the device behavior is in a normal state; preset abnormal threshold. The preset anomaly threshold is obtained by using the weighted median and interquartile range extended standard deviation of the anomaly sensitivity dataset from the historical observation period. The calculation logic is as follows: ,in, The statistical significance coefficient is used to determine the width of the anomaly threshold, and its value ranges from [2.5, 3.5]. The weighted median represents a robust estimate of the central trend of historical normal behavior. The extended standard deviation of the interquartile range is a robust estimator representing the dispersion of historical data; in this embodiment, The preferred value is 3, based on the statistical concept of 3. The principle is improved by replacing the traditional arithmetic mean and standard deviation with robust statistics (such as the weighted median and interquartile range standard deviation). Its core physical meaning is that when the device currently exhibits abnormal sensitivity... When the deviation from the central trend of historical normal behavior exceeds the fluctuation range of most historical normal data points, the behavior is judged to be in an abnormal state with high confidence.

[0096] Example 2

[0097] Please see Figure 2 This exemplary IoT device behavior analysis system based on adaptive feature extraction includes:

[0098] Signal acquisition module: used to acquire the raw timing signals of the target device, and synchronously acquire real-time communication quality parameters, resource load parameters, environmental status parameters and protocol characteristic parameters through a preset sampling frequency;

[0099] Perturbation calculation module: used to calculate the perturbation curvature of communication quality modulation based on the original timing signal and communication quality parameters;

[0100] Delay Coupling Potential Calculation Module: Used to calculate the delay coupling potential of resource load modulation based on the perturbation curvature, combined with the original timing signal and resource load parameters;

[0101] Residual inertia factor calculation module: used to calculate the residual inertia factor of environmental abrupt modulation based on the time delay coupling potential and environmental state parameters;

[0102] Protocol stability construction module: used to construct a protocol-aware protocol stability function based on the residual inertia factor and protocol characteristic parameters;

[0103] Anomaly detection modeling module: used to construct anomaly detection models of equipment behavior based on residual inertia factor and protocol stability function, and output real-time anomaly sensitivity.

[0104] Abnormal state determination module: used to determine the abnormal state of device behavior in real time based on the comparison result of abnormal sensitivity and preset abnormal threshold.

[0105] It should be noted that the IoT device behavior analysis system based on adaptive feature extraction provided in the above embodiments and the IoT device behavior analysis method based on adaptive feature extraction provided in the above embodiments belong to the same concept. The specific ways in which each module and unit performs operations have been described in detail in the method embodiments, and will not be repeated here. In practical applications, the IoT device behavior analysis system based on adaptive feature extraction provided in the above embodiments can be assigned to different functional modules as needed, that is, the internal structure of the system can be divided into different functional modules to complete all or part of the functions described above, and this is not a limitation here.

[0106] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for analyzing the behavior of IoT devices based on adaptive feature extraction, characterized in that, include: S1: Acquire the raw timing signal of the target device, and synchronously collect communication quality parameters, resource load parameters, environmental status parameters and protocol characteristic parameters according to the preset sampling frequency; S2: Normalize the original time-series signal to obtain the normalized original time-series signal; based on the normalized original time-series signal, perform third-order difference accumulation operation within a preset local time window to obtain the bending intensity of the signal; based on communication quality parameters, construct a curvature suppression function for communication degradation response, wherein the communication quality parameters include delay jitter and packet loss rate. The bending strength quantity is modulated by the curvature suppression function to output the perturbation curvature quantity; the delay jitter is calculated by the standard deviation of transmission delay within a preset time window; and the packet loss rate is calculated by the proportion of packet loss events within the same time window. S3: Based on the perturbation curvature, combined with the normalized original time-series signal and its time delay differential components, perform time-domain integration of historical coupling contributions to generate an initial coupling potential; based on resource load parameters, construct a multi-dimensional load coupling resource attenuation function, whereby the resource load parameters include processor utilization, memory occupancy, and battery discharge curve curvature; modulate the initial coupling potential with the resource attenuation function to output a time delay coupling potential; S4: Perform time-weighted integral operation on the time-delay coupling potential to generate the basic inertial quantity; construct an inertial suppression function for the environmental gradient response based on environmental state parameters, including temperature change gradient, humidity change gradient and vibration intensity integral; modulate the basic inertial quantity with environmental abrupt response through the inertial suppression function to output the residual inertial factor. S5: Perform fourth-order difference integral operation on the residual inertia factor to generate the inertia change intensity quantity; construct a stability modulation function for the protocol state response based on protocol characteristic parameters, the protocol characteristic parameters including protocol type and protocol switching acceleration; perform protocol adaptive dynamic modulation on the inertia change intensity quantity through the stability modulation function to construct a protocol stability function. S6: Construct an effective dataset based on three-dimensional constraints, and extract a subset of residual inertia factor data from the sampling times corresponding to the effective dataset; Based on a subset of residual inertia factor data, protocol-related aggregation operations are performed to generate a device-specific reference inertia center; the deviation between historical residual inertia factors and the reference inertia center is accumulated in the time domain to generate a deviation accumulation; based on the deviation accumulation and the stability function, an anomaly detection model for device behavior is constructed, and the device's real-time anomaly sensitivity is output. S7: Based on the comparison between the abnormal sensitivity and the preset abnormal threshold, determine the abnormal state of the device behavior in real time.

2. The IoT device behavior analysis method based on adaptive feature extraction according to claim 1, characterized in that, The stability modulation function performs differentiated modulation according to the protocol type: When the protocol type is an unreliable transmission protocol, an exponential amplification mechanism based on protocol switching acceleration is adopted; When the protocol type is a reliable transmission protocol, a quadratic polynomial weighting mechanism based on protocol switching acceleration is adopted; When the protocol is in a switching state, the cubic term of the protocol switching change intensity is used to enhance the modulation sensitivity. The protocol switching acceleration is calculated using the second derivative of the protocol state change rate, and the protocol switching mutation intensity is calculated using the frequency and amplitude of protocol type switching events per unit time.

3. The IoT device behavior analysis method based on adaptive feature extraction according to claim 1, characterized in that, The steps for constructing the effective dataset include: Iterate through all sampling times of the target device within the preset total observation time, and perform three-dimensional constraint condition judgment for each sampling time: The communication quality index calculated based on the communication quality parameters is greater than or equal to the preset communication quality threshold. The Euclidean norm of the resource load index calculated based on the resource load parameters is less than or equal to the preset resource load threshold. The Euclidean norm of the environmental response index calculated based on environmental state parameters is less than or equal to the preset environmental gradient threshold. A sampling time is included in the valid dataset only if it simultaneously satisfies the above three-dimensional constraints. The valid dataset consists of sampling times that satisfy all constraints.

4. The IoT device behavior analysis method based on adaptive feature extraction according to claim 1, characterized in that, S7 includes: When the abnormal sensitivity exceeds the preset abnormal threshold, the device behavior is determined to be in an abnormal state. When the abnormal sensitivity is less than or equal to the preset abnormal threshold, the device behavior is determined to be in a normal state.

5. An IoT device behavior analysis system based on adaptive feature extraction, used to implement the IoT device behavior analysis method based on adaptive feature extraction as described in any one of claims 1-4, characterized in that, include: Signal acquisition module: used to acquire the raw timing signals of the target device, and synchronously acquire real-time communication quality parameters, resource load parameters, environmental status parameters and protocol characteristic parameters through a preset sampling frequency; Perturbation calculation module: used to calculate the perturbation curvature of communication quality modulation based on the original timing signal and communication quality parameters; Delay Coupling Potential Calculation Module: Used to calculate the delay coupling potential of resource load modulation based on the perturbation curvature, combined with the original timing signal and resource load parameters; Residual inertia factor calculation module: used to calculate the residual inertia factor of environmental abrupt modulation based on the time delay coupling potential and environmental state parameters; Protocol stability construction module: used to construct a protocol-aware protocol stability function based on the residual inertia factor and protocol characteristic parameters; Anomaly detection modeling module: used to construct anomaly detection models of equipment behavior based on residual inertia factor and protocol stability function, and output real-time anomaly sensitivity. Abnormal state determination module: used to determine the abnormal state of device behavior in real time based on the comparison result of abnormal sensitivity and preset abnormal threshold.

Citation Information

Patent Citations

  • Multi-dimensional time sequence equipment abnormal state prediction method and system

    CN120639589A

  • Energy-storage synchronous and coordinated management method and system based on virtual synchronization technique

    WO2025138710A1