Park multi-source heterogeneous data analysis method and system based on industrial Internet of Things
By using a multi-source heterogeneous data analysis method based on the Industrial Internet of Things (IIoT) in industrial parks, image information and anomaly detection algorithms are used to identify suspicious targets, predict their movement paths and obtain feature information. Combined with working data, the probability of anomalies is judged, which solves the problem of false alarms and missed alarms caused by data silos and realizes accurate risk identification and dynamic control.
Patent Information
- Application Number
- CN202511360565.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-23
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-09-23
AI Technical Summary
Existing technologies in industrial IoT smart parks suffer from data silos and lagging response mechanisms, making it difficult to achieve accurate risk identification and dynamic control in complex industrial scenarios, and are prone to false alarms or missed alarms.
The Industrial Internet of Things-based multi-source heterogeneous data analysis method for industrial parks identifies suspicious targets through image information anomaly detection algorithms, predicts their movement paths and obtains feature information, combines working data to predict anomaly probabilities, and marks and tracks abnormal targets.
It achieves 24/7 automated monitoring, identifies potential abnormal targets, shortens response time, improves data acquisition efficiency, reduces information silos, lowers the false judgment rate, and ensures the scientific nature of anomaly judgment.
Smart Images

Figure CN120850180A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial IoT park data analysis technology, and in particular to a method and system for analyzing multi-source heterogeneous data in industrial parks based on industrial IoT. Background Technology
[0002] In smart parks driven by the Industrial Internet of Things (IIoT), the deep interconnection of equipment, personnel, logistics, and production processes generates massive amounts of heterogeneous data from multiple sources, such as video surveillance, equipment sensors, personnel positioning, and business system logs. However, due to data silos and lagging response mechanisms, existing technologies struggle to achieve accurate risk identification and dynamic control in complex industrial scenarios, easily leading to false alarms or missed alarms. Summary of the Invention
[0003] The main purpose of this application is to provide a method and system for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things. This aims to solve the technical problems of existing technologies, which are difficult to achieve accurate risk identification and dynamic control in complex industrial scenarios due to data silos and lagging response mechanisms, and are prone to false alarms or missed alarms.
[0004] To achieve the above objectives, firstly, this application provides a method for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things, including: Based on the image information of the target area, suspicious targets are identified using an anomaly detection algorithm; Based on the movement trend of the suspected target, predict the movement path of the suspected target, and obtain the characteristic information of the suspected target through the monitoring equipment along the movement path; Based on the aforementioned feature information and combined with the work data of the suspected target within a preset time period, the probability of the suspected target exhibiting abnormal behavior is predicted, and it is determined whether the probability of abnormal behavior exceeds a preset threshold. If the anomaly probability exceeds a preset threshold, the suspicious target is marked as an abnormal target and the abnormal target is tracked.
[0005] Optionally, the step of determining suspicious targets based on image information of the target region and an anomaly detection algorithm includes: Acquire image information of the target area; if the observed object is a staff member, acquire the observed object's behavior trajectory and safety equipment wearing status. Abnormal actions are detected by spatiotemporal graph convolutional networks, and the wearing status of safety equipment is compared with preset standards in real time to determine whether the observed object is suspected of being abnormal. If so, it is marked as a suspicious target.
[0006] Optionally, the step of determining suspicious targets based on image information of the target region and an anomaly detection algorithm includes: Acquire image information of the target area; if the observed object is an AGV device, acquire the running posture and surface state of the observed object. By comparing the dynamic path planning of the observed object, detecting abnormal robot arm angles, detecting sudden speed changes, detecting surface defects, and detecting abnormal temperatures, it is determined whether the observed object is suspected of being abnormal. If so, it is marked as a suspicious target.
[0007] Optionally, the step of determining suspicious targets based on image information of the target region and an anomaly detection algorithm includes: Traverse all observed objects in the target area to obtain the number of suspicious targets within a preset time period; If the number of suspicious targets exceeds the first target threshold, the target area will be marked as an abnormal area, and the facilities in the target area will be maintained. If the number of suspicious targets exceeds the second target threshold but is less than the first target threshold, the target area will be marked as a high-risk area, and the inspection frequency of the target area will be increased.
[0008] Optionally, the step of predicting the probability of an anomaly in the suspected target's behavior based on the feature information and in conjunction with the suspected target's work data over a preset time period, and determining whether the anomaly probability exceeds a preset threshold, includes: Obtain the work data of the target under investigation over a preset time period, including at least one of the following: product yield rate, workload completion rate, continuous working hours, attendance records, and / or maintenance records.
[0009] Optionally, the step of predicting the probability of an anomaly in the suspected target's behavior based on the feature information and in conjunction with the suspected target's work data over a preset time period, and determining whether the anomaly probability exceeds a preset threshold, includes: The expression for predicting the probability of an anomaly in the suspected target is as follows:
[0010] In the formula, , and These are the weighting coefficients. Let represent the probability that a suspicious target passes through monitoring point s, and z represent the total number of monitoring points. This represents the i-th real-time feature collected at monitoring point s. and Representing features respectively The mean and standard deviation under normal conditions. The weight of real-time feature i is represented by m, and the number of real-time features is represented by m. This represents the j-th historical work indicator. and Representing indicators The mean and standard deviation under normal conditions. Indicators The weights, where n represents the total number of historical work indicators. This represents the spatiotemporal coordinates of the actual trajectory of the questionable target at time k. Represents theoretical coordinates based on movement trend prediction. This indicates the measurement error tolerance of the positioning system, and q represents the number of coordinates collected. This represents the normalization function.
[0011] Optionally, the weight expression for the real-time features is:
[0012] In the formula, This represents the dynamic weight of the i-th real-time feature at time t. This represents the probability that a suspicious target passes through monitoring point s at time t. This represents the i-th real-time feature collected at monitoring point s. This represents the historical mean of the i-th feature under normal conditions. Let z represent the historical standard deviation of the i-th feature under normal conditions, z represent the total number of monitoring points, and m represent the number of real-time feature types.
[0013] Optionally, the step of predicting the probability of an anomaly in the suspected target's behavior based on the feature information and in conjunction with the suspected target's work data over a preset time period, and determining whether the anomaly probability exceeds a preset threshold, includes: If the anomaly probability does not exceed a preset threshold, the suspicious status of the target is lifted.
[0014] Optionally, the step of marking the suspicious target as an abnormal target and tracking the abnormal target if the anomaly probability exceeds a preset threshold includes: When the probability of an anomaly exceeds one standard deviation of a preset threshold, a level three alarm is set, and the anomaly event is recorded to the log system. When the probability of an anomaly exceeds twice the standard deviation of a preset threshold, a level two alarm is set, and the abnormal target is continuously recorded by the monitoring equipment. When the probability of an anomaly exceeds three times the standard deviation of a preset threshold, a Level 1 alarm is triggered, and the drone continues to track the abnormal target.
[0015] Secondly, this application provides a multi-source heterogeneous data analysis system for industrial parks based on the Industrial Internet of Things, characterized by comprising a management platform, a sensor network platform, and an object platform that are sequentially established for communication: The sensor network platform is configured as follows: Based on the image information of the target area, suspicious targets are identified using an anomaly detection algorithm; Based on the movement trend of the suspected target, predict the movement path of the suspected target, and obtain the characteristic information of the suspected target through the monitoring equipment along the movement path; Based on the aforementioned feature information and combined with the work data of the suspected target within a preset time period, the probability of the suspected target exhibiting abnormal behavior is predicted, and it is determined whether the probability of abnormal behavior exceeds a preset threshold. The management platform is configured as follows: If the anomaly probability exceeds a preset threshold, the suspicious target is marked as an abnormal target and the abnormal target is tracked.
[0016] The beneficial effects that this application can achieve are: This application proposes a method and system for analyzing multi-source heterogeneous data in a park based on the Industrial Internet of Things (IIoT). The method includes: identifying suspicious targets based on image information of a target area using an anomaly detection algorithm; predicting the movement path of the suspicious targets based on their movement trends, and acquiring feature information of the suspicious targets through monitoring devices along the movement path; predicting the probability of anomalies in the suspicious targets based on the feature information and their work data over a preset time period, and determining whether the probability exceeds a preset threshold; if the probability exceeds the preset threshold, marking the suspicious target as an anomaly and tracking it. By combining image information and anomaly detection algorithms, all-weather automated monitoring is achieved, enabling the identification of potential anomalies and shortening the response time of traditional manual inspections. By combining movement path prediction and monitoring device linkage, existing sensors, cameras, and other multi-source devices are used to collect target feature information in real time, improving data acquisition efficiency, reducing information silos, and integrating real-time features with historical work data. Multi-dimensional analysis reduces the false judgment rate, ensures the scientific nature of anomaly judgments, and reduces invalid alarms. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating the multi-source heterogeneous data analysis method for industrial parks according to an embodiment of this application. Figure 2 This is a schematic diagram of the framework of the service platform involved in this application; Figure 3 This is a schematic diagram of the framework of the management platform involved in this application; Figure 4 This is a schematic diagram of the sensor network platform involved in this application.
[0018] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0020] It should be noted that all directional indications (such as up, down, left, right, front, back, etc.) in the embodiments of the present invention are only used to explain the relative position relationship, movement status, etc. between the various components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.
[0021] In this invention, unless otherwise explicitly specified and limited, the terms "connection," "fixed," etc., should be interpreted broadly. For example, "fixed" can mean a fixed connection, a detachable connection, or an integral part; it can mean a mechanical connection or an electrical connection; it can mean a direct connection or an indirect connection through an intermediate medium; it can mean the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0022] Furthermore, if the embodiments of this invention involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the meaning of "and / or" throughout the text includes three parallel solutions; for example, "A and / or B" includes solution A, solution B, or a solution where both A and B are satisfied simultaneously. Furthermore, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. When the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed by this invention.
[0023] Example 1 Reference Figure 1 The first embodiment of this application provides a method for analyzing multi-source heterogeneous data in a park based on the Industrial Internet of Things, including the following steps: S10. Based on the image information of the target area, identify suspicious targets using an anomaly detection algorithm.
[0024] Optionally, multiple cameras can be strategically deployed within the target area of the park to ensure coverage of key areas and passageways. Through an industrial IoT platform, image data from each camera is collected in real time, forming a continuous image sequence. The acquired images are preprocessed, employing histogram equalization to enhance image contrast and improve image quality in low-light conditions; Gaussian filtering or median filtering algorithms are used to remove noise from the images, improving image clarity and purity, providing a reliable image foundation for subsequent anomaly detection.
[0025] Pre-trained deep learning models (such as Faster R-CNN) are used to perform object recognition on pre-processed images, accurately identifying various objects such as workers, AGV equipment, and goods in the images, and marking their positions and bounding boxes in the images. AGV is short for Automated Guided Vehicle.
[0026] In an industrial park setting based on the Industrial Internet of Things (IIoT), multi-source heterogeneous data refers to data from different sources (multi-source) and with different data types and structures (heterogeneous). These data sources are extensive, covering image information of the target area (used for anomaly detection and marking of suspicious targets), feature information obtained by monitoring equipment along the movement path of suspicious targets, work data of suspicious targets over a preset time period (including product yield, workload completion, continuous working hours, attendance records, maintenance records, etc.), and data obtained through various detection methods (such as spatiotemporal graph convolutional networks for detecting abnormal actions, real-time comparison of safety equipment wearing status, dynamic path planning comparison, and abnormal detection of robotic arm angles, etc.). This diverse range of data constitutes the multi-source heterogeneous data for the industrial park, used to analyze and assess anomalies in objects within the park (such as staff, AGV equipment, etc.).
[0027] Examples of questionable targets for different objects are illustrated below: Workers exhibiting unusual behavior: In image information, if a worker is in a dangerous area (such as being near heavy machinery without protective measures) or performs actions that are inconsistent with work procedures (such as touching critical equipment during non-operational hours), their behavior trajectory and action patterns may be identified as suspicious targets after analyzing them through a spatiotemporal graph convolutional network.
[0028] Workers who do not wear safety equipment as required: If a worker in the image is not wearing necessary safety equipment such as a safety helmet, safety shoes, or protective glasses, the worker will be marked as a suspicious target by comparing the wearing status of the safety equipment with the preset specifications in real time.
[0029] AGV equipment with abnormal operating posture: In the image information, if the angle of the robotic arm of the AGV equipment deviates significantly from the normal working angle, or if the vehicle body is tilted or the wheels are off the ground, it may be identified as a suspicious target through dynamic path planning comparison and abnormal robotic arm angle detection.
[0030] AGV equipment with abnormal surface condition: If the AGV equipment in the image information has obvious damage, oil leakage, deformation or other conditions on the surface, it will be marked as a suspicious target through surface defect detection.
[0031] AGV devices with abnormal speed or position: Although the image information is static, by combining historical data and preset paths, if the AGV device should be in a different position at the time shown in the image, or if the current position is unreasonable based on its historical speed, there may be a speed change or path deviation problem. Through speed change detection and dynamic path planning comparison, it may be identified as a suspicious target.
[0032] S20. Based on the movement trend of the suspected target, predict the movement path of the suspected target, and obtain the characteristic information of the suspected target through the monitoring equipment on the movement path.
[0033] Optionally, historical movement data of the suspected target can be extracted from the database of the Industrial Internet of Things (IIoT) platform, including movement time, location coordinates, speed, and direction. This data is cleaned and preprocessed to remove outliers and noise, ensuring accuracy and reliability. Time series analysis methods (such as ARIMA models) or machine learning algorithms (such as LSTM neural networks) are used to model the historical movement data of the suspected target, analyzing its movement trends and patterns. For example, an LSTM model can be used to learn the movement patterns of the suspected target in different time periods and environments, predicting its future movement direction and speed trends. Using historical movement data as a reference, the movement trend of the suspected target can be determined based on its current movement direction, speed, current task, and carried items.
[0034] By combining the digital map of the park with consideration of obstacles (walls, equipment, cargo storage areas, etc.), passage restrictions, and traffic rules, the possible movement paths of the suspected target are predicted based on its movement trends. The A* algorithm or Dijkstra's algorithm is used for path planning to select the optimal movement path. During the prediction process, real-time information on changes in the surrounding environment of the suspected target is acquired, such as the movement of other targets and the appearance or disappearance of obstacles. Based on this dynamic information, the predicted movement path is adjusted promptly to ensure its accuracy and feasibility.
[0035] Various monitoring devices, such as high-definition cameras, temperature sensors, pressure sensors, and vibration sensors, are strategically deployed along the predicted movement path. When a suspected target enters the monitoring range of these devices, its relevant characteristic information is collected in real time. For example, cameras capture images of the suspected target's appearance, color, and shape; temperature sensors measure its surface temperature; and pressure and vibration sensors detect the pressure and vibration during its operation. The characteristic information obtained from different monitoring devices is then fused to eliminate redundancy and inconsistencies, improving data integrity and accuracy. For instance, image information from cameras is correlated with physical quantity information from sensors for a more comprehensive understanding of the suspected target's status.
[0036] S30. Based on the feature information and combined with the work data of the suspected target in the past preset time period, predict the probability of the suspected target having an abnormal situation, and determine whether the probability of the abnormal situation exceeds a preset threshold.
[0037] Optionally, a reasonable preset threshold for the probability of anomalies can be set based on the park's safety standards and actual needs. The calculated probability of anomalies is compared with the preset threshold. If the probability of anomalies exceeds the preset threshold, the suspicious target is determined to have a high risk of anomalies; if the probability of anomalies does not exceed the preset threshold, the suspicious target is considered to be within the normal range in its current state, and its suspicious status is lifted.
[0038] The following are examples illustrating abnormal situations: Examples of abnormal situations involving staff are as follows: Abnormal Action Detection: In industrial workshops, spatiotemporal graph convolutional networks are used to analyze worker behavior. Under normal circumstances, when operating machine tools, workers' actions should be fluid and standardized, such as slowly approaching the machine and accurately pressing operating buttons. If a worker suddenly rushes towards a machine tool without following the operating procedures, and the probability of this abnormal action exceeds a preset threshold in the spatiotemporal graph convolutional network model output, then the behavior is judged as abnormal. For example, in an automotive parts production workshop, if a worker suddenly reaches out and touches a high-speed rotating mechanical part without wearing protective gloves, this dangerous action would be identified as abnormal.
[0039] Unauthorized Equipment Operation: After acquiring the worker's behavioral trajectory using deep learning object detection and multi-object tracking algorithms, if it is found that a worker violates preset operating procedures while operating equipment. For example, in the reactor operating area of a chemical industrial park, regulations stipulate that workers must add raw materials in a specific order and dosage. If a worker does not add raw materials in the correct order and the dosage exceeds the prescribed range, by comparing it with the preset procedures, it is determined that the worker has engaged in abnormal behavior of unauthorized equipment operation.
[0040] Failure to wear necessary equipment: At park entrances or industrial workshops, a trained safety equipment recognition model detects the safety equipment wearing status of workers. If a worker enters a construction site without wearing a safety helmet, the model detects this and records the result as "not wearing," and according to preset standards, determines that the worker has an abnormal safety equipment wearing situation.
[0041] Improper equipment wearing: Taking goggles as an example, although the staff wore goggles, they did not adjust them properly, resulting in a large gap between the goggles and their face, thus failing to provide effective protection. Analysis using image processing technology and deep learning feature extraction methods revealed that the goggles were not worn correctly, and this was determined to be an abnormality due to improper equipment wearing.
[0042] Fatigue-related work: This involves analyzing workers' work data over a preset time period, such as continuous working hours. If a worker has worked continuously for more than 12 hours and exhibits fatigue characteristics such as a vacant stare and slow reaction time in the image data, the abnormal probability prediction formula is used to calculate, based on their work data and real-time status. If the abnormal probability exceeds a preset threshold, the worker is determined to be in an abnormal state of fatigue-related work.
[0043] Examples of AGV equipment malfunctions are as follows: Abnormal Robotic Arm Angle: The posture of the robotic arm in an AGV (Automated Guided Vehicle) is analyzed using posture recognition algorithms from computer vision technology. Based on the design parameters and normal operating range of the robotic arm, reasonable angle thresholds are set for each joint. If, during the handling of goods, the angle of a joint of the robotic arm exceeds the set threshold range—for example, if the normal operating angle range for that joint is 30° - 120°, but the actual detected angle is 130°—then the robotic arm angle is determined to be abnormal, the AGV is identified as potentially abnormal, and it is marked as a suspicious target.
[0044] Vehicle tilt: The tilt angle and other operating posture parameters of the AGV equipment are calculated through posture recognition algorithms. If the tilt angle of an AGV equipment exceeds the normal range during operation, for example, the tilt angle should be less than 5° during normal operation, but the actual detected tilt angle is 8°, it indicates that the AGV equipment may have wheel failure or unbalanced cargo loading, which is considered an abnormal operating posture.
[0045] Speed Abnormality: The real-time operating speed of the AGV is obtained using its own speed sensor or through image analysis. Speed data is collected every 0.1 seconds. If, during operation, the rate of change (acceleration) of the speed data between adjacent moments exceeds a set threshold—for example, if the absolute value of the acceleration exceeds a certain threshold twice consecutively—then an anomaly will occur. If the AGV suddenly accelerates to 3 m / s within 0.1 seconds, it is considered an abnormal speed change.
[0046] Surface Defect Detection: Image feature extraction algorithms are used to analyze the surface images of AGV equipment, extracting features such as texture, color, and shape. A deep learning-based surface defect detection model is constructed and trained using a large dataset containing images of both normal and defective AGV equipment surfaces. If scratches, dents, cracks, or other defects appear on the surface of an AGV equipment, and the model detects the severity of the defects as moderate or higher (e.g., scratches exceeding 5 cm in length and depth), the surface condition of the AGV equipment is determined to be abnormal.
[0047] Temperature Anomaly: Temperature sensors are installed in critical components of the AGV equipment (such as the motor, battery, and controller) to collect real-time temperature data. Corresponding temperature thresholds are set based on the normal operating temperature range of each component. If the operating temperature threshold for the motor of an AGV is 80℃, and the motor temperature is detected to exceed 80℃ in real-time, it is determined that the AGV equipment has a temperature anomaly, which may indicate problems such as motor overload or poor heat dissipation.
[0048] S40. If the anomaly probability exceeds a preset threshold, the suspicious target is marked as an abnormal target and the abnormal target is tracked.
[0049] Optionally, when the anomaly probability of a suspected target exceeds a preset threshold, it is immediately marked as an anomalous target and specially identified in the industrial IoT platform's management system so that relevant personnel can quickly identify it. Detailed information about the anomalous target is recorded, including the time and location of the anomaly, the type of anomaly (e.g., equipment failure, personnel violation), the anomaly probability value, characteristic information, and operational data. This information is stored in a database to form an anomaly event archive, providing a basis for subsequent analysis and processing.
[0050] Multiple tracking methods are employed to monitor abnormal targets in real time. Video tracking is conducted using the park's camera network, and image recognition technology is used to pinpoint the location and movement trajectory of abnormal targets. Positioning devices mounted on AGVs or drones are used to precisely track moving abnormal targets. Simultaneously, sensor data from the Industrial Internet of Things (IIoT) is combined to analyze the operational status of abnormal targets and changes in their surrounding environment.
[0051] Example 2 Based on Example 1, this example provides a method for analyzing multi-source heterogeneous data in a park based on the Industrial Internet of Things, including the following steps: S10. Based on the image information of the target area, identify suspicious targets using an anomaly detection algorithm.
[0052] Optionally, the step of determining suspicious targets based on image information of the target region and an anomaly detection algorithm includes: S101. Obtain image information of the target area. If the observed object is a staff member, obtain the observed object's behavior trajectory and safety equipment wearing status. Optionally, multiple cameras can be deployed in the target area (such as industrial workshops, park entrances and exits, office areas, etc.) according to actual needs and monitoring range. For example, in industrial workshops, cameras can be set up for different production lines and equipment operation areas to ensure full coverage of the workers' work areas without blind spots; at park entrances and exits, high-definition cameras can be installed to capture people's entry and exit behavior and facial features.
[0053] Adjust camera parameters such as resolution, frame rate, exposure time, and white balance based on factors like lighting conditions and distance in the monitored scene. In low-light areas, activate the camera's infrared night vision function or add supplementary lighting to ensure clear and accurate images. The camera acquires image data in real time and transmits it to a backend server or edge computing device via wired (e.g., Ethernet) or wireless (e.g., Wi-Fi, 5G) networks. To ensure stable and real-time data transmission, data compression technology is used to reduce bandwidth consumption, and a data caching mechanism is implemented to prevent data loss due to network fluctuations.
[0054] Deep learning-based object detection algorithms (such as the YOLO series and Faster R-CNN) are used to detect workers in images in real time, identifying their positions and bounding boxes. Based on the object detection results, multi-object tracking algorithms (such as DeepSORT and FairMOT) are used to continuously track the workers. These algorithms, by combining target appearance features and motion information, can accurately associate the same person in different frames and obtain their motion trajectory.
[0055] For different safety equipment (such as helmets, safety shoes, goggles, and protective gloves), unique appearance features are extracted. For example, helmets typically have specific colors, shapes, and markings; safety shoes have obvious protective structures at the toe. Image processing techniques (such as edge detection and color segmentation) and deep learning feature extraction methods (such as features extracted by convolutional neural networks) are used to describe these features. A large dataset of images of people wearing and not wearing safety equipment is collected. This dataset is then used to train a safety equipment recognition model, such as a deep learning-based classification model (ResNet, EfficientNet, etc.). During training, data augmentation techniques (such as rotation, flipping, and adding noise) are used to expand the dataset and improve the model's generalization ability. The trained safety equipment recognition model is then applied to real-time acquired images to detect the safety equipment wearing status of each worker. For each detected person, it is determined whether they are wearing various safety equipment, and the detection result (wearing / not wearing) is recorded. Considering the visibility of safety equipment on staff in different postures and angles, multi-camera collaborative detection or image stitching technology is used to acquire images of personnel from multiple angles, thereby improving the accuracy of detecting the wearing status of safety equipment.
[0056] S102. Abnormal actions are detected by spatiotemporal graph convolutional network. By comparing the wearing status of safety equipment with the preset specifications in real time, it is determined whether the observed object is suspected of being abnormal. If so, it is marked as a suspicious target; otherwise, it is marked as a normal target and is not processed subsequently.
[0057] Optionally, each worker can be considered a node in the graph, with node attributes including behavioral characteristics (such as posture, speed, and acceleration) and appearance characteristics (such as clothing color and body shape). Behavioral characteristics can be obtained through further analysis of worker trajectory data, such as using motion analysis algorithms to calculate worker motion parameters; appearance characteristics can be extracted from the results of target detection and recognition.
[0058] A large amount of video data containing both normal and abnormal human behavior was collected. The video data was labeled to clarify the category (normal / abnormal) of each action segment. The video data was converted into spatiotemporal graph data, which served as the training and testing set for the model. The Spatiotemporal Graph Convolutional Network (ST-GCN) consists of multiple spatiotemporal graph convolutional layers, pooling layers, and fully connected layers. The spatiotemporal graph convolutional layers are used to extract features from the spatiotemporal graph, capturing local and global features of human actions through convolution operations in the spatial and temporal dimensions. Pooling layers are used to reduce the dimensionality of the feature map, improving the computational efficiency of the model. Fully connected layers are used to classify the extracted features, outputting the probability that the action belongs to the normal or abnormal category.
[0059] Real-time collected data on personnel behavior trajectories and physical characteristics are used to construct a spatiotemporal graph, which is then input into a trained ST-GCN model. The model outputs the probability of a person's action belonging to a normal or abnormal category. If the probability of an abnormal category exceeds a preset threshold, the person is considered to have engaged in abnormal behavior. Abnormal behaviors include sudden falls, unsteady gait, frequent looking around, and unauthorized operation of equipment. Optionally, the step of determining suspicious targets based on image information of the target region and an anomaly detection algorithm includes: S110. Obtain image information of the target area. If the observed object is an AGV device, obtain the running posture and surface state of the observed object. Optionally, posture recognition algorithms from computer vision technology, such as deep learning-based posture estimation models (e.g., OpenPose, AlphaPose), can be used to analyze the posture of AGV devices in images. By training the model, key joints of the AGV device (e.g., wheels, body connections, robotic arm joints) can be identified, and the relative positions and angles between these joints can be calculated to determine the AGV device's operating posture. Key operating posture parameters, such as the AGV device's tilt angle, turning radius, robotic arm extension angle, and rotation angle, can be extracted from the posture recognition results. These parameters can intuitively reflect whether the AGV device is operating normally.
[0060] Image feature extraction algorithms (such as SIFT, SURF, HOG, etc.) are used to analyze the surface images of AGV equipment, extracting features such as texture, color, and shape. For example, the SIFT algorithm is used to detect key points on the AGV equipment surface, and feature descriptors of these key points are calculated for subsequent surface condition analysis. A deep learning-based surface defect detection model, such as a convolutional neural network (CNN) model, is constructed. The model is trained using a large dataset containing images of both normal and defective AGV equipment surfaces, enabling it to automatically learn and identify defect features on the AGV equipment surface, such as scratches, dents, and cracks.
[0061] S120. By comparing the dynamic path planning of the observed object, detecting abnormal angles of the robotic arm, detecting sudden speed changes, detecting surface defects, and detecting abnormal temperatures, determine whether the observed object is suspected of being abnormal. If so, mark it as a suspected target; otherwise, mark it as a normal target and do not process it further.
[0062] Optionally, AGV devices typically employ preset path planning algorithms (such as A* algorithm, Dijkstra's algorithm, etc.) for navigation. During normal operation, the AGV device should travel along the planned path. The system acquires the actual travel path of the AGV device in real time and compares it with the preset planned path. It calculates the deviation between the actual travel path and the planned path, such as lateral deviation, longitudinal deviation, and angular deviation. A reasonable deviation threshold is set; when the actual path deviation exceeds the threshold, the AGV device is deemed to have a potential anomaly. For example, if the lateral deviation continuously exceeds 10 cm and lasts for more than 5 seconds, it is identified as a suspected anomaly and marked as a suspicious target.
[0063] Based on the design parameters and normal operating range of the AGV's robotic arm, reasonable angle thresholds are set for each joint. For example, if the angle range of a certain joint during normal operation is 30°-120°, then angles less than 30° or greater than 120° are set as abnormal thresholds. Angle changes at each joint are monitored in real time using angle sensors installed at the joints or angle data obtained through image analysis. When a detected angle exceeds the set threshold range, the robotic arm angle is determined to be abnormal, the AGV is identified as potentially abnormal, and it is marked as a suspicious target.
[0064] The real-time operating speed of the AGV is obtained using its own speed sensor or through image analysis (such as optical flow-based methods). The time interval for collecting speed data should be sufficiently small to accurately capture sudden speed changes; for example, speed data should be collected every 0.1 seconds. The rate of change of speed data between adjacent time points, i.e., acceleration, is calculated. A reasonable acceleration threshold is set; when the acceleration exceeds the threshold, it is considered that the AGV has experienced an abnormal speed change. For example, if the absolute value of the acceleration exceeds the threshold twice consecutively... If the AGV equipment speed is abnormal, it is considered to be a suspected abnormality and marked as a suspicious target.
[0065] The surface features of the AGV equipment, obtained through surface feature extraction, are input into a trained surface defect detection model. The model outputs whether defects exist on the surface and the type of defects (such as scratches, dents, cracks, etc.). Simultaneously, the severity of the defects is assessed, for example, by classifying defects into mild, moderate, and severe based on indicators such as area and depth. Anomaly judgment rules are defined for defect detection; for example, when a moderate or severe defect is detected on the AGV equipment surface, the surface condition is judged as abnormal, identified as a suspected anomaly, and marked as a suspicious target.
[0066] Temperature sensors are installed on key components of the AGV equipment (such as motors, batteries, and controllers) to collect real-time temperature data. The accuracy of the temperature sensors should meet the requirements for anomaly detection, for example, an accuracy of ±0.5℃. Corresponding temperature thresholds are set based on the normal operating temperature range of each component of the AGV equipment. The real-time collected temperature data is compared with the set thresholds. When the temperature exceeds the threshold, it is determined that the AGV equipment has a temperature anomaly, identified as a suspected anomaly, and marked as a suspicious target. For example, if the operating temperature threshold for the motor is 80℃, a temperature anomaly alarm is triggered when the motor temperature is detected to exceed 80℃ in real time.
[0067] Optionally, the step of determining suspicious targets based on image information of the target region and an anomaly detection algorithm includes: S1001. Traverse all observed objects in the target area to obtain the number of suspicious targets within a preset time period; Optionally, a reasonable time window (preset time period) can be set according to the actual scenario requirements and the sensitivity requirements of anomaly detection, such as 1 hour, half a day, or 1 day. Within each time window, the number of observed objects identified as suspicious targets is counted, and the number of suspicious targets is updated in real time. A counter can be used, incrementing the counter by 1 each time a suspicious target is detected. Simultaneously, at the end of the time window, the currently counted number of suspicious targets is saved for later comparison with the target threshold.
[0068] S1002. If the number of suspicious targets exceeds the first target threshold, the target area is marked as an abnormal area, and the facilities in the target area are maintained. Optionally, data on the number of suspicious targets in the target area under normal operating conditions can be collected, and their distribution patterns and trends analyzed. For example, the number of suspicious targets at different times each day over the past month can be statistically analyzed, and the average, standard deviation, and other statistical measures can be calculated as a reference for setting the first target threshold. Exceeding the first target threshold indicates that the number of suspicious targets obtained is inaccurate, which may indicate a malfunction in the monitored facilities. Therefore, it is necessary to inspect and maintain the facilities in the target area.
[0069] S1003. If the number of suspicious targets exceeds the second target threshold but is less than the first target threshold, mark the target area as a high-risk area and increase the inspection frequency of the target area.
[0070] Optionally, the second target threshold should be lower than the first target threshold, and the difference between the two should be reasonably set based on the actual situation of the target area and the accuracy requirements of anomaly detection. Generally, the difference should not be too large to ensure that potential anomalies in the target area can be detected in a timely manner. The inspection plan should be dynamically adjusted according to changes in the risk level of the target area and the number of suspicious targets. For example, under normal circumstances, the inspection frequency of the target area is once a day; when the number of suspicious targets exceeds the second target threshold, the inspection frequency is increased to four times a day, with inspections conducted at different times such as morning, afternoon, and evening.
[0071] Optionally, the step of predicting the probability of an anomaly in the suspected target's behavior based on the feature information and in conjunction with the suspected target's work data over a preset time period, and determining whether the anomaly probability exceeds a preset threshold, includes: Obtain the work data of the target under investigation over a preset time period, including at least one of the following: product yield rate, workload completion rate, continuous working hours, attendance records, and / or maintenance records.
[0072] S20. Based on the movement trend of the suspected target, predict the movement path of the suspected target, and obtain the characteristic information of the suspected target through the monitoring equipment on the movement path.
[0073] S30. Based on the feature information and combined with the work data of the suspected target in the past preset time period, predict the probability of the suspected target having an abnormal situation, and determine whether the probability of the abnormal situation exceeds a preset threshold.
[0074] Optionally, the expression for predicting the probability of an anomaly in the suspected target is:
[0075] In the formula, , and These are the weighting coefficients. Let represent the probability that a suspicious target passes through monitoring point s, and z represent the total number of monitoring points. This represents the i-th real-time feature collected at monitoring point s. and Representing features respectively The mean and standard deviation under normal conditions. The weight of real-time feature i is represented by m, and the number of real-time features is represented by m. This represents the j-th historical work indicator. and Representing indicators The mean and standard deviation under normal conditions. Indicators The weights, where n represents the total number of historical work indicators. This represents the spatiotemporal coordinates of the actual trajectory of the questionable target at time k. Represents theoretical coordinates based on movement trend prediction. This indicates the measurement error tolerance of the positioning system, and q represents the number of coordinates collected. This represents the normalization function.
[0076] It is the Sigmoid normalization function, which maps the calculation result of the formula to the (0,1) interval, making the range of values for the anomaly probability P reasonable.
[0077] , and The weighting coefficients represent the relative importance of the degree of deviation of real-time features from normal, the degree of deviation of historical work indicators from normal, and the degree of trajectory prediction deviation in the anomaly probability calculation. By adjusting these three weighting coefficients, the influence of different factors in anomaly detection can be flexibly set according to the actual scenario. For example, in scenarios primarily focused on monitoring equipment operating status, more attention may be paid to real-time features, in which case the weighting coefficients could be appropriately increased. In scenarios where the long-term operating trend of the equipment needs to be considered, the value can be increased. In scenarios requiring precise monitoring of device movement trajectories, the value can be increased. The value of .
[0078] This indicates the probability that a suspicious target will appear at monitoring point s. When calculating the weighted sum of deviations from normal levels in real-time features, this probability is used to weight the real-time features collected from different monitoring points. If the probability of a suspicious target passing through a monitoring point is high, then the real-time features collected from that monitoring point contribute more to the anomaly probability calculation, because these features are more likely to reflect the true state of the suspicious target.
[0079] Z represents the number of monitoring points set up within the target area. As an upper limit for the summation, it determines the scope of comprehensive analysis of the real-time features collected from all monitoring points. The more monitoring points there are, the more comprehensive the monitoring of suspicious targets will be, but this will also increase the computational complexity.
[0080] This refers to a real-time feature value of a suspicious target, such as temperature, speed, or attitude angle, collected at a specific monitoring point 's'. It serves as the foundational data for calculating the degree to which this real-time feature deviates from the normal range. By comparing it with the mean and standard deviation under normal conditions, the degree of anomaly of this feature at a specific monitoring point can be quantified.
[0081] This represents the historical average value of the i-th real-time feature under normal conditions. It serves as a reference benchmark for measuring real-time features under normal conditions. Whether it deviates from the normal range is one of the key parameters for calculating the degree of deviation of a feature.
[0082] This represents the historical standard deviation of the i-th real-time feature under normal conditions, reflecting the fluctuation range of the feature value. (Compared to the mean) Together, used to standardize real-time features The degree of deviation. By dividing the deviation by the standard deviation, the dimensions of different features can be unified, making the contributions of different features to the probability of anomalies comparable.
[0083] This represents the relative importance of the i-th real-time feature in the anomaly probability calculation. Different real-time features have different sensitivities to anomalies, and their weights vary accordingly. The weighting can be adjusted based on the importance of the feature and its ability to responsive to anomalies. For example, the temperature feature of a device can be given a higher weight if it is more sensitive to anomalies.
[0084] 'm' represents the number of real-time features monitored for suspicious targets. It determines the dimensions for comprehensive analysis of these features. A larger number of features results in a more comprehensive description of the suspicious target, but also increases computational complexity and the difficulty of data collection.
[0085] These are specific indicators of the questionable target in historical work data, such as the equipment's cumulative operating time, number of failures, and energy consumption; and the staff's yield rate, continuous working hours, and attendance. By comparing these with the mean and standard deviation under normal conditions, the degree of abnormality of the questionable target in terms of historical work indicators can be measured. Historical work indicators can reflect the long-term operating status and potential problems of the equipment, providing additional information for calculating the probability of anomalies. Furthermore, the yield rate, continuous working hours, and attendance of staff reflect the staff's condition. A significant drop in yield rate, excessively long continuous working hours, and frequent lateness or early departures recently indicate a higher probability of staff abnormalities.
[0086] This represents the historical average value of the j-th historical work indicator under normal conditions. It serves as a reference benchmark for the normal state of historical work indicators and is used to measure... Does it deviate from the normal range?
[0087] This represents the historical standard deviation of the j-th historical work indicator under normal conditions, reflecting the fluctuation range of the indicator value. (Compared to the mean) Together, they are used to standardize historical work indicators. The degree of deviation makes the contributions of different factors to the anomaly probability comparable.
[0088] This represents the relative importance of the j-th historical work indicator in the anomaly probability calculation. Weight The weight of the indicator can be adjusted based on its importance and correlation with anomalies. For example, the number of equipment failures can be given a higher weight if it is closely related to anomalies.
[0089] n represents the number of historical performance indicators used for anomaly probability calculation. This determines the scope of the comprehensive analysis of historical performance indicators.
[0090] This indicates the specific location and time information of the questionable target at time k during actual operation. This is compared with theoretical coordinates based on movement trend prediction. By making comparisons, we can measure whether the movement trajectory of a suspect target deviates from expectations and reflect any abnormalities in the movement of the suspect target.
[0091] This represents the theoretically expected position and time of the suspected target at time k, based on the predicted movement trend algorithm. It serves as a reference point for the actual trajectory, used to assess whether the target's movement conforms to expectations. A significant deviation between the actual trajectory and the theoretical coordinates may indicate an anomaly with the suspected target.
[0092] This indicates the maximum possible error range of a positioning system when measuring the location of a questionable target. It is used to standardize trajectory prediction bias. This approach incorporates the measurement error of the positioning system. By dividing the square of the deviation by the square of the error tolerance, the influence of measurement error on the anomaly probability calculation can be eliminated, making the contributions of trajectory prediction deviations at different times to the anomaly probability comparable.
[0093] q represents the number of spatiotemporal coordinates of questionable targets collected within a certain period. This determines the time span for comprehensive analysis of trajectory prediction bias.
[0094] Optionally, the weight expression for real-time features is:
[0095] In the formula, This represents the dynamic weight of the i-th real-time feature at time t. This represents the probability that a suspicious target passes through monitoring point s at time t. This represents the i-th real-time feature collected at monitoring point s. This represents the historical mean of the i-th feature under normal conditions. Let z represent the historical standard deviation of the i-th feature under normal conditions, z represent the total number of monitoring points, and m represent the number of real-time feature types.
[0096] This represents the relative importance of the i-th real-time feature in the anomaly probability calculation at a specific time t. It dynamically adjusts as time and the real-time feature itself change. By considering the time factor and the degree of deviation of the real-time feature, the weights can more accurately reflect the feature's sensitivity to anomalies at the current moment. For example, when a real-time feature deviates significantly at a certain moment, its weight will increase accordingly, thus playing a greater role in the anomaly probability calculation.
[0097] This represents the probability that a suspicious target will appear at monitoring point s at a specific time t. (This is related to the anomaly probability prediction formula.) Similarly, when calculating the dynamic weights of real-time features, this probability is used to weight the real-time features collected from different monitoring points. The probability of a suspicious target passing through a monitoring point may differ at different time points, so considering the time factor can make the weight calculation more accurate.
[0098] S40. If the anomaly probability exceeds a preset threshold, the suspicious target is marked as an abnormal target and the abnormal target is tracked.
[0099] Optionally, if the anomaly probability does not exceed a preset threshold, the suspicious status of the target is lifted.
[0100] Specifically, when the "questionable" status is lifted, the system updates the target's status identifier, changing it from "questionable" to "normal," and simultaneously updates the relevant database records. At the same time, the system generates a status change log, recording the time the "questionable" status was lifted, the target identifier, and the reason for lifting the status (the anomaly probability does not exceed the threshold), and stores this log in the log system for subsequent querying and auditing.
[0101] Optionally, the step of marking the suspicious target as an abnormal target and tracking the abnormal target if the anomaly probability exceeds a preset threshold includes: S401. When the probability of an anomaly exceeds one standard deviation of the preset threshold, a level three alarm is set and the anomaly event is recorded to the log system. Optionally, the system calculates the standard deviation S of the anomaly probability based on historical anomaly probability data. The standard deviation reflects the dispersion of the anomaly probability and is used to measure the degree to which the anomaly probability deviates from a preset threshold.
[0102] The system records relevant information about this abnormal event in the log system. The record includes key information such as the abnormal target identifier, the time of occurrence, the probability value of the abnormality, the alarm level, the target's current location, movement speed, and direction. Simultaneously, the abnormal event is categorized and coded to facilitate subsequent data analysis and statistics. Upon receiving a Level 3 alarm, monitoring personnel must manually review the abnormal event within a specified time (e.g., within 10 minutes). The review includes checking the target's historical data, replaying monitoring video, and communicating with relevant personnel to confirm whether there were any false alarms.
[0103] S402. When the probability of an anomaly exceeds twice the standard deviation of a preset threshold, a level two alarm is set, and the abnormal target is continuously recorded by the monitoring equipment. Optionally, the alarm information can be displayed on the monitoring interface as an orange icon or text prompt, along with a prominent audible alert to draw the attention of monitoring personnel. The system continuously records abnormal targets using monitoring equipment, including cameras and sensors, which collect multi-dimensional data such as images, sounds, location, and speed of the target in real time. This data is then transmitted to the monitoring center for storage and analysis. The system automatically analyzes and evaluates the continuously recorded data.
[0104] S403. When the probability of an anomaly exceeds three times the standard deviation of the preset threshold, a Level 1 alarm is set, triggering the alarm and the drone continuously tracks the abnormal target.
[0105] Optionally, the alarm information can be displayed on the monitoring interface as a red icon or text prompt, triggering a high-decibel alarm to ensure that monitoring personnel and relevant personnel notice it immediately. The system automatically dispatches drones to continuously track abnormal targets. The drones are equipped with high-definition cameras, thermal imagers, and other equipment, enabling them to acquire high-definition images and thermal imaging information of the target in real time and transmit this information to the monitoring center in real time.
[0106] Example 3 Based on Example 1, this application discloses a multi-source heterogeneous data analysis system for industrial parks based on the Industrial Internet of Things, including a management platform, a sensor network platform, and an object platform that are established in sequence for communication: The sensor network platform is configured as follows: Based on the image information of the target area, suspicious targets are identified using an anomaly detection algorithm; Based on the movement trend of the suspected target, predict the movement path of the suspected target, and obtain the characteristic information of the suspected target through the monitoring equipment along the movement path; Based on the aforementioned feature information and combined with the work data of the suspected target within a preset time period, the probability of the suspected target exhibiting abnormal behavior is predicted, and it is determined whether the probability of abnormal behavior exceeds a preset threshold. The management platform is configured as follows: If the anomaly probability exceeds a preset threshold, the suspicious target is marked as an abnormal target and the abnormal target is tracked.
[0107] The user platform is configured to provide front-end services to users; users obtain the necessary perception service information through the user platform, process the perception service information, and transform it into user perception information; users analyze the user perception information and make corresponding decisions based on their own wishes, and transform the user perception information into user control information through the corresponding information system and send it to the service platform, thereby demonstrating the user's corresponding service needs and wishes.
[0108] The physical entities of the user platform include various user terminals, such as mobile phones, computers, and dedicated terminals, which provide user services through integration with user information system software.
[0109] The service platform is configured as an API server or other server used to establish communication between the management platform and the user platform to achieve corresponding functions; the physical entity of the service platform includes various servers.
[0110] The management platform is configured to perform at least one of the following: device operation status monitoring and management, data monitoring and management, device parameter management, and lifecycle management; the management platform is the overall operation platform for the Internet of Things, which may include various management sub-platforms, with different management sub-platforms performing different management tasks; the physical entities of the management platform include various servers.
[0111] The sensor network platform is configured to perform at least one of the following functions: network management, command management, device status management, data protocol management, data parsing, data classification, data transmission monitoring, and data transmission security management. The sensor network platform provides functions such as data communication, transmission, parsing, identification, and classification, avoiding the direct aggregation of data from various object platforms onto the management platform, which would otherwise result in data redundancy and low data processing efficiency. The physical entities of the object platforms include various gateways, edge computing devices, etc.
[0112] The object platform is configured to perform specific production control, detection, measurement and other production tasks; the physical entities in the object platform include various production equipment, sensors and so on.
[0113] Optionally, the sensor network platform includes a main database that communicates with the management platform and at least two sensor network sub-platforms that communicate with the main database. Optionally, each sensor network sub-platform may correspond to an API function or API server.
[0114] Example 4 This embodiment provides a computer device, including a memory and a processor. The memory stores a computer program that can run on the processor, and the processor executes the computer program to implement any of the methods described above.
[0115] Example 5 This embodiment provides a computer-readable storage medium storing a computer program that can be loaded by a processor and executed as described above.
[0116] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A method for analyzing multi-source heterogeneous data in a park based on the Industrial Internet of Things, characterized in that, include: Based on the image information of the target area, suspicious targets are identified using an anomaly detection algorithm; Based on the movement trend of the suspected target, predict the movement path of the suspected target, and obtain the characteristic information of the suspected target through the monitoring equipment along the movement path; Based on the aforementioned feature information and combined with the work data of the suspected target within a preset time period, the probability of the suspected target exhibiting abnormal behavior is predicted, and it is determined whether the probability of abnormal behavior exceeds a preset threshold. If the anomaly probability exceeds a preset threshold, the suspicious target is marked as an abnormal target and the abnormal target is tracked.
2. The method for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things as described in claim 1, characterized in that, The step of determining suspicious targets based on image information of the target area and an anomaly detection algorithm includes: Acquire image information of the target area; if the observed object is a staff member, acquire the observed object's behavior trajectory and safety equipment wearing status. Abnormal actions are detected by spatiotemporal graph convolutional networks, and the wearing status of safety equipment is compared with preset standards in real time to determine whether the observed object is suspected of being abnormal. If so, it is marked as a suspicious target.
3. The method for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things as described in claim 1, characterized in that, The step of determining suspicious targets based on image information of the target area and an anomaly detection algorithm includes: Acquire image information of the target area; if the observed object is an AGV device, acquire the running posture and surface state of the observed object. By comparing the dynamic path planning of the observed object, detecting abnormal robot arm angles, detecting sudden speed changes, detecting surface defects, and detecting abnormal temperatures, it is determined whether the observed object is suspected of being abnormal. If so, it is marked as a suspicious target.
4. The method for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things as described in claim 1, characterized in that, The step of determining suspicious targets based on image information of the target area and an anomaly detection algorithm includes: Traverse all observed objects in the target area to obtain the number of suspicious targets within a preset time period; If the number of suspicious targets exceeds the first target threshold, the target area will be marked as an abnormal area, and the facilities in the target area will be maintained. If the number of suspicious targets exceeds the second target threshold but is less than the first target threshold, the target area will be marked as a high-risk area, and the inspection frequency of the target area will be increased.
5. The method for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things as described in claim 1, characterized in that, The step of predicting the probability of an anomaly in the suspected target's behavior based on the feature information and in conjunction with the suspected target's work data over a preset time period, and determining whether the anomaly probability exceeds a preset threshold, includes: Obtain the work data of the target under investigation over a preset time period, including at least one of the following: product yield rate, workload completion rate, continuous working hours, attendance records, and / or maintenance records.
6. The method for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things as described in claim 1, characterized in that, The step of predicting the probability of an anomaly in the suspected target's behavior based on the feature information and in conjunction with the suspected target's work data over a preset time period, and determining whether the anomaly probability exceeds a preset threshold, includes: The expression for predicting the probability of an anomaly in the suspected target is as follows: In the formula, , and These are the weighting coefficients. Let represent the probability that a suspicious target passes through monitoring point s, and z represent the total number of monitoring points. This represents the i-th real-time feature collected at monitoring point s. and Representing features respectively The mean and standard deviation under normal conditions. The weight of real-time feature i is represented by m, and the number of real-time features is represented by m. This represents the j-th historical work indicator. and Representing indicators The mean and standard deviation under normal conditions. Indicators The weights, where n represents the total number of historical work indicators. This represents the spatiotemporal coordinates of the actual trajectory of the questionable target at time k. Represents theoretical coordinates based on movement trend prediction. This indicates the measurement error tolerance of the positioning system, and q represents the number of coordinates collected. This represents the normalization function.
7. The method for analyzing multi-source heterogeneous data in a park based on the Industrial Internet of Things as described in claim 6, characterized in that, The weight expression for real-time features is: In the formula, This represents the dynamic weight of the i-th real-time feature at time t. This represents the probability that a suspicious target passes through monitoring point s at time t. This represents the i-th real-time feature collected at monitoring point s. This represents the historical mean of the i-th feature under normal conditions. Let z represent the historical standard deviation of the i-th feature under normal conditions, z represent the total number of monitoring points, and m represent the number of real-time feature types.
8. The method for analyzing multi-source heterogeneous data in industrial parks based on the Industrial Internet of Things as described in claim 1, characterized in that, The step of predicting the probability of an anomaly in the suspected target's behavior based on the feature information and in conjunction with the suspected target's work data over a preset time period, and determining whether the anomaly probability exceeds a preset threshold, includes: If the anomaly probability does not exceed a preset threshold, the suspicious status of the target is lifted.
9. The method for analyzing multi-source heterogeneous data in a park based on the Industrial Internet of Things as described in claim 1, characterized in that, The step of marking the suspicious target as an abnormal target and tracking the abnormal target if the anomaly probability exceeds a preset threshold includes: When the probability of an anomaly exceeds one standard deviation of a preset threshold, a level three alarm is set, and the anomaly event is recorded to the log system. When the probability of an anomaly exceeds twice the standard deviation of a preset threshold, a level two alarm is set, and the abnormal target is continuously recorded by the monitoring equipment. When the probability of an anomaly exceeds three times the standard deviation of a preset threshold, a Level 1 alarm is triggered, and the drone continues to track the abnormal target.
10. A multi-source heterogeneous data analysis system for industrial parks based on the Industrial Internet of Things, characterized in that, This includes establishing a communication management platform, a sensor network platform, and an object platform in sequence: The sensor network platform is configured as follows: Based on the image information of the target area, suspicious targets are identified using an anomaly detection algorithm; Based on the movement trend of the suspected target, predict the movement path of the suspected target, and obtain the characteristic information of the suspected target through the monitoring equipment along the movement path; Based on the aforementioned feature information and combined with the work data of the suspected target within a preset time period, the probability of the suspected target exhibiting abnormal behavior is predicted, and it is determined whether the probability of abnormal behavior exceeds a preset threshold. The management platform is configured as follows: If the anomaly probability exceeds a preset threshold, the suspicious target is marked as an abnormal target and the abnormal target is tracked.
Citation Information
Patent Citations
Smart park management method and device based on identifier analysis, and medium
CN116757894A
Security and protection method and device based on full-range feature recognition and four-dimensional trajectory tracking
CN119720064A
Equipment anomaly detection method and system based on multi-source heterogeneous data
CN120145206A
Smart park safety management method and system based on AI visual identification
CN120339947A
Object behavior anomaly detection using neural networks
US20190294869A1
Cited By
Trajectory prediction and abnormal behavior detection system and method
CN121074811A
A trajectory prediction and abnormal behavior detection system and method
CN121074811B
Data processing method and device and electronic equipment
CN122112098A