A gas meter abnormality detection method based on wireless remote transmission technology

CN121302204BActive Publication Date: 2026-09-15ZHEJIANG SONGCHUAN GASOMETER
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511480186.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-16
Publication Date
2026-09-15
Estimated Expiration
2045-10-16

AI Technical Summary

Technical Problem

此类行为在流量曲线层面几乎不形成显著波动,极易被传统识别方法视为正常使用,从而造成经济损失及管理漏洞

Benefits of technology

本发明通过行为频率结构解析与用户用气行为序列模型的构建,实现了对用气数据的深层次结构化表达,显著提升了异常检测的精度与适应性。本发明将无线远传燃气表实时采集的用户用气时间、用气流量及用气持续时长等原始数据传输至后台管理处后,首先对其进行行为频率结构解析,并提取单位时间内的用气事件频率、事件间隔、波动幅度一致性以及事件差异特征等关键行为参数,通过这些参数构建用户用气行为序列模型,从而实现从“数值级数据”向“行为级表达”的转换。该方式突破了传统燃气监控技术仅基于气量波动或单一阈值检测的局限性,使得系统能够捕获到反映用户真实用气模式的时序特征和结构特征。通过行为序列建模,系统可以有效识别如周期性低幅波动、短周期高频行为等传统算法难以发现的细微异常特征。此外,本发明的行为模型构建过程不依赖固定模板,而是依据采集数据的动态变化进行实时更新,使模型具备自适应特性。当用户的用气习惯、时间周期或设备运行状态发生变化时,模型能够自动调整结构参数,保证识别精度长期保持在稳定范围内。相较于现有基于静态规则或固定算法的检测机制,本发明的行为频率结构解析过程提供了更高的敏感度和泛化能力,为后续异常检测和风险判定奠定了坚实的数据基础。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121302204B_ABST
    Figure CN121302204B_ABST
Patent Text Reader

Abstract

The application discloses a kind of gas meter abnormality detection methods based on wireless remote transmission technology, specifically related to gas energy detection technical field, based on wireless remote transmission technology, user gas data is collected, constructs gas behavior sequence model, extracts behavior frequency and fluctuation characteristics, identifies limited behavior mode after dynamic adjustment abnormality identification threshold and starts high-precision sampling;By generating operation logic confidence score, upstream and downstream user behavior difference score, jointly judge whether there is atypical abnormal behavior, if it is identified as abnormal, an early warning is issued, if it is not abnormal, a more matching identification model is loaded from the model library;The application constructs gas behavior sequence model and dynamically adjusts abnormality identification threshold, combines operation logic confidence score and neighborhood behavior difference score, realizes the accurate identification and real-time early warning of atypical abnormal gas behavior, if it is normal behavior, then automatically match more adaptive identification model, improve detection accuracy and system adaptive ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of gas energy consumption detection technology, and more specifically, to a method for detecting gas meter anomalies based on wireless remote transmission technology. Background Technology

[0002] With the digital development of urban gas management systems, wireless remote gas meters are gradually becoming the main metering devices for residential and commercial users. These devices possess real-time data acquisition and remote transmission capabilities, synchronizing key data such as gas usage time, flow rate, and duration to the back-end management department. This provides gas companies with the foundation for remote meter reading, user profiling analysis, and anomaly detection. Anomaly detection mechanisms built upon this type of equipment have become one of the key technological pathways for ensuring the safety and operational efficiency of gas systems.

[0003] However, in actual gas usage, numerous complex behavioral patterns remain that are difficult to identify using traditional anomaly detection methods. In particular, atypical abnormal behaviors characterized by "low intensity and high frequency" are highly concealed and have a high false alarm rate, gradually becoming a technical weakness in current intelligent identification systems. On one hand, unscrupulous users may steal gas by using homemade devices or fine-tuning pipelines through "intermittent gas release." This behavior manifests as extremely short gas usage times and minimal flow changes, sometimes even remaining entirely within the equipment's set normal fluctuation threshold. By accumulating gas consumption through a "high frequency + low amplitude" approach, they circumvent abrupt detection mechanisms. Such behavior produces almost no significant fluctuations in the flow curve, making it easily mistaken for normal use by traditional identification methods, leading to economic losses and management loopholes.

[0004] On the other hand, some old or incorrectly configured gas appliances (such as timed sprinkler systems and malfunctioning water heaters) may automatically start releasing gas when unattended due to accidental triggering or abnormal control logic, resulting in frequent but minor automatic gas consumption. Such behavior is also difficult to accurately identify using absolute flow rates or single fluctuations, and can easily be misjudged as low-intensity normal use. More seriously, such malfunctions may cause incomplete combustion or leakage of gas, leading to indoor carbon monoxide poisoning or fire hazards, posing significant safety risks.

[0005] Most current data-driven identification methods still rely on flow surge detection, threshold violation judgment, or single-point behavior analysis. When faced with the aforementioned "micro-amplitude, high-frequency" behavior patterns, they lack the ability to model behavioral structure sequences and understand the semantic context of behavior. This results in slow response and insufficient accuracy of the identification mechanism to periodic anomalies, spoofing behavior, and control logic mismatch. Furthermore, existing technologies typically employ static identification models, making it difficult to automatically adjust to changes in user behavior. The system's adaptive capability is limited, and long-term use can lead to increased false alarm rates and model failure. Therefore, this invention proposes a gas meter anomaly detection method based on wireless remote transmission technology to address these problems. Summary of the Invention

[0006] To achieve the above objectives, the present invention provides the following technical solution: A method for detecting gas meter anomalies based on wireless remote transmission technology includes the following steps: The gas consumption data collected in real time by the wireless remote gas meter is transmitted to the back-end management office. The gas consumption data includes the user's gas consumption time, gas flow rate and gas consumption duration. The back-end management department analyzes the collected gas consumption data by behavioral frequency structure, extracts the consistency of gas consumption event frequency, event interval, fluctuation amplitude, and event difference characteristics within a unit of time, and constructs a user gas consumption behavior sequence model. Feature analysis is performed on the gas consumption behavior sequence model to identify gas consumption patterns with defined behavioral characteristics, triggering dynamic adjustment of the anomaly identification threshold and initiating a fine-grained data sampling process; Based on the fine-grained data sampling results, the gas usage behavior of the target user is compared with the preset operation behavior template, the degree of matching between the operation response characteristics and the control logic is calculated, and the operation logic confidence score is generated. At the same time, the gas consumption density and behavioral characteristics of upstream and downstream adjacent users of the target user within the same time window are obtained, and behavioral difference scores are calculated to assess the degree of deviation of the target user's behavior from that of neighboring users. Based on the confidence score of the operational logic and the behavioral difference score, determine whether the target user's current gas usage behavior is atypical or abnormal behavior; If the behavior is atypical or abnormal, an abnormal warning signal will be issued. If the behavior is not abnormal, the behavior recognition model that is closest to the combination of confidence score and behavior difference score from the built-in model library is selected and loaded into the target user behavior detection process for adaptation.

[0007] The back-end management department performs behavioral frequency structure analysis on the collected gas consumption data, including the following steps: The continuous gas consumption data is grouped according to the preset time window, and each complete gas consumption event is identified based on the rising and falling edges of the gas flow curve within each time window. The number of gas consumption events within the time window is counted as the gas consumption event frequency index per unit time. Based on the start and end times of each identified gas consumption event, the time interval between two adjacent gas consumption events is calculated, and the variance analysis method is used to calculate the dispersion of the time interval sequence, which serves as a time interval feature characterizing the stability of the user's gas consumption behavior rhythm. The flow fluctuation range within each gas consumption event is calculated separately. By calculating the average value and the maximum difference of the fluctuation range of each event, the consistency of gas consumption behavior fluctuation is judged. At the same time, the difference of the morphological parameters of each gas consumption event is evaluated, and the event difference characteristics are extracted. The frequency of gas consumption events per unit time, time interval characteristics, consistency index of fluctuation amplitude, and event difference characteristics are uniformly normalized to construct a multi-dimensional gas consumption behavior sequence model for users.

[0008] The morphological parameters of each gas consumption event are evaluated for differences, and the event difference characteristics are extracted. The difference evaluation includes the following steps: The flow rate change curve of each gas consumption event is analyzed, and the duration, maximum flow rate, average flow rate, and the rate of increase and decrease of flow rate change are extracted and used as the basic morphological parameters of the event. Based on all identified gas consumption events, an event morphology parameter set is constructed, and the mean, range, and standard deviation of each morphology parameter in all events are calculated to measure the degree of difference between events in terms of time length, flow characteristics, and changing trends. The difference index of all morphological parameters is normalized to form a multidimensional difference vector, and the difference score of each gas consumption event relative to the overall behavior sequence is evaluated by a preset distance measurement method. The difference score is used as the event difference feature value and input into the user behavior sequence model.

[0009] The default distance metric is any one of Euclidean distance, Manhattan distance, or cosine similarity.

[0010] Feature analysis of gas consumption behavior sequence models refers to: The gas consumption behavior sequence model extracts the gas consumption event frequency, event duration and event interval to form a feature vector set for each time period. The density-based time series clustering method is used to identify the time periods with concentrated event frequency distribution and regular time interval distribution as gas consumption behavior segments with defined behavioral characteristics. For gas consumption behavior segments with defined behavioral characteristics identified by clustering, the time series change rates of event frequency variation and flow fluctuation amplitude are calculated in multiple consecutive time windows corresponding to them. The above change rates are used as input parameters to dynamically calculate the lower limit of the anomaly identification threshold control range, which is used to update the current sensitivity configuration of the behavior anomaly identification logic. After updating the anomaly identification threshold, the system determines whether the target user is in a time range of abnormal behavior fluctuations based on the degree of clustering of behavioral changes. If the preset triggering conditions are met, a fine-grained data sampling mechanism is activated. The fine-grained data sampling mechanism refers to changing the sampling period to be shorter than the preset basic sampling period.

[0011] When dynamically calculating the lower limit of the anomaly identification threshold control range, the gas consumption behavior segment of the target user is divided into multiple consecutive time windows of equal length according to the time sequence. The number of gas consumption events in each time window is counted, the change value of the number of events between adjacent time windows is calculated, and the change value is divided by the time span between the two time windows to obtain the event frequency change rate sequence, which is used to reflect the frequency fluctuation trend of the user's gas consumption behavior. Within each time window, the maximum and minimum flow values ​​of all gas consumption events are extracted, and their difference is calculated as the flow fluctuation amplitude within the current time window. Then, the change in flow fluctuation amplitude between adjacent time windows is calculated and divided by the corresponding time span to obtain the flow fluctuation change rate sequence, which is used to reflect the fluctuation trend of gas consumption behavior in intensity. Based on the event frequency change rate sequence and the flow fluctuation change rate sequence, their average value and maximum change rate in the current identification period are calculated respectively as quantitative indicators of the degree of abnormal change. The above two indicators are used as input parameters and input into the threshold control model based on the weighted linear function to output the lower limit of the abnormal identification threshold in the current identification period.

[0012] The threshold control model based on a weighted linear function refers to: The average rate of change extracted from the event frequency change rate sequence is used as the first input parameter, and the maximum rate of change extracted from the traffic fluctuation change rate sequence is used as the second input parameter, and preset first weight coefficients and second weight coefficients are assigned respectively. Multiply the first input parameter by the first weight coefficient, multiply the second input parameter by the second weight coefficient, add the two weighted results together, and then subtract the weighted sum from the preset benchmark constant value to obtain the lower limit of the abnormal identification threshold in the current identification period.

[0013] The operational logic confidence score is generated through the following steps: After triggering fine-grained data sampling, multiple gas usage events of the target user within a specific identification period are extracted, response feature parameters of each event are obtained, and the set of parameters is combined into a behavioral response feature vector. Select the corresponding standard operation behavior template from the operation behavior template library, organize its response feature parameters into template vectors, and use the vector distance calculation method to measure the distance between the numerical difference between the target user's behavior response feature vector and the template vector, and evaluate the similarity between the target behavior and the standard operation logic. The vector distance value obtained from the distance metric is then mapped to a confidence score value according to a preset standard to form an evaluation result of the degree of matching of the operation logic, which is used to measure whether the current gas usage behavior meets the expectations of the human control logic.

[0014] Behavioral difference scores are generated through the following steps: The behavioral feature parameters of the target user within the same time window are standardized and processed in a unified manner with the parameter set of neighboring users. All users are sorted by numerical value under each feature dimension to determine the ranking position of the target user under each indicator and its offset value relative to the median or average position of the neighboring user group. Statistical analysis is performed on the ranking offset values ​​of all behavioral features. An offset judgment threshold is set for each indicator to define the judgment criteria for significant deviation. Then, the number of indicators in which the target user falls into the significant deviation range among all indicators is counted, and the corresponding offset distance value is recorded. Finally, the behavioral difference score is calculated. The score consists of two parts: the ratio of the total number of significantly deviating indicators to the total number of all indicators, and the arithmetic mean of the ranking offset values ​​corresponding to all significantly deviating indicators. The product of the two is used as the final output result to reflect the relative deviation of the target user in the neighborhood behavior model.

[0015] After independently calculating the operational logic confidence score and the behavioral difference score, the two scores are used as input to construct a joint judgment index and set a joint score threshold area to divide the criteria for determining whether atypical abnormal behavior is constituted. If the confidence score is lower than the preset operational confidence interval and the behavioral difference score is higher than the neighborhood deviation tolerance range, it is judged as atypical abnormal behavior. When the target user's behavior is determined to be atypical abnormal behavior, the system immediately issues an abnormal warning signal and marks the current identification period behavior as a high-risk behavior segment, and includes it in the abnormal behavior tracking record; if it does not constitute atypical abnormal behavior, the current joint score combination is used as a feature vector, and its similarity is calculated one by one with the feature vectors corresponding to all models in the pre-built behavior recognition model library. After completing the feature similarity calculation, the recognition model that is closest to the current joint scoring combination features is selected and loaded into the target user behavior detection process for dynamic adaptation, replacing the initially used default recognition model.

[0016] In a preferred embodiment, controlling the smooth transition of the charging process to the constant current charging stage and the constant voltage charging stage refers to: During the rhythmic cycle control process, the ion relaxation index and the rate of change of the terminal voltage rebound are continuously acquired for multiple cycles. After each cycle, the fluctuation amplitude and the trend of change of the two are calculated respectively. When the fluctuation amplitude is lower than the preset stability threshold and the trend of change is maintained within the positive and negative tolerance range for multiple cycles, it is determined that the ion distribution state and voltage rebound characteristics are within the preset safety range. When the determination result meets the safety conditions, the charging current is gradually increased to the target current of the constant current charging stage and kept constant according to the preset smooth switching strategy until the cell voltage reaches the conversion voltage point of the constant voltage charging stage. Finally, the charging voltage is kept constant at the conversion voltage point and the charging current is dynamically reduced until charging is completed.

[0017] The technical effects and advantages of this invention are as follows: This invention achieves a deep, structured representation of gas usage data through behavioral frequency structure analysis and the construction of a user gas usage behavior sequence model, significantly improving the accuracy and adaptability of anomaly detection. After transmitting the raw data (such as user gas usage time, flow rate, and duration) collected in real-time from the wireless remote gas meter to the backend management system, this invention first performs behavioral frequency structure analysis on the data, extracting key behavioral parameters such as the frequency of gas usage events per unit time, event intervals, consistency of fluctuation amplitude, and event difference characteristics. These parameters are then used to construct a user gas usage behavior sequence model, thus achieving a transformation from "numerical data" to "behavioral representation." This approach overcomes the limitations of traditional gas monitoring technologies that rely solely on gas volume fluctuations or single threshold detection, enabling the system to capture the temporal and structural features reflecting the user's actual gas usage patterns. Through behavioral sequence modeling, the system can effectively identify subtle anomalies that are difficult for traditional algorithms to detect, such as periodic low-amplitude fluctuations and short-cycle high-frequency behaviors. Furthermore, the behavioral model construction process of this invention does not rely on a fixed template but updates in real-time based on the dynamic changes in the collected data, giving the model adaptive characteristics. When users' gas usage habits, time cycles, or equipment operating status change, the model can automatically adjust its structural parameters to ensure that the recognition accuracy remains within a stable range over a long period. Compared with existing detection mechanisms based on static rules or fixed algorithms, the behavioral frequency structure analysis process of this invention provides higher sensitivity and generalization ability, laying a solid data foundation for subsequent anomaly detection and risk assessment.

[0018] This invention, by jointly calculating the operational logic confidence score and the behavioral difference score, achieves a shift from single-dimensional anomaly judgment to multi-dimensional behavioral cognition, significantly improving the accuracy and robustness of identifying atypical abnormal behaviors. Traditional gas anomaly detection is mostly based on single numerical anomaly judgments, such as sudden changes in flow, rapid reduction in gas volume, or continuous zero flow, which are prone to failure in complex behavioral patterns. This invention, however, compares the target user's gas usage behavior with a preset operational behavior template based on fine-grained data sampling, calculates the matching degree between operational response characteristics and control logic, generates an operational logic confidence score, and simultaneously combines the gas usage density and behavioral characteristics of upstream and downstream neighboring users within the same time window to calculate a behavioral difference score, thus forming a dual quantitative description of user behavior. This joint judgment mechanism can effectively distinguish different types of abnormal behavior. For example, when faced with periodic, low-intensity gas theft, the operational logic confidence score will be significantly low, while the behavioral difference score will increase due to its large deviation from neighboring users. Both indicators deviating from the normal range simultaneously can trigger an anomaly warning. However, for minor anomalies mistakenly triggered by automated equipment, although the confidence score may decrease, the behavioral difference score usually remains within the tolerance range, so the system will not misjudge it as an anomaly. This two-way complementary mechanism effectively reduces the false alarm rate and false negative rate, making anomaly detection no longer dependent on single-point data anomalies, but based on a comprehensive analysis of behavioral logic consistency and group comparison deviation, thereby achieving accurate identification of "atypical abnormal behavior." The scoring mechanism of this invention also has dynamic expansion capabilities. As historical data accumulates and behavioral samples become richer, the scoring criteria can be automatically updated through periodic training or experience-based correction, achieving continuous optimization. This method allows the system to maintain stable detection accuracy and judgment reliability even when facing different geographical regions, seasonal changes, or differences in equipment types.

[0019] This invention drives the dynamic adaptation of the recognition model through joint scoring results, achieving self-learning and personalized optimization of the recognition process, thus improving the system's adaptability and model transfer efficiency. In traditional anomaly detection systems, models typically have a fixed structure and cannot be dynamically adjusted according to changes in user characteristics or behavioral environment, leading to overfitting or insufficient generalization ability. This invention, after calculating the operational logic confidence score and behavioral difference score, does not directly terminate the judgment if the current behavior does not constitute atypical abnormal behavior. Instead, it combines these two scores into a joint scoring feature vector and performs similarity calculations with the feature vectors of multiple behavioral recognition models in the built-in model library. The system selects the closest recognition model using a distance metric algorithm and loads it into the target user detection process, replacing the original default recognition model and achieving dynamic model adaptation.

[0020] The default identification model is the initial configuration model used when the system is first run or when individual feature data is lacking. Its parameters are set based on general statistical laws and dynamically adjusted anomaly identification thresholds, used to achieve basic anomaly detection. Once the system determines the characteristic trends of the target user's behavior pattern through joint scoring analysis, the identification model in the model library that best matches that behavioral characteristic will be dynamically loaded. In this way, the model will form a personalized detection strategy based on differences in the user's long-term behavioral habits, gas usage frequency, and equipment response characteristics. For example, for users using high-frequency, short-duration hot water equipment, the system can select a model that focuses more on high-frequency gas usage behavior; while for industrial gas users, the system can match a model based on flow fluctuation characteristics. This design makes the identification process no longer a fixed discrimination structure, but rather a closed-loop iterative mechanism of "data-driven—scoring judgment—model optimization". After each model adaptation, the system sends the new identification results back to the data layer for correction, gradually bringing the model closer to the optimal matching state. This dynamic model management method significantly improves the system's intelligence and generalization ability in diverse application scenarios, ensuring the long-term efficient operation of the gas monitoring system. Attached Figure Description

[0021] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings; Figure 1 This is a schematic diagram of a gas meter anomaly detection method based on wireless remote transmission technology according to the present invention. Detailed Implementation

[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0023] Reference Figure 1 The following examples were obtained: Example 1: A gas meter anomaly detection method based on wireless remote transmission technology includes the following steps: transmitting real-time gas consumption data collected by the wireless remote transmission gas meter to the back-end management system. The gas consumption data includes the user's gas consumption time, gas flow rate, and duration. This step is used to build the system's data acquisition framework, enabling high-frequency, continuous, and reliable data upload through the wireless remote transmission gas meter, ensuring that the entire process of the user's gas consumption behavior is recorded without omission. The data fields include time, flow rate, and duration, which helps to subsequently form high-dimensional behavioral patterns.

[0024] The back-end management department performs behavioral frequency structure analysis on the collected gas consumption data, extracting the frequency of gas consumption events, event intervals, consistency of fluctuation amplitude, and event difference characteristics within a unit of time to construct a user gas consumption behavior sequence model. This step aims to structure the raw gas consumption data, transforming the time distribution, flow rate changes, and event differences in the raw data into statistically significant indicator parameters, thereby generating a behavioral sequence model for pattern recognition. This model forms the basis for all subsequent intelligent analyses.

[0025] Feature analysis is performed on the gas consumption behavior sequence model to identify gas consumption patterns with defined behavioral characteristics, triggering dynamic adjustment of the anomaly identification threshold and initiating a fine-grained data sampling process. This step is used to mine potential periodicity, repetition and other defining characteristics in the behavior patterns, identify possible disguised gas consumption or equipment failure behaviors, and automatically adjust the current anomaly judgment sensitivity of the system accordingly to ensure improved detection accuracy during critical behavior stages, while acquiring higher resolution data with a smaller sampling cycle.

[0026] Based on fine-grained data sampling results, the target user's gas usage behavior is compared with a preset operation behavior template. The degree of matching between the operation response characteristics and the control logic is calculated, and an operation logic confidence score is generated. This step is used to analyze whether the user's behavior has the logical characteristics of human control. By matching the user's actual gas usage behavior with the standard operation behavior template and calculating the confidence score, it is determined whether it is the expected human operation, which helps to identify abnormal automated equipment or deliberately concealed behavior patterns.

[0027] At the same time, the gas consumption density and behavioral characteristics of upstream and downstream adjacent users of the target user within the same time window are obtained, and a behavioral difference score is calculated to assess the degree of deviation of the target user's behavior relative to neighboring users. This step introduces a neighboring user comparison mechanism, using the gas consumption behavior of other users in the same gas source environment as a reference to calculate the degree of deviation of the target user's behavior in the group, so as to determine whether its behavior constitutes an anomaly in statistics, and to provide support for enhancing the robustness and objectivity of identification.

[0028] Based on the operational logic confidence score and the behavioral difference score, the system determines whether the target user's current gas usage behavior is atypical or abnormal. This step realizes a fusion judgment mechanism for behavioral assessment results from two different sources, comprehensively considering the logical rationality of individual behavior and the relative deviation of group behavior, in order to achieve more accurate classification and identification of abnormal behavior and avoid false alarms or missed alarms caused by single-dimensional analysis.

[0029] If the behavior is atypical or abnormal, an abnormal warning signal will be issued. When a user's behavior is identified as having atypical or abnormal characteristics, the system will immediately trigger an alarm process and can implement emergency response measures such as gas source cutoff and background review to ensure gas safety and control energy loss.

[0030] If the behavior is not abnormal, the system selects the behavior recognition model from the built-in model library that most closely matches the combination of confidence score and behavior difference score, and loads it into the target user behavior detection process for adaptation. When the target user does not belong to the current abnormal scenario but the behavior has specific characteristics, the system retrieves the model most suitable for its behavior characteristics from the model library and replaces the default recognition model, thereby realizing a personalized and dynamically evolving behavior recognition optimization mechanism.

[0031] In the specific implementation process, in order to achieve accurate modeling and structured representation of users' daily gas consumption behavior, the back-end management department performs structural deconstruction and feature reconstruction on the raw gas consumption data collected in real time by the wireless remote gas meter. This behavior frequency structure analysis process includes the following steps: grouping continuous gas consumption data according to preset time windows, and identifying gas consumption events within each time window. The length of the time window can be flexibly configured according to the frequency characteristics of users' daily gas consumption behavior, for example, it can be set to ten minutes, thirty minutes, or one hour. Within each time window, trend analysis is performed on the data sequence of gas flow rate changes over time, identifying continuous rising and falling edges in the flow rate curve, and using this to divide a complete gas consumption event. This identification logic is based on the peak structure of the flow rate curve. If there are three obvious flow rate rise-stabilize-fall phases within a certain time window, it can be determined that there are three independent gas consumption events within that window. For example, if a user's gas usage data within the window of 08:00 to 08:10 shows a rapid increase at 08:02 followed by a decrease at 08:03, another increase at 08:05 followed by a decrease at 08:06:30, and a brief peak around 08:08 before quickly falling back, then three complete gas usage events can be identified. The total number of events within this time window is marked as the gas usage event frequency index per unit time for that window, serving as an important basic indicator for describing the user's activity level.

[0032] After identifying gas usage events, the time interval between any two adjacent events is calculated based on the start and end times of each event, thus extracting the user's time interval characteristics. The event interval data within each time window are aggregated into a time series, and then the variance analysis method in statistics is used to calculate the dispersion of the time interval series. The smaller the dispersion value, the closer the user's gas usage events are to an evenly spaced distribution in time, and the stronger the rhythm stability; conversely, if the time intervals differ significantly, it indicates that the user's behavior has greater temporal volatility. For example, if five gas usage events are detected within an hour, occurring at minutes 5, 15, 25, 35, and 45, the time interval is 10 minutes, and the standard deviation is close to zero, indicating strong temporal regularity in the behavior. Conversely, if the five events occur at minutes 3, 9, 31, 39, and 52, the time intervals are 6, 22, 8, and 13 minutes, respectively, with a significantly increased time interval variance, indicating unstable user behavior. This indicator is of significant value for subsequent identification of automatically triggered or manually operated behaviors.

[0033] After extracting the time interval features, the flow fluctuation amplitude is calculated for each identified gas consumption event. Specifically, within each gas consumption event, the difference between the maximum and minimum values ​​in its flow change curve is taken as the flow fluctuation amplitude for that event. Subsequently, the flow fluctuation amplitudes of all gas consumption events within the time window are statistically processed, and their average and maximum differences are calculated. The average value reflects the range of average gas consumption intensity variation for the user within the current behavior cycle, while the maximum difference is used to identify the extreme degree of fluctuation differences between different events. For example, if within a certain time window, the flow fluctuation amplitudes of three gas consumption events are 0.25 cubic meters / hour, 0.30 cubic meters / hour, and 0.27 cubic meters / hour, respectively, then the average fluctuation amplitude is 0.273, and the maximum difference is 0.05, indicating that the overall volatility of the behavior is relatively consistent. However, if the three events are 0.1, 0.6, and 0.25 cubic meters / hour, the maximum difference reaches 0.5, indicating a significant difference in the intensity of gas consumption behavior. This indicator is mainly used to assess the amplitude stability of behavior and is an important parameter for identifying abnormal patterns of "constant frequency but drastic intensity changes".

[0034] After extracting the three key feature indicators mentioned above, the back-end management department performs unified normalization on all indicators to ensure the comparability of values ​​across different dimensions. Normalization methods can include max-min scaling or Z-score standardization, integrating the frequency of gas usage events per unit time, time interval characteristics, and consistency indicators of fluctuation amplitude with subsequently generated event difference features into a unified feature vector. This vector serves as the basic input for the user's multi-dimensional gas usage behavior sequence model. This sequence model not only reflects the user's behavioral activity, rhythmic regularity, and intensity fluctuations but also provides a structured model foundation for subsequent feature clustering, behavior classification, and intelligent recognition.

[0035] To more accurately identify the degree of behavioral differences between different gas usage events within the same time window, and thus better reveal the micro-characteristic changes in gas usage behavior, the back-end management department extracts morphological parameters and conducts differential assessment analysis on the identified gas usage events to form quantifiable event difference characteristic indicators. Morphological analysis is performed on the flow rate change curve of each gas usage event to extract the basic morphological parameters of the event. The flow rate change curve of each gas usage event typically exhibits a "rising-stable-falling" characteristic shape, reflecting the actual dynamic changes of gas in the three stages of valve opening, stable combustion, and valve closing. The back-end management department calculates the flow rate curve of each event point by point, extracting the duration, maximum flow rate, average flow rate, and the rate of increase and decrease of flow rate change, and uses these values ​​as the basic morphological parameters of the event. For example, in a certain data collection period, it was detected that a user turned on the water heater between 8:32 AM and 8:34 AM. The gas flow rate rapidly increased from zero to 0.35 cubic meters per hour, and then slowly decreased to zero after about 90 seconds. At this time, the event lasted for 120 seconds, the maximum flow rate was 0.35 cubic meters per hour, the average flow rate was about 0.26 cubic meters per hour, the rate of increase was 0.028 cubic meters per second, and the rate of decrease was 0.018 cubic meters per second. By processing the flow rate curve for each event in the same way, a set of morphological parameters corresponding to multiple events can be formed, providing a basis for subsequent statistical analysis and quantification of differences.

[0036] Based on all identified gas usage events, a set of event morphology parameters is constructed. The distribution characteristics of each morphology parameter across all events are statistically calculated to measure the degree of difference between events in terms of duration, flow characteristics, and trends. The back-end management department calculates the mean, range, and standard deviation for each morphology parameter (such as duration, maximum flow, average flow, rate of increase, and rate of decrease). The mean reflects the central tendency of all events on this indicator, the range represents the largest difference between events, and the standard deviation reflects the volatility of events on this parameter. By combining these three statistics, a parameter evaluation framework for measuring the degree of difference between events can be constructed. For example, if five events are identified within a time window, with durations of 80 seconds, 90 seconds, 120 seconds, 110 seconds, and 100 seconds respectively, the mean is 100 seconds, the range is 40 seconds, and the standard deviation is approximately 15 seconds. This indicates that the overall event durations are relatively concentrated, but there is some fluctuation. If the standard deviation of the maximum flow is much higher than the standard deviation of the duration, it indicates that the user's gas usage behavior varies more in terms of flow intensity, possibly reflecting behavioral characteristics of using different terminal devices. Through such statistical evaluation, the system can quantify the differences in behavioral patterns between different events, providing a quantitative basis for subsequent differential modeling.

[0037] All morphological parameters' differences are normalized to form a multidimensional difference vector. A pre-defined distance metric is then used to calculate the difference score of each event relative to the overall behavioral sequence. Because different morphological parameters have different numerical ranges and units (e.g., duration in seconds, flow rate in cubic meters per hour, and speed in cubic meters per second), failure to normalize would result in some parameters having excessively high weight in the distance calculation. Therefore, a maximum-minimum normalization method is used to map the value of each parameter to the interval between zero and one, ensuring equal weight for each dimension in the calculation. The normalized multidimensional difference vector can be represented as a point in a parameter space, representing the morphological performance of the event in different dimensions. Next, a distance metric is used to calculate the degree of difference of each event relative to the overall behavioral sequence. The distance metric can be any of Euclidean distance, Manhattan distance, or cosine similarity. For example, in Euclidean distance calculation, if the coordinates of the dissimilarity vector of an event in the five dimensions are (0.8, 0.6, 0.5, 0.4, 0.7), while the average vector of all events is (0.6, 0.5, 0.6, 0.3, 0.6), then the distance value reflects the intensity of the difference between the event and the center of the overall behavioral characteristics. The larger the distance value, the more the event deviates from the average behavioral pattern, and the higher the probability of it belonging to an abnormal form. If cosine similarity calculation is used, the angular relationship is used to measure whether the direction of change between events is consistent, thereby identifying abnormal differences in the trend of change.

[0038] The calculated difference scores are input as event difference feature values ​​into the user behavior sequence model to supplement the multidimensional expression of user behavior features. Each event difference feature value can be understood as a "deviation index" of the event in the overall behavior space, used to reflect whether the event has characteristics that are significantly different from conventional behavior. For example, when the difference score of an event is significantly higher than that of other events (such as a distance value greater than twice the standard deviation of the average distance), the event is marked as a high-difference event, which may represent that the user has performed a special operation, the equipment has been abnormally turned on, or there is gas volume interference. By incorporating the difference scores into the behavior sequence model, behavior analysis can be extended from a single time series to multidimensional discrimination in the morphological feature space, achieving a more comprehensive expression of behavioral structure. After obtaining this difference feature dimension, the user behavior sequence model can combine time features, frequency features, and amplitude features for joint analysis in the subsequent identification process, significantly improving the identification accuracy of atypical abnormal behaviors.

[0039] To further identify whether users exhibit highly periodic, slightly fluctuating, but unusually frequent behavioral patterns in their actual gas usage, the back-end management department, after constructing the user behavior sequence model, needs to conduct in-depth behavioral feature analysis. This involves extracting behavioral feature parameters such as gas usage event frequency, event duration, and event interval for each time period in the gas usage behavior sequence model, and then combining them into a structured feature vector set. Each time period corresponds to a complete sliding time window. The system extracts structural features from all gas usage events within this window. For example, event frequency is the total number of events divided by the total window duration; event duration is the average duration of each event; and event interval is the sequence average of the time differences between the start points of events. For instance, in a user's evening period from 6:00 PM to 7:00 PM, the system detected 14 gas usage events, totaling 3600 seconds. Each event lasted approximately 120 seconds on average, the average interval between events was approximately 120 seconds, and the event frequency was approximately 0.23 events per minute. The system converts these values ​​into three-dimensional vector data to construct a feature vector set, which serves as the basis for subsequent clustering analysis.

[0040] A density-based time series clustering method is employed to perform pattern recognition on the aforementioned feature vector set, aiming to identify time periods with defined behavioral characteristics exhibiting clustering and rhythmic regularity. In the clustering analysis, the system uses a sliding window approach to classify feature vectors, setting a similarity threshold and a minimum cluster density. Time periods exhibiting concentrated distribution in event frequency and small variations in event intervals are identified as candidate "gas consumption behavior segments with defined behavioral characteristics." For example, if in a user's seven-day behavior sequence, multiple consecutive time periods show event frequencies concentrated between 0.2 and 0.3 per minute, with a standard deviation of less than 10 seconds per event interval, the system marks these time periods as behavior-intensive segments, indicating that the user may be engaging in periodically triggered automated equipment behavior or suspected deceptive behavior patterns within this time interval. The advantage of this clustering method is its ability to automatically identify concentrated behavior intervals and avoid mis-clustering caused by short-term abrupt changes, making it particularly suitable for handling continuous and highly rhythmic atypical gas consumption behaviors.

[0041] For gas consumption behavior segments with defined behavioral characteristics identified through clustering, the system calculates the time-series rate of change for event frequency and flow fluctuation within their corresponding multiple consecutive time windows. This helps determine whether the current behavior exhibits a trend of "frequency solidification and fluctuation convergence." The system arranges the event frequency and flow fluctuation values ​​within these consecutive windows in chronological order and calculates the degree of change between adjacent windows. For example, if the event frequencies of five consecutive windows within a segment are identified as 0.20, 0.21, 0.20, 0.19, and 0.20 times / minute, respectively, and their fluctuation amplitudes are all less than 0.01, with fluctuation rates also below a preset threshold, it indicates extremely high behavioral stability and periodicity. Simultaneously, the system also evaluates the rate of change for flow fluctuation amplitude (e.g., maximum value minus minimum value). If the fluctuation values ​​in each window are close (e.g., all around 0.1 cubic meters per hour), it indicates a high degree of consistency in the behavioral intensity dimension. The rate of change for these two sequences will be used as input to the subsequent dynamic adjustment model for anomaly identification thresholds to determine whether the current segment should be included in the high-sensitivity monitoring zone.

[0042] After calculating the behavior change rate sequence, the backend management department determines whether the target user is in a time range of abnormal behavior fluctuations based on the degree of clustering of behavior changes. Based on the determination, it decides whether to trigger a fine-grained data sampling mechanism. The judgment criteria are based on whether the change trend of event frequency and traffic fluctuations within a behavior segment meets a stability threshold and whether it continuously exhibits convergence or low-amplitude oscillation characteristics. If the degree of clustering reaches the set requirements, it indicates that the segment is highly likely to have highly disguised or automated characteristics. The system then triggers the fine-grained sampling mechanism, shortening the original data sampling cycle from once every 10 seconds to once every 1 second to capture micro-behavioral changes. For example, if the system detects that the event frequency change amplitude is less than 0.02 and the maximum value of the fluctuation change rate sequence is less than 0.01 within a segment over 15 consecutive minutes, it will immediately switch the sampling frequency to obtain a data stream with higher time-series accuracy for subsequent behavioral control inference processes such as operation response feature identification and confidence matching. This mechanism ensures that the system can still achieve deep behavioral modeling and early warning response in situations where behavior does not change abruptly but the structure is highly repetitive, effectively improving the accuracy and dynamic response capability of abnormal behavior detection. When the system detects that the frequency of events changes very little within a continuous time period and the rate of fluctuation is also close to stable, it indicates that the target user's behavior is highly consistent, and there is a possibility of deliberate spoofing or automatic gas recycling by the equipment. Therefore, the system needs to switch to fine-grained sampling mode to obtain behavioral data with higher time-series accuracy and improve the ability to identify atypical abnormal behaviors.

[0043] To achieve high-precision identification of whether a target user's gas usage behavior constitutes atypical abnormal behavior, threshold adaptive control processing needs to be implemented for gas usage behavior segments with defined behavioral characteristics. The key lies in dynamically calculating the lower limit of the anomaly identification threshold control range to reflect the actual fluctuation trend of the target behavior in terms of frequency and intensity. The target user's gas usage behavior segments are divided into multiple equal-length continuous time windows in chronological order. The length of each time window can be set to five or ten minutes, with the specific value dynamically configured based on the stability of historical behavior. For each time window, the number of complete gas usage events is counted, and this is used as the gas usage event frequency index within the current window. Next, the difference in the number of gas usage events between adjacent time windows is calculated, and this difference is divided by the time span between the two time windows to obtain the event frequency change rate sequence. This sequence can be used to reflect the trend characteristics of the target user's behavioral frequency fluctuations within adjacent time periods. Taking a typical behavior as an example, if a user records 6, 8, and 7 gas usage events within a five-minute period, the change in the number of events between the first pair of time windows is 2, with a frequency change rate of 0.4 events per minute. The change in the second pair is -1, with a frequency change rate of -0.2 events per minute. This method effectively captures the rising, falling, or stable fluctuations in behavior frequency, serving as a frequency input indicator for subsequent determination of behavior sensitivity.

[0044] After extracting the event frequency change rate sequence, an intensity analysis is performed on the gas consumption event flow rate values ​​within each time window. Specifically, the maximum and minimum flow rates of all gas consumption events are identified within each time window, and their difference is calculated as the flow rate fluctuation amplitude value within that time window. Subsequently, the flow rate fluctuation amplitude difference between adjacent time windows is calculated, and the time span is used as the divisor to obtain the flow rate change rate sequence. This sequence is used to measure the fluctuation trend of behavior at the gas consumption intensity level. For example, if a user's flow rate fluctuation amplitudes in two consecutive time windows are 0.5 cubic meters and 0.7 cubic meters respectively, with a difference of 0.2 cubic meters, and the time span is still five minutes, then the corresponding change rate is 0.04 cubic meters per minute. By calculating the fluctuation rate change rate sequence of multiple consecutive windows, it is possible to assess whether there are implicit instabilities in user behavior at the intensity level, which helps to further identify the patterns of subtle fluctuations.

[0045] Based on the obtained event frequency change rate sequence and traffic fluctuation change rate sequence, their average value and maximum change rate within the current identification period are calculated respectively, serving as dual quantitative indicators of the degree of abnormal change. The average value of the event frequency change rate sequence reflects the overall fluctuation trend of user behavior frequency. If the average value approaches zero, it usually indicates that the behavior rhythm is relatively stable; conversely, it indicates significant frequency fluctuations, possibly indicating disguised behavior. The maximum change rate of the traffic fluctuation change rate sequence is used to capture the most significant intensity abrupt change points, so as to quickly identify local anomalies of suspicious behavior intensity under low-frequency conditions. These two indicators serve as joint input parameters to drive the adaptive adjustment of the anomaly identification threshold, thereby avoiding the risk of false positives or false negatives caused by static thresholds.

[0046] The two indicators mentioned above are input into a threshold control model constructed based on a weighted linear function. This model assigns a first weighting coefficient to the average value of the event frequency change rate sequence and a second weighting coefficient to the maximum change rate of the flow fluctuation change rate sequence. These weighted coefficients are then multiplied by their corresponding parameters and summed. The resulting weighted sum is subtracted from a preset baseline constant value, ultimately outputting the lower limit of the anomaly identification threshold for the current identification period. For example, if the average frequency change rate is 0.15 with a weighting coefficient of 0.4, and the maximum fluctuation change rate is 0.1 with a weighting coefficient of 0.6, the weighted sum is 0.15 × 0.4 + 0.1 × 0.6 = 0.06 + 0.06 = 0.12. If the baseline constant value is set to 0.2, the final lower threshold is 0.2 - 0.12 = 0.08. This lower threshold will serve as the sensitivity basis for subsequent behavior identification and will be input into the anomaly identification logic of the target user. Combined with subsequent operation response evaluation and group behavior comparison mechanisms, this will enable dynamic identification and response to atypical abnormal behaviors.

[0047] The first and second weighting coefficients are set based on large-scale statistical regression analysis of historical gas consumption behavior sample data. By analyzing a large amount of real user gas consumption behavior change data, the sensitivity contribution of event frequency change rate and flow fluctuation change rate in different types of abnormal behavior is evaluated, thereby determining their relative influence weights in threshold control. The statistical process revealed that in disguised high-frequency, low-amplitude gas consumption behavior, the anomaly of event frequency change is often more discriminative; therefore, the weight of event frequency change rate is relatively high in the corresponding scenario. Conversely, in sudden equipment failure behavior, the anomaly of flow fluctuation is more significant; therefore, the weight of flow fluctuation change rate will be correspondingly increased. Based on these findings, and combined with the behavior type classification model, corresponding weight configuration tables are constructed, and the matching weight configuration scheme is invoked as needed during system deployment.

[0048] The preset baseline constant value is derived from empirical analysis of the variation range of the anomaly identification threshold in normal gas usage behavior segments. By analyzing the frequency and intensity fluctuation index distribution of a large sample group under anomaly-free conditions, a global reference constant independent of specific behavioral characteristics is determined as the initial baseline for adjusting behavioral sensitivity. This constant value can be dynamically updated with changes in region, season, or gas usage scenario to ensure its inclusiveness of normal behavior and its effective distinguishing ability in anomaly behavior determination. The introduction of this constant value not only avoids interference with the threshold due to extreme values ​​of samples but also provides a unified starting point for sensitivity offset, enhancing the adaptability of the anomaly identification logic under different user behavior backgrounds.

[0049] To effectively determine whether a user's current gas usage behavior conforms to manual control logic, the system, after dynamically adjusting the anomaly identification threshold and initiating a fine-grained data sampling mechanism, generates an operational logic confidence score through the following steps, thereby improving the accuracy of identifying atypical abnormal behaviors. After triggering the fine-grained data sampling mechanism, the system extracts multiple gas usage events within a specific identification period from the target user's continuous gas usage data. In each gas usage event, the system records behavioral response feature parameters across multiple dimensions, including response delay time, flow rate increase rate, steady-state duration, instantaneous maximum flow value, and response recovery time. Taking a specific user as an example, if the user generates five consecutive gas usage events within the identification period, the aforementioned parameters are extracted from each event, ultimately forming a behavioral response feature set containing five sets of response features. For ease of subsequent calculation, this set is structured into a vector representation of a unified dimension, constituting the user's behavioral response feature vector within the current identification period, reflecting the comprehensive characteristics of their gas usage behavior in terms of time rhythm, response curve, and intensity changes.

[0050] The system retrieves the most suitable standard operation behavior template for the current identification period scenario from the operation behavior template library. The operation behavior templates are pre-constructed standard behavior sample sets derived from typical operation behavior patterns selected from large-scale user behavior samples, such as manually turning on a gas water heater, igniting a stove, and timed valve shut-off. Each type of behavior template includes corresponding response feature parameters. The templates selected by the system are uniformly processed according to the aforementioned feature parameters to form a template vector. For example, if the template is "user manually turns on the water heater," the corresponding template vector includes behavioral features such as a startup response time of approximately five seconds, a rapid increase in flow rate to 300 liters per minute, a steady-state holding time of ten minutes, and a slow flow recovery time. After structured processing, this template vector and the target user behavior response feature vector form a comparable numerical dimension space.

[0051] The system calculates the vector distance between the target user's behavioral response feature vector and a selected template vector to assess the similarity between the user's current behavior and standard operating behavior. The vector distance calculation method employs experimentally validated similarity metrics, such as Euclidean distance or Manhattan distance. For example, if the traffic increase rate in the target user's behavioral response feature vector is significantly lower than the standard rate recorded in the template vector, while the steady-state duration is significantly longer than the template value, then the distance between the two in the corresponding dimensions is large, indicating a significant deviation between the user's behavior and standard operating behavior. The system uses a preset vector distance calculation method (e.g., Euclidean distance or Manhattan distance) to measure the similarity between the target user's behavioral response feature vector and the standard operating behavior template vector. This vector distance value is directly used to measure the degree of deviation of the target behavior within the overall operational logic space.

[0052] Based on the calculated vector distance value, combined with a pre-defined standard mapping interval, it is converted into a specific operational logic confidence score. This score quantitatively represents the credibility of the current gas usage behavior from an operational logic perspective. For example, if the vector distance value is less than the lower limit of the threshold interval set by the standard deviation, the system marks the behavior as highly consistent with standard operating behavior, and the score is set to a high confidence interval; if the distance value is close to or exceeds the upper limit of the set interval, the score drops significantly, indicating that the behavior is questionable in terms of human operational logic. In practical applications, if the distance between a user's behavioral response feature vector and the template vector is 0.5, and the confidence score mapping interval is set to an inverse mapping between zero and one, then the operational logic confidence score of this behavior is 0.5, which is within the medium confidence range. Alternatively, existing piecewise functional scoring strategies can be employed. For example, a piecewise functional scoring strategy works as follows: when the normalized distance value is less than 15% (i.e., the behavior is highly close to the template), the score is consistently set above 90 (highly reliable), and can be directly used for manually controlled logical behavior; when the normalized distance value is between 15% and 35%, the score decreases non-linearly according to a second-order concave curve to enhance sensitivity to moderate deviations; when the normalized distance value is higher than 35%, the score drops sharply, and a safety lower limit threshold (e.g., 40) is set; exceeding this value will trigger a suspicious behavior flag. The system uses this score as a key input variable for subsequent joint judgments on whether user behavior constitutes atypical abnormal behavior, thus participating in the decision-making logic process together with the behavior difference score, enhancing the robustness and accuracy of the overall behavior recognition results.

[0053] In identifying whether a target user exhibits atypical abnormal behavior, a behavioral difference score is constructed to reflect the degree of deviation by comparing the user's behavior with that of neighboring user groups. This score not only reflects the target user's relative position within the overall gas usage behavior pattern but also provides a quantitative basis for subsequent joint scoring and identification model adaptation. The generation process of the behavioral difference score includes the following steps: After collecting the target user's gas usage behavior characteristic parameters within the current identification period, the target user and its directly connected upstream and downstream users in the network structure are considered as neighboring user groups based on a preset time window. The system normalizes and standardizes the behavioral characteristic parameters of all users within this time window, unifying the dimensions and scale. Behavioral characteristic parameters include, but are not limited to, the frequency of gas usage events per unit time, the average duration of gas usage events, the stability of event intervals, the fluctuation range of gas usage volume, and the event pattern difference value. After standardization, the system sorts the standardized values ​​of all users under each indicator as a dimension and marks the target user's ranking position under that dimension. For example, in the event frequency dimension, if there are twenty users in the neighborhood and the target user is the seventeenth, then its ranking value is seventeen, corresponding to a percentile of 85%. Subsequently, the system calculates the offset of this ranking value relative to the median or average ranking value of the neighborhood group in this dimension, as the ranking offset value in this dimension.

[0054] After obtaining the ranking offset values ​​across all behavioral feature dimensions, the system analyzes these offset values ​​based on statistical principles and sets a threshold for each indicator. This threshold can be automatically set according to the ranking distribution of the surrounding user group under that indicator dimension. For example, a ranking offset exceeding 30% of the group median is considered a "significant deviation." Next, the system compares the target user's offset across all indicators, counts the number of indicators falling within the significant deviation range, and records the ranking offset distance values ​​corresponding to these significant deviation indicators. For example, if six behavioral indicators are set, and the target user's ranking offset value exceeds the set significant deviation threshold on four of these indicators, then the number of significant deviation indicators is four, with ranking offset values ​​of 45%, 50%, 60%, and 35%, respectively.

[0055] Based on the above statistical results, the behavioral difference score is calculated. The behavioral difference score consists of two elements: first, the ratio between the number of significantly deviating indicators and the total number of indicators, reflecting the breadth of the user's overall deviating behavior; second, the arithmetic mean of the ranking offsets corresponding to all significantly deviating indicators, reflecting the intensity of the user's deviating behavior. Using the example above, the significant deviation ratio is four divided by six, i.e., 60%. The average offset of the four indicators is (45% + 50% + 60% + 35%) divided by four, resulting in 47.5%. The system multiplies the two elements to obtain the final behavioral difference score, which is 60% multiplied by 47.5%, resulting in 28.5%, numerically expressed as 0.285. This score will serve as a quantitative result of the target user's behavioral deviation relative to neighboring users within the current time window, used to determine whether they possess significant behavioral differences.

[0056] After obtaining the target user's behavior difference score, the user's score is judged according to a preset scoring interval division standard. The scoring interval division can be determined based on risk assessment experience during model training. For example, 0 to 0.2 can be set as the "low deviation" interval, 0.2 to 0.4 as the "moderate deviation" interval, and above 0.4 as the "significant deviation" interval. If the target user's score falls into the "significant deviation" interval, the user is marked as having suspicious behavior and participates in the subsequent atypical abnormal behavior identification process. If the score is in the "moderate deviation" interval, it can be further jointly judged by combining the operational logic confidence score. If the score is in the "low deviation" interval, the target user's behavior can be preliminarily considered to be consistent with that of neighboring users.

[0057] In this invention, to address the problem that high-frequency, low-intensity micro-abnormal behaviors are difficult to accurately identify using traditional detection methods, a joint judgment method based on operational logic confidence scores and behavioral difference scores is proposed. This further enables dynamic adaptation and replacement of the identification model, thereby improving overall identification accuracy and system robustness. After independently calculating the operational logic confidence scores and behavioral difference scores, the system uses these two scores as feature inputs to construct a joint judgment index. The operational logic confidence score reflects the degree of matching between the target user's current gas usage behavior and typical manual control logic, while the behavioral difference score quantifies the degree of deviation of this behavior from its upstream and downstream neighboring users. To ensure the judgment logic has flexible adaptability, the system pre-sets a lower threshold of the confidence interval for the operational logic confidence score and an upper threshold of the tolerance for the behavioral difference score. The joint scoring judgment criterion is set as a dual-condition trigger mechanism, meaning that the behavior is only judged as atypical abnormal behavior when the operational logic confidence score is lower than the confidence interval threshold and the behavioral difference score is higher than the tolerance interval threshold. Taking actual data as an example, if the operational logic confidence score is 0.3 within a certain recognition period, which is lower than the confidence threshold of 0.4, and the behavior difference score is 0.5, which is higher than the deviation tolerance threshold of 0.45, then the double threshold condition is met, constituting atypical abnormal behavior. This judgment strategy can effectively avoid the recognition bias caused by the failure of a single dimension of scoring, and is especially suitable for the recognition needs of frequent mild interventions or intelligent camouflage behaviors.

[0058] The preset operational confidence interval and neighborhood deviation tolerance range are set based on a comprehensive consideration of the statistical characteristics of user gas consumption behavior, the consistency of operational responses, and the historical data distribution characteristics of large-scale user groups. The lower limit of the operational confidence interval is mainly derived from the comparative analysis of multiple typical manual operation behavior templates and actual response data. Values ​​with similarity scores greater than the 75th percentile of the median are selected as the confidence lower limit, ensuring that anomaly judgment is triggered only when the target behavior is significantly inconsistent with the manual control logic, avoiding false alarms for normal behavior. The neighborhood deviation tolerance range is set based on the concentration of parameters such as gas consumption density, event frequency, and fluctuation amplitude within similar time windows for the same gas supply area or user group. By statistically analyzing the mean and standard deviation of corresponding features in a large number of historical samples, a standard fluctuation band is constructed, and a certain multiple (such as one to one and a half times the standard deviation) exceeding the standard fluctuation band is used as the tolerance boundary for significant deviation, thereby ensuring that the deviation judgment has sufficient statistical significance and stability, and does not cause misjudgment due to local short-term changes.

[0059] If the judgment result indicates that the target user's current behavior constitutes atypical abnormal behavior, the system will immediately issue an abnormal warning signal and mark the gas usage behavior corresponding to the current identification period as a high-risk behavior segment. This high-risk behavior segment will be included in the abnormal behavior tracking record database, with additional information including the identification period timestamp, the score used for identification, the triggering reason, and the original data segment number of the behavior, to facilitate subsequent analysis and tracing or pipeline auditing. For example, within a certain identification period, if the identification algorithm detects that the target user continuously exhibits six small flow gas usage behaviors per unit time from 9:30 to 9:45, with the flow rate stable below the set mutation threshold, the confidence score is 0.25, and the behavior difference score is 0.55, the system will immediately complete the warning marking after both indicators reach the abnormal threshold.

[0060] If the judgment result shows that the target user's current gas usage behavior does not constitute atypical abnormal behavior, that is, any score does not reach the preset abnormal threshold standard, the system will not immediately perform abnormal processing. Instead, it will construct a joint scoring feature vector from the operational logic confidence score and the behavior difference score within the current period, and compare this vector with the feature vector corresponding to each model in the built-in behavior recognition model library one by one. In this invention, the behavior recognition model library contains multiple behavior recognition models trained and generated based on actual usage scenarios, historical user behavior types, and recognition experience. Each model is accompanied by a set of predefined applicable scoring vectors. The system uses distance metrics, such as Euclidean distance, Manhattan distance, or cosine similarity, to calculate the similarity score between the current joint scoring vector and each model in the library, and selects the closest model as the candidate adaptation model. For example, if the current joint scoring vector is 0.5 and 0.35, and the system finds that the applicable scoring vector of a certain recognition model in the model library is 0.55 and 0.32, with the smallest Euclidean distance, then selects this model to enter the adaptation process.

[0061] After completing model similarity matching, the system loads the selected recognition model into the target user behavior detection process for adaptation and replacement. The "loading" process mentioned here refers to dynamically replacing the current default recognition model and updating the behavior recognition rules and parameter configurations based on the selected model. The default recognition model is the basic discrimination model used in this invention when the target user first accesses the recognition platform or when the historical behavior sample size is insufficient. Its rules mainly rely on set frequency thresholds, traffic mutation recognition thresholds, and behavior fluctuation tolerance ranges, combined with dynamically adjusting anomaly recognition thresholds and initiating a fine-grained data sampling mechanism to achieve basic-level behavior recognition. In the early stages, when sufficient feature background support is lacking, the default recognition model provides a tolerant but conservative behavior screening mechanism. As behavior data accumulates and enters the joint scoring mechanism, the system will initiate a dynamic adaptation mechanism for the recognition model based on the need for improved recognition accuracy and the differences in scoring vectors, thereby completing risk behavior monitoring in a way that better matches the target user's behavioral characteristics. For example, if a user is determined to have no abnormal behavior, but the joint scoring features show that their behavior has certain fluctuations or deviates from the neighborhood model, the current identification logic will no longer use the default model, but will replace it with an identification model that is more suitable for the scoring, thereby improving the sensitivity and coverage of capturing abnormal behavior.

[0062] In this invention, the model library refers to a pre-built collection of diverse behavior recognition models used to identify various typical and atypical gas consumption patterns. Each model in the model library is an application example of an existing publicly available algorithm in the field of gas behavior recognition. The model library aims to provide a basis for differentiated model matching for different users under different behavioral characteristics, thereby improving recognition accuracy and adaptability. Typical components of this model library include, but are not limited to, the following types of models: Standard models for time-series anomaly detection: These models use sliding window technology to analyze users' gas consumption time series, combined with anomaly distribution judgment strategies (such as standard deviation multiples, percentile deviations, or Z-Score methods). They are suitable for identifying scenarios such as short-term flow mutations, abnormal rhythms, or sudden changes in behavioral rhythms. For example, using the historical 24-hour sliding window statistical mean and deviation to detect whether there are abnormal deviations in the current flow is a traditional and widely used time-series detection solution for gas companies.

[0063] User behavior clustering models based on cluster analysis: These models use techniques such as K-means clustering, density-based clustering (e.g., DBSCAN), and spectral clustering to aggregate and model indicators such as the frequency, interval, and fluctuation amplitude of users' long-term gas usage events. This allows for the identification of long-term stable behavioral groups and individuals exhibiting abnormal deviations. It is suitable for distinguishing between habitual user operating patterns and occasional abnormal behaviors, improving the system's ability to understand new behavioral patterns.

[0064] Supervised learning-based classification and recognition models: These models use existing labeled data on normal and abnormal behaviors to train classification models such as logistic regression, decision trees, random forests, and support vector machines for multi-dimensional classification and judgment of real-time data. They possess strong anomaly detection capabilities and are suitable for gas usage scenarios where there are sufficient existing samples and known anomaly patterns.

[0065] Template matching models based on sequence pattern matching: These models use a preset behavioral template as a benchmark and employ methods such as Dynamic Time Warping (DTW), longest common subsequence, and similarity matrix to calculate the time and magnitude offset between the current user behavior and the template, determining whether a behavioral deviation exists. They are suitable for recognizing repetitive behaviors over fixed time periods, such as timed water heaters and industrial fixed-point jetting equipment.

[0066] Deep learning-based gas usage behavior prediction models: These models use recurrent neural networks (RNNs), long short-term memory networks (LSTMs), or Transformer architectures to model and predict trends in users' historical gas usage sequences. By comparing the expected output of future gas usage behavior with the actual observed behavior, they determine whether there are potential anomalies. They are suitable for user groups with complex, drastic, or periodically unstable behaviors.

[0067] Neighborhood behavior fusion models based on graph neural networks: These models construct a virtual adjacency graph among users, forming nodes from geographically or behaviorally adjacent users. Behavioral information is propagated through the graph neural network, enabling mutual verification of behavioral deviations among users and identification of local anomaly clustering. Suitable for large-scale urban pipeline network linkage anomaly monitoring tasks, this enhances the model's upstream and downstream collaborative judgment capabilities.

[0068] Lightweight rule engine model: This type of model is a rule-driven model designed for embedded operating environments. It embeds simple logical judgment rules based on thresholds, time periods, and the continuity and discontinuity of gas usage. It is suitable for edge nodes with limited data or computational capabilities. Although its recognition ability is relatively weak, it can be used as an initial or backup detection model under extreme conditions.

[0069] All the aforementioned models are stored in a structured format in the model library, with each model bound to a set of corresponding applicable behavioral feature vectors. Once the target user's operational logic confidence score and behavioral difference score are determined, the system combines them into a feature input vector and calculates similarity with the feature matching vectors of all models in the model library one by one. Using Euclidean distance, cosine similarity, or other metrics, the model closest to this combination is determined and loaded into the current user's behavior recognition process to achieve optimal model adaptation.

[0070] The above algorithms or formulas are all dimensionless and numerical calculations, and the results are obtained by software simulation based on a large amount of collected data to obtain the most recent real-world results. The preset parameters are set by those skilled in the art according to the actual situation.

[0071] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0072] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0073] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the devices and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0074] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for detecting gas meter anomalies based on wireless remote transmission technology, characterized in that, Includes the following steps: The gas consumption data collected in real time by the wireless remote gas meter is transmitted to the back-end management office. The gas consumption data includes the user's gas consumption time, gas flow rate and gas consumption duration. The back-end management department analyzes the collected gas consumption data by behavioral frequency structure, extracts the consistency of gas consumption event frequency, event interval, fluctuation amplitude, and event difference characteristics within a unit of time, and constructs a user gas consumption behavior sequence model. Feature analysis is performed on the gas consumption behavior sequence model to identify gas consumption patterns with defined behavioral characteristics, triggering dynamic adjustment of the anomaly identification threshold and initiating a fine-grained data sampling process; Based on the fine-grained data sampling results, the gas usage behavior of the target user is compared with the preset operation behavior template, the degree of matching between the operation response characteristics and the control logic is calculated, and the operation logic confidence score is generated. At the same time, the gas consumption density and behavioral characteristics of upstream and downstream adjacent users of the target user within the same time window are obtained, and the behavioral difference score is calculated to assess the degree of deviation of the target user's behavior from that of neighboring users. Based on the confidence score of the operational logic and the behavioral difference score, determine whether the target user's current gas usage behavior is atypical abnormal behavior; If the behavior is atypical, an abnormal warning signal will be issued. If the behavior is not abnormal, the behavior recognition model that is closest to the combination of confidence score and behavior difference score from the built-in model library is selected and loaded into the target user behavior detection process for adaptation.

2. The gas meter anomaly detection method based on wireless remote transmission technology according to claim 1, characterized in that, The back-end management department performs behavioral frequency structure analysis on the collected gas consumption data, including the following steps: The continuous gas consumption data is grouped according to the preset time window, and each complete gas consumption event is identified based on the rising and falling edges of the gas flow curve within each time window. The number of gas consumption events within the time window is counted as the gas consumption event frequency index per unit time. Based on the start and end times of each identified gas consumption event, the time interval between two adjacent gas consumption events is calculated, and the variance analysis method is used to calculate the dispersion of the time interval sequence, which serves as a time interval feature characterizing the stability of the user's gas consumption behavior rhythm. The flow fluctuation range within each gas consumption event is calculated separately. By calculating the average value and the maximum difference of the fluctuation range of each event, the consistency of gas consumption behavior fluctuation is judged. At the same time, the difference of the morphological parameters of each gas consumption event is evaluated, and the event difference characteristics are extracted. The frequency of gas consumption events per unit time, time interval characteristics, consistency index of fluctuation amplitude, and event difference characteristics are uniformly normalized to construct a multi-dimensional gas consumption behavior sequence model for users.

3. The gas meter anomaly detection method based on wireless remote transmission technology according to claim 2, characterized in that, The morphological parameters of each gas consumption event are evaluated for differences, and the event difference characteristics are extracted. The difference evaluation includes the following steps: The flow rate change curve of each gas consumption event is analyzed, and the duration, maximum flow rate, average flow rate, and the rate of increase and decrease of flow rate change are extracted and used as the basic morphological parameters of the event. Based on all identified gas consumption events, an event morphology parameter set is constructed, and the mean, range, and standard deviation of each morphology parameter in all events are calculated to measure the degree of difference between events in terms of time length, flow characteristics, and changing trends. The difference index of all morphological parameters is normalized to form a multidimensional difference vector, and the difference score of each gas consumption event relative to the overall behavior sequence is evaluated by a preset distance measurement method. The difference score is used as the event difference feature value and input into the user behavior sequence model.

4. The gas meter anomaly detection method based on wireless remote transmission technology according to claim 3, characterized in that, The default distance metric is any one of Euclidean distance, Manhattan distance, or cosine similarity.

5. The gas meter anomaly detection method based on wireless remote transmission technology according to claim 4, characterized in that, Feature analysis of gas consumption behavior sequence models refers to: The gas consumption behavior sequence model extracts the gas consumption event frequency, event duration and event interval to form a feature vector set for each time period. The density-based time series clustering method is used to identify the time periods with concentrated event frequency distribution and regular time interval distribution as gas consumption behavior segments with defined behavioral characteristics. For gas consumption behavior segments with defined behavioral characteristics identified by clustering, the time series change rates of event frequency variation and flow fluctuation amplitude are calculated in multiple consecutive time windows corresponding to them. The above change rates are used as input parameters to dynamically calculate the lower limit of the anomaly identification threshold control range, which is used to update the current sensitivity configuration of the behavior anomaly identification logic. After updating the anomaly identification threshold, the system determines whether the target user is in a time range of abnormal behavior fluctuations based on the degree of clustering of behavioral changes. If the preset triggering conditions are met, a fine-grained data sampling mechanism is activated. The fine-grained data sampling mechanism refers to changing the sampling period to be shorter than the preset basic sampling period.

6. The gas meter anomaly detection method based on wireless remote transmission technology according to claim 5, characterized in that, When dynamically calculating the lower limit of the anomaly identification threshold control range, the gas consumption behavior segment of the target user is divided into multiple continuous time windows of equal length according to the time sequence. The number of gas consumption events in each time window is counted, the change value of the number of events between adjacent time windows is calculated, and the change value is divided by the time span between the two time windows to obtain the event frequency change rate sequence, which is used to reflect the frequency fluctuation trend of the user's gas consumption behavior. Within each time window, the maximum and minimum flow values ​​of all gas consumption events are extracted, and their difference is calculated as the flow fluctuation amplitude within the current time window. Then, the change in flow fluctuation amplitude between adjacent time windows is calculated and divided by the corresponding time span to obtain the flow fluctuation change rate sequence, which is used to reflect the fluctuation trend of gas consumption behavior in intensity. Based on the event frequency change rate sequence and the flow fluctuation change rate sequence, their average value and maximum change rate in the current identification period are calculated respectively as quantitative indicators of the degree of abnormal change. The above two indicators are used as input parameters and input into the threshold control model based on the weighted linear function to output the lower limit of the abnormal identification threshold in the current identification period.

7. The gas meter anomaly detection method based on wireless remote transmission technology according to claim 6, characterized in that, The threshold control model based on a weighted linear function refers to: The average rate of change extracted from the event frequency change rate sequence is used as the first input parameter, and the maximum rate of change extracted from the traffic fluctuation change rate sequence is used as the second input parameter, and preset first weight coefficients and second weight coefficients are assigned respectively. Multiply the first input parameter by the first weight coefficient, multiply the second input parameter by the second weight coefficient, add the two weighted results together, and then subtract the weighted sum from the preset benchmark constant value to obtain the lower limit of the abnormal identification threshold in the current identification period.

8. A gas meter anomaly detection method based on wireless remote transmission technology according to claim 7, characterized in that, The operational logic confidence score is generated through the following steps: After triggering fine-grained data sampling, multiple gas usage events of the target user within a specific identification period are extracted, response feature parameters of each event are obtained, and the set of parameters is combined into a behavioral response feature vector. Select the corresponding standard operation behavior template from the operation behavior template library, organize its response feature parameters into template vectors, and use the vector distance calculation method to measure the distance between the numerical difference between the target user's behavior response feature vector and the template vector, and evaluate the similarity between the target behavior and the standard operation logic. The vector distance value obtained from the distance metric is then mapped to a confidence score value according to a preset standard to form an evaluation result of the degree of matching of the operation logic, which is used to measure whether the current gas usage behavior meets the expectations of the human control logic.

9. A gas meter anomaly detection method based on wireless remote transmission technology according to claim 7, characterized in that, Behavioral difference scores are generated through the following steps: The behavioral feature parameters of the target user within the same time window are standardized and processed in a unified manner with the parameter set of neighboring users. All users are sorted by numerical value under each feature dimension to determine the ranking position of the target user under each indicator and its offset value relative to the median or average position of the neighboring user group. Statistical analysis is performed on the ranking offset values ​​of all behavioral features. An offset judgment threshold is set for each indicator to define the judgment criteria for significant deviation. Then, the number of indicators in which the target user falls into the significant deviation range among all indicators is counted, and the corresponding offset distance value is recorded. Finally, the behavioral difference score is calculated. The score consists of two parts: the ratio of the total number of significantly deviating indicators to the total number of all indicators, and the arithmetic mean of the ranking offset values ​​corresponding to all significantly deviating indicators. The product of the two is used as the final output result to reflect the relative deviation of the target user in the neighborhood behavior model.

10. A gas meter anomaly detection method based on wireless remote transmission technology according to claim 9, characterized in that, After independently calculating the operational logic confidence score and the behavioral difference score, the two scores are used as input to construct a joint judgment index and set a joint score threshold area to divide the criteria for determining whether atypical abnormal behavior is constituted. If the confidence score is lower than the preset operational confidence interval and the behavioral difference score is higher than the neighborhood deviation tolerance range, it is judged as atypical abnormal behavior. When the target user's behavior is determined to be atypical abnormal behavior, the system immediately issues an abnormal warning signal and marks the current identification period behavior as a high-risk behavior segment, and includes it in the abnormal behavior tracking record; if it does not constitute atypical abnormal behavior, the current joint score combination is used as a feature vector, and its similarity is calculated one by one with the feature vectors corresponding to all models in the pre-built behavior recognition model library. After completing the feature similarity calculation, the recognition model that is closest to the current joint scoring combination features is selected and loaded into the target user behavior detection process for dynamic adaptation, replacing the initially used default recognition model.

Citation Information

Patent Citations

  • Natural gas consumption behavior anomaly detection method and system based on unsupervised model

    CN118194183A

  • Gas consumption data anomaly detection method based on big data

    CN118690311A