Abnormal behavior detection system, method and device, electronic equipment and storage medium

By using a hierarchical collaborative consensus mechanism between sensing node clusters and aggregation node devices, local decision-making ambiguities are eliminated, improving the reliability of the network system and the real-time performance of detection results. This solves the problems of local decision-making conflicts in distributed detection and the performance bottlenecks of centralized solutions.

CN121508907APending Publication Date: 2026-02-10CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511454297.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-11
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing technologies, the independent judgment of node devices in distributed detection architectures leads to poor network system reliability, and centralized solutions suffer from performance bottlenecks and single points of failure in large-scale node scenarios, making it difficult to achieve real-time performance and accuracy.

Method used

The first consensus is reached through a cluster of sensing nodes to obtain the second anomaly information. Then, the aggregation node device reaches consensus again. The hierarchical collaboration mechanism eliminates local decision ambiguity and ensures the real-time performance and reliability of the detection results.

Benefits of technology

It improves the overall reliability of the network system and the accuracy of detection results, solves the problems of local decision-making conflicts in distributed detection and the performance bottleneck of centralized schemes, and realizes efficient and reliable abnormal behavior detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508907A_ABST
    Figure CN121508907A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal behavior detection system, method and device, electronic equipment and a storage medium, relates to the technical field of informatization software systems, and is used for improving the reliability of a network system. Reporting the second abnormal information to the first aggregation node equipment; the first sink node equipment is used for carrying out anomaly identification on the second anomaly information to obtain third anomaly information and transmitting the third anomaly information to the first sensing node equipment; and the first sensing node equipment is further used for executing corresponding operation on the first sensing node equipment based on the received third exception information, and the method and the device are applied to an exception detection scene of the node equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information software systems, and in particular to abnormal behavior detection systems, methods, devices, electronic devices, and storage media. Background Technology

[0002] Currently, to improve the efficiency of anomaly detection in network systems, a distributed detection architecture is typically used. In related technologies, each node in the distributed detection architecture can acquire corresponding device data and perform anomaly detection independently based on that data.

[0003] However, since each device makes independent judgments based on its own device data, decision conflicts may occur due to network disturbances or malicious node interference. For example, adjacent node devices may make opposite judgments on the same event, resulting in poor overall reliability of the network system. Summary of the Invention

[0004] This application provides an abnormal behavior detection system, method, apparatus, electronic device, and storage medium for improving the reliability of network systems.

[0005] In a first aspect, this application provides an abnormal behavior detection system, comprising: at least two sensing node clusters and at least two aggregation node devices, each sensing node cluster comprising N sensing node devices, where N is an even number not equal to 0; a first sensing node device, configured to acquire first abnormal information corresponding to abnormal behavior data of the first sensing node device, and to acquire first abnormal information corresponding to abnormal behavior data of other sensing node devices in the first sensing node cluster to which the first sensing node device is located, wherein the first sensing node device is any one of the N sensing node devices; the first sensing node device is further configured to determine second abnormal information corresponding to the first sensing node cluster based on all acquired first abnormal information, and to report the second abnormal information to a first aggregation node device associated with the first sensing node cluster; the first aggregation node device is configured to send the second abnormal information reported by the first sensing node cluster to other aggregation node devices in the at least two aggregation node devices for abnormal identification, obtain third abnormal information fed back by the other aggregation node devices, and transmit the third abnormal information to the first sensing node device in the first sensing node cluster associated with the first aggregation node; the first sensing node device is further configured to perform corresponding operations on the first sensing node device based on the received third abnormal information.

[0006] The technical solution provided in this application brings at least the following beneficial effects: by reaching a consensus through the sensing node devices in the sensing node cluster to obtain the second abnormal information, and then by reaching a consensus again through the aggregation node devices on the second abnormal information to obtain the third abnormal information, the hierarchical cooperation mechanism eliminates local decision ambiguity, ensures the real-time performance and credibility of the detection results, and improves the overall reliability of the network system.

[0007] In one possible implementation, the above-mentioned abnormal behavior detection system further includes: at least three core arbitration node devices, any one of the at least three core arbitration node devices being associated with one of the at least two aggregation node devices; a first aggregation node device, further configured to upload the third abnormal information to the first core arbitration node device associated with the first aggregation node device when the third abnormal information indicates that the first sensing node device has experienced a preset behavior event; the first core arbitration node device, configured to receive the third abnormal information and send the third abnormal information to other core arbitration node devices among the at least three core arbitration node devices for abnormal identification, obtaining fourth abnormal information corresponding to the first core arbitration node device and other core arbitration node devices, and transmitting the fourth abnormal information to the first aggregation node device; the first aggregation node device, further configured to transmit the fourth abnormal information to the first sensing node device associated with the first aggregation node device; and the first sensing node device, further configured to perform corresponding operations on the first sensing node device based on the received fourth abnormal information.

[0008] Another possible implementation is that the aforementioned first aggregation node device is specifically used to calculate the first weight corresponding to each of the at least two aggregation node devices. The first weight is the sum of the initial weight of each aggregation node device and the weight of the core arbitration node device associated with each aggregation node device. The aggregation node device corresponding to the highest weight among the first weights is determined as the target aggregation node device. In the event that there is a dispute over the abnormal information output by all aggregation node devices in the at least two aggregation node devices, the abnormal information output by the target aggregation node device is determined as the third abnormal information.

[0009] Another possible implementation is that the aforementioned first sensing node device is specifically used to acquire abnormal behavior data of the first sensing node device, and to perform abnormal behavior detection on the abnormal behavior data of the first sensing node device to obtain first abnormal information.

[0010] Secondly, this application provides an abnormal behavior detection method, comprising: a first sensing node device in an abnormal behavior detection system acquiring first abnormal information corresponding to abnormal behavior data of at least two sensing node devices on a sensing node device, and determining second abnormal information based on all the first abnormal information; at least two aggregation node devices in the abnormal behavior detection system performing consensus processing on the abnormal behavior data based on the second abnormal information to obtain third abnormal information; and the first sensing node device performing corresponding operations on a sensing node device based on the third abnormal information.

[0011] The technical solution provided in this application brings at least the following beneficial effects: by reaching a consensus through the sensing node devices in the sensing node cluster to obtain the second abnormal information, and then by reaching a consensus again through the aggregation node devices on the second abnormal information to obtain the third abnormal information, the hierarchical cooperation mechanism eliminates local decision ambiguity, ensures the real-time performance and credibility of the detection results, and improves the overall reliability of the network system.

[0012] In one possible implementation, the above-mentioned abnormal behavior detection method further includes: when the third abnormal information indicates that the first sensing node device has experienced a preset behavior event, the first aggregation node device uploads the third abnormal information to the first core arbitration node device associated with the first aggregation node device; the first core arbitration node device in the abnormal behavior detection system receives the third abnormal information and sends the third abnormal information to other core arbitration node devices among at least three core arbitration node devices for abnormal identification, thereby obtaining fourth abnormal information corresponding to the first core arbitration node device and other core arbitration node devices, and transmitting the fourth abnormal information to the first aggregation node device; the first aggregation node device transmits the fourth abnormal information to the first sensing node device associated with the first aggregation node device; the first sensing node device performs corresponding operations on the first sensing node device based on the received fourth abnormal information.

[0013] Another possible implementation involves at least two aggregation node devices in the aforementioned abnormal behavior detection system performing consensus processing on abnormal behavior data based on the second abnormal information to obtain third abnormal information. This includes: the first aggregation node device calculating a first weight corresponding to each of the at least two aggregation node devices, where the first weight is the sum of the initial weight of each aggregation node device and the weight of the core arbitration node device associated with each aggregation node device; determining the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device; and determining the abnormal information output by the target aggregation node device as the third abnormal information in the case of a disputed event among the abnormal information output by all aggregation node devices in the at least two aggregation node devices.

[0014] Another possible implementation is that the first sensing node device in the above-mentioned abnormal behavior detection system obtains first abnormal information corresponding to the abnormal behavior data of at least two sensing node devices for a sensing node device, including: the first sensing node device obtains the abnormal behavior data of the first sensing node device, and performs abnormal behavior detection on the abnormal behavior data of the first sensing node device to obtain the first abnormal information.

[0015] Thirdly, this application provides a consensus method, comprising: receiving second abnormal information sent by a first sensing node device; calculating a first weight corresponding to each of at least two aggregation node devices, wherein the first weight is the sum of the initial weight of each aggregation node and the weight of the core arbitration node device associated with each aggregation node; determining the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device; and determining the abnormal information output by the target aggregation node device as third abnormal information in the case where there is a dispute event in the abnormal information output by all aggregation node devices in the at least two aggregation node devices.

[0016] The technical solution provided in this application brings at least the following beneficial effects: by determining the most critical and influential target aggregation node device from all aggregation node devices through the first weight, the abnormal information output by the target aggregation node device can be used as the third abnormal information when there is a dispute over the voting results output by all aggregation node devices, thereby improving the accuracy of determining abnormal information.

[0017] One possible implementation involves calculating the first weight corresponding to each of the at least two aggregation node devices, which includes: generating a directed weighted acyclic graph based on the location information of each aggregation node device in the abnormal behavior detection system and the initial weight of each aggregation node device; and calculating the first weight corresponding to each of the at least two aggregation node devices based on the directed weighted acyclic graph.

[0018] Fourthly, this application provides a consensus device, comprising: a receiving module, a processing module, and a determining module. The receiving module is configured to receive second abnormal information sent by a first sensing node device. The processing module is configured to calculate a first weight corresponding to each of the at least two aggregation node devices, wherein the first weight is the sum of the initial weight of each aggregation node and the weight of the core arbitration node device associated with each aggregation node; and to determine the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device. The determining module is configured to determine the abnormal information output by the target aggregation node device as third abnormal information in the event that there is a dispute among the abnormal information output by all aggregation node devices in the at least two aggregation node devices.

[0019] One possible implementation is that the aforementioned processing module is specifically used to generate a directed weighted acyclic graph based on the location information of each of the at least two aggregation node devices in the abnormal behavior detection system and the initial weight of each aggregation node device; and to calculate the first weight corresponding to each of the at least two aggregation node devices based on the directed weighted acyclic graph.

[0020] Fifthly, this application provides an electronic device comprising: a processor and a memory; the memory storing processor-executable instructions; when the processor is configured to execute the instructions, causing the electronic device to implement the method of the third aspect described above.

[0021] Sixthly, this application provides a computer-readable storage medium comprising: computer software instructions; which, when executed in an electronic device, cause the electronic device to implement the methods of the second or third aspect described above.

[0022] In a seventh aspect, this application provides a computer program product comprising a computer program; when the computer program is run in an electronic device, the electronic device causes the electronic device to implement the methods of the second or third aspect described above.

[0023] The beneficial effects of aspects four through seven mentioned above are described in the corresponding descriptions of aspects two or three, and will not be repeated here. Attached Figure Description

[0024] Figure 1 This application provides a schematic diagram of the system structure of an abnormal behavior detection system. Figure 2 A schematic diagram of the system structure of another abnormal behavior detection system provided in this application; Figure 3 A schematic diagram of the system structure of another abnormal behavior detection system provided in this application; Figure 4 A flowchart illustrating an abnormal behavior detection method provided in this application; Figure 5 An interactive schematic diagram of an abnormal behavior detection method provided in this application; Figure 6 A flowchart illustrating another abnormal behavior detection method provided in this application; Figure 7 A flowchart illustrating another abnormal behavior detection method provided in this application; Figure 8 A flowchart illustrating a consensus method provided in this application; Figure 9 A flowchart illustrating another consensus method provided in this application; Figure 10 A schematic diagram of a directed weighted acyclic graph provided in this application; Figure 11 A flowchart illustrating yet another consensus method provided in this application; Figure 12 A schematic diagram of the composition of a consensus device provided in this application; Figure 13 This is a schematic diagram of the composition of an electronic device provided in this application. Detailed Implementation

[0025] The abnormal behavior detection system, method, apparatus, electronic device, and storage medium provided in this application will now be described in detail with reference to the accompanying drawings.

[0026] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0027] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0028] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0029] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0030] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.

[0031] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0032] The abnormal behavior detection system provided in this application embodiment can be applied to scenarios involving abnormal detection of node devices.

[0033] For example, embodiments of this application can be applied to anomaly detection of network devices in a computer room.

[0034] Currently, with the widespread application of cloud computing, the Internet of Things, edge computing, and distributed systems, system scale is becoming increasingly large and nodes are highly dispersed, posing a severe challenge to traditional centralized anomaly detection methods. Centralized solutions rely on a single or a few central nodes to collect and analyze global data. In scenarios with a surge in the number of nodes, massive amounts of data, and high real-time requirements, this easily leads to performance bottlenecks and single points of failure. Network transmission latency and bandwidth limitations make real-time aggregation of massive amounts of data difficult or even impossible, severely hindering the timeliness of anomaly responses. Simultaneously, the wide geographical distribution of nodes and the heterogeneous and potentially dynamic nature of network environments make centralized models ill-suited to adapt to changes in local environmental characteristics, resulting in decreased detection accuracy and adaptability. Therefore, there is an urgent need to develop efficient, reliable, and scalable distributed real-time anomaly detection technologies to extend detection capabilities to the network edge or local nodes to address the complexity of large-scale distributed environments.

[0035] While distributed detection architectures alleviate the problems of centralized systems, they introduce new complexities and challenges. The core difficulty lies in ensuring the consistency, reliability, and effectiveness of final decisions regarding potential anomalies across nodes or local detection units in the absence of a global view and central authority. Typically, distributed detection architectures rely on independent detection based on local information, leading to potentially conflicting results (e.g., false positives, false negatives, or inconsistent severity assessments of the same event), and even the output of malicious information due to node failures or intrusions. Furthermore, unreliable factors such as network partitioning, latency, and packet loss further complicate decision-making coordination. Simple voting or majority-rule mechanisms often prove fragile and inefficient in the face of node heterogeneity, malicious behavior, or complex anomaly patterns. Therefore, a robust consensus mechanism is urgently needed to enable distributed participants to reach a consensus on detection results or decisions under harsh conditions of failures and network asynchrony, eliminating the influence of unreliable nodes and providing a trustworthy basis for anomaly judgment for the entire system.

[0036] The core flaws of existing technologies lie in the performance bottleneck of centralized architecture and the unreliability of distributed collaboration. Traditional anomaly detection technologies have three major limitations: 1. Centralized solutions rely on a single data center to aggregate global information, which leads to massive data transmission congestion and a surge in response latency (especially in IoT large-scale node scenarios), and the failure of the central node will cause the entire network detection function to be paralyzed.

[0037] 2. Although the distributed solution reduces the computational burden, when nodes make independent judgments based on local data, they are prone to decision conflicts due to network disturbances or malicious node interference (such as adjacent nodes making opposite judgments on the same event). Furthermore, the lack of a reliable mechanism to verify the authenticity of local results leads to a sharp drop in the overall reliability of the system.

[0038] 3. Classic consensus algorithms require all nodes in the network to participate in multiple rounds of negotiation to achieve global consistency, but they face fundamental contradictions: 1. Sacrifice of real-time performance: When the number of nodes increases, the time complexity reaches O(N2), and the negotiation delay increases exponentially, which cannot meet the real-time response requirements of <100ms in industrial scenarios; 2. Unsustainable resources: The limited computing power and bandwidth of edge devices are difficult to support continuous network-wide consensus, and they are prone to failure due to resource exhaustion in high-frequency detection scenarios.

[0039] To address the aforementioned technical problems, this application provides an abnormal behavior detection system, method, apparatus, electronic device, and storage medium. The system achieves a second abnormality by reaching a consensus among sensing nodes in a cluster, and then reaches a third abnormality by reaching a consensus again through a convergence node. This hierarchical collaboration mechanism eliminates local decision-making ambiguities, ensures the real-time nature and reliability of the detection results, and improves the overall reliability of the network system.

[0040] It should be noted that the system architecture described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of system architecture, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0041] See Figure 1 This is a schematic diagram of an abnormal behavior detection system provided in an embodiment of this application. The abnormal behavior detection system includes at least two sensing node clusters 10 and at least two aggregation node devices 11. Each sensing node cluster 10 includes N sensing node devices 1011, where N is an even number that is not zero.

[0042] It should be noted that, Figure 1 Taking five aggregation node devices 11 as an example, two sensing node devices 1011 as an example, and three sensing node clusters 10 as an example.

[0043] The first sensing node device 1011 is used to acquire first abnormal information corresponding to the abnormal behavior data of the first sensing node device 1011, and to acquire first abnormal information corresponding to the abnormal behavior data of other sensing node devices in the first sensing node cluster where the first sensing node device 1011 is located.

[0044] In some embodiments, the first sensing node device is any one of N sensing node devices.

[0045] For example, the first sensing node device 1011 described above can be any network device with a server. For example, a programmable logic controller (PLC) device.

[0046] In some embodiments, the aforementioned abnormal behavior data may include at least one of the following: network latency data, network packet loss data, one-way request data, etc. The specific data can be determined based on actual usage requirements, and this application embodiment does not impose any limitations.

[0047] In some embodiments, the aforementioned first abnormal information refers to the normal or abnormal result output by the first sensing node device 1011 after detecting the first abnormal behavior data. This normal or abnormal result is the first abnormal information.

[0048] It is understandable that after other sensing node devices in the first sensing node cluster obtain the first abnormal information corresponding to the abnormal behavior data, the other sensing node devices can send their respective first abnormal information to the first sensing node device 1011.

[0049] It should be noted that the other sensing node devices in the first sensing node cluster mentioned above refer to all sensing node devices in the first sensing node cluster except for the first sensing node device 1011.

[0050] In some embodiments, all sensing node devices in the first sensing node cluster can be connected wirelessly or via a wired connection.

[0051] For example, the wireless connection described above can be any of the following: Wireless Fidelity (WiFi) connection, Bluetooth connection, or mobile network connection.

[0052] For example, other sensing node devices in the first sensing node cluster can send their respective first abnormal information to the first sensing node device 1011 via WiFi.

[0053] The aforementioned first sensing node device 1011 is also used to determine the second abnormal information corresponding to the first sensing node cluster 10 based on all the acquired first abnormal information, and to report the second abnormal information to the first aggregation node device 110 associated with the first sensing node cluster.

[0054] In some embodiments, the first sensing node device 1011 can collect all first abnormal information to determine the second abnormal information.

[0055] For example, suppose there are a total of 10 first abnormal information, which include 5 normal results and 5 abnormal results respectively. In this case, the second abnormal information is 5 normal results and 5 abnormal results.

[0056] It should be noted that if the 10 first abnormal information items include 6 normal results and 4 abnormal results, the first sensing node device 1011 can directly perform the corresponding processing based on the first abnormal information item. In other words, the first sensing node device 1011 will only report the second abnormal information item to the first aggregation node device associated with the first sensing node cluster if there is a decision conflict in the first abnormal information item, i.e., a tie.

[0057] In some embodiments, the first sensing node cluster may be wirelessly connected to the first aggregation node device 110.

[0058] In some embodiments, the first sensing node device 1011 is specifically used to acquire abnormal behavior data of the first sensing node device and perform abnormal behavior detection on the abnormal behavior data of the first sensing node device to obtain first abnormal information.

[0059] For example, the first sensing node device 1011 may include a lightweight detection module, which uses the Raft consensus algorithm to detect abnormal behavior data of the first sensing node device to obtain the first abnormal information corresponding to the abnormal behavior data.

[0060] It should be noted that each of the above N sensing node devices can include the aforementioned lightweight detection module, and the abnormal behavior detection method is different for each sensing node device.

[0061] The aforementioned first aggregation node device 110 is used to send the second abnormal information reported by the first sensing node cluster 10 to other aggregation node devices in at least two aggregation node devices 11 for abnormal identification, obtain the third abnormal information fed back by the other aggregation node devices, and transmit the third abnormal information to the first sensing node device in the first sensing node cluster associated with the first aggregation node.

[0062] In some embodiments, the second abnormal information may include: an event hash and the signatures of all sensing node devices in the first sensing node cluster 10.

[0063] For example, the above event hash refers to the hash value obtained after performing a hash operation on the first abnormal information.

[0064] For example, the above signature is used to uniquely identify a sensing node device.

[0065] In some embodiments, each of the at least two aggregation node devices 11 described above can be connected wirelessly or via a wired connection. The specific connection can be determined based on actual usage requirements, and this application embodiment does not impose any limitations.

[0066] It should be noted that the specific process of the above-mentioned aggregation node device to identify the second abnormal information can be found in the following embodiments, and will not be repeated here to avoid repetition.

[0067] In some embodiments, the first aggregation node device 110 is specifically used to calculate the first weight corresponding to each of the at least two aggregation node devices; and to determine the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device; and in the event that there is a dispute over the abnormal information output by all the aggregation node devices in the at least two aggregation node devices, to determine the abnormal information output by the target aggregation node device as the third abnormal information.

[0068] In some embodiments, the first weight is the sum of the initial weight of each aggregation node device and the weight of the core arbitration node device associated with each aggregation node device.

[0069] In some embodiments, the aforementioned disputed event is a situation where there is a tie in the abnormal information output by all aggregation node devices.

[0070] It should be noted that the specific process of calculating the first weight corresponding to each aggregation node device can be found in the following embodiments, and will not be repeated here to avoid repetition.

[0071] It is understandable that, in the absence of disputed events in the abnormal information output by all the aggregation node devices in at least two aggregation node devices, the aforementioned first aggregation node device 110 can determine the abnormal information output by all the aggregation node devices as the third abnormal information.

[0072] The aforementioned first sensing node device 1011 is also used to perform corresponding operations on the first sensing node device based on the received third abnormal information.

[0073] In some embodiments, the aforementioned third abnormal information is an abnormal result information, such as normal or abnormal.

[0074] For example, if the third abnormal information is normal, the first sensing node device may not perform any operation; if the third abnormal information is abnormal, the first sensing node device may terminate the operation being performed.

[0075] It should be noted that the above-mentioned abnormal behavior detection system can be divided into an edge perception layer and a convergence consensus layer. The edge perception layer includes the above-mentioned N clusters of at least two perception nodes 10, and the convergence consensus layer includes at least two convergence node devices 11.

[0076] It can be understood that the above division is a virtual division.

[0077] For example, the above process will be explained in detail below with a specific example. Assume that a smart manufacturing workshop deploys 200 sensor nodes, divided into 20 dynamic clusters. When nodes A and B in cluster 5 have conflicting judgments on the vibration data of the same equipment (A reports an anomaly, B reports normal), the nodes in cluster 5 trigger a local fast consensus. This can be implemented through S1 to S7 as described below.

[0078] S1, the first sensing node device collects votes from cluster 5 nodes.

[0079] S2. If consensus is reached (>60% agreement), the first sensing node device will directly issue an alarm and isolate the device.

[0080] S3. If no agreement is reached (e.g., a 2:2 tie), submit the event hash and signature evidence to the first aggregation node device.

[0081] S4. The first aggregation node device receives the event hash and signature evidence, and parses the signature to verify its authenticity.

[0082] S5: The first aggregation node device dynamically elects nine trusted nodes to form a consensus group.

[0083] S6. The first aggregation node device performs three rounds of message exchange, requiring ≥6 nodes to reach consensus.

[0084] S7. The first aggregation node device returns the consensus result to the first sensing node device for execution and simultaneously files the record.

[0085] In the abnormal behavior detection system provided in this application embodiment, a consensus is reached through the sensing node devices in the sensing node cluster to obtain the second abnormal information. Then, the aggregation node device reaches a consensus again through the second abnormal information to obtain the third abnormal information. The hierarchical cooperation mechanism eliminates local decision ambiguity, ensures the real-time performance and credibility of the detection results, and improves the overall reliability of the network system.

[0086] In some embodiments, combined with Figure 1 ,like Figure 2 As shown, the above-mentioned abnormal behavior detection system also includes: at least three core arbitration node devices 12, any one of the at least three core arbitration node devices 12 being associated with one of the at least two aggregation node devices 11.

[0087] It should be noted that, Figure 2 Taking the three core arbitration node devices 12 as an example.

[0088] The first aggregation node device 110 is also used to upload the third abnormal information to the first core arbitration node device 120 associated with the first aggregation node device 110 when the third abnormal information indicates that the first sensing node device has experienced a preset behavior event.

[0089] In some embodiments, the aforementioned preset behavior event can be any of the following: cross-domain aggregation event, unauthorized access to the core database, or unauthorized tampering with the core database, etc. The specific event can be determined according to actual usage requirements, and this application embodiment does not impose any limitations.

[0090] For example, the aforementioned cross-domain convergence event could be a failure in the collaborative production line between workshop A and workshop B.

[0091] It should be noted that the above-mentioned abnormal behavior detection system may also include a core arbitration layer, which includes at least three core arbitration node devices 12.

[0092] In some embodiments, the first aggregation node device 110 can be wirelessly connected to the first core arbitration node device 120.

[0093] For example, the first aggregation node device 110 can upload third abnormal information to the first core arbitration node device 120 associated with the first aggregation node device 110 via WiFi.

[0094] The aforementioned first core arbitration node device 120 is used to receive the third abnormal information, send the third abnormal information to other core arbitration node devices among the at least three core arbitration node devices 12 for abnormal identification, obtain the fourth abnormal information corresponding to the first core arbitration node device 120 and other core arbitration node devices, and transmit the fourth abnormal information to the first aggregation node device.

[0095] In some embodiments, each of the at least three core arbitration node devices 12 described above can be wirelessly or wired connected. The specific connection can be determined based on actual usage requirements, and this application embodiment does not impose any limitations.

[0096] In some embodiments, the other core arbitration node devices among the above-mentioned at least three core arbitration node devices 12 are all core arbitration node devices other than the first core arbitration node device 120 among the at least three core arbitration node devices 1.

[0097] It should be noted that the specific process of anomaly identification by the other core arbitration node devices among the above-mentioned at least three core arbitration node devices 12 based on the third anomaly information can be found in the general description of the relevant technology. To avoid repetition, it will not be repeated here.

[0098] In some embodiments, the fourth abnormal information is an abnormal result information, such as normal or abnormal.

[0099] The aforementioned first aggregation node device 110 is also used to transmit fourth abnormal information to the first sensing node device 1011 associated with the first aggregation node device.

[0100] In some embodiments, the first aggregation node device 110 can transmit fourth abnormal information to the first sensing node device 1011 associated with the first aggregation node device via WiFi.

[0101] The aforementioned first sensing node device 1011 is also used to perform corresponding operations on the first sensing node device 1011 based on the received fourth abnormal information.

[0102] In some embodiments, if the fourth abnormal information is normal, the first sensing node device 1011 may not perform any operation; or, if the fourth abnormal information is abnormal, the first sensing node device 1011 may perform a power-off operation or a restart operation.

[0103] In this way, the abnormal behavior detection system breaks down single-point bottlenecks through a hierarchical architecture, reduces resource overhead through a lightweight consensus protocol, and ensures real-time performance through hardware acceleration, thus balancing the long-standing triangular contradiction of "reliability-real-time performance-resource efficiency" in the field of distributed anomaly detection. Furthermore, at least three core arbitration nodes only judge high-risk events, reducing communication overhead, while hierarchical isolation allows high-risk events to be directly connected to the higher-level consensus, ensuring the real-time determination of critical anomalies in resource-constrained environments.

[0104] like Figure 3 As shown below, the abnormal behavior detection system provided in the embodiments of this application will be explained in detail through specific examples.

[0105] In the edge perception layer, PLC1 reports abnormal behavior data to node dynamic cluster 1. All nodes in node dynamic cluster 1 detect the abnormal behavior data and vote on it. In the event of a tie, node dynamic cluster 1 performs a hash operation on the abnormal behavior data to obtain a hash value, and reports the hash value to the aggregation node associated with node dynamic cluster 1 in the aggregation consensus layer. The aggregation node broadcasts the abnormal behavior data to other aggregation nodes in the aggregation consensus layer. Then, the aggregation nodes and other aggregation nodes perform consensus processing and vote on it. In the event of no tie, the aggregation node associated with node dynamic cluster 1 sends the voting result to node dynamic cluster 1. After receiving the voting result, node dynamic cluster 1 controls PLC1 to execute the corresponding operation.

[0106] In the event of a tie, the abnormal behavior detection system will send the voting results of the target aggregation node in the consensus layer to node dynamic cluster 1. After receiving the voting results, node dynamic cluster 1 will control PLC1 to perform the corresponding operation.

[0107] If the aggregation node associated with node dynamic cluster 1 detects that the event indicated by the abnormal behavior data is a cross-domain aggregation event or a high-risk behavior, it reports the abnormal behavior data to the adjudication evaluation engine in the core arbitration layer. The adjudication evaluation engine determines the abnormal behavior result through evaluation decision and broadcasts the abnormal behavior result to the aggregation node. After receiving the abnormal behavior result, the aggregation node sends the abnormal behavior result to node dynamic cluster 1. After receiving the voting result, node dynamic cluster 1 controls PLC1 to execute the corresponding operation.

[0108] See Figure 4 This is a flowchart illustrating an abnormal behavior detection method provided in this application. Figure 4 As shown, the abnormal behavior detection method provided in this application can be implemented through the above-mentioned abnormal behavior detection system, specifically including the following steps S201 to S203.

[0109] S201. In the abnormal behavior detection system, the first sensing node device acquires first abnormal information corresponding to the abnormal behavior data of at least two sensing node devices on a sensing node device, and determines second abnormal information based on all the first abnormal information.

[0110] S202. At least two aggregation node devices in the abnormal behavior detection system perform consensus processing on the abnormal behavior data based on the second abnormal information to obtain the third abnormal information.

[0111] S203. The first sensing node device performs a corresponding operation on a sensing node device based on the third abnormal information.

[0112] It should be noted that the specific implementation process of S201 to S203 can be found in the above embodiments, and will not be repeated here to avoid repetition.

[0113] For example, such as Figure 5 As shown, the following example illustrates the interaction between the first sensing node device and the first aggregation node device. Specifically, this can be achieved through steps S1 to S3 described below.

[0114] S1. The first sensing node device determines the first abnormal information corresponding to the abnormal behavior data of at least two sensing node devices for a sensing node device, and determines the second abnormal information based on all the first abnormal information, and sends the second abnormal information to the first aggregation node device.

[0115] S2. The first aggregation node device receives the second abnormal information and broadcasts the second abnormal information to all aggregation node devices to obtain the third abnormal information after consensus processing by all aggregation node devices, and sends the third abnormal information to the first sensing node device.

[0116] S3. The first sensing node device receives the third abnormal information and performs corresponding processing based on the third abnormal information.

[0117] In the abnormal behavior detection method provided in this application, a consensus is reached through the sensing node devices in the sensing node cluster to obtain the second abnormal information. Then, the aggregation node device reaches a consensus again through the second abnormal information to obtain the third abnormal information. The hierarchical cooperation mechanism eliminates local decision ambiguity, ensures the real-time performance and credibility of the detection results, and improves the overall reliability of the network system.

[0118] In the abnormal behavior detection method provided in this application, a consensus is reached through the sensing node devices in the sensing node cluster to obtain the second abnormal information. Then, the aggregation node device reaches a consensus again through the second abnormal information to obtain the third abnormal information. The hierarchical cooperation mechanism eliminates local decision ambiguity, ensures the real-time performance and credibility of the detection results, and improves the overall reliability of the network system.

[0119] In some embodiments, the abnormal behavior detection method provided in this application further includes the following steps S301 to S304.

[0120] S301. When the third abnormal information indicates that the first sensing node device has a preset behavior event, the first aggregation node device uploads the third abnormal information to the first core arbitration node device associated with the first aggregation node device.

[0121] S302. The first core arbitration node device in the abnormal behavior detection system receives the third abnormal information and sends the third abnormal information to other core arbitration node devices among the at least three core arbitration node devices for abnormal identification, thereby obtaining the fourth abnormal information corresponding to the first core arbitration node device and other core arbitration node devices, and transmitting the fourth abnormal information to the first aggregation node device.

[0122] S303, The first aggregation node device transmits the fourth abnormal information to the first sensing node device associated with the first aggregation node device.

[0123] S304. Based on the received fourth abnormal information, the first sensing node device performs corresponding operations.

[0124] It should be noted that the specific implementation process of S301 to S304 can be found in the above embodiments, and will not be repeated here to avoid repetition.

[0125] In this way, the abnormal behavior detection system breaks down single-point bottlenecks through a hierarchical architecture, reduces resource overhead through a lightweight consensus protocol, and ensures real-time performance through hardware acceleration, thus balancing the long-standing triangular contradiction of "reliability-real-time performance-resource efficiency" in the field of distributed anomaly detection. Furthermore, at least three core arbitration nodes only judge high-risk events, reducing communication overhead, while hierarchical isolation allows high-risk events to be directly connected to the higher-level consensus, ensuring the real-time determination of critical anomalies in resource-constrained environments.

[0126] In some embodiments, combined with Figure 4 ,like Figure 6 As shown, the above S202 can be specifically implemented as S202a and S202b.

[0127] S202a. The first aggregation node device calculates the first weight corresponding to each of the at least two aggregation node devices, and determines the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device.

[0128] In some embodiments, the first weight is the sum of the initial weight of each aggregation node device and the weight of the core arbitration node device associated with each aggregation node device.

[0129] S202b: In the event of a dispute over the abnormal information output by all aggregation node devices in at least two aggregation node devices, the abnormal information output by the target aggregation node device shall be determined as the third abnormal information.

[0130] It should be noted that the specific implementation process of S202a and S202b described above can be found in the following embodiments, and will not be repeated here to avoid repetition.

[0131] In this way, by using weights to determine the most critical and influential target aggregation node from all aggregation node devices, the abnormal information output by the target aggregation node can be used as the third abnormal information when there is a dispute over the abnormal information output by all aggregation node devices, thereby improving the accuracy of the abnormal behavior detection system in determining abnormal information.

[0132] In some embodiments, combined with Figure 4 ,like Figure 7 As shown, the "first sensing node device in the abnormal behavior detection system acquires the first abnormal information corresponding to the abnormal behavior data of at least two sensing node devices on a sensing node device" in the above S201 can be specifically implemented as S201a as follows.

[0133] S201a. The first sensing node device acquires abnormal behavior data of the first sensing node device, and performs abnormal behavior detection on the abnormal behavior data of the first sensing node device to obtain the first abnormal information.

[0134] It is understood that all the sensing nodes in the above-mentioned at least two sensing node devices obtain their respective first abnormal information through the above process; each of the at least two sensing node devices performs abnormal behavior detection in a different way.

[0135] It should be noted that the specific implementation process of S201a above can be found in the following embodiments, and will not be repeated here to avoid repetition.

[0136] In this way, the anomaly detection task is pushed down to the nearest node cluster, and microsecond-level fast consensus is used to process abnormal events. Only a few node devices within the cluster need to determine the abnormal information, which improves the efficiency of the abnormal behavior detection system in determining abnormal information.

[0137] See Figure 8 This is a flowchart illustrating a consensus method provided in an embodiment of this application. Figure 8 As shown, the consensus method provided in this application can be implemented by a consensus device, specifically including the following steps S401 to S403.

[0138] S401, The consensus device receives the second abnormal information sent by the first sensing node device.

[0139] For example, the consensus device described above can be the first aggregation node device described above.

[0140] In some embodiments, the consensus device can receive second anomaly information sent by the first sensing node device via WiFi.

[0141] S402. The consensus device calculates the first weight corresponding to each of the at least two aggregation node devices, and determines the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device.

[0142] In some embodiments, the first weight is the sum of the initial weight of each aggregation node and the weight of the core arbitration node device associated with each aggregation node.

[0143] It should be noted that the specific implementation process of S402 described above can be found in the following embodiments, and will not be repeated here to avoid repetition.

[0144] S403. In the event that there is a dispute over the abnormal information output by all the aggregation node devices in at least two aggregation node devices, the abnormal information output by the target aggregation node device shall be determined as the third abnormal information.

[0145] In some embodiments, the aforementioned disputed events may be cases where there is a tie in the abnormal information output by all aggregation node devices.

[0146] In the consensus method provided in this application embodiment, the most critical and influential target aggregation node device is determined from all aggregation node devices by using a first weight. This allows the abnormal information output by the target aggregation node device to be used as the third abnormal information when there is a dispute over the voting results output by all aggregation node devices, thereby improving the accuracy of the consensus device in determining abnormal information.

[0147] In some embodiments, combined with Figure 8 ,like Figure 9 As shown, the above S402 can be specifically implemented as S402a and S402b.

[0148] S402a The consensus device generates a directed weighted acyclic graph based on the location information of each of the at least two aggregation node devices in the abnormal behavior detection system and the initial weight of each aggregation node device.

[0149] In some embodiments, the location information may include: x-coordinate and y-coordinate.

[0150] In some embodiments, the initial weight of each of the above-mentioned aggregation node devices can be preset by the user in advance.

[0151] For example, such as Figure 10 As shown, the consensus device can model the system as a distributed multi-node directed weighted acyclic graph based on the location information and initial weight of each of the at least two aggregation node devices in the abnormal behavior detection system.

[0152] It should be noted that the consensus mechanism regenerates a directed weighted acyclic graph each time consensus is reached, where nodes represent entities participating in the consensus, edges represent communication links, and weights can represent trust levels, etc. Figure 10 In this process, a set of aggregation nodes is usually selected to collect, integrate, and disseminate voting or state information during the consensus process.

[0153] Understandably, current research commonly chooses the number of aggregation nodes to be 3, 5, or 7. This design aims to balance system performance and resource overhead while tolerating a certain number of node failures or malicious behavior. If the number of aggregation nodes is too small (e.g., 3), the system's fault tolerance is weak, facing potential security threats; while if the number of nodes is too large (e.g., 7), although it can improve the system's robustness and resistance to attacks, it will also significantly increase communication complexity, computational load, and coordination costs, reducing consensus efficiency.

[0154] Therefore, to achieve a reasonable trade-off between security and economy, this application selects a scenario with 5 aggregation node devices for event iteration consensus. This configuration can tolerate up to 2 malicious nodes under typical Byzantine fault tolerance settings, while maintaining relatively low coordination overhead, making it suitable for most practical application scenarios, such as consortium blockchains, IoT collaborative decision-making, and distributed database replication.

[0155] The S402b consensus device is based on a directed weighted acyclic graph. It calculates the first weight corresponding to each of the at least two aggregation node devices and determines the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device.

[0156] For example, the consensus device can calculate the first weight corresponding to a convergence node device using the following formula (1).

[0157] (1) in, The initial weight of a convergence node device, For all instructions, the set of parent nodes of a convergence node device, Let α and β be the edge weights from parent node j to node i, α and β be the harmonic parameters, and W(j) be the weight of the parent node, where j is the parent node.

[0158] In some embodiments, the initial weight can be a configurable parameter, and all aggregation node devices can have the same initial weight, or different initial weights can be assigned based on external information.

[0159] For example, the initial weight mentioned above can be 1.

[0160] In some embodiments, the aforementioned edge weights are used to characterize the contribution strength or influence factor of parent node j to child node i.

[0161] In some embodiments, the parent node is all core arbitration node devices associated with the aforementioned aggregation node device.

[0162] In some embodiments, if α=1 and β=1, the weight corresponding to the above-mentioned aggregation node device is the sum of its own weight and the weights of all parent nodes; or, if α=0 and β=1, the weight corresponding to the above-mentioned aggregation node device is entirely derived from the parent nodes.

[0163] For example, the calculation process of the first weight corresponding to each of the at least two aggregation node devices is explained in detail below. Specifically, it can be implemented through S20 to S22 as described below.

[0164] S20. The consensus device initializes the weights of each of the at least two aggregation node devices.

[0165] For example, the weight of the source aggregation node device, i.e., the node with an in-degree of 0, is set to 1. The initial weights of other aggregation node devices can be set to 0.

[0166] S21, The consensus device performs topology sorting.

[0167] For example, in a distributed environment, each sink node device needs to collaborate or have a coordinator determine a global topology order. This order ensures that when a sink node device is computed, all of its parent nodes have already been computed.

[0168] S22, The consensus device performs sequential calculations and propagation.

[0169] For example, the consensus device can process each aggregation node device sequentially according to the topological order.

[0170] For example, when the current aggregation node device receives the weights from all parent nodes, the consensus device can calculate the first weight corresponding to the current aggregation node device according to the above formula (1), and broadcast the calculated first weight to all child nodes associated with the current aggregation node device.

[0171] In some embodiments, the algorithm terminates naturally once all sink nodes have calculated their respective first weights and broadcast them. Since the graph is acyclic, this process is guaranteed to be completed in a finite number of steps and does not require iterative convergence.

[0172] Moreover, the above method is a variant algorithm based on eigenvector centrality. By utilizing the topological sorting properties of directed weighted acyclic graphs, it transforms the original iterative convergence problem into a single forward propagation process, making it suitable for distributed computing frameworks.

[0173] For example, suppose there is a node 1 (source node), node 2 references node 1, node 3 references node 1, node 4 references node 2 and node 3, and node 5 references node 1, node 3 and node 4. Then the topological order is [1,2,3,4,5].

[0174] At this point, the first weight corresponding to each node is calculated as follows: Node 1: In-degree is 0. W(1)=1. Broadcast to Node 2 and Node 3.

[0175] Node 2: Receives weight (1) from node 1. W(2) = 1 * 1 = 1; broadcasts to node 4.

[0176] Node 3: Receives weight (1) from node 1. W(3) = 1 * 1 = 1; broadcasts to nodes 24 and 5.

[0177] Node 4: Receives weights from nodes 2 and 3. W(4) = 1*1 + 1*1 = 2.

[0178] Node 5: Receives weights from nodes 3 and 4. W(5) = 1*1 + 1*1+1*1 = 3.

[0179] Results Analysis: The node with the highest weight is 3 because it achieved consensus from 3 nodes. Node 1, as the pioneering node, has a weight of 1 and indirectly influenced node 5 through nodes 2 and 3. This aligns with the intuitive understanding of consensus mechanism propagation.

[0180] It is understandable that the consensus device can regenerate a new directed weighted acyclic graph and recalculate the first weight corresponding to each aggregation node device before each consensus begins, based on the number of aggregation node devices. In other words, the first weight corresponding to each aggregation node device is dynamically generated.

[0181] In this way, by dynamically generating a directed weighted acyclic graph and calculating the weights of the aggregation node devices, the aggregation node devices can achieve self-updating and mutual evaluation. Without the need for a central institution, the decision weight of reliable nodes can be automatically increased and malicious nodes can be suppressed. This is naturally suitable for scenarios with extremely high requirements for real-time performance and anti-attack capabilities.

[0182] In some embodiments, combined with Figure 8 ,like Figure 11 As shown, after S402 above, the consensus method provided in this application embodiment further includes the following S501.

[0183] S501. If there are no disputed events in the abnormal information output by all the aggregation node devices in at least two aggregation node devices, the consensus device determines the third abnormal information based on the abnormal information output by all the aggregation node devices.

[0184] It is understood that if there are no disputed events in the abnormal information output by all the aggregation nodes in at least two aggregation nodes, it means that there are no tied events in the abnormal information output by all the aggregation nodes in at least two aggregation nodes. All consensus devices can determine the anomaly detection result based on the abnormal information output by all aggregation nodes.

[0185] In this way, the consensus device can determine whether there is a disputed event in the abnormal information output by all the aggregation nodes in at least two aggregation nodes, and thus perform different operations, improving the flexibility and accuracy of the consensus device in determining the third abnormal information.

[0186] This application embodiment can divide the consensus device into functional modules according to the above method example. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0187] In some embodiments, this application also provides a consensus apparatus. The consensus apparatus may include one or more functional modules for implementing the consensus method of the above method embodiments.

[0188] For example, Figure 12 This is a schematic diagram illustrating the composition of a consensus device provided in an embodiment of this application. Figure 12 As shown, the consensus device 900 includes: a receiving module 901, a processing module 902, and a determining module 903.

[0189] The receiving module 901 is used to receive the second abnormal information sent by the first sensing node device. The processing module 902 is used to calculate the first weight corresponding to each of the at least two aggregation node devices, wherein the first weight is the sum of the initial weight of each aggregation node and the weight of the core arbitration node device associated with each aggregation node; and to determine the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device. The determining module 903 is used to determine the abnormal information output by the target aggregation node device as the third abnormal information in the case where there is a dispute over the abnormal information output by all aggregation node devices in the at least two aggregation node devices.

[0190] In the consensus device provided in this application, the most critical and influential target aggregation node device is determined from all aggregation node devices by using a first weight. This allows the abnormal information output by the target aggregation node device to be used as the third abnormal information when there is a dispute over the voting results output by all aggregation node devices, thereby improving the accuracy of the consensus device in determining abnormal information.

[0191] In some embodiments, the processing module 902 is specifically used to generate a directed weighted acyclic graph based on the location information of each of the at least two aggregation node devices in the abnormal behavior detection system and the initial weight of each aggregation node device; and to calculate the first weight corresponding to each of the at least two aggregation node devices based on the directed weighted acyclic graph.

[0192] In other embodiments, the determination module 903 is further configured to, after determining the aggregation node device corresponding to the highest weight in each first weight as the target aggregation node device, determine the third abnormal information based on the abnormal information output by all aggregation node devices, provided that there are no disputed events in the abnormal information output by all aggregation node devices in at least two aggregation node devices.

[0193] It should be noted that the consensus device can implement all the processes implemented in the above method embodiments and achieve the same beneficial effects. To avoid repetition, it will not be described again here.

[0194] In the case where the functions of the integrated modules described above are implemented in hardware, this application provides a possible structural schematic diagram of the electronic device involved in the above embodiments. For example... Figure 13 As shown, the electronic device 90 includes: a processor 92, a communication interface 93, and a bus 94. Optionally, the electronic device 90 may also include a memory 91.

[0195] Processor 92 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 92 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 92 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0196] Communication interface 93 is used to connect with other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.

[0197] The memory 91 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0198] As one possible implementation, the memory 91 can exist independently of the processor 92. The memory 91 can be connected to the processor 92 via a bus 94 and is used to store instructions or program code. When the processor 92 calls and executes the instructions or program code stored in the memory 91, it can implement the consensus method provided in the embodiments of this application.

[0199] In another possible implementation, memory 91 can also be integrated with processor 92.

[0200] Bus 94 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 94 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 13 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0201] Through the above description of the implementation methods, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the service calling device can be divided into different functional modules to complete all or part of the functions described above.

[0202] This application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be executed by computer instructions instructing related hardware. The program can be stored in the aforementioned computer-readable storage medium, and when executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be any of the foregoing embodiments or memory. The aforementioned computer-readable storage medium can also be an external storage device of the aforementioned service invocation device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the aforementioned service invocation device. Further, the aforementioned computer-readable storage medium can include both internal storage units of the aforementioned service invocation device and external storage devices. The aforementioned computer-readable storage medium is used to store the aforementioned computer program and other programs and data required by the aforementioned service invocation device. The aforementioned computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0203] This application also provides a computer program product comprising a computer program that, when run on a computer, causes the computer to execute any of the consensus methods provided in the above embodiments.

[0204] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An abnormal behavior detection system, characterized in that, include: At least two sensing node clusters and at least two aggregation node devices, each sensing node cluster comprising N sensing node devices, where N is an even number that is not zero; The first sensing node device is used to acquire first abnormal information corresponding to the abnormal behavior data of the first sensing node device, and to acquire first abnormal information corresponding to the abnormal behavior data of other sensing node devices in the first sensing node cluster where the first sensing node device is located. The first sensing node device is any one of the N sensing node devices. The first sensing node device is further configured to determine the second abnormal information corresponding to the first sensing node cluster based on all the acquired first abnormal information, and to report the second abnormal information to the first aggregation node device associated with the first sensing node cluster. The first aggregation node device is used to send the second abnormal information reported by the first sensing node cluster to other aggregation node devices among the at least two aggregation node devices for abnormal identification, obtain the third abnormal information fed back by the other aggregation node devices, and transmit the third abnormal information to the first sensing node device in the first sensing node cluster associated with the first aggregation node. The first sensing node device is further configured to perform corresponding operations on the first sensing node device based on the received third abnormal information.

2. The abnormal behavior detection system according to claim 1, characterized in that, The abnormal behavior detection system further includes: at least three core arbitration node devices, any one of the at least three core arbitration node devices being associated with one of the at least two aggregation node devices; The first aggregation node device is further configured to upload the third abnormal information to the first core arbitration node device associated with the first aggregation node device when the third abnormal information indicates that the first sensing node device has experienced a preset behavior event. The first core arbitration node device is used to receive the third abnormal information, send the third abnormal information to other core arbitration node devices among the at least three core arbitration node devices for abnormal identification, obtain the fourth abnormal information corresponding to the first core arbitration node device and the other core arbitration node devices, and transmit the fourth abnormal information to the first aggregation node device. The first aggregation node device is also used to transmit the fourth abnormal information to the first sensing node device associated with the first aggregation node device; The first sensing node device is further configured to perform corresponding operations on the first sensing node device based on the received fourth abnormal information.

3. The abnormal behavior detection system according to claim 1 or 2, characterized in that, The first aggregation node device is specifically used to calculate the first weight corresponding to each of the at least two aggregation node devices, wherein the first weight is the sum of the initial weight of each aggregation node device and the weight of the core arbitration node device associated with each aggregation node device; and to determine the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device. In the event of a dispute over the abnormal information output by all of the at least two aggregation node devices, the abnormal information output by the target aggregation node device shall be identified as the third abnormal information.

4. The abnormal behavior detection system according to claim 1 or 2, characterized in that, The first sensing node device is specifically used to acquire abnormal behavior data of the first sensing node device, and to perform abnormal behavior detection on the abnormal behavior data of the first sensing node device to obtain the first abnormal information.

5. A method for detecting abnormal behavior, characterized in that, The system is applied to the abnormal behavior detection system as described in any one of claims 1-4, comprising: The first sensing node device in the abnormal behavior detection system acquires first abnormal information corresponding to the abnormal behavior data of at least two sensing node devices on one sensing node device, and determines second abnormal information based on all the first abnormal information. Based on the second abnormal information, at least two aggregation node devices in the abnormal behavior detection system perform consensus processing on the abnormal behavior data to obtain the third abnormal information. Based on the third abnormal information, the first sensing node device performs a corresponding operation on the sensing node device.

6. A consensus method, characterized in that, The method is applied to a consensus device, wherein the consensus device is applied to the abnormal behavior detection system as described in any one of claims 1-4, and the method comprises: Receive the second abnormal information sent by the first sensing node device; Calculate a first weight for each of the at least two aggregation node devices, where the first weight is the sum of the initial weight of each aggregation node and the weight of the core arbitration node device associated with each aggregation node; and determine the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device. In the event of a dispute over the abnormal information output by all of the at least two aggregation node devices, the abnormal information output by the target aggregation node device shall be identified as the third abnormal information.

7. The consensus method according to claim 6, characterized in that, The calculation of the first weight corresponding to each of the at least two aggregation node devices includes: Based on the location information of each of the at least two aggregation node devices in the abnormal behavior detection system and the initial weight of each aggregation node device, a directed weighted acyclic graph is generated. Based on the directed weighted acyclic graph, calculate the first weight corresponding to each of the at least two aggregation node devices.

8. A consensus device, characterized in that, include: The module consists of a receiving module, a processing module, and a determining module. The receiving module is used to receive the second abnormal information sent by the first sensing node device; The processing module is used to calculate a first weight corresponding to each of the at least two aggregation node devices, wherein the first weight is the sum of the initial weight of each aggregation node and the weight of the core arbitration node device associated with each aggregation node; and to determine the aggregation node device corresponding to the highest weight among the first weights as the target aggregation node device. The determining module is used to determine the abnormal information output by the target aggregation node device as the third abnormal information when there is a dispute over the abnormal information output by all aggregation node devices in the at least two aggregation node devices.

9. An electronic device, characterized in that, It includes a processor and a memory, the processor being coupled to the memory; the memory is used to store computer instructions, which are loaded and executed by the processor to enable a computer device to implement or the consensus method as described in claim 6 or 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions that, when executed on a computer, cause the computer to perform the abnormal behavior detection method as described in claim 5 or the consensus method as described in claim 6 or 7.

11. A computer program product, characterized in that, The computer program product includes a computer program that, when run on a computer, causes the computer to perform the abnormal behavior detection method as described in claim 5 or the consensus method as described in claim 6 or 7.