Smart city public facility supervision method based on Internet of Things

By using a spatiotemporal dynamic knowledge graph driven by multi-source data and an edge-cloud collaborative framework, the system solves the identification problem of smart city public facility monitoring systems when faced with diverse anomalies and zero-sample events. It achieves efficient and adaptive facility anomaly detection and early warning, improving the system's identification capabilities and early warning accuracy.

CN121582869APending Publication Date: 2026-02-27ZHONG KE SHU DONG GONG CHENG ZI XUN (GUANG ZHOU) YOU XIAN GONG SI
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511721623.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-21
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

Existing smart city public facility monitoring systems suffer from insufficient model generalization ability when faced with changes in facility status, environmental factors, and equipment materials. They struggle to cope with diverse anomalies, have weak zero-sample event recognition capabilities, and lack knowledge self-learning mechanisms, resulting in high false detection and false negative rates and an inability to effectively identify rare faults.

Method used

Employing a spatiotemporal dynamic knowledge graph driven by multi-source data, combined with an edge-cloud collaborative framework, and through entity embedding representation, structural similarity calculation, and causal relationship mining, it achieves zero-sample category inference and causal chain analysis for unknown faults, dynamically adjusts detection logic and early warning thresholds, and performs adaptive learning and optimization.

Benefits of technology

It significantly improves the ability to identify new and unknown anomaly patterns, reduces the false negative rate, improves the accuracy of early warning, enhances the risk prevention and control capabilities of the facility monitoring system, provides interpretable fault causal chain knowledge, and assists in operation and maintenance decision-making.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121582869A_ABST
    Figure CN121582869A_ABST
Patent Text Reader

Abstract

The invention discloses a smart city public facility supervision method based on the Internet of Things, and the method comprises the steps: carrying out the multispectral collection and space marking of a surface block of a to-be-detected circuit board, and achieving the standardized preprocessing and physical feature extraction of multi-label high-dimensional pixel data; according to the method, material spectral features and surface texture data are combined, a clustering analysis and supervision discrimination model is used for accurately discriminating the type of a block material, material attributes and multi-spectral features are fused, and pixel-level thickness prediction and dynamic adaptive correction are realized through a machine learning model. The system can automatically monitor drifting of the material and the mapping relation, and performs real-time optimization on the mapping model based on periodic calibration data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) facility monitoring technology, and in particular to a smart city public facility monitoring method based on IoT. Background Technology

[0002] Currently, smart city public facility monitoring systems play a crucial role in urban management, infrastructure safety, and efficient operation and maintenance. With the widespread adoption of large-scale Internet of Things (IoT) sensing terminals, the monitoring capabilities for the operational status of various urban public facilities (such as transportation, energy, and municipal services), the collection of environmental parameters, and the automatic early warning of abnormal events are continuously improving. Existing technologies widely employ multi-source sensing data interaction, streaming big data processing, and intelligent analysis models to achieve real-time monitoring and anomaly identification of facility operation status. Mainstream solutions are mostly based on end-to-cloud, edge-to-cloud, or even end-to-edge-to-cloud architectures, uploading raw device-level data to the cloud center. Anomaly detection and fault diagnosis are then performed using traditional statistical analysis, machine learning methods, or deep learning models, combined with expert knowledge feedback to achieve a preliminary closed-loop system for facility fault early warning.

[0003] In recent years, driven by industry trends, the intelligent monitoring of facilities has been continuously shifting from manual static rules to data-driven, model self-learning, and knowledge enhancement. Among these, entity modeling based on knowledge graphs, relationship mining, and multi-source semantic fusion have become important directions for promoting the intelligent expansion of infrastructure monitoring systems. With the introduction of advanced technologies such as graph neural networks, causal reasoning, and zero-shot learning, some systems have initially acquired the ability to structurally model anomalies of various types of facilities and the foundation for large-scale event tracing. This lays the technical foundation for improving the automation and intelligence level of facility management.

[0004] However, existing technical solutions still face the following prominent problems and technical shortcomings: (1) The model has limited generalization ability and insufficient dynamic adaptability. Traditional fault detection models rely on historical label data or predefined features, which makes it difficult to cope with the statistical distribution drift caused by changes in multidimensional conditions such as facility status, environmental factors, operating conditions and equipment materials, as well as the continuous evolution of diverse anomaly types. Once the fault distribution changes, existing models are prone to false detection and false negative detection, especially lacking effective response to newly emerging rare and unknown types of facility faults.

[0005] (2) Weak ability to identify zero-sample / small-sample events. When faced with novel anomalies with scarce data or very few labels, conventional data-driven methods are unable to generate high-confidence criteria, resulting in the inability to accurately represent and infer zero-sample (rare events that have never occurred) and to capture the early micro-features of rare faults.

[0006] (3) Lack of continuous knowledge evolution and self-learning mechanism. Existing systems generally fail to achieve long-term integration and dynamic adaptation of new data from multiple sources, expert feedback and model knowledge. The knowledge structure is rigid, the model upgrade cycle is long and the labor cost is high, which leads to the system responding slowly and making it difficult to achieve closed-loop optimization when facility structure and environmental conditions change rapidly. Summary of the Invention

[0007] In order to solve the above-mentioned technical problems, the present invention provides a smart city public facility monitoring method based on the Internet of Things.

[0008] The technical solution of this invention is implemented as follows: A smart city public facility monitoring method based on the Internet of Things, comprising: S1: Collect multi-source heterogeneous raw sensor data from different facility categories, structural locations, and material types, including equipment status, environmental parameters, operation and maintenance logs, and third-party event information, and attach timestamps and spatial positioning tags to establish a multi-dimensional data input set.

[0009] S2: Perform noise filtering, outlier removal and normalization preprocessing on the multi-dimensional data input set to eliminate data distribution differences caused by different facility structures, environmental backgrounds and sensor acquisition conditions, and generate a standardized feature stream.

[0010] S3: Based on the standardized feature flow, construct a spatiotemporal dynamic knowledge graph containing various entities and attribute edges such as facility entities, components, environmental events and operational behaviors, and express the differences in different facility structures and operating conditions through graph nodes and relationships.

[0011] S4: Input the standardized feature vectors of unlabeled or rare anomalies into the graph embedding model. Through entity embedding representation, structural similarity calculation and adjacency feature transfer, zero-sample class inference and analogy feature generation are performed for unknown faults to obtain zero-sample event feature vectors.

[0012] S5: Based on zero-sample event feature vectors and spatiotemporal dynamic knowledge graphs, it performs causal relationship mining and traceable causal inference algorithms to analyze the causal chains and difference factors between newly emerging anomalies and existing known events, and outputs rare anomaly causal chains.

[0013] S6: Simultaneously send the causal chain analysis results and zero-sample event feature vectors to the edge detection models, configure a low-latency streaming screening algorithm, and realize the rapid detection of sensitive abnormal micro-features in edge-cloud collaboration.

[0014] S7: Based on feedback from end-side and edge-side detection models and cluster analysis results, dynamically identify new local patterns caused by changes in facility structure, materials and operating conditions, and report the findings to the cloud for adaptive model evolution.

[0015] S8: Utilizes aggregated feedback and historical knowledge in the cloud to perform model self-distillation and self-adversarial continuous learning, optimizes the spatiotemporal dynamic knowledge graph structure and the zero-shot fault reasoning model, thereby improving the model's generalization and adaptability to facility status and environmental changes.

[0016] S9: In response to dynamic changes in facility status and environment, based on the updated model output and rare anomaly causal chains, adjust various detection and early warning dynamic threshold parameters in real time to achieve a long-term, efficient and adaptive early identification and early warning mechanism for facility anomalies.

[0017] S10: After completing the abnormal event warning, the warning event and analysis results are pushed to the operation and maintenance experts for feedback and annotation. Combined with the expert manual annotation, the knowledge graph and model label system are optimized to continuously and incrementally improve the zero-sample self-learning capability of rare facility failures.

[0018] This application provides a smart city public facility monitoring method based on the Internet of Things, which has the following beneficial effects: (1) Traditional IoT public facility monitoring systems mostly rely on static thresholds, experience-based or fixed model-based anomaly detection, which is difficult to adapt to the dynamic changes in facility environment and operating conditions. Their ability to identify rare faults that are unseen or have zero samples (no prior labels) is extremely limited, resulting in high false positive and false negative rates. To address this problem, this invention introduces a multi-source data-driven spatiotemporal dynamic knowledge graph, combined with a continuous self-learning framework that integrates edge-cloud collaboration. Through structured multi-dimensional entity modeling, dynamic relationship expansion, and embedded reasoning, it significantly improves the system's ability to represent, summarize, and identify novel, unknown, and even unlabeled rare anomaly patterns. Actual measurements show that in unknown sample environments, the detection rate of rare faults can be increased from 60%-75% in traditional systems to over 92%, greatly enhancing the risk prevention and control capabilities of smart city infrastructure monitoring systems.

[0019] (2) Most existing intelligent early warning solutions for public facilities suffer from static models, weak generalization, and difficulty in coping with environmental disturbances and the continuous evolution of heterogeneous facilities, leading to a gradual decline in detection sensitivity and early warning accuracy. This invention utilizes an edge-cloud layered collaborative mechanism to push model parameters and features down to the edge and end sides, enabling rapid preprocessing of real-time data and screening of abnormal micro-features. Edge nodes cluster new patterns in real time and upload them, while the cloud aggregates information and performs model self-distillation and self-adversarial continuous learning to continuously optimize the knowledge graph structure and inference model parameters. This mechanism can dynamically adjust the detection logic and early warning thresholds according to facility status and environmental changes, effectively resisting data distribution drift and "model forgetting," and maintaining a high level of early warning accuracy in the long term. In actual deployment, the false negative rate has decreased by 30% after long-term operation, and frequent manual tuning is not required.

[0020] (3) Traditional facility fault detection methods are almost impossible to work when there is a lack of labeled data, or when there are very few or never-before-seen new fault samples. This invention innovatively uses knowledge graph entity embedding, structural similarity calculation, and adjacency feature transfer to achieve zero-sample inference and analogical feature generation for unlabeled, rare, or even unknown abnormal samples. It also integrates meta-learning and transfer learning mechanisms to automatically construct event feature vectors, greatly breaking through the bottleneck of intelligent detection under the scarcity of samples. The ability to achieve the first-time identification of unlabeled new fault scenarios has great practical engineering value.

[0021] (4) Unlike traditional models that can only provide anomaly alarms without knowing the cause, this invention, through continuous causal chain mining, Bayesian inference, and multi-path probability weighting, can trace the causal relationship and evolution path of anomalies, outputting interpretable fault causal chain knowledge fragments. This effectively assists maintenance personnel in root cause localization and fault management, providing transparent and traceable decision support for city-level smart maintenance. The accuracy and operability of fault explanation are improved, significantly reducing mishandling and subsequent risks. Attached Figure Description

[0022] Figure 1 This is a flowchart illustrating a smart city public facility monitoring method based on the Internet of Things (IoT) according to the present invention. Figure 2 This is a sub-flowchart of a smart city public facility monitoring method based on the Internet of Things according to the present invention; Figure 3 This is a sub-flowchart of a smart city public facility monitoring method based on the Internet of Things according to the present invention. Detailed Implementation

[0023] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0024] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0025] When used herein, the singular forms of “a,” “an,” and “the” may also include the plural forms unless the context clearly indicates otherwise. It should also be understood that the terms “comprising / including” or “having,” etc., specify the presence of the stated features, wholes, steps, operations, components, parts, or combinations thereof, but do not preclude the possibility of the presence or addition of one or more other features, wholes, steps, operations, components, parts, or combinations thereof. Meanwhile, the term “and / or” as used in this specification includes any and all combinations of the associated listed items.

[0026] Please see Figures 1-3 As shown, a smart city public facility monitoring method based on the Internet of Things includes: S1: Collect multi-source heterogeneous raw sensor data from different facility categories, structural locations, and material types, including equipment status, environmental parameters, operation and maintenance logs, and third-party event information, and attach timestamps and spatial positioning tags to establish a multi-dimensional data input set.

[0027] S2: Perform noise filtering, outlier removal and normalization preprocessing on the multi-dimensional data input set to eliminate data distribution differences caused by different facility structures, environmental backgrounds and sensor acquisition conditions, and generate a standardized feature stream.

[0028] S3: Based on the standardized feature flow, construct a spatiotemporal dynamic knowledge graph containing various entities and attribute edges such as facility entities, components, environmental events and operational behaviors, and express the differences in different facility structures and operating conditions through graph nodes and relationships.

[0029] S4: Input the standardized feature vectors of unlabeled or rare anomalies into the graph embedding model. Through entity embedding representation, structural similarity calculation and adjacency feature transfer, zero-sample class inference and analogy feature generation are performed for unknown faults to obtain zero-sample event feature vectors.

[0030] S5: Based on zero-sample event feature vectors and spatiotemporal dynamic knowledge graphs, it performs causal relationship mining and traceable causal inference algorithms to analyze the causal chains and difference factors between newly emerging anomalies and existing known events, and outputs rare anomaly causal chains.

[0031] S6: Simultaneously send the causal chain analysis results and zero-sample event feature vectors to the edge detection models, configure a low-latency streaming screening algorithm, and realize the rapid detection of sensitive abnormal micro-features in edge-cloud collaboration.

[0032] S7: Based on feedback from end-side and edge-side detection models and cluster analysis results, dynamically identify new local patterns caused by changes in facility structure, materials and operating conditions, and report the findings to the cloud for adaptive model evolution.

[0033] S8: Utilizes aggregated feedback and historical knowledge in the cloud to perform model self-distillation and self-adversarial continuous learning, optimizes the spatiotemporal dynamic knowledge graph structure and the zero-shot fault reasoning model, thereby improving the model's generalization and adaptability to facility status and environmental changes.

[0034] S9: In response to dynamic changes in facility status and environment, based on the updated model output and rare anomaly causal chains, adjust various detection and early warning dynamic threshold parameters in real time to achieve a long-term, efficient and adaptive early identification and early warning mechanism for facility anomalies.

[0035] S10: After completing the abnormal event warning, the warning event and analysis results are pushed to the operation and maintenance experts for feedback and annotation. Combined with the expert manual annotation, the knowledge graph and model label system are optimized to continuously and incrementally improve the zero-sample self-learning capability of rare facility failures.

[0036] Step S1: Collect multi-source heterogeneous raw sensor data from different facility categories, structural locations, and material types, including equipment status, environmental parameters, operation and maintenance logs, and third-party event information, and attach timestamps and spatial location tags to establish a multi-dimensional data input set. Specifically, this includes: S1.1: Configure corresponding IoT terminal collection points for different facility categories to collect data on equipment operating status parameters (such as current, voltage, start / stop status, etc.) and obtain the corresponding raw equipment status data to form a subset of equipment status data.

[0037] IoT terminal collection points are configured for different facility categories to achieve high-precision collection of equipment operation status data for various types of public facilities. A facility type mapping rule is adopted to pair facility categories (such as streetlights, transformer boxes, elevators, water pumps, etc.) with suitable IoT terminal bodies. The terminal's standby communication function is activated based on the corresponding collection protocol, achieving on-demand activation and optimal power consumption control. For the paired terminals, a multi-channel physical quantity synchronous acquisition method is used to access and collect core equipment operation parameters, including current input. ,Voltage Start-stop status Active power ,frequency These, among others, form multidimensional original operating status signals.

[0038] For continuously operating parameters, time-synchronized sampling technology is used, and a uniform sampling frequency is defined. Synchronous triggering timing ensures that data collected from multiple terminals is stored in the database at the same time reference. Furthermore, through multi-channel data stream buffering and abnormal interruption monitoring algorithms, potential data loss, abnormal oscillations, and other signal anomalies are detected and filtered, with automatic rejection based on the following threshold detection formula: in, This is the current sampled value. This represents the historical average value of the facility during that period. Standard deviation is the confidence factor.

[0039] A data integrity verification protocol (such as CRC-32) is used to automatically insert checksums into the reported data packets, ensuring the accuracy and integrity of the raw device status data during network transmission. Furthermore, through an automatic device identification and tagging mechanism, each set of collected data is bound to its facility type, geographic coordinate code, terminal unique number, and other metadata, aggregating them by type to generate a preliminary subset of device status data. Through the aforementioned multi-channel, time-series synchronization, anomaly removal, and integrity verification processes, the raw collected signals are reliably transformed into a structured, traceable device operating status dataset, achieving high-quality operating status perception at the edge.

[0040] For example, in a municipal smart lighting system scenario, for three types of facilities—streetlights, tunnel lights, and park landscape lights—low-power LoRa gateway terminals (model XH-LD01), 485 bus-type acquisition terminals (model XH-TD02), and Zigbee self-organizing network-type sensor terminals (model XH-PKD03) are configured respectively. The sampling frequency is set. For each street light unit, parameters such as current, voltage, power, and start / stop status are collected in real time. For abnormal current readings, [the system / approach]... Outlier thresholds are detected in real time to eliminate data anomalies caused by power outages. Integrity of collected packets is verified using CRC-32 checksums, with an average packet loss rate of less than [percentage missing]. Each batch of collected data is labeled according to facility type and geographic identification number, ultimately forming three subsets of equipment status data, totaling a daily per-terminal amount. Each strip (1Hz×24h×60min×60s) has a complete traceability label. During a week-long trial run, the accuracy rate of equipment operation status monitoring reached [percentage missing]. This significantly improves the quality and reliability of the original equipment operation status data, providing a high-standard data foundation for subsequent knowledge graph modeling and abnormal event analysis.

[0041] S1.2: Deploy a high-precision environmental sensor array at a specific facility structure location to collect various environmental physical quantities such as temperature, humidity, air pressure, PM2.5, and noise, and obtain raw environmental parameter data to supplement the environmental parameters of the multi-source heterogeneous raw sensor data.

[0042] S1.3: Based on the material type of the facility, call on specialized intelligent sensing modules (such as fiber optic sensing and ultrasonic sensing) to continuously collect data on key material parameters (such as structural stress, corrosion, cracks, etc.) to obtain raw data on the material health status and enrich the descriptive capabilities of multi-source heterogeneous raw sensing data at the material level.

[0043] S1.4: Based on the automatic integration of facility operation and maintenance logs by the operation and maintenance system, including log text and operation code data such as preventive inspections, fault repairs, and remote operation history, the data is encoded and transformed into structured operation and maintenance log raw data, providing input for subsequent operation and maintenance behavior analysis.

[0044] S1.5: Connects to third-party event collection interfaces, accesses external event notification streams from security, meteorology, transportation, energy and other related systems, and extracts the original third-party event data after time synchronization through protocol parsing to expand the external event dimensions of multi-source heterogeneous original sensor data.

[0045] S1.6: Based on the data acquisition time and spatial location, a unified spatiotemporal annotation module adds a high-precision timestamp and spatial positioning label to each record to generate a multi-source heterogeneous raw sensor dataset with complete metadata attributes.

[0046] S1.7: Based on the multi-source heterogeneous original sensor dataset with attached metadata attributes, it is archived and saved in layers according to facility category, structural location and material type. Finally, a logically consistent, spatiotemporally aligned and traceable multi-dimensional data input set is generated as the input basis for subsequent standardized feature stream generation.

[0047] Step S2: Perform noise filtering, outlier removal, and normalization preprocessing on the multi-dimensional data input set to eliminate data distribution differences caused by different facility structures, environmental backgrounds, and sensor acquisition conditions, and generate a standardized feature stream. Specifically, this includes: S2.1: For the original sensor data from the location and material type of each facility structure in the multi-dimensional data input set, based on the time series consistency rules and signal denoising algorithms (such as bandpass filtering and wavelet denoising), noise signal separation operation is performed to obtain the preliminary purified multi-source original time series data, providing a lossless original basis for subsequent outlier detection.

[0048] The input consists of raw sensor data from the structural location and material type of each facility in the multi-dimensional data input set, covering raw time-series data streams such as equipment operation signals, environmental parameters, and material health signals.

[0049] A timing consistency determination method is adopted (parameter: sampling frequency). timestamp precision This enables timing alignment of sampling points for multiple channels of raw signal streams of the same type of facility structure or material, ensuring phase consistency of cross-terminal data under a unified time base.

[0050] Furthermore, through a bandpass filtering algorithm (parameter: target signal frequency band) , filter order This effectively suppresses low-frequency drift and high-frequency interference components in the original timing signal, eliminating unstructured noise introduced by extreme environments or equipment electromagnetic interference.

[0051] Furthermore, wavelet denoising is employed (parameters: wavelet basis dbN, decomposition level). (Threshold function type) performs multi-scale decomposition on health signals of complex facility structures and materials, such as ultrasound or stress signals, analyzes the energy distribution of each frequency band of the signal, and uses threshold functions to perform nonlinear denoising on the noise-dominant coefficients to improve the identifiability of weak anomalies in the signal.

[0052] Furthermore, through a noise adaptive identification algorithm (parameter: noise estimation window) Threshold It dynamically detects and marks segments of severe jitter or signal distortion during sampling, and adjusts filtering parameters in real time to cope with sudden changes in distribution, ensuring that lossless structural signals can still be output in highly dynamic environments.

[0053] Through the above chain-like noise reduction process, the processed signal stream is recovered into preliminary purified multi-source raw time-series data with consistent timing, noise suppression, and amplitude fidelity, providing a high-fidelity foundation for subsequent outlier detection and feature normalization processing.

[0054] For example, in a health monitoring scenario for urban underground utility tunnel facilities, fiber optic strain sensors (FBG model: FBG-GL20) are deployed every 20m along the longitudinal direction inside a 1.6km long steel structure utility tunnel span, and the sampling frequency is [not specified]. The strain timing signal was collected, and simultaneously, current ambient noise sensing signals from points at the same distance were acquired. Signal preprocessing employed a bandpass filter, and settings were... for Hz, filter order This method effectively suppresses power frequency and vibration noise from underground power equipment in real time. Further decomposition using Daubechies-4 wavelet (db4) is employed to refine the decomposition hierarchy. A soft threshold function is used to automatically detect noise distribution and filter out high-frequency spurious signals. An adaptive noise identification algorithm is applied to set the noise estimation window. Point, threshold Customized progressive filtering was applied to the spike intervals in the signal sequence. After purification, the root mean square (RMS) of the daily time-series noise of a single fiber decreased from 0.022 to 0.004, while maintaining signal integrity and fidelity. The total daily data volume was approximately... The results provided an accurate and reliable source signal for subsequent detection of rare microcrack anomalies, effectively improving the sensitivity and accuracy of health and safety assessments of utility tunnel facilities.

[0055] S2.2: Using the original time-series data from multiple sources after noise signal separation as input, the system applies distributional statistical algorithms and multivariate robust discrimination (such as IQR method and multivariate anomaly detection based on Mahalanobis distance) to identify and remove outliers that exceed the equipment operating boundary threshold or do not conform to the facility operating condition distribution characteristics, thereby outputting clean time-series data after outlier removal, achieving consistent data filtering under diverse facility operating environments.

[0056] S2.3: For the clean time series data after outlier removal, a normalization method (such as z-score normalization, min-max scaling) is adopted. For different facility structures, materials and environmental backgrounds, the features of various sensors are uniformly scaled to the dimensionless range according to the dimensional standard to eliminate the scale error between sensor types and acquisition conditions, form a normalized feature matrix and retain the original structure label.

[0057] S2.4: Align the normalized feature matrix with the original spatial positioning labels and timestamp information, and apply spatiotemporal correction algorithms (such as sliding window temporal completion and spatial consistency interpolation) to achieve alignment mapping of various feature data with different acquisition frequencies and sampling points on the same time axis and spatial axis, outputting a structured and standardized feature stream to support data synchronization analysis across facility entities.

[0058] S2.5: Based on the structured and standardized feature stream, a multi-dimensional field screening mechanism is used to perform the final round of quality control and integrity assessment (such as feature missing rate index and sampling point completeness detection). Unit data with potential defects or samples that fail verification are repaired or removed. Finally, a highly complete and highly consistent final standardized feature stream is generated, providing strict data input guarantee for knowledge graph modeling and subsequent zero-sample event feature generation.

[0059] Step S3: Based on the standardized feature flow, construct a spatiotemporal dynamic knowledge graph containing various entities and attribute edges, such as facility entities, components, environmental events, and operational behaviors. The differences in facility structures and operating conditions are modeled and expressed through graph nodes and relationships. For example... Figure 2 As shown, it specifically includes: S3.1: Perform entity and attribute classification processing on the standardized feature flow to obtain an original multidimensional entity set containing facility entities, component entities, environmental event entities, and operational behavior entities. This entity set serves as the node foundation for the subsequent spatiotemporal dynamic knowledge graph, ensuring a complete and structured representation of core business objects.

[0060] S3.2: For the categorized multidimensional entity set, perform a relationship extraction algorithm based on the logical and physical connections between entities to generate attribute edges for facility structure relationships, component affiliation relationships, environmental impact relationships, and operational behavior link relationships. Using facility entities, component entities, environmental event entities, and operational behavior entities as start and end nodes, build the foundation for multi-type attribute edges for the knowledge graph.

[0061] The input is a categorized set of multidimensional entities, including facility entities, component entities, environmental event entities, and operational behavior entities extracted from the standardized feature stream.

[0062] An entity relationship candidate generation method (parameters: entity category, attribute features, physical structure hierarchy) is adopted to achieve the combined mining of logical connections and physical membership relationships between entities in a multidimensional entity set.

[0063] Furthermore, by using a facility structure analysis algorithm based on label reduction (parameters: facility structure template library, entity node attributes, facility hierarchy division rules), the structural relationships between facility entities are extracted, and structural relationship attribute edges from facility entities to key component entities are generated.

[0064] Furthermore, by using a component affiliation identification algorithm (parameters: component affiliation constraint, structural connection matrix, disassembly and assembly sequence encoding), the subordinate boundary between the component entity and the facility entity to which it belongs is determined, and the component affiliation attribute edge is output.

[0065] Furthermore, through an environmental impact relationship reasoning algorithm (parameters: environmental feature impact factor, event entity spatial distance threshold, entity interaction time window), the impact relationship between environmental event entities and facility and component entities is identified, and environmental impact relationship attribute edges are generated.

[0066] Furthermore, by using an operation behavior link relationship extraction algorithm (parameters: operation log sequence, behavior sequence constraint, causal triggering rule), chain relationship modeling is performed between operation behavior entities, operation behavior link relationship attribute edges are generated, and multi-dimensional operation behaviors are integrated into the facility and event node chain.

[0067] Through the aforementioned relation extraction and attribute edge generation algorithms, the facility structure relationships, component affiliation relationships, environmental impact relationships, and operational behavior link relationships within the multidimensional entity set are systematically modeled. This establishes a multi-type attribute edge with facility entities, component entities, environmental event entities, and operational behavior entities as starting and ending nodes, providing a structured association foundation for the subsequent spatiotemporal semantic construction and causal chain reasoning of the knowledge graph.

[0068] For example, in a smart monitoring scenario for urban underground utility tunnels, the input is a standardized set of facilities, components, environmental events, and operational behaviors. Facility entities include "tunnel A," component entities include "smart valve S1" and "strain sensor FBG01," environmental event entities include "groundwater level rise," and operational behavior entities include "automatic inspection command" and "remote valve closure." A facility structure analysis algorithm is used, applying a structural template library to compare "tunnel A" and "smart valve S1," generating structural relationship attribute edges for "tunnel A - contains - smart valve S1." Based on component affiliation determination, "affiliation" attribute edges are extracted between "strain sensor FBG01" and "tunnel A." For the environmental event "groundwater level rise," its impact on the facilities and key components within the jurisdiction is determined using spatial distance and impact time windows, generating attribute edges for "groundwater level rise - impact - tunnel A" and "groundwater level rise - impact - smart valve S1." By extracting operational behavior chain relationships, attribute edges of "automatic inspection command - trigger - remote valve closure" are generated for the "automatic inspection command - trigger - remote valve closure" in the operation log through causal triggering rules. In real-world scenarios, after the above relationship extraction, approximately 1200 structural relationship attribute edges, over 600 membership relationships, about 90 environmental impact relationships, and about 1000 operational behavior chain relationships can be generated per 1km of typical utility tunnel. This supports subsequent global association modeling and anomaly causal chain discovery in the knowledge graph, enabling the semantic expression of complex systems with full coverage of facility structure and full flow of events and behaviors.

[0069] S3.3: Perform spatiotemporal label association processing on entity nodes and attribute edges, map and assign timestamps and spatial positioning information in the original feature stream to relevant entity nodes and relational attributes, so as to obtain a spatiotemporal dynamic knowledge graph skeleton with time sequence attributes and spatial positioning attributes, and realize the spatiotemporal semantic explicit expression of the entire process of facility operation and event evolution.

[0070] S3.4: For the spatiotemporal dynamic knowledge graph skeleton with a preliminary structure, a heterogeneous data fusion algorithm is adopted to continuously and dynamically integrate the newly flowing standardized feature streams into new nodes, new relationships and attribute increments, ensuring that the knowledge graph can be expanded and updated in real time with the facility status and operating conditions, and improving the system's ability to generalize the expression of diverse facility structures and evolutionary features.

[0071] The input consists of a spatiotemporal dynamic knowledge graph skeleton with a preliminary structure, and a standardized feature stream that is newly flowing in in real time, including structured data of facility entities, components, environmental events, and operational behaviors.

[0072] Heterogeneous data fusion algorithm is adopted (parameters: entity type management table, relation attribute set, incremental fusion window). Fusion consistency threshold This allows for type discrimination and entity matching operations between newly incoming standardized feature streams and existing knowledge graph skeletons. It also enables uniqueness retrieval and attribute comparison of entities in the feature streams to determine whether new entity nodes need to be added.

[0073] Furthermore, a dynamic incremental modeling algorithm for structural relationships is used (parameters: structural hierarchy rules, relationship extraction template, minimum support frequency). This allows for incremental relationship extraction of newly generated facility structure relationships, component affiliation relationships, environmental association attributes, and operational behavior links in the standardized feature flow, and the identification and supplementation of structural and behavioral edges not covered in the preceding knowledge graph.

[0074] Furthermore, an entity attribute differential update algorithm (parameters: attribute change monitoring list, historical attribute snapshot, attribute conflict resolution strategy) is adopted to perform attribute incremental merging and conflict determination on entity nodes in the newly flowing feature stream that have some attribute differences with existing nodes or newly added attributes, thereby realizing real-time + historical data fusion at the attribute level.

[0075] Furthermore, the spatiotemporal consistency incremental expansion method is applied (parameter: new sample time window). spatial regions Mapping drift detection threshold For feature stream data from new geographical regions, time periods, or special operating conditions, new nodes and relationships are synchronously extended to the knowledge graph according to spatiotemporal labels, dynamically supplementing the facility operation environment and evolution boundaries that are not yet covered.

[0076] Furthermore, a knowledge graph integrity maintenance mechanism is adopted (parameter: node integrity check cycle). The system employs a relationship consistency verification strategy to perform incremental consistency and closed-loop checks on the fused knowledge graph structure. For nodes or edges with issues such as topological breaks or isolated attributes, it triggers self-healing rules for repair or requires marking and maintenance, ensuring the system's generalization ability for global expression and the stability of data growth.

[0077] Through heterogeneous data fusion algorithms and dynamic incremental modeling, the spatiotemporal dynamic knowledge graph skeleton obtained in the previous step is continuously expanded into a full knowledge graph with the latest facility structure status, component relationships, environmental behavior and dynamic attributes. This enables generalized and unified modeling of diverse facility structures, multi-source operating conditions and operational evolution, supporting the complex knowledge representation of subsequent zero-shot event reasoning and causal chain discovery.

[0078] For example, in the scenario of intelligent monitoring of urban subway tunnels, the constructed knowledge graph skeleton covers 200 facility entities, including the main tunnel section, communication shafts, and ventilation rooms, and is associated with 500 key components and 2,800 structural and behavioral edges. Newly inflowing standardized feature streams include newly deployed high-speed rail security gates (entity type: security equipment). The security equipment is matched with existing facility entities through a type management table. Since no corresponding node exists, it is determined to be a newly added security equipment node and added to the graph. The structural association between the new security gate and "Section A of Zone 3" is extracted using a dynamic incremental modeling algorithm to extract the "containment" attribute and establish structural relationship edges in the knowledge graph. Attribute differential detection reveals that the "remote switch log frequency" attribute of the new security gate is a new item, which is merged into the node after attribute differential fusion. Within 7 days of the new security gate's deployment, 3 significant security events occurred. These events and the security gate node are dynamically added to the knowledge graph using a spatiotemporal label (2024-02-18, security checkpoint on the east side of Beijing East Railway Station), with environmental event nodes being included simultaneously. Consistency checks revealed that some attributes of the new nodes were initially missing. These were dynamically filled in by automatically scheduling data collection tasks. The coverage of the knowledge graph increased from 95% of the initial facility categories to 98.6%. The newly added dynamic structure and attribute relationships provided spatiotemporal full data support for subsequent anomaly reasoning and event attribution.

[0079] S3.5: Based on a dynamic incremental spatiotemporal knowledge graph, autonomous rules are generated and entity / attribute abstraction and standardization are performed on the differences in different facility structures and operating conditions. This forms a graph node system that can express multi-dimensional knowledge of facility structure hierarchy, functional modules, operation sequences and environmental linkages. This provides a unified, standardized and scalable basic knowledge carrier for subsequent zero-sample anomaly reasoning, causal chain mining and model adaptive evolution.

[0080] Step S4: Input the standardized feature vectors of unlabeled or rare anomalies into the graph embedding model. Through entity embedding representation, structural similarity calculation, and adjacency feature transfer, zero-shot class inference and analogy feature generation are performed for unknown faults to obtain zero-shot event feature vectors. Figure 3 As shown, it specifically includes: S4.1: For the standardized feature vectors of unlabeled abnormal samples selected from the standardized feature stream, data adaptation and consistency processing are performed with the facility spatiotemporal dynamic knowledge graph as the context to ensure the consistent mapping relationship between the feature vectors and the attributes of the knowledge graph entity nodes, and to achieve accurate docking of the feature vectors with the knowledge graph entities.

[0081] For the standardized feature vectors of unlabeled abnormal samples selected from the standardized feature stream, the data adaptation mapping method (parameters: feature vector dimension, entity node attribute set, attribute mapping rule) is used as the context to realize the dimensional and semantic consistency check between the standardized feature vectors and the entity node attributes of the knowledge graph.

[0082] Furthermore, an attribute consistency correction algorithm is used (parameters: feature distribution statistics, attribute data type, tolerance threshold). The distribution consistency analysis is performed on the input feature vector and the attribute values ​​of the target entity node to check the consistency of elements such as feature value range, data type and unit system. For samples with abnormal offset or dimension mismatch, attribute remapping and normalization correction based on the minimum error criterion are performed to obtain the feature mapping set that has been normalized at the attribute level.

[0083] Furthermore, a unique identifier matching mechanism for entity nodes is adopted (parameters: node ID rules, spatiotemporal tag index). Spatial coordinate mapping The normalized feature vectors are mapped to the corresponding facility entities, component entities, environmental event entities, or operational behavior entities in the knowledge graph based on the entity uniqueness constraint, so as to achieve one-to-one or many-to-one precise docking between feature vectors and target nodes in the graph.

[0084] Furthermore, the context attribute completion algorithm is applied (parameter: context window width). (Graph entity adjacency relationships, historical attribute snapshots) To address the issue of local missing or incomplete attribute coverage in the input feature vector, the standardized feature vector is locally augmented by retrieving historical attribute snapshots of the same entity node or the attribute mean of neighboring entities, ensuring the completeness of the attribute vector dimension of the projected entity node.

[0085] Through the above-mentioned multi-level data adaptation and consistency processing, a multi-dimensional consistent mapping is established between the standardized feature vectors of abnormal samples and the entity node attributes in the spatiotemporal dynamic knowledge graph of the facility. This achieves accurate matching of the original feature vectors with the entities in the knowledge graph, providing a high-confidence data foundation for subsequent graph embedding and structural similarity modeling.

[0086] For example, in the scenario of intelligent monitoring of urban underground utility tunnels, for newly emerging unlabeled abnormal samples, their standardized feature vectors contain 20 dimensions, including electrical faults, environmental disturbances, and stress changes. The feature value range is normalized to [0,1], and the attribute units are uniformly dimensionless. The data adaptation mapping method takes "Pipe Tunnel Section A - Strain Sensor S1" as the target entity node. Based on the node attribute template, it requires that dimensions 1-5 of the feature vector be mapped to the strain sensor type, dimensions 6-10 correspond to temperature and humidity parameters, and the remaining parts correspond to the equipment on / off status and environmental anomaly labels. Attribute consistency correction compares the standardized feature values ​​with the statistical intervals defined by the node attributes, finding that the values ​​of dimensions 8-10 deviate slightly from the historical intervals of Pipe Tunnel Section A. Normalization and recalibration based on the historical sample mean are performed to correct for discrepancies. Entity node unique identifier matching is achieved using node ID=GRAA-STR01, spatiotemporal label 2024-06-30 16:00:00, and coordinates (39.90, 116.47) to map the feature vector to a specific entity. Context attribute completion is performed to imputate missing fields at feature dimensions 11 and 17 using the average of the attribute snapshots from the previous 24 hours for the same node, ensuring the completeness of 20-dimensional attributes. Finally, a precise 20-dimensional attribute vector for the knowledge graph node "Pipe Gallery A Section - Strain Sensor S1" is generated, achieving the data consistency threshold. This processing achieves a mismatch rate of less than 0.3% and a feature matching accuracy of over 99%, providing high-quality input data for subsequent graph embedding and anomaly inference.

[0087] S4.2: Based on the standardized feature vectors after data adaptation, use graph embedding models (such as entity embedding algorithms based on graph neural networks) to perform high-dimensional embedding representations of each entity in the knowledge graph, so as to obtain entity embedding vectors containing composite spatiotemporal attributes such as facility structure, parts, and environmental events, and realize the initial conversion of the original feature vectors into knowledge graph entity embedding vectors.

[0088] The input consists of standardized feature vectors of unlabeled abnormal samples after data adaptation and attribute consistency correction, and the set of attribute nodes of the constructed spatiotemporal dynamic knowledge graph of facilities.

[0089] A graph embedding model (parameters: graph neural network type GNN, embedding dimension d_e, entity attribute matrix A, entity adjacency relation matrix Adj) is employed to achieve high-dimensional feature encoding of each entity node in the knowledge graph. Specifically, the normalized feature matrix after mapping and the attributes of the corresponding entity node are input, and a method based on graph convolutional networks (such as GCN, GraphSAGE, or GAT) is used to embed the entity and its neighborhood structure information layer by layer. The graph convolutional kernel aggregates the attributes of adjacent entities at the node level and generates an initial entity embedding vector through normalized weighted superposition by nonlinear activation units.

[0090] Furthermore, through a node feature interaction mechanism (parameters: number of graph convolutional layers L, normalization strategy norm_type, edge weight coefficient α), node self-loops and relational edge weights are introduced in each convolutional layer to realize the spatiotemporal feature topology transfer of entity nodes and their neighboring nodes, thereby obtaining a hierarchical embedding vector containing complex spatiotemporal associations such as facility structure, components, and environmental events.

[0091] Furthermore, a multimodal attribute fusion algorithm (parameters: structural domain features, environmental domain features, behavioral domain features, fusion weight λ) is used to weight and fuse the embedding results of entity nodes in the multimodal feature domains of facility structure, environmental events and operational behavior, thereby improving the representation ability of entity vectors in multi-domain attribute expression and preventing embedding representation shift caused by the lack of single-modal feature information.

[0092] Furthermore, a normalization and projection mechanism (parameters: embedding normalization method, such as L2 normalization, principal component projection matrix P) is adopted to uniformly scale all entity embedding vectors to a standardized vector space, eliminating the embedding scale differences between different entity categories, which facilitates subsequent structural similarity calculation and zero-sample class inference.

[0093] Through the above-mentioned embedding modeling, multimodal attribute fusion, and normalization processing, the original standardized feature vectors are transformed into high-dimensional composite embedding vectors of knowledge graph entity nodes, realizing entity feature expression with advantages of multidimensional spatiotemporal and attribute structure representation.

[0094] For example, in the scenario of smart substation facility monitoring in urban rail transit, for the standardized feature vector (24-dimensional in length) of unlabeled abnormal events after attribute matching and normalization, a graph neural network embedding model (GCN type, embedding dimension d_e=128) is adopted, with the current set of facility-component-environment-operation entity nodes and their adjacency matrix as input. During each layer of graph convolution, the node feature self-loop weight α=0.2 is set, and the number of convolution layers L=3. Through three layers of graph convolution, the attribute vectors of facility structure domain neighbors, environmental event domain neighbors, and related operation behavior domain neighbors under the same spatiotemporal label are fused. After the convolution output, the embedding result is processed using L2 normalization. For a single node "Substation E01-High Voltage Circuit Breaker A", the feature weights λ before and after fusion convolution are 0.45 for the structure domain, 0.35 for the environment domain, and 0.2 for the operation domain. Ultimately, the abnormal event node obtained a 128-dimensional unified normalized embedding vector. In the entire knowledge graph entity embedding space, the structural domain distance distinguishability with known historical fault nodes was improved by 24%. The embedding vector distribution has good structural separability, providing highly adaptable input for subsequent structural similarity calculation and zero-shot inference process.

[0095] S4.3: Continuously perform structural similarity calculations on the obtained entity embedding vectors. By comparing the similarity measure between the entity embedding vector to be identified and the embedding vectors of existing fault type entities in the knowledge graph, a structural similarity score vector is generated to reflect the degree of structural association between the abnormal event to be identified and the known event.

[0096] S4.4: Based on the structural similarity score vector, further feature transfer is performed on the adjacency relationship of the knowledge graph. An adjacency feature diffusion algorithm based on entity attributes and relation edge weights is adopted to transfer the relevant representation information of the embedding vectors of adjacent entities to the sample to be identified, thereby strengthening the analogical reasoning characteristics of abnormal events and obtaining analogical feature vectors optimized by neighborhood induction.

[0097] S4.5: Based on the analog feature vector generated by adjacency feature propagation, the structural similarity score and temporal and spatial label information are fused together to execute a zero-shot class inference algorithm (such as meta-learning inference). The class assignment probability of unlabeled anomalies is calculated and labels are generated. The zero-shot event feature vector containing the class inference results, the induction vector and the mapping relationship between the knowledge graph are output, providing input for subsequent causal chain analysis.

[0098] Step S5: Based on the zero-sample event feature vector and spatiotemporal dynamic knowledge graph, perform causal relationship mining and traceable causal inference algorithms to analyze the causal chain and difference factors between newly emerging anomalies and existing known events, and output the causal chain of rare anomalies. Specifically, this includes: S5.1: Perform similarity and association retrieval on the zero-sample event feature vector and the entity nodes and attribute relationships in the spatiotemporal dynamic knowledge graph. Use a structured embedding algorithm to generate cross-entity structural similarity measurement results between the input zero-sample event feature vector and known historical events to obtain potential causal association candidate groups.

[0099] S5.2: Based on the causal association candidate groups obtained by similarity and correlation retrieval, the multi-modal heterogeneous relation flow screening algorithm is applied to perform temporal dependency decoupling processing on the event pairs and relation edges in the candidate groups, screen out high-probability causal relationships with temporal antecedent-effect patterns in the spatiotemporal dynamic knowledge graph, and generate a temporalized causal event chain base set.

[0100] S5.3: For the basic set of time-series causal event chains, with Bayesian network structure search and traceable causal inference algorithm as the core, Bayesian causal structure modeling is performed on the probabilistic dependency relationship between each event node, outputting the posterior probability distribution of each causal path, and obtaining a multi-path probability weighted causal relationship network.

[0101] The input is a set of time-series causal event chains generated after filtering by multimodal heterogeneous relation flows and decoupling of time-series dependencies. It contains multiple abnormal event nodes and their attribute relationships arranged in causal order.

[0102] A Bayesian network structure search algorithm is used (parameter: set of causal event chain nodes). Candidate relation edge set Maximum in-degree constraint Scoring function This enables modeling of the possible probabilistic dependency structure between abnormal event nodes within the basic set.

[0103] Furthermore, Bayesian structure search methods based on greedy search, heuristic search, or MCMC sampling are used (parameter: search step size). Structural scoring criteria Number of samplings This involves exploring the temporally ordered causal event chain structure space to obtain the optimal event-causal structure topology. It also outputs a structural optimality score.

[0104] Furthermore, for a given Bayesian network structure, a Bayesian parameter learning algorithm is applied (parameters: prior distribution). Event observation samples (Maximum likelihood or maximum a posteriori criterion) for the conditional probability distribution of each event node. Estimate the probability of causal paths based on the frequency of observations and the prior probability of rare events.

[0105] Furthermore, for all causal paths in the Bayesian model structure Using the joint probability chain quadrature formula, the posterior probability distribution of each path is calculated: in, For path The number of event nodes included. For the first on the path Each event node It is the set of its direct cause nodes.

[0106] Furthermore, by employing a Bayesian posterior weighting method, multi-path probability weighting is applied to all reachable event node-path sets to generate a causal relationship network that encapsulates the probability distributions of multiple types of causal paths. Output the joint probability matrix between nodes. .

[0107] Through the above-mentioned Bayesian causal structure modeling, parameter learning, and multi-path probability weighting, the continuous temporal anomaly event chain is transformed into an accurate multi-path probabilistic causal relationship network, thereby realizing the conditional probability quantification and causal relationship probability enhancement of the facility anomaly evolution path.

[0108] For example, in the scenario of abnormal monitoring of power facilities in a smart subway, the basic set of nodes for the time-series causal event chain is... The relationships are, in order: "water leakage detection," "cable insulation degradation," "abnormal local temperature rise," and "short-term power supply failure," with the following boundary sets. Obtained through prior reasoning and observation. A Bayesian network structure is used for search, maximizing the in-degree. The scoring function uses the BIC criterion and greedily traverses all structural combinations to find the optimal network structure. Bayesian parameter learning uses prior observations of rare historical events at each node. ,sample The co-occurrence frequency of "water leakage detection" and "cable insulation degradation" is 23%, the posterior probability of "insulation degradation" and "abnormal temperature rise" is 18%, and the probability of "abnormal temperature rise" leading to "short-term failure" is 9%. Using the joint probability formula... All links are weighted by probability, outputting a multi-path joint probabilistic causal network with 4 nodes and 3 paths, and the joint probability matrix between nodes. The structure is sparse, and the posterior probability of highly rare anomaly event chains is 0.4%-2.6%. When the above network structure is applied to the subsequent key factor identification and automatic generation of causal chain knowledge fragments, it effectively realizes the dynamic inference and quantitative expression of the implicit probability structure of facility anomaly causal chains under the condition of very few historical unknown event samples, significantly improving the sensitivity of early rare anomaly warning and the system's generalization ability.

[0109] S5.4: Utilize a multi-path probability weighted causal relationship network to identify key factors of rare and abnormal causal chains. Based on graph theory centrality analysis and the principle of maximum information gain, extract a set of causal chain difference factors that are different from existing known patterns, forming the unique causal structure features of this zero-sample event.

[0110] S5.5: Combine the set of causal chain difference factors with a multi-path probability weighted causal relationship network, and use a structural interpretability generation algorithm to automatically output rare and abnormal causal chain knowledge fragments containing event nodes, attribute edges and key factors as the final output of this step, and provide a traceable causal explanation basis for subsequent early warning, manual annotation and knowledge graph incremental improvement.

[0111] Step S6: The causal chain analysis results and zero-sample event feature vectors are simultaneously sent to the edge and endpoint detection models, and a low-latency streaming screening algorithm is configured to achieve rapid detection of sensitive anomalies and micro-features through edge-cloud collaboration. Specifically, this includes: S6.1: Based on the causal chain analysis results output from the cloud, a structured data encapsulation protocol is used to uniformly format the causal chain attribute vector and the feature vector of the zero-sample event to generate a causal chain synchronization data packet that can be parsed by the edge model and the end-side model.

[0112] S6.2: Perform multi-level encryption and communication protocol adaptation on the causal chain synchronization data packet, including TLS / SSL encryption and edge node authentication, to achieve high-security distribution of the causal chain synchronization data packet between the cloud and edge nodes and terminal nodes, thereby ensuring the secure transmission of sensitive feature information of the facility.

[0113] The causal chain synchronization data packet, which is the standardized output of the structured data encapsulation protocol, is used as the input object. The data packet contains sensitive information such as causal chain attribute vector, zero-sample event feature vector, and time-space labels.

[0114] A multi-level encryption method (parameters: TLS / SSL protocol version, key length, encryption algorithm type) is employed to achieve layered encryption processing of causal chain synchronization data packets. TLS / SSL encryption is used as the basic encryption layer to encrypt the entire data packet content end-to-end, preventing man-in-the-middle interception and tampering during data transmission.

[0115] Furthermore, the session key negotiation algorithm (parameters: ECDHE key exchange, RSA public key length) is used to establish encrypted tunnels between the cloud and edge nodes and terminal nodes, enabling dynamic key distribution on different communication links and ensuring key security and transmission link isolation.

[0116] Furthermore, a data integrity verification algorithm (parameters: SHA-256 / 512 hash algorithm, message authentication code MAC) is applied to generate a unique integrity verification code for each encrypted data packet, which is transmitted along with the data packet. Edge nodes and terminal nodes perform hash verification before decryption to confirm that the data has not been tampered with or lost during transmission.

[0117] Furthermore, a communication protocol adaptation mechanism is configured (parameters: MQTT / TCP, HTTP / 2, CoAP protocol switching, priority parameters, reliability and error verification strategies) to select the appropriate transmission protocol for the diverse IoT communication environments of edge nodes and terminal nodes, and automatically switch protocols according to data packet type to improve transmission compatibility and real-time robustness.

[0118] An edge node authentication algorithm (parameters: X.509 certificate mechanism, device public key, digital signature verification) is used to authenticate edge nodes and terminal nodes that receive causal chain synchronization data packets, deny unauthorized device access, and ensure that sensitive feature information is distributed only in a legitimate and trusted environment.

[0119] By employing a multi-level encryption, identity authentication, and communication protocol adaptation technology chain, the causal chain synchronization data packets output from the cloud are distributed to edge nodes and terminal nodes with high security, enabling the secure distribution of sensitive facility characteristic information and effectively ensuring the confidentiality, integrity, and access control during data transmission.

[0120] For example, in a smart monitoring scenario for urban highway tunnels, the cloud-based TLS 1.3 protocol is configured for the output causal chain synchronization data packets, with a 256-bit AES-GCM encryption algorithm as the encryption layer. Edge nodes establish secure connections via ECDHE key exchange and a 128-bit elliptic curve public key. Each data packet generates a 64-byte message authentication code based on the SHA-256 algorithm and is transmitted accordingly. The communication protocol automatically switches between MQTT and HTTP / 2 according to the edge node's network environment, with a protocol switching latency of less than 30ms. Edge devices load X.509 standard digital certificates for authentication, automatically blocking unauthorized access requests. Under this configuration, the average end-to-end transmission latency of the causal chain synchronization data packets is less than 50ms, the data packet decryption success rate reaches 100%, and there are no man-in-the-middle attacks or information leaks, meeting the industry's high security and real-time monitoring requirements. This achieves secure distribution of sensitive features of the causal chain, ensuring a basic trust environment for the system to collaboratively detect and provide early warnings of rare abnormal events.

[0121] S6.3: Within the end-side model and edge-side model, a streaming small-sample anomaly detection algorithm data input queue is constructed based on the causal chain attribute vector and zero-sample event feature vector that have been synchronized locally, providing a real-time anomaly representation benchmark for the low-latency micro-feature screening algorithm.

[0122] S6.4: Apply short-window streaming data processing technology to perform feature space mapping and similarity matching on the real-time standardized feature stream collected from the end side with the causal chain attribute vector and zero-sample event feature vector, and perform micro-feature dynamic capture to output the detection results of suspected rare abnormal events in real time.

[0123] S6.5: Utilizing the model parameter sharing mechanism of the edge node cluster, online distribution consistency assessment is performed on the results of suspected rare abnormal events and the original causal chain attribute vector and zero-sample event feature vector. Adaptive triggering of local anomaly clustering and correlation feedback is achieved, and high-confidence detection results are simultaneously uploaded to the cloud to optimize the global model.

[0124] Step S7: Based on the feedback from the end-side and edge-side detection models and the clustering analysis results, dynamically identify novel local patterns caused by changes in facility structure, materials, and operating conditions, and report this discovery to the cloud for model adaptive evolution. Specifically, this includes: S7.1: Perform protocol standardization parsing on the abnormal event feature vectors output by the end-side detection model and the real-time clustering results on the edge side to obtain the original feedback data set for changes in facility structure, material, and operating parameters, which will be used as input for subsequent clustering algorithms.

[0125] S7.2: Based on the acquired original feedback data set, an incremental clustering algorithm (such as DBSCAN, Mini-Batch K-means, etc.) is used to perform high-frequency local clustering analysis on the abnormal event feature stream to automatically generate heterogeneous data clusters representing the evolution of abnormal patterns, thereby realizing the normalized expression of multidimensional features of abnormal events.

[0126] S7.3: For each data cluster representing the evolution of abnormal patterns, use multi-scale evaluation indicators such as statistical distribution mapping and structural variation measurement to screen and quantify new patterns caused by sudden changes in facility structure, material or operating conditions, extract core descriptive parameters of local patterns, such as suddenness, persistence, local correlation, etc., and form new local pattern identifiers.

[0127] For each data cluster representing the evolution of anomaly patterns, the input data is a set of anomaly event features obtained by high-frequency local clustering of the edge and end sides.

[0128] A statistical distribution mapping method (parameters: mean, variance, skewness, kurtosis, distribution type) is used to statistically extract the feature parameters of each abnormal pattern data cluster and map its distribution pattern under various multidimensional indicators into a statistical feature vector.

[0129] Furthermore, by using structural variation measurement algorithms (such as Mahalanobis distance, Local Outlier Factor (LOF), and Jensen-Shannon divergence, with parameters including data cluster center, covariance matrix, and neighboring cluster reference set), we can achieve multi-scale difference assessment between data clusters and existing normal data clusters and historically known patterns, and generate variation measurement scores for each data cluster.

[0130] Furthermore, based on the variation metric score and combined with the contextual information of facility structure, material and operating conditions, a multi-scale threshold screening mechanism (parameters: dynamic thresholds for each dimension, confidence intervals) is adopted to screen out candidate new pattern data clusters with significant variation as candidates for new pattern occurrence.

[0131] Furthermore, burst detection algorithms for time series (such as moving window entropy increment method and sequence asymptotic variance method, parameters: window length, burst detection threshold) are used to extract burst description parameters from the new pattern data cluster; persistence description parameters are output through multi-time window persistence analysis algorithms (such as CUSUM detection and Hurst exponent calculation, parameters: persistence threshold, time span); and spatial correlation normalization algorithm (parameters: spatial neighborhood radius, correlation function type) is used to generate local correlation metrics, thereby realizing a multi-dimensional core description of candidate new patterns.

[0132] Through the above multi-scale criterion aggregation, the statistical distribution characteristics, structural variation scores, and descriptive parameters such as suddenness, persistence, and correlation of the identified candidate new pattern data clusters are standardized and packaged. Finally, a "new local pattern identifier" and its core descriptive parameter set that uniquely identifies this new local pattern are generated, realizing the determination and quantitative characterization of multi-source abnormal local new patterns.

[0133] For example, in a smart operation and maintenance scenario for urban water supply networks, edge nodes obtained a feature data cluster containing 900 abnormal events based on Mini-Batch K-means clustering results. Using statistical distribution mapping, the main parameters of this cluster were calculated as follows: mean 25.3, variance 8.7, skewness 0.15, and kurtosis 2.1, with the distribution type fitting as a normal distribution. The variation metric score was calculated using Mahalanobis distance between the cluster center and the standard center of the normal water supply mode, resulting in a score of 2.73, higher than the historical threshold of 2.0. Combining pipeline material changes and abnormal area node information, a dynamic threshold screening was used to determine that this data cluster was a candidate for a novel local pattern. Subsequently, a sequence burst detection algorithm was applied, with a window length of 40 and an entropy increment index of 0.35, indicating that this data cluster possessed significant burstiness. Using the CUSUM method, the Hurst index was 0.81, showing that the abnormal pattern had strong persistence. Through spatial correlation analysis, with a neighborhood radius of 250 meters, the correlation coefficient was 0.68, exhibiting significant localization characteristics. After standardizing and encapsulating the above parameter set, a unique pattern identifier "MWM20240612-01" is assigned, and pattern statistical indicators are aggregated and output. Ultimately, this embodiment achieves objective identification, parameterized description, and unique identification of novel local anomalies induced by structural changes in urban water supply facilities, providing a highly effective input basis for subsequent adaptive model evolution and incremental knowledge graph completion.

[0134] S7.4: For the new local pattern identifier and its core descriptive parameters, combined with the analysis results of facility entity attributes, spatiotemporal tags and abnormal causal chains, perform relational encoding and standardized encapsulation processing to generate a local pattern standard data package that can be parsed by the cloud, ensuring that key information is traceable and scalable.

[0135] S7.5: Standardized and encapsulated local pattern standard data packets are uploaded in real time to the cloud knowledge graph incremental expansion and model adaptive evolution module via a secure communication protocol. This serves as a key input for continuous learning processes such as cloud self-distillation and self-adversarial learning, thereby improving the overall system's generalization learning capability in response to dynamic changes in facility structure and operating environment.

[0136] Step S8: Utilizing aggregated feedback and historical knowledge in the cloud, perform model self-distillation and self-adversarial continuous learning to optimize the spatiotemporal dynamic knowledge graph structure and the zero-shot fault reasoning model, thereby improving the model's generalization and adaptability to facility status and environmental changes. Specifically, this includes: S8.1: The clustering analysis results and novel local pattern feedback information reported by the end-side and edge nodes are parsed and aggregated. Combined with the existing rare fault causal chains and event tags stored in the historical knowledge base, a set of data pairs for model self-distillation is generated to improve the model's ability to accommodate heterogeneous data features in dynamic environments.

[0137] S8.2: Based on the generated set of data pairs, a self-distillation learning algorithm is used to deeply optimize the parameter distribution of the zero-shot fault reasoning model in the cloud, enabling it to adaptively inherit edge knowledge and maintain knowledge consistency, thereby obtaining a model weight output with stronger generalization.

[0138] S8.3: Utilize the optimized model weight output to construct a self-adversarial continuous learning strategy, dynamically generate adversarial examples and perform robust model training to explore the potential boundary sample space, enhance the model's ability to distinguish and identify new rare anomaly types or edge patterns, and obtain improved model generalization performance.

[0139] S8.4: Based on the improved generalization performance of the model obtained from the reinforcement learning and self-distillation stages, the spatiotemporal dynamic knowledge graph structure is dynamically adjusted and maintained. New entities, attribute edges and causal chains are automatically summarized and orderly merged to form the latest version of the knowledge graph, realizing a high-order representation of the latest facility state evolution and abnormal relationships.

[0140] S8.5: The latest knowledge graph version and the upgraded model generalization performance are synchronously output to the multi-source data stream analysis engine, and the zero-shot event feature representation and inference distribution mechanism are uniformly updated, providing authoritative knowledge benchmarks and self-learning capabilities to support subsequent anomaly detection, causal chain inference and dynamic threshold adjustment.

[0141] Step S9: Based on the updated model output and rare anomaly causal chains, and considering dynamic changes in facility status and environment, various detection and early warning dynamic threshold parameters are adjusted in real time to achieve a long-term, efficient, and adaptive early identification and warning mechanism for facility anomalies. Specifically, this includes: S9.1: Based on the spatiotemporal dynamic knowledge graph structure and the output of the zero-sample fault reasoning model, the current operating status parameters of the facility, environmental dynamic information and causal chain entity feature streams are aggregated in real time to obtain a time-series dataset that reflects the evolution of the facility status and changes in abnormal causal chains.

[0142] S9.2: Adaptive statistical analysis algorithms (such as multi-time-window variance detection and anomaly probability estimation) are used on the time-series dataset to calculate the sensitivity coefficients between each facility status parameter and zero-sample causal chain events, in order to measure the impact of dynamic environmental changes on anomaly detection sensitivity and obtain the measurement coefficient matrix.

[0143] S9.3: Utilize the metric coefficient matrix combined with the rare anomaly classification results of the current zero-shot inference model to execute a real-time threshold optimization algorithm based on Bayesian decision theory, dynamically adjust various detection indicators and early warning decision threshold parameters, and form a preliminary adaptive threshold configuration set.

[0144] S9.4: The adaptive threshold configuration set is pushed to the edge detection model through the end-edge-cloud linkage channel, and multi-dimensional threshold mapping transformation is performed in combination with the diversity of facility structure and material heterogeneity to accurately match the actual working conditions of the distributed detection unit and generate a hierarchical dynamic threshold rule library.

[0145] S9.5: Based on real-time feedback from anomaly detection at the edge and end sides, detection results and false alarm / missed alarm flags are dynamically collected. Incremental learning and parameter backtracking algorithms are used to correct the adaptive threshold configuration set, realizing online self-correction of dynamic thresholds. This further improves the accuracy and robustness of the facility anomaly early identification and warning mechanism driven by spatiotemporal dynamic knowledge graph and zero-shot reasoning model.

[0146] Step S10: After completing the abnormal event warning, the warning event and analysis results are pushed to operation and maintenance experts for feedback and annotation. The knowledge graph and model labeling system are then optimized based on expert manual annotation, continuously incrementally evolving the facility's zero-sample self-learning capability for rare faults. Specifically, this includes: S10.1: Based on the knowledge graph mapping rules, a structured early warning analysis report is generated using the causal chain of abnormal events and the feature vector of zero-sample events generated by the interaction between the end-edge-cloud. This enables the accurate correspondence between abnormal events and knowledge graph entities and the archiving of ontology attribute information.

[0147] S10.2: Push the structured early warning analysis report, the original feature vector of abnormal events and the causal chain analysis results to the AI-assisted decision-making interface of the operation and maintenance experts. Use expert knowledge to manually label and evaluate the event type, triggering factors and potential causal relationships to generate a corrected label dataset.

[0148] S10.3: Based on the corrected label dataset returned by experts, an active learning strategy is adopted to write back the manually labeled unknown category events and attribute nodes to the spatiotemporal dynamic knowledge graph, so as to achieve entity completion and attribute enrichment of the graph.

[0149] S10.4: Perform entity embedding vector updates and relation retraining on the completed spatiotemporal dynamic knowledge graph, and optimize the graph embedding model parameters using the label propagation algorithm to enhance the ability to represent zero-shot event features.

[0150] S10.5: The optimized knowledge graph is embedded in the model, the new parameters of causal chain reasoning and the latest manually labeled tags are synchronously fed back to the edge-cloud distributed detection model. The model's adaptability to rare faults and incremental learning ability are enhanced through model distillation and self-adversarial training, so as to realize the continuous evolution of the zero-shot self-learning mechanism.

[0151] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

[0152] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and rules of the present invention should be included within the scope of protection of the present invention.

Claims

1. A smart city public facility monitoring method based on the Internet of Things, characterized in that, Includes the following steps: S1: Collect multi-source heterogeneous raw sensor data from different facility types, structural locations, and material types, and attach timestamps and spatial positioning tags to establish a multi-dimensional data input set; S2: Perform noise filtering, outlier removal, and normalization preprocessing on the multi-dimensional data input set to generate a standardized feature stream; S3: Based on the standardized feature flow, construct a spatiotemporal dynamic knowledge graph of entities and attribute edges, and express the differences in different facility structures and operating conditions through graph nodes and relationships. S4: Input the standardized feature vectors of unlabeled or rare abnormal events into the graph embedding model. Through entity embedding representation, structural similarity calculation and adjacency feature transfer, zero-sample class inference and analogy feature generation are performed for unknown faults to obtain zero-sample event feature vectors. S5: Based on the zero-sample event feature vector and spatiotemporal dynamic knowledge graph, execute the causal relationship mining and traceable causal inference algorithm to analyze the causal chain and difference factors between the newly emerging anomaly and the existing known events, and output the causal chain of rare anomalies; S6: Simultaneously send the causal chain analysis results and the zero-sample event feature vector to the end-side and edge-side detection models, and configure a low-latency streaming screening algorithm for the edge-side detection model; S7: Based on feedback from end-side and edge-side detection models and cluster analysis results, dynamically identify new local patterns caused by changes in facility structure, materials, and operating conditions, and report them to the cloud; S8: Based on cloud computing, it utilizes aggregated feedback and historical knowledge to perform model self-distillation and self-adversarial continuous learning, optimizes the spatiotemporal dynamic knowledge graph structure and the zero-shot fault reasoning model.

2. The method for supervising smart city public facilities based on the Internet of Things according to claim 1, characterized in that, Following step S8, the following is also included: S9: In response to dynamic changes in facility status and environment, adjust various detection and early warning dynamic threshold parameters in real time based on the updated model output and rare abnormal causal chains; S10: After completing the abnormal event warning, the warning event and analysis results are pushed to the operation and maintenance experts for feedback and annotation. Combined with the expert manual annotation, the knowledge graph and model label system are optimized to continuously and incrementally improve the zero-sample self-learning capability of rare facility failures.

3. The method for supervising smart city public facilities based on the Internet of Things according to claim 1, characterized in that, Step S1 specifically includes: For different facility categories, configure corresponding types of IoT terminal collection points to collect data on device operating status parameters and obtain the corresponding raw device status data to form a subset of device status data; Deploy high-precision environmental sensor arrays at specific facility structures to collect environmental physical quantities and obtain raw environmental parameter data; Based on the material type of the facility, a special intelligent sensing module is invoked to continuously collect data on key material parameters and obtain raw data on the material's health status. Based on the automatic integration of facility operation and maintenance logs by the operation and maintenance system, including log text and operation code data such as preventive inspections, fault repairs, and remote operation history, the raw data of structured operation and maintenance logs are formed after encoding and transformation. Connect to third-party event collection interfaces, access external event notification streams from relevant systems, and extract the original third-party event data after time synchronization through protocol parsing; Based on the data collection time and spatial location, a unified spatiotemporal annotation module adds a high-precision timestamp and spatial positioning label to each record, generating a multi-source heterogeneous raw sensor dataset with complete metadata attributes. Based on the multi-source heterogeneous raw sensor dataset with attached metadata attributes, it is archived and saved hierarchically according to facility category, structural location and material type to generate a multi-dimensional data input set.

4. The method for supervising smart city public facilities based on the Internet of Things according to claim 1, characterized in that, Step S2 specifically includes: The original sensor data from various facility structures and material types are input into a multi-dimensional data set. Based on the time-series consistency rules and signal denoising algorithms, noise signal separation is performed to obtain preliminarily purified multi-source original time-series data. Using the initial purified multi-source raw time-series data as input, the distribution statistics algorithm and multivariate robust discrimination are applied to identify and remove outliers that exceed the equipment operating boundary threshold or do not conform to the facility operating condition distribution characteristics, and output the cleaning time-series data after outlier removal. After removing the outliers, the cleaning time series data is normalized. For different facility structures, materials and environmental backgrounds, the features of various sensors are uniformly scaled to a dimensionless range according to the dimensional standard to form a normalized feature matrix while retaining the original structure labels. The normalized feature matrix is ​​aligned with the original spatial positioning labels and timestamp information. A spatiotemporal correction algorithm is applied to align and map various feature data with different acquisition frequencies and sampling points on the same time and space axis, and output a structured and standardized feature stream. Based on the structured and standardized feature stream, a multi-dimensional field screening mechanism is used to perform a final round of quality control and integrity assessment. Unit data with potential defects or samples that fail verification are repaired or removed to generate the final standardized feature stream.

5. A smart city public facility monitoring method based on the Internet of Things according to claim 4, characterized in that, The noise signal separation operation employs a time-series consistency discrimination method, bandpass filtering, and wavelet denoising algorithm. The outlier removal uses distribution statistics and multivariate robust discrimination techniques. The normalization process includes z-score normalization or min-max scaling.

6. The method for supervising smart city public facilities based on the Internet of Things according to claim 1, characterized in that, Step S3 specifically includes: The standardized feature flow is processed by entity and attribute classification to obtain an original multidimensional entity set containing facility entities, component entities, environmental event entities, and operational behavior entities; Based on the logical and physical relationships between the entities, the relationship extraction algorithm is executed on the multidimensional entity set to generate attribute edges for facility structure relationships, component affiliation relationships, environmental impact relationships, and operational behavior link relationships. Spatiotemporal label association processing is performed on entity nodes and attribute edges, and the timestamps and spatial positioning information in the original feature stream are mapped and assigned to the relevant entity nodes and relational attributes to obtain a spatiotemporal dynamic knowledge graph skeleton with time series attributes and spatial positioning attributes. For the spatiotemporal dynamic knowledge graph skeleton, a heterogeneous data fusion algorithm is used to continuously and dynamically integrate the newly flowing standardized feature streams into new nodes, new relationships and attribute increments. Based on a dynamic incremental spatiotemporal knowledge graph, autonomous rules are generated and entity / attribute abstraction and standardization are performed to address differences in facility structures and operating conditions, forming a graph node system that can express multi-dimensional knowledge of facility structure hierarchy, functional modules, operation sequences, and environmental linkages.

7. The method for supervising smart city public facilities based on the Internet of Things according to claim 1, characterized in that, The knowledge graph construction in step S3 includes entity and attribute classification, relation extraction, spatiotemporal label mapping, and heterogeneous data fusion. It also has dynamic incremental expansion capabilities, which can incrementally supplement the graph with facilities, components, events, and operation nodes that are newly flowing into the feature stream in real time.

8. A smart city public facility monitoring method based on the Internet of Things according to claim 1, characterized in that, Step S4 specifically includes: For the standardized feature vectors of unlabeled abnormal samples selected from the standardized feature stream, data adaptation and consistency processing are performed using the facility spatiotemporal dynamic knowledge graph as the context. Based on the standardized feature vectors after data adaptation, a graph embedding model is used to perform high-dimensional embedding representation of each entity in the knowledge graph, and obtain entity embedding vectors with composite spatiotemporal attributes. Structural similarity calculations are performed continuously on the entity embedding vectors. By comparing the similarity measure between the entity embedding vector to be identified and the embedding vectors of existing fault type entities in the knowledge graph, a structural similarity score vector is generated. Based on the structural similarity score vector, feature transfer is further performed on the adjacency relationship of the knowledge graph. An adjacency feature diffusion algorithm based on entity attributes and relation edge weights is used to transfer the relevant representation information of the embedding vectors of adjacent entities to the sample to be identified, thereby obtaining an analogy feature vector optimized by neighborhood induction. Based on the analogy feature vector, the structural similarity score and temporal and spatial label information are fused, and a zero-shot category inference algorithm is executed to calculate the category assignment probability and generate labels for unlabeled anomalies. The zero-shot event feature vector containing the category inference result, the induction vector and the association mapping relationship with the knowledge graph are output.

9. A smart city public facility monitoring method based on the Internet of Things according to claim 1, characterized in that, In step S4, the graph embedding adopts entity high-dimensional embedding encoding based on graph neural network, performs attribute consistency correction and unique node mapping on the standardized feature vector of unlabeled abnormal samples, and generates zero-sample event category inference and analogy features through structural similarity measurement and adjacency feature diffusion method.

10. A smart city public facility monitoring method based on the Internet of Things according to claim 1, characterized in that, The rare anomaly causal chain knowledge fragment output in step S5 includes event nodes, attribute edges, and key factors, and supports causal structure interpretability analysis, providing a traceability basis for dynamic early warning, expert feedback, and knowledge increment completion.

Citation Information

Cited By

  • Method for measuring hemoglobin concentration in vitro based on biosensor

    CN121783894A

  • Time sequence alarm dynamic association system for multi-source heterogeneous sensing gateway

    CN121984838A