Industrial Internet of Things risk early warning method based on data analysis

By extracting and analyzing the current data of industrial IoT devices from multiple dimensions and adaptively obtaining the normal feature value range, the problem of misjudging abnormal risks caused by equipment operation phase transitions is solved, and the accuracy and efficiency of risk warning are improved.

CN121638867APending Publication Date: 2026-03-10SUZHOU IND & IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-10
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing industrial IoT risk warning methods are prone to misjudging abnormal risks during equipment operation transitions and are susceptible to noise interference, leading to reduced warning accuracy.

Method used

By collecting current data from industrial IoT devices, and utilizing multi-dimensional feature extraction and feature value sequence analysis, the degree of abnormal risk response and the normal feature value range are obtained. Combined with anomaly detection methods, risk warnings are issued. By adjusting the weights of different dimensional features, the normal feature value range is adaptively obtained, thereby improving the accuracy of warnings.

Benefits of technology

It effectively reduces the misjudgment of abnormal risks caused by equipment operation phase transitions, improves the accuracy and efficiency of industrial IoT risk warning, and can identify abnormal risks more quickly.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121638867A_ABST
    Figure CN121638867A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to an industrial Internet of Things risk early warning method based on data analysis, and the method comprises the steps: carrying out the multi-dimensional feature extraction of a historical current data sequence of equipment in the industrial Internet of Things in a preset time period before a current monitoring moment, and obtaining a multi-dimensional feature value sequence; according to an accident feature value sequence and all normal historical feature values under each dimension feature in the multi-dimensional feature value sequence, obtaining an abnormal risk reaction degree and a normal feature value range of each dimension feature; the method comprises the steps of obtaining a multi-dimensional prediction feature value in a prediction time period, performing anomaly detection on the multi-dimensional prediction feature value by using a normal feature value range of each dimension feature to obtain a prediction anomaly degree of each dimension feature, and performing risk early warning on the industrial Internet of Things in combination with the prediction anomaly degree of each dimension feature and an anomaly risk reaction degree. And the accuracy of abnormal risk assessment of the predicted feature value is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to an industrial internet of things risk early warning method based on data analysis. BACKGROUND

[0002] Industrial internet of things refers to connecting industrial equipment, sensors, controllers, communication networks, management analysis systems, etc., to realize functions such as equipment operation state monitoring, fault prediction and diagnosis, and production optimization, which can promote industrial digital transformation, improve production efficiency and quality, and enhance production safety and risk prevention and control capabilities. Among them, through the analysis of real-time monitoring data, potential abnormal risks in equipment operation are warned, which is an important function of industrial internet of things to ensure the safety of industrial production.

[0003] The existing industrial internet of things risk early warning method mainly predicts the monitoring data at the future time by analyzing the change trend of the monitoring data, and when the predicted data exceeds the normal data range, the abnormal risk early warning of the industrial internet of things can be carried out. However, because the data change characteristics of the equipment are different in different running stages, and the normal range of the monitoring data also has differences, if a fixed normal data range is used for risk early warning, the equipment will be misidentified as having abnormal risks when the running stage changes, and only judging the abnormal risks from the numerical value of the monitoring data is easy to be affected by noise and other interference factors, resulting in reduced accuracy of abnormal risk early warning.

[0004] Therefore, how to reduce the abnormal risk misjudgment caused by the change of the equipment running stage and improve the risk early warning accuracy of the industrial internet of things has become a problem to be solved. SUMMARY

[0005] Therefore, the embodiments of the present application provide an industrial internet of things risk early warning method based on data analysis to solve the problem of how to reduce the abnormal risk misjudgment caused by the change of the equipment running stage and improve the risk early warning accuracy of the industrial internet of things.

[0006] The industrial internet of things risk early warning method based on data analysis provided in the embodiments of the present application comprises the following steps: The current data of the equipment in the industrial internet of things is collected to obtain a historical current data sequence in a preset time period before the current monitoring time, and a multi-dimensional feature extraction is performed on the historical current data sequence by using a preset length time window to obtain a multi-dimensional feature value sequence. For any dimension feature, extract the accident feature value sequence of M historical risk accidents and all normal historical feature values of the any dimension feature in the multi-dimensional feature value sequence, and obtain the abnormal risk response degree of the any dimension feature according to the local trend change difference and the feature value difference between each accident feature value in each accident feature value sequence and the normal historical feature value; Divide the multi-dimensional normal historical feature values in the multi-dimensional feature value sequence into data segments to obtain multi-dimensional normal data segments, and obtain the normal feature value range of each dimension feature suitable for a prediction period after the current monitoring moment according to the multi-dimensional feature value change trend similarity between a current period containing the current monitoring moment and each multi-dimensional normal data segment; Obtain multi-dimensional prediction feature values in the prediction period, perform abnormality detection on the multi-dimensional prediction feature values by using the normal feature value range of each dimension feature to obtain the prediction abnormality degree of each dimension feature, and combine the prediction abnormality degree of each dimension feature and the abnormal risk response degree to perform risk early warning on the industrial Internet of Things.

[0007] Preferably, the multi-dimensional features include mean value, root mean square, peak value, main frequency and kurtosis, and the multi-dimensional feature value sequence obtained by performing multi-dimensional feature extraction on the historical current data sequence by using the preset length time window includes: The historical current data sequence is divided into a plurality of subsequences by using the preset length time window, for any subsequence, the mean value, root mean square, peak value, main frequency and kurtosis of the any subsequence are calculated to form the multi-dimensional feature value of the any subsequence, the multi-dimensional feature value of each subsequence is obtained, and all multi-dimensional feature values are normalized to obtain the multi-dimensional feature value sequence.

[0008] Preferably, the abnormal risk response degree of the any dimension feature is obtained according to the local trend change difference and the feature value difference between each accident feature value in each accident feature value sequence and the normal historical feature value, and includes: For any accident feature value sequence, the local trend difference between each accident feature value in the any accident feature value sequence and each normal historical feature value is obtained to obtain the possibility index of each accident feature value in the any accident feature value sequence belonging to abnormal response data, and the cumulative value of all possibility indexes is normalized to obtain the response speed of the any dimension feature reflected by the any accident feature value sequence to abnormal risk; acquiring a time sequence of at least one normal historical characteristic value among all normal historical characteristic values, the time sequence of normal historical characteristic values being the same length as the any accident characteristic value sequence, weighting the any accident characteristic value sequence with a possibility index as a weight, linearly fitting the any accident characteristic value sequence to obtain a fitting value sequence, and obtaining a sensitive degree of the any dimension characteristic reflected by the any accident characteristic value sequence to abnormal risk according to a characteristic value difference between the fitting value sequence and each of the time sequence of normal historical characteristic values; obtaining a product between a response speed and a sensitive degree of the any dimension characteristic reflected by the any accident characteristic value sequence to abnormal risk, denoted as a reflection degree of the any dimension characteristic to abnormal risk under the any accident characteristic value sequence, and calculating an average value between reflection degrees of the any dimension characteristic to abnormal risk under all accident characteristic value sequences to obtain an abnormal risk reaction degree of the any dimension characteristic.

[0009] Preferably, the acquiring of the possibility index of each accident characteristic value in the any accident characteristic value sequence belonging to abnormal response data according to a local trend difference between each accident characteristic value in the any accident characteristic value sequence and each normal historical characteristic value comprises: for any accident characteristic value in the any accident characteristic value sequence, acquiring a local characteristic value set composed of the any accident characteristic value and a preset number of accident characteristic values closest to the any accident characteristic value, linearly fitting the local characteristic value set to obtain a fitting slope, denoted as a local trend value of the any accident characteristic value, acquiring a local trend value of each normal historical characteristic value, calculating an absolute value of a difference between the local trend value of the any accident characteristic value and the local trend value of each normal historical characteristic value to obtain an accumulated value of the absolute value of the difference, and normalizing the accumulated value of the absolute value of the difference to obtain the possibility index of the any accident characteristic value belonging to abnormal response data.

[0010] Preferably, the obtaining of the sensitive degree of the any dimension characteristic reflected by the any accident characteristic value sequence to abnormal risk according to a characteristic value difference between the fitting value sequence and each of the time sequence of normal historical characteristic values comprises: for any fitting value in the fitting value sequence, acquiring a normal historical characteristic value at a same position in each of the time sequence of normal historical characteristic values according to the position of the any fitting value in the fitting value sequence, denoted as a reference characteristic value, calculating an absolute value of a characteristic value difference between the any fitting value and each of the reference characteristic values, and accumulating all absolute values of the characteristic value difference to obtain an abnormal degree of the any fitting value. obtaining abnormality degrees of each of the fitting values in the sequence of fitting values, normalizing a sum of the abnormality degrees of all of the fitting values in the sequence of fitting values to obtain a sensitivity degree of the any-dimension feature to abnormal risk reflected by the sequence of any-incident feature values.

[0011] Preferably, the data segment division on the multi-dimension normal historical feature values in the sequence of multi-dimension feature values comprises: composing all of the multi-dimension normal historical feature values in the sequence of multi-dimension feature values into a sequence of multi-dimension normal historical feature values according to time sequence, extracting all of the normal historical feature values under the any-dimension feature in the sequence of multi-dimension normal historical feature values, and composing normal historical feature value sequences according to time sequence, obtaining a local trend value of each of the normal historical feature values in the normal historical feature value sequences, and obtaining at least two segmented feature values in the normal historical feature value sequences according to a single change feature of the local trend value. obtaining all of the segmented feature values under each dimension feature, calculating a sampling time mean value according to a sampling time corresponding to the i-th segmented feature value under each dimension feature, and taking the sampling time mean value as an i-th segmented time by rounding down; obtaining all of the segmented times, and dividing the sequence of multi-dimension normal historical feature values into at least three multi-dimension normal data segments according to the segmented times.

[0012] Preferably, the obtaining of the normal feature value range of each dimension feature suitable for the prediction period after the current monitoring time according to the multi-dimension feature value change trend similarity between the current period containing the current monitoring time and each multi-dimension normal data segment comprises: obtaining an overall feature value change trend value under each dimension feature in each of the multi-dimension normal data segments respectively, obtaining an overall feature value change trend value under each dimension feature in the current period respectively, and obtaining a running state similarity between the any multi-dimension normal data segment and the current period according to a difference between the overall feature value change trend values under the same dimension feature between the any multi-dimension normal data segment and the current period. obtaining a normal feature value upper limit and a normal feature value lower limit under each dimension feature in the any multi-dimension normal data segment by using the 3σ principle respectively; and obtaining the normal feature value range of each dimension feature suitable for the prediction period after the current monitoring time by comprehensively considering the running state similarity between each of the multi-dimension normal data segments and the current period and the normal feature value upper limit and the normal feature value lower limit under each dimension feature in each of the multi-dimension normal data segments.

[0013] Preferably, the running state similarity between each of the multi-dimensional normal data segments and the current time period and the upper limit and the lower limit of the normal feature value of each dimension feature in each of the multi-dimensional normal data segments are comprehensively used to obtain the normal feature value range of each dimension feature applicable to the prediction time period after the current monitoring time, including: For any dimension feature, the upper limit of the normal feature value of the any dimension feature in each of the multi-dimensional normal data segments is weighted and summed with the running state similarity between each of the multi-dimensional normal data segments and the current time period as the weight to obtain a summation value, and the adaptive upper limit of the normal feature value of the any dimension feature is obtained by taking the summation value as the numerator and the number of multi-dimensional normal data segments as the denominator. The lower limit of the normal feature value of the any dimension feature in each of the multi-dimensional normal data segments is weighted and summed with the running state similarity between each of the multi-dimensional normal data segments and the current time period as the weight to obtain a summation value, and the adaptive lower limit of the normal feature value of the any dimension feature is obtained by taking the summation value as the numerator and the number of multi-dimensional normal data segments as the denominator. The normal feature value range of the any dimension feature applicable to the prediction time period after the current monitoring time is obtained according to the adaptive upper limit and the adaptive lower limit of the normal feature value of the any dimension feature.

[0014] Preferably, the normal feature value range of each dimension feature is used for abnormality detection of the multi-dimensional prediction feature value to obtain the prediction abnormality degree of each dimension feature, including: For any prediction feature value in the multi-dimensional prediction feature value, if the any prediction feature value is within the normal feature value range of the corresponding dimension feature, the prediction abnormality degree of the dimension feature corresponding to the any prediction feature value is 0; if the any prediction feature value is not within the normal feature value range of the corresponding dimension feature, the absolute value of the difference between the any prediction feature value and the upper limit and the lower limit of the normal feature value range of the corresponding dimension feature is calculated to obtain the minimum difference absolute value, and the minimum difference absolute value is normalized to obtain the prediction abnormality degree of the dimension feature corresponding to the any prediction feature value.

[0015] Preferably, the prediction abnormality degree of each dimension feature and the abnormal risk reaction degree are combined to perform risk early warning on the industrial Internet of Things, including: The product between the prediction abnormality degree of each dimension feature and the abnormal risk reaction degree is obtained to obtain a product mean, which is recorded as the risk prediction degree of the prediction time period, and if the risk prediction degree of the prediction time period is greater than or equal to a preset risk prediction degree threshold, the risk early warning is performed on the industrial Internet of Things.

[0016] Compared with the prior art, the embodiment of the present application has the following beneficial effects: The application adjusts the weight of different dimensional features in abnormal risk assessment according to the degree of reflection of the feature values under different dimensional features on abnormal risk, obtains the abnormal risk reaction degree of each dimensional feature, improves the influence of the feature values under the dimensional features with more obvious abnormal performance and faster abnormal response speed, and can effectively improve the efficiency of abnormal risk identification. Further, according to the difference in the change law of the feature values of different equipment operation stages, the multi-dimensional normal historical feature values with similar change trends are divided into multiple multi-dimensional normal data segments according to the single change feature of the feature values, the normal feature value range of each dimensional feature suitable for the prediction period is adaptively obtained through the similarity of the feature value change trend between each multi-dimensional normal data segment and the current period, and the accuracy of the abnormal risk assessment of the predicted feature value can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0018] Figure 1 is a method flowchart of an industrial Internet of Things risk early warning method based on data analysis provided by the first embodiment of the present application. DETAILED DESCRIPTION

[0019] The embodiments of the present disclosure will be described in detail below, and examples of the embodiments are shown in the drawings. The embodiments described below by referring to the drawings are exemplary and are intended to explain the present disclosure, and cannot be understood as a limitation of the present disclosure.

[0020] It should be noted that the terms "first", "second" and the like in the specification of the present disclosure and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The implementation described in the following exemplary embodiments does not represent all the implementations consistent with the present disclosure. On the contrary, they are only examples of devices and methods consistent with some aspects of the present disclosure.

[0021] In order to illustrate the technical solutions of the present application, the following will be described by specific embodiments.

[0022] Reference Figure 1 is a method flowchart of an industrial Internet of Things risk early warning method based on data analysis provided by the first embodiment of the present application, as shown inFigure 1 As shown, the method can comprise: In step S101, current data of devices in the industrial Internet of Things is collected to obtain a historical current data sequence in a preset time period before a current monitoring time, a time window of a preset length is used to perform multi-dimensional feature extraction on the historical current data sequence to obtain a multi-dimensional feature value sequence.

[0023] During the operation of the industrial equipment, according to the needs of industrial production, there can be switching of the operating state of the equipment, and the normal data range applicable in the operating state of different equipment is different, and the traditional risk early warning method based on the fixed normal data range can misjudge the data generated by the change of the operating state of the equipment as an abnormal risk. Therefore, the embodiments of the present application combine the data change law of different operating stages of the equipment to perform risk prediction, so as to improve the accuracy of the risk early warning of the industrial Internet of Things.

[0024] Specifically, since the current data is one of the key data in the risk early warning of the industrial Internet of Things, it can directly reflect the load state and operation health state of the equipment, therefore, in the embodiments of the present application, the current data is used as the basis for the risk early warning of the industrial Internet of Things, a current sensor is arranged at the power input position of the industrial equipment to monitor the current data of the industrial equipment in real time, in order to accurately identify the abnormal change of the current data, the monitoring frequency of the current sensor is 100 Hz, so that the historical current data sequence in a preset time period before the current monitoring time can be obtained, it should be noted that, since the operation law of the equipment needs to be analyzed according to the historical operation data of the industrial equipment, and the industrial production will have changes such as production optimization and production technology adjustment, therefore, the reference of the historical operation data with a large time span is low, therefore, the preset time period is preferably set to one month, that is, the historical current data in one month before the current monitoring time is used as the analysis data, but the historical current data of at least 5 risk accidents needs to be included in one month, if there are less than 5 risk accidents, the preset time period is expanded, and the risk accidents include but are not limited to excessive load, loose wiring, equipment heating, motor current continuously higher than normal, and increased mechanical resistance.

[0025] After obtaining the historical current data sequence, the historical current data sequence is divided into a plurality of subsequences by using a time window of 1s, and the feature values of each subsequence are extracted, specifically, for any subsequence, the mean, root mean square, peak value, dominant frequency and kurtosis of the any subsequence are calculated to form the multi-dimensional feature values of the any subsequence, the multi-dimensional feature values of each subsequence are obtained, based on the dimensional features, each feature value in each multi-dimensional feature value is normalized by using a Norm function, and the normalized multi-dimensional feature values are obtained to form a multi-dimensional feature value sequence. It should be noted that the normalization processing belongs to the prior art, and will not be described in detail here.

[0026] In step S102, for any dimension feature, a sequence of accident feature values of M historical risk accidents and all normal historical feature values in the sequence of multi-dimensional feature values are extracted under the any dimension feature, and the abnormal risk response degree of the any dimension feature is obtained according to the local trend change difference and the feature value difference between each accident feature value in each sequence of accident feature values and the normal historical feature value.

[0027] Since the historical current data is extracted in step S101 to obtain the sequence of multi-dimensional feature values, but the emphasis of the device running state reflected by each dimension feature is different, therefore, the reflection degree of different dimension features on the abnormal risk is different, based on this, the embodiment of the application can make the final risk assessment closer to the real risk situation by improving the influence weight of the dimension feature with higher abnormal reflection degree in the risk assessment result.

[0028] Before the risk accident occurs, the current data will have a certain abnormal trend, in order to facilitate the analysis of the data difference between the abnormal risk period and the normal period, 5 minutes before each historical risk accident is taken as the historical risk accident period, and the period except the historical risk accident period and the historical risk accident period is taken as the normal period. If the change of the feature value of the any dimension feature in the historical risk accident period relative to the feature value of the normal period is obvious, it indicates that the sensitivity of the dimension feature to the abnormal risk is higher, and the abnormal response speed of each dimension feature is different, that is, not all multi-dimensional feature values in the historical risk accident period show abnormality, therefore, in order to more accurately show the change trend of the feature value under each dimension feature after the abnormal risk, it is necessary to improve the influence weight of the dimension feature with obvious abnormal performance on the risk analysis result.

[0029] Specifically, for any dimension feature A, a sequence of accident feature values of M historical risk accidents and all normal historical feature values in the sequence of multi-dimensional feature values are extracted under the any dimension feature A, M is equal to the number of risk accidents contained in the preset period corresponding to the sequence of historical current data, M is greater than or equal to 5, the sequence of accident feature values refers to the sequence of feature values corresponding to the any dimension feature A in the historical risk accident period, one sequence of accident feature values corresponds to one historical risk accident period, and the normal historical feature value refers to the feature value corresponding to the any dimension feature A in the normal period.

[0030] When the industrial equipment is in a normal state, the feature value of any dimensional feature A is relatively stable, and when the industrial equipment is in an abnormal risk state, the feature value of any dimensional feature A continuously changes in an abnormal direction, that is, the change trend of the feature value in the abnormal operation state is greatly different from the change trend of the feature value in the normal operation state, and therefore, in the embodiment of the present application, the abnormal risk response degree of any dimensional feature A is obtained according to the local trend change difference and the feature value difference between each accident feature value in each accident feature value sequence under any dimensional feature A and the normal historical feature value.

[0031] Taking any accident feature value sequence as an example, for any accident feature value in the any accident feature value sequence, a local feature value set composed of the nearest preset number of accident feature values of the any accident feature value is obtained, a fitting slope is obtained by linear fitting of the local feature value set by using the least square method, and the fitting slope is recorded as the local trend value of the any accident feature value, wherein the preset number is 4, that is, the number of data in the local feature value set is 5, and according to the method of obtaining the local trend value of any accident feature value, the local trend value of each normal historical feature value is obtained. Further, according to the local trend difference between any accident feature value and each normal historical feature value, the possibility index of any accident feature value belonging to abnormal response data is obtained: the absolute value of the difference between the local trend value of the any accident feature value and the local trend value of each normal historical feature value is calculated, the absolute value of the difference is obtained, the absolute value of the difference is normalized to obtain the possibility index of the any accident feature value belonging to abnormal response data.

[0032] wherein the calculation formula of the possibility index of any accident feature value belonging to abnormal response data is: wherein, indicates the possibility index of the vth accident feature value in any accident feature value sequence under any dimensional feature A belonging to abnormal response data, indicates the local trend value of the vth accident feature value in any accident feature value sequence under any dimensional feature A, indicates the local trend value of the nth normal historical feature value under any dimensional feature A, N1 indicates the number of normal historical feature values under any dimensional feature A, and | | indicates the absolute value symbol, indicates a normalization function.

[0033] It should be noted that, The difference between the change trend of the characteristic value representing the risk accident and the change trend of the characteristic value in the normal state is greater, the difference between the vth accident characteristic value in any accident characteristic value sequence under any dimensional characteristic A and the change rule of the characteristic value in the normal state is greater, it is more likely to be abnormal response data, and the possibility index of each accident characteristic value under any dimensional characteristic A belonging to abnormal response data is greater.

[0034] Similarly, the possibility index of each accident characteristic value under any dimensional characteristic A belonging to abnormal response data is obtained. If the characteristic value of any dimensional characteristic A changes earlier in the historical risk accident period, that is, there are more characteristic values in any accident characteristic value sequence under any dimensional characteristic A that are abnormal data, it is indicated that the response speed of any dimensional characteristic A to abnormal risk is faster. Therefore, according to the possibility index of each accident characteristic value under any dimensional characteristic A belonging to abnormal response data, the response speed of any dimensional characteristic A to abnormal risk reflected by any accident characteristic value sequence is quantified, and the specific quantification method is that the cumulative value of all possibility indexes is normalized to obtain the response speed of any dimensional characteristic to abnormal risk reflected by the any accident characteristic value sequence.

[0035] wherein, the calculation formula of the response speed of any dimensional characteristic A to abnormal risk reflected by any accident characteristic value sequence is: wherein, indicates the response speed of any dimensional characteristic A to abnormal risk reflected by the u th accident characteristic value sequence, indicates a normalization function, indicates the possibility index of the v th accident characteristic value in the u th accident characteristic value sequence under any dimensional characteristic A belonging to abnormal response data, indicates the number of data in the u th accident characteristic value sequence under any dimensional characteristic A.

[0036] Further, at least one normal historical feature value time series is obtained in all normal historical feature values in a 5-minute time window, and the normal historical feature value time series has the same length as the any accident feature value sequence. A possibility index of each accident feature value in the any accident feature value sequence under any dimension feature A belonging to abnormal response data is used as a weight, and a weighted linear fitting is performed on the any accident feature value sequence by using a weighted least square method to obtain a fitting value sequence, so that each accident feature value in the any accident feature value sequence corresponds to a fitting value in the fitting value sequence, and then a sensitive degree of any dimension feature A reflected by the any accident feature value sequence to abnormal risk is obtained according to a feature value difference between the fitting value sequence and each normal historical feature value time series. The sensitive degree of any dimension feature A reflected by the any accident feature value sequence to abnormal risk is obtained by the following method: For any fitting value in the fitting value sequence, a normal historical feature value at the same position in each normal historical feature value time series is obtained according to the position of the any fitting value in the fitting value sequence, and is recorded as a reference feature value. An absolute value of a feature value difference between the any fitting value and each reference feature value is calculated, and all absolute values of the feature value differences are accumulated to obtain an abnormal degree of the any fitting value. The abnormal degree of each fitting value in the fitting value sequence is obtained, and a sum of the abnormal degrees of all fitting values in the fitting value sequence is normalized to obtain the sensitive degree of any dimension feature A reflected by the any accident feature value sequence to abnormal risk.

[0037] The calculation formula of the sensitive degree of any dimension feature A reflected by the any accident feature value sequence to abnormal risk is as follows: wherein, represents the sensitive degree of any dimension feature A reflected by the u-th accident feature value sequence to abnormal risk, represents a normalization function, represents a number of data in the u-th accident feature value sequence under any dimension feature A, represents a number of normal historical feature value time series, represents a j-th normal historical feature value in the w-th normal historical feature value time series under any dimension feature A, represents a j-th fitting value in the fitting value sequence, that is, a fitting value of a j-th accident feature value in the u-th accident feature value sequence under any dimension feature A, and | | represents an absolute value symbol.

[0038] It should be noted that, represents the difference between the normal historical feature value and the accident feature value of any one-dimensional feature A, the greater the feature value difference, the more obvious the abnormal performance of any one-dimensional feature A when there is an abnormal risk, that is, the higher the sensitivity of any one-dimensional feature A to abnormal risk.

[0039] Similarly, the response speed and sensitivity of any one-dimensional feature A to abnormal risk reflected by each accident feature value sequence are obtained, and then the response speed and sensitivity of any one-dimensional feature A to abnormal risk reflected by all accident feature value sequences are comprehensively analyzed to analyze the reflection degree of any one-dimensional feature A to abnormal risk, wherein the analysis method is: obtaining the product between the response speed and the sensitivity of any one-dimensional feature A to abnormal risk reflected by any one accident feature value sequence, denoted as the reflection degree of any one-dimensional feature A to abnormal risk under the any one accident feature value sequence, and calculating the average value between the reflection degrees of any one-dimensional feature A to abnormal risk under all accident feature value sequences to obtain the abnormal risk reaction degree of any one-dimensional feature A.

[0040] wherein the calculation formula of the abnormal risk reaction degree of any one-dimensional feature A is: wherein, represents the abnormal risk reaction degree of any one-dimensional feature A, represents the response speed of any one-dimensional feature A to abnormal risk reflected by the u-th accident feature value sequence, represents the sensitivity of any one-dimensional feature A to abnormal risk reflected by the u-th accident feature value sequence, and M represents the number of accident feature value sequences, that is, the number of historical risk accidents.

[0041] Similarly, the abnormal risk reaction degree of each dimensional feature is obtained according to the obtaining method of the abnormal risk reaction degree of any one-dimensional feature A, which is used to represent the reflection degree of the dimensional feature to abnormal risk.

[0042] In step S103, the multi-dimensional normal historical feature values in the multi-dimensional feature value sequence are divided into data segments to obtain multi-dimensional normal data segments, and the normal feature value range of each dimensional feature suitable for the prediction period after the current monitoring time is obtained according to the multi-dimensional feature value change trend similarity between the current period containing the current monitoring time and each multi-dimensional normal data segment.

[0043] Since the current data features of different devices in different running stages may have some differences, the normal ranges of the feature values of the current data in different running stages may also be different, therefore, the running stage of the industrial device in the prediction stage needs to be analyzed, and the abnormal data range of the running stage is analyzed.

[0044] First, all multidimensional normal historical feature values ​​are divided into multiple data segments, where the feature values ​​in a data segment are all data from the same operating state. Specifically, all multidimensional normal historical feature values ​​in the multidimensional feature value sequence are arranged in time sequence to form a multidimensional normal historical feature value sequence. For any dimension feature A, all normal historical feature values ​​under that dimension feature A are extracted from the multidimensional normal historical feature value sequence and arranged in time sequence to form a normal historical feature value sequence. Following the method for obtaining local trend values ​​described above, the local trend value of each normal historical feature value in the normal historical feature value sequence is obtained, and a change curve of the local trend value is constructed. Based on the single change characteristic of the local trend value (monotonic throughout), key points in the change curve are obtained to divide the change curve into several intervals according to the key points, and each interval shows only one change trend, such as monotonically increasing or monotonically decreasing. The normal historical feature value corresponding to each key point in the normal historical feature value sequence is obtained as the segmented feature value, that is, the segmentation node of the normal historical feature value sequence.

[0045] Similarly, all segmented feature values ​​under each dimension are obtained. Since the segmentation results of the normal historical feature value sequence under different dimensions will have certain differences, in order to ensure that all dimensions are in the same working stage, for the i-th segmented feature value under all dimensions, the average sampling time is calculated according to the sampling time corresponding to the i-th segmented feature value under each dimension, and the average sampling time is rounded down to obtain the i-th segmented time; all segmented times are obtained, and the multidimensional normal historical feature value sequence is divided into at least three multidimensional normal data segments according to the segmented times.

[0046] Then, considering that data closer to the prediction period better reflects the current data characteristics of the prediction period, if the prediction period is in the process of transitioning between two operating states, the current data with a long time interval may smooth out the data change characteristics during the transition. Therefore, in order to improve the accuracy of judging the equipment operating stage of the prediction period, the most recent 5 seconds including the current monitoring time are taken as the current period. Based on the similarity of the multidimensional feature value change trend between the current period and each multidimensional normal data segment, the similarity of the operating state between the current period and each multidimensional normal data segment is analyzed to adaptively obtain the normal feature value range of each dimension feature within the prediction period. For any multidimensional normal data segment, taking any dimension feature A as an example, following the method for obtaining local trend values ​​described above, the local trend value of each feature value under any dimension feature A in the any multidimensional normal data segment is obtained, and the average of the local trend values ​​of each feature value under any dimension feature A is taken as the overall feature value change trend value under any dimension feature A. Similarly, the overall feature value change trend value under each dimension feature in the any multidimensional normal data segment is obtained. The current data sequence for the current time period is obtained, resulting in the corresponding multidimensional feature value sequence. Following the method for obtaining the overall feature value change trend value described above, the overall feature value change trend value under each dimension feature in the current time period is obtained based on the multidimensional feature value sequence. Based on the difference in the overall feature value change trend value under the same dimension feature between the any multidimensional normal data segment and the current time period, the similarity of the operating states between the any multidimensional normal data segment and the current time period is obtained. The formula for calculating the similarity of the operating states between the any multidimensional normal data segment and the current time period is: in, This represents the similarity of the operational status between the y-th multidimensional normal data segment and the current time period. This represents the normalization function, and N3 represents the number of features in the dimension. This represents the overall feature value trend under any dimension feature A in the y-th multidimensional normal data segment. This represents the overall feature value trend under any dimension feature A in the current time period, where | represents the absolute value sign. This represents a hyperparameter used to ensure that the fraction is meaningful; we set 𝜀=0.01.

[0047] It should be noted that, The smaller the value, the more similar the current time period is to the operating state of the y-th multidimensional normal data segment under any dimension feature A. When the difference in the overall feature value change trend value under all dimensions is small, the similarity between the operating state of the y-th multidimensional normal data segment and the current time period is greater.

[0048] Similarly, the similarity of the operating state between each multidimensional normal data segment and the current time period is obtained. Finally, combining the similarity of the operating state between each multidimensional normal data segment and the current time period, the normal feature value range for each dimension feature applicable to the prediction time period after the current monitoring time is obtained. The specific method is as follows: for any multidimensional normal data segment, the upper limit and lower limit of the normal feature value under each dimension feature in the any multidimensional normal data segment are obtained using the 3σ principle. Let the upper limit of the normal feature value under any dimension feature A in the y-th multidimensional normal data segment be denoted as... The lower limit of normal characteristic values ​​is Similarly, the upper limit and lower limit of normal feature values ​​for each dimension feature in each multidimensional normal data segment are obtained. Then, by combining the similarity of the operating state between each multidimensional normal data segment and the current time period, as well as the upper limit and lower limit of normal feature values ​​for each dimension feature in each multidimensional normal data segment, the range of normal feature values ​​for each dimension feature applicable to the prediction period after the current monitoring time is obtained.

[0049] The method for obtaining the normal feature value range for each dimension feature applicable to the prediction period after the current monitoring time by combining the similarity of the operating state between each multidimensional normal data segment and the current time period, as well as the upper limit and lower limit of the normal feature value under each dimension feature in each multidimensional normal data segment, is as follows: For any dimension feature A, the similarity of the operating state between each of the multidimensional normal data segments and the current time period is used as a weight. The upper limit of the normal feature value under any dimension feature A in each of the multidimensional normal data segments is weighted and summed to obtain a sum. The adaptive upper limit of the normal feature value for any dimension feature A is obtained by using the sum as the numerator and the number of multidimensional normal data segments as the denominator. The formula for calculating the adaptive upper limit of the normal feature value for any dimension feature A is as follows: in, This represents the upper bound of the adaptive normal feature value for any feature A in any dimension. This represents the similarity of the operational status between the y-th multidimensional normal data segment and the current time period. N represents the upper limit of normal feature values ​​under any dimension feature A in the y-th multidimensional normal data segment, and N4 represents the number of multidimensional normal data segments.

[0050] Similarly, using the similarity of the operating state between each of the multidimensional normal data segments and the current time period as a weight, the lower bound of the normal feature value under any dimension feature A in each of the multidimensional normal data segments is weighted and summed to obtain a sum. The adaptive lower bound of the normal feature value of any dimension feature A is obtained by using the sum as the numerator and the number of multidimensional normal data segments as the denominator. Then, based on the upper limit and lower limit of the adaptive normal feature value of any dimension feature A, the range of normal feature values ​​of any dimension feature A applicable to the prediction period after the current monitoring time is obtained. .

[0051] According to the method for obtaining the normal feature value range of any dimension feature A applicable to the prediction period after the current monitoring time, the normal feature value range of each dimension feature applicable to the prediction period after the current monitoring time is obtained.

[0052] Step S104: Obtain multidimensional prediction feature values ​​within the prediction period, use the normal feature value range of each dimension feature to perform anomaly detection on the multidimensional prediction feature values, obtain the prediction anomaly degree of each dimension feature, and combine the prediction anomaly degree and anomaly risk response degree of each dimension feature to provide risk warning for the industrial Internet of Things.

[0053] The LSTM algorithm is used to predict the current data within 1 second after the current monitoring time, resulting in a current prediction data sequence for the prediction period, which is 1 second after the current monitoring time. The LSTM algorithm is existing technology and will not be described in detail here. The mean, root mean square, peak value, dominant frequency, and kurtosis of the current prediction data sequence are extracted to form multidimensional prediction feature values ​​for the prediction period. Anomaly detection is performed on the multidimensional prediction feature values ​​using the normal feature value range of each dimension. The anomaly detection method is as follows: For any predicted feature value in the multidimensional prediction feature values, if the predicted feature value is within the normal feature value range of the corresponding dimension feature, then the prediction anomaly degree of the dimension feature corresponding to the predicted feature value is 0; if the predicted feature value is not within the normal feature value range of the corresponding dimension feature, then the absolute value of the difference between the predicted feature value and the upper and lower limits of the normal feature value range of the corresponding dimension feature is calculated to obtain the minimum absolute value of the difference. The minimum absolute value of the difference is then normalized to obtain the prediction anomaly degree of the dimension feature corresponding to the predicted feature value.

[0054] The formula for calculating the degree of anomaly in the prediction of any predicted feature value corresponding to a dimensional feature is as follows: in, This indicates the degree of anomaly in the prediction of any dimension feature A. Represents the normalization function. This represents the function that takes the minimum value. This represents the upper bound of the adaptive normal feature value for any feature A in any dimension. This represents the adaptive lower bound of normal feature values ​​for any dimension of feature A. This represents the predicted feature value corresponding to any dimension feature A, that is, the predicted feature value belonging to any dimension feature A among the multidimensional predicted feature values, where | represents the absolute value symbol.

[0055] It should be noted that the more the predicted feature value exceeds the boundary of the normal feature value range of its corresponding dimension, the more... The larger the value, the greater the predicted degree of anomaly, indicating a higher probability of abnormal risks occurring in industrial equipment.

[0056] Similarly, the predicted anomaly level of each dimension feature is obtained. Since an anomaly in a single feature value may be due to accidental factors and does not necessarily indicate an abnormal risk, anomalies are only considered when multiple features show abnormal trends. Therefore, in this embodiment of the invention, the predicted anomaly level of each dimension feature is analyzed based on the predicted anomaly level and the abnormal risk response level of each dimension feature to provide risk warning for the Industrial Internet of Things: the product of the predicted anomaly level and the abnormal risk response level of each dimension feature is obtained, and the average of the products is recorded as the risk prediction level of the prediction period.

[0057] Abnormal current data will show high abnormality in multiple dimensions, while non-abnormal current data will show low abnormality in multiple dimensions or only show a certain abnormality in a certain dimension. By weighted averaging of the predicted abnormality of multiple dimensions, the risk prediction degree of abnormal and non-abnormal feature values ​​will be concentrated at both ends of the value range [0, 1]. Therefore, the midpoint of the value range, 0.5, is taken as the risk prediction degree threshold. The specific threshold can be adjusted according to the monitoring accuracy. If the risk prediction degree during the prediction period is greater than or equal to the preset risk prediction degree threshold, a risk warning will be issued for the industrial Internet of Things.

[0058] The formula for calculating the degree of risk prediction during the forecast period is as follows: Where E represents the degree of risk prediction for the prediction period, and N3 represents the number of dimensional features. This represents the degree of abnormal risk response of any dimension feature A. This indicates the degree of prediction anomaly for any dimension of feature A.

[0059] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. An industrial Internet of Things risk early warning method based on data analysis, characterized in that, The method comprises: Current data collection of the equipment in the industrial Internet of Things, obtaining a historical current data sequence in a preset time period before the current monitoring time, using a time window of a preset length, multi-dimensional feature extraction of the historical current data sequence, obtaining a multi-dimensional feature value sequence; For any dimension feature, extracting an accident feature value sequence of M historical risk accidents and all normal historical feature values of the any dimension feature in the multi-dimensional feature value sequence, according to the local trend change difference and the feature value difference between each accident feature value in each accident feature value sequence and the normal historical feature value, obtaining the abnormal risk response degree of the any dimension feature; Data segment division of the multi-dimensional normal historical feature values in the multi-dimensional feature value sequence, obtaining multi-dimensional normal data segments, according to the multi-dimensional feature value change trend similarity between the current time period containing the current monitoring time and each multi-dimensional normal data segment, obtaining the normal feature value range of each dimension feature suitable for the prediction period after the current monitoring time; Obtaining multi-dimensional prediction feature values in the prediction period, using the normal feature value range of each dimension feature, abnormality detection of the multi-dimensional prediction feature values, obtaining the prediction abnormality degree of each dimension feature, combining the prediction abnormality degree and the abnormal risk response degree of each dimension feature, risk warning of the industrial Internet of Things.

2. The industrial Internet of Things risk early warning method based on data analysis according to claim 1, characterized in that, The multi-dimensional features include mean, root mean square, peak value, main frequency and kurtosis, and the multi-dimensional feature extraction of the historical current data sequence using the time window of the preset length to obtain the multi-dimensional feature value sequence comprises: Using the time window of the preset length, dividing the historical current data sequence into a plurality of subsequences, for any subsequence, calculating the mean, root mean square, peak value, main frequency and kurtosis of the any subsequence to form the multi-dimensional feature value of the any subsequence, obtaining the multi-dimensional feature value of each subsequence, and normalizing all multi-dimensional feature values to obtain the multi-dimensional feature value sequence. 3.The industrial Internet of Things risk early warning method based on data analysis of claim 1, characterized in that, The abnormal risk response degree of the any dimension feature is obtained according to the local trend change difference and the feature value difference between each accident feature value in each accident feature value sequence and the normal historical feature value, which comprises: For any accident feature value sequence, according to the local trend difference between each accident feature value in the any accident feature value sequence and each normal historical feature value, obtaining the possibility index of each accident feature value in the any accident feature value sequence belonging to abnormal response data, and normalizing the cumulative value of all possibility indexes to obtain the response speed of the any dimension feature to abnormal risk reflected by the any accident feature value sequence. acquire a normal historical characteristic value time sequence in all normal historical characteristic values, the normal historical characteristic value time sequence is same in length with any accident characteristic value sequence, weight any accident characteristic value sequence with possibility index as weight, linear fitting any accident characteristic value sequence to obtain fitting value sequence, acquire sensitivity degree of any dimension characteristic reflected by any accident characteristic value sequence to abnormal risk according to characteristic value difference between fitting value sequence and each normal historical characteristic value time sequence; acquire product between response speed and sensitivity degree of any dimension characteristic reflected by any accident characteristic value sequence to abnormal risk, mark as reflecting degree of any dimension characteristic to abnormal risk under any accident characteristic value sequence, calculate average value between reflecting degrees of any dimension characteristic to abnormal risk under all accident characteristic value sequences to obtain abnormal risk reaction degree of any dimension characteristic.

4. The industrial Internet of Things risk early warning method based on data analysis according to claim 3, characterized in that, the acquiring possibility index of each accident characteristic value in any accident characteristic value sequence belonging to abnormal response data according to local trend difference between each accident characteristic value in any accident characteristic value sequence and each normal historical characteristic value, comprising: for any accident characteristic value in any accident characteristic value sequence, acquire local characteristic value set composed of nearest preset number of accident characteristic values of any accident characteristic value and any accident characteristic value, linear fitting local characteristic value set to obtain fitting slope, mark as local trend value of any accident characteristic value; acquire local trend value of each normal historical characteristic value, calculate absolute value of difference between local trend value of any accident characteristic value and local trend value of each normal historical characteristic value to obtain absolute value accumulation of difference, normalize absolute value accumulation of difference to obtain possibility index of any accident characteristic value belonging to abnormal response data.

5. The data analysis-based industrial Internet of Things risk early warning method according to claim 3, characterized in that, the acquiring sensitivity degree of any dimension characteristic reflected by any accident characteristic value sequence to abnormal risk according to characteristic value difference between fitting value sequence and each normal historical characteristic value time sequence, comprising: for any fitting value in fitting value sequence, acquire normal historical characteristic value at same position in each normal historical characteristic value time sequence according to position of any fitting value in fitting value sequence, mark as reference characteristic value, calculate absolute value of characteristic value difference between any fitting value and each reference characteristic value, accumulate all absolute values of characteristic value difference to obtain abnormal degree of any fitting value; acquire abnormal degree of each fitting value in fitting value sequence, normalize adding value of abnormal degrees of all fitting values in fitting value sequence to obtain sensitivity degree of any dimension characteristic reflected by any accident characteristic value sequence to abnormal risk.

6. The data analysis-based industrial Internet of Things risk early warning method according to claim 1, characterized in that, the data segment division of multi-dimensional normal historical characteristic value in multi-dimensional characteristic value sequence to obtain multi-dimensional normal data segment, comprising: All multi-dimensional normal historical feature values in the multi-dimensional feature value sequence are sequentially grouped into a multi-dimensional normal historical feature value sequence, for any dimensional feature, all normal historical feature values under the any dimensional feature are extracted from the multi-dimensional normal historical feature value sequence and sequentially grouped into a normal historical feature value sequence, a local trend value of each normal historical feature value in the normal historical feature value sequence is obtained, and at least two segmented feature values in the normal historical feature value sequence are obtained according to a single change characteristic of the local trend value; All segmented feature values under each dimensional feature are obtained, for an i th segmented feature value under all dimensional features, a sampling time point mean value is calculated according to a sampling time point corresponding to the i th segmented feature value under each dimensional feature, the sampling time point mean value is rounded down to obtain an i th segmented time point, and all segmented time points are obtained, and the multi-dimensional normal historical feature value sequence is divided into at least three multi-dimensional normal data segments according to the segmented time points.

7. The data analysis-based industrial Internet of Things risk early warning method according to claim 1, characterized in that, The normal feature value range of each dimensional feature suitable for a prediction period after the current monitoring time point is obtained according to a multi-dimensional feature value change trend similarity between a current period containing the current monitoring time point and each multi-dimensional normal data segment, and the method comprises the following steps: For any multi-dimensional normal data segment, an overall feature value change trend value of each dimensional feature in the any multi-dimensional normal data segment is obtained, an overall feature value change trend value of each dimensional feature in the current period is obtained, and a running state similarity between the any multi-dimensional normal data segment and the current period is obtained according to a difference between the overall feature value change trend values of the same dimensional feature between the any multi-dimensional normal data segment and the current period; The normal feature value upper limit and the normal feature value lower limit of each dimensional feature in the any multi-dimensional normal data segment are obtained by using the 3σ principle, and the normal feature value range of each dimensional feature suitable for the prediction period after the current monitoring time point is obtained by comprehensively considering the running state similarity between each multi-dimensional normal data segment and the current period and the normal feature value upper limit and the normal feature value lower limit of each dimensional feature in each multi-dimensional normal data segment.

8. The industrial Internet of Things risk early warning method based on data analysis according to claim 7, characterized in that, The normal feature value range of each dimensional feature suitable for the prediction period after the current monitoring time point is obtained by comprehensively considering the running state similarity between each multi-dimensional normal data segment and the current period and the normal feature value upper limit and the normal feature value lower limit of each dimensional feature in each multi-dimensional normal data segment, and the method comprises the following steps: For any dimensional feature, the running state similarity between each multi-dimensional normal data segment and the current period is taken as a weight, the normal feature value upper limit of the any dimensional feature in each multi-dimensional normal data segment is weighted and summed to obtain a sum value, and the adaptive normal feature value upper limit of the any dimensional feature is obtained by taking the sum value as a numerator and the number of multi-dimensional normal data segments as a denominator. The adaptive lower limit of the normal feature value of the any one dimensional feature is obtained by weighting and summing the normal feature values of the any one dimensional feature in each of the multi-dimensional normal data segments, with the running state similarity between each of the multi-dimensional normal data segments and the current time period as the weight, and the sum value is obtained, and the adaptive lower limit of the normal feature value of the any one dimensional feature is obtained by taking the sum value as the numerator and the number of multi-dimensional normal data segments as the denominator. The normal feature value range of the any one dimensional feature applicable to the prediction period after the current monitoring moment is obtained according to the adaptive upper limit of the normal feature value and the adaptive lower limit of the normal feature value of the any one dimensional feature.

9. The industrial Internet of Things risk early warning method based on data analysis according to claim 1, characterized in that, The abnormality detection of the multi-dimensional prediction feature value is performed by using the normal feature value range of each dimensional feature, and the prediction abnormality degree of each dimensional feature is obtained, including: For any one of the multi-dimensional prediction feature values, if the any one prediction feature value is within the normal feature value range of the corresponding dimensional feature, the prediction abnormality degree of the dimensional feature corresponding to the any one prediction feature value is 0; if the any one prediction feature value is not within the normal feature value range of the corresponding dimensional feature, the absolute values of the differences between the any one prediction feature value and the upper limit and the lower limit of the normal feature value range of the corresponding dimensional feature are calculated to obtain the minimum difference absolute value, and the minimum difference absolute value is normalized to obtain the prediction abnormality degree of the dimensional feature corresponding to the any one prediction feature value.

10. The data analysis-based industrial Internet of Things risk early warning method according to claim 1, characterized in that, The risk early warning of the industrial internet of things is performed by combining the prediction abnormality degree of each dimensional feature and the abnormal risk reaction degree, including: The product mean of the product of the prediction abnormality degree of each dimensional feature and the abnormal risk reaction degree is obtained as the risk prediction degree of the prediction period, and if the risk prediction degree of the prediction period is greater than or equal to the preset risk prediction degree threshold, the risk early warning of the industrial internet of things is performed.