Road equipment anomaly detection and operation and maintenance method based on Internet of Vehicles
By constructing a unified equipment status dataset and edge-cloud collaborative computing, combined with a hybrid anomaly identification model and an automatic hierarchical operation and maintenance strategy, the problems of data fragmentation, heavy cloud burden, and slow operation and maintenance response of road equipment have been solved, achieving efficient anomaly detection and intelligent operation and maintenance.
Patent Information
- Application Number
- CN202511896264.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-16
- Publication Date
- 2026-03-17
AI Technical Summary
Existing technologies for anomaly detection and maintenance of road equipment suffer from problems such as data fragmentation, excessive cloud load, low anomaly identification accuracy, and slow maintenance response. There is a lack of effective solutions for integrating data from multiple devices, balancing edge and cloud computing loads, improving anomaly identification accuracy, and achieving intelligent maintenance.
By constructing a unified equipment status dataset, adopting edge-cloud collaborative computing, and combining a hybrid anomaly identification model and an automatic hierarchical operation and maintenance strategy, dynamic weight fusion of multimodal data, preliminary anomaly identification, and in-depth analysis are achieved to enable real-time monitoring and intelligent management of equipment status.
It achieves efficient integration of data from multiple devices, reduces cloud computing latency, improves anomaly identification accuracy, shortens operation and maintenance response time, increases the utilization rate of operation and maintenance resources, and realizes intelligent operation and maintenance.
Smart Images

Figure CN121690954A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of vehicle networking and intelligent transportation technology, and more specifically, to a method for anomaly detection and maintenance of road equipment based on vehicle networking. Background Technology
[0002] With the rapid development of vehicle-to-everything (V2X) technology, the number of cameras, radars, roadside units (RSUs), and other equipment deployed along roads has increased significantly. These devices are core infrastructure for realizing vehicle-road cooperation, traffic flow monitoring, and emergency early warning. However, the current anomaly detection and maintenance of road equipment faces the following key challenges: Severe data fragmentation: Cameras, radars, RSUs and other devices belong to different manufacturers or management systems, and the data formats are not uniform. There is a lack of a unified device status dataset, which makes it impossible to achieve collaborative monitoring across devices.
[0003] Cloud computing overload: Existing technologies, such as the Industrial Internet security dynamic protection method and protection system with patent number CN115550145A, package and transmit device data to the cloud, relying solely on the cloud for big data analysis. Similarly, many existing technical solutions rely on the cloud platform to directly process the raw data of all devices. The large volume of raw data and the high real-time requirements lead to excessive cloud bandwidth consumption and increased computing latency, which cannot meet the needs of real-time anomaly detection.
[0004] Insufficient accuracy and generalization ability in anomaly detection: Existing anomaly detection methods, such as the method and device for detecting anomalies in the appearance of road traffic facilities, electronic equipment and media with patent number CN116798006A, use a pre-trained single ResNet network model for anomaly detection. As mentioned above, existing anomaly detection methods mostly use a single threshold judgment or supervised learning model. The former is easily affected by environmental interference, and the latter relies on a large number of labeled samples. However, anomaly samples of road equipment are scarce, resulting in poor model generalization ability.
[0005] Low operational and maintenance response efficiency: The road traffic facility appearance anomaly detection method, device, electronic equipment, and medium, as described in patent number CN116798006A, can report events to relevant departments in real time, providing real-time detection and early warning. However, existing systems, upon detecting anomalies, often only issue alarm signals, lacking classification of anomaly levels and corresponding handling strategy recommendations, leading to wasted operational and maintenance resources and response delays.
[0006] To address the aforementioned issues, existing technologies have not yet offered effective solutions. For example, early edge computing-based road equipment monitoring methods only achieved simple data filtering for single devices at the edge, without addressing the integration of data from multiple devices or the construction of a unified dataset. Further solutions have emerged, such as anomaly detection models for connected vehicle devices, but these employ purely supervised learning, rely on labeled samples, and fail to achieve collaborative computing between the edge and cloud, or tiered maintenance recommendations. Therefore, there is an urgent need for a technical solution that can integrate data from multiple devices, balance the computing load between the edge and cloud, improve anomaly identification accuracy, and achieve intelligent operation and maintenance. Summary of the Invention
[0007] In view of this, the present invention proposes a method for anomaly detection and maintenance of road equipment based on vehicle-to-everything (V2X) technology to solve the problems existing in the prior art.
[0008] To achieve the above objectives, this invention proposes a method for anomaly detection and maintenance of road equipment based on the Internet of Vehicles, including: The system acquires multimodal operational data of road equipment, performs standardization processing and dynamic weight fusion on the operational data, and integrates the standardized data and the dynamic weight fusion results in a hierarchical manner to obtain an equipment status dataset. Based on the device status dataset, preliminary anomaly identification is performed in the edge computing unit, and the device status dataset is uploaded to the cloud based on the preliminary anomaly identification results; Based on the device status data, anomalies are identified in the cloud using a hybrid anomaly identification model, and the anomaly identification results are fused and judged to obtain a health index. Anomalies are classified and determined based on the health indicators, and automatic operation and maintenance strategies are recommended based on the anomaly classification results to obtain anomaly state operation and maintenance strategies.
[0009] Optionally, the operational data includes device operational data, environment-related data, and interaction data, wherein the device operational data includes operational data of different devices, the environment-related data includes data of different environmental parameters, and the interaction data includes inter-device collaboration logs.
[0010] Optionally, the dynamic weight fusion process includes:
[0011] in, The global state vector is fused with weights. , For equipment physical distance, The correlation coefficient is the historical data. Represents distance and relevance weights. ;n This represents the total number of devices; the fusion weight is calculated based on the device correlation. This indicates that the dataset is being run.
[0012] Optionally, the preliminary anomaly identification may be preceded by: The device status dataset is preprocessed, including data cleaning, data dimensionality reduction, and data compression.
[0013] Optionally, the initial anomaly identification process includes: The device status dataset is judged by a dynamic threshold to obtain a suspicious anomaly judgment result, wherein the dynamic threshold is adjusted by environmental correlation data in the running data; A sliding window is used to perform first-order difference calculations on the running data, and the results of the first-order difference calculations are judged to obtain potential anomaly judgment results; The process of obtaining the dynamic threshold includes: The initial threshold is obtained by setting the initial threshold based on the normal equipment status using the normal distribution method; The contribution of environmental parameters is calculated using linear or exponential mapping. The correlation weight and mutual information weight between the operating status and environmental parameters are calculated, and the comprehensive weight is calculated based on the correlation weight and mutual information weight. The initial threshold is then adjusted based on the contribution of environmental parameters and the comprehensive weight to obtain the dynamic threshold.
[0014] Optionally, the hybrid anomaly recognition model includes a temporal sub-model for detecting temporal anomalies and an unsupervised learning sub-model for detecting pattern anomalies.
[0015] Optionally, in the hybrid anomaly recognition model, the temporal sub-model employs a long short-term memory network, and the unsupervised learning sub-model employs the isolated forest algorithm; The temporal sub-model takes device status data at different scales as input and output. In this sub-model, features at different scales are extracted from the device status data using a Long Short-Term Memory (LSTM) network. Self-attention features are calculated on the concatenated features at different scales using a self-attention mechanism. Importance weights at different scales are calculated separately using a query attention mechanism. These importance weights are then weighted with the features at different scales to obtain fused features. Finally, the fused features are weighted with the self-attention features to obtain temporal prediction data. The prediction error is then calculated based on the temporal prediction data. The Isolation Forest algorithm is used to calculate and judge equipment status data and prediction errors at the equipment level, road segment level, and region level to obtain equipment anomaly scores at these levels. The final anomaly score is obtained by weighting these equipment anomaly scores. In the road segment level judgment, the input data of the Isolation Forest algorithm consists of the characteristics of the equipment itself and the characteristics of related equipment at the road segment level. In the region level judgment process, the equipment status data and prediction errors at the region level are spatiotemporally aggregated and used as the input data of the Isolation Forest algorithm.
[0016] Optionally, the health index The acquisition process includes: ; in, 、 Representing different weights, This represents the time-series prediction bias output by the hybrid anomaly detection model. This represents the anomaly score output by the hybrid anomaly detection model.
[0017] Optionally, the process of obtaining abnormal state operation and maintenance strategies includes: Anomaly classification is performed on health indicators. Based on the anomaly classification results, the current fault characteristics are obtained. Based on the current fault characteristics, maintenance strategies are recommended to obtain the abnormal state maintenance strategy. The historical maintenance database includes related fault types, handling solutions, and repair times.
[0018] On the other hand, the present invention also provides a road equipment anomaly detection and maintenance system based on vehicle-to-everything (V2X) communication, for performing the above-described method; including: A unified equipment status dataset construction module is used to acquire multimodal operating data of road equipment, perform standardization processing and dynamic weight fusion on the operating data, and perform hierarchical integration of the standardized data and the dynamic weight fusion results to obtain the equipment status dataset. The edge-cloud collaborative computing module is used to perform preliminary anomaly identification in the edge computing unit based on the device status dataset, and upload the device status dataset to the cloud based on the preliminary anomaly identification results; The hybrid model anomaly identification module based on time series prediction and unsupervised learning is used to perform hybrid anomaly identification in the cloud based on the device status data through the hybrid anomaly identification model, and to perform fusion judgment based on the hybrid anomaly identification results to obtain health indicators. The automatic graded alarm and operation and maintenance strategy recommendation module is used to determine the anomaly grade based on the health index, and to recommend an automatic operation and maintenance strategy based on the anomaly grade determination result, so as to obtain the operation and maintenance strategy for the abnormal state.
[0019] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention achieves the following significant beneficial effects through the above technical solution: Improved data integration efficiency: The unified device status dataset solves the problem of data fragmentation across multiple devices, improves data standardization rate, and reduces cross-device data association time to the second level, providing comprehensive data support for anomaly identification.
[0020] The cloud burden is significantly reduced: edge preprocessing and preliminary anomaly identification reduce the amount of data uploaded to the cloud and lower cloud computing latency, thus meeting the real-time monitoring needs of vehicle networking.
[0021] Improved anomaly identification accuracy: The use of a hybrid model enhances the accuracy of anomaly identification and reduces the false alarm rate. Compared with existing single threshold methods and supervised learning methods, the accuracy is significantly improved, and it can effectively identify various anomaly types such as sudden and patterned anomalies.
[0022] Improved operation and maintenance response efficiency: Tiered alarms and intelligent strategy recommendations shorten the response time for Level 1 anomalies, improve the utilization rate of operation and maintenance resources, reduce operation and maintenance costs, and achieve the intelligent operation and maintenance goal of "early detection, early handling, and low cost" for road equipment. Attached Figure Description
[0023] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. In the drawings: Figure 1 This is a system module diagram in an embodiment of the present invention; Figure 2 This is an overall architecture diagram in an embodiment of the present invention; Figure 3 This is a flowchart of the anomaly detection process in an embodiment of the present invention. Detailed Implementation
[0024] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the disclosure to those skilled in the art. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0025] This invention relates to the field of vehicle-to-everything (V2X) and intelligent transportation technologies, specifically to a method for detecting and maintaining abnormal road equipment based on V2X, and further to a method for detecting abnormal road equipment and maintaining the entire process based on multi-source data fusion and edge-cloud collaborative reasoning. This method is applicable to real-time monitoring, anomaly identification, and intelligent operation and maintenance scheduling of key equipment such as roadside cameras, millimeter-wave radars, and roadside units (RSUs), which can improve the efficiency of road equipment fault response and ensure the stability of V2X data transmission and traffic control.
[0026] This invention aims to solve the problems of data fragmentation, heavy cloud burden, low anomaly recognition accuracy, and slow operation and maintenance response in the existing road equipment anomaly detection and operation and maintenance. It provides a road equipment anomaly detection and operation and maintenance method based on vehicle network, which realizes efficient monitoring and intelligent management of road equipment by constructing a unified equipment status dataset, edge-cloud collaborative computing, hybrid model anomaly recognition, and automatic hierarchical operation and maintenance.
[0027] This invention proposes a method for anomaly detection and maintenance of road equipment based on the Internet of Vehicles, including: A dynamic weighted multimodal data fusion mechanism addresses the issues of heterogeneity and correlation in device data. Edge-cloud collaborative inference balances real-time performance and detection accuracy, reducing the burden on the cloud. A hybrid model combining time-series prediction and unsupervised learning enables accurate identification of known / unknown anomalies; A tiered operation and maintenance closed loop based on health index upgrades from passive repair to proactive prediction.
[0028] This invention does not employ the single-device threshold detection or manual inspection mode found in existing technologies. Instead, it forms a unique technical solution through multi-source fusion, intelligent reasoning, and closed-loop operation and maintenance, demonstrating a certain degree of innovation.
[0029] This invention proposes a three-tier architecture of "edge preprocessing - cloud-based deep analysis - intelligent operation and maintenance closed loop," such as... Figures 1 to 3 As shown, the core technical solution includes the following four key modules, which work together to achieve anomaly detection and maintenance of road equipment: 1. Unified Device Status Dataset Construction Module: Data Acquisition and Standardization: Real-time operational data of road equipment is collected through vehicle-to-everything (V2X) communication protocols such as LTE-V2X and 5G-V2X. This includes: camera frame rate, resolution, lens temperature, power supply voltage, and recognition accuracy; radar detection range, point cloud density, and signal-to-noise ratio; and RSU communication bandwidth, signal strength, data transmission latency, and packet loss rate. To address the differences in data formats across different devices, a device data standardization protocol is designed: video stream data is converted into frame interval statistics, which can be expressed as the number of frames lost per second; point cloud data is converted into the percentage of effective detection points per unit time; and communication data is converted into minute-level average signal strength. Data dimensions are unified, such as timestamp, device ID, parameter type, value, and collection location, forming standardized data units.
[0030] The dataset is constructed in a hierarchical manner: a unified three-level dataset is built, consisting of "device-road segment-region". The device-level dataset records the real-time operating parameters of a single device; the road segment-level dataset integrates and dynamically merges standardized data from all devices within the same road segment; and the region-level dataset aggregates device data from multiple road segments to support collaborative analysis across road segments. The dataset is stored using a time-series index to ensure that the data can be traced back to specific time points and device locations.
[0031] The computational content of the unified device status dataset construction module mentioned above is as follows: Multi-source device status data is processed to perform dynamic weighted multimodal data standardization.
[0032] Data Acquisition Layer: Integrates three types of data: Equipment operation data: communication latency, packet loss rate, communication bandwidth and signal strength of RSU; frame rate, recognition accuracy, resolution, lens temperature and power supply voltage of camera; point cloud density, noise value and detection range of radar. Environmental data: rainfall, light intensity, and traffic flow, with traffic flow data obtained from vehicle-to-everything (V2X) terminals; Interactive data: Inter-device collaboration logs, which record the time synchronization deviation between the RSU and the radar.
[0033] Data standardization is achieved through a device data standardization protocol: defining a unified data format. ,in: For device types, such as RSU=1, camera=2, different devices are indicated by labels. These are the equipment operating status parameters. For environmental parameters, For interactive parameters; Standardize heterogeneous parameters : ,in This represents standardized heterogeneous data. For equipment The mean and standard deviation under normal conditions are calculated based on historical data.
[0034] In addition to standardizing the operational data of all devices, it also includes dynamic weight fusion: calculating fusion weights based on device correlation. Generate a global state vector To represent the global information content:
[0035] in , For equipment physical distance, The correlation coefficient is the historical data. Represents distance and relevance weights. .
[0036] 2. Edge-Cloud Collaborative Computing Module: Edge computing unit (ECU) real-time preprocessing and preliminary anomaly identification: Deploy edge computing units in each road segment, and connect with devices within that segment via short-range communication, such as WiFi 6 or LoRa, to achieve the following functions: Real-time data preprocessing: Standardized data is cleaned and dimensionality reduced. Cleaning removes outliers caused by communication interference, such as radar suddenly appearing ultra-long-range detection points. Principal component analysis (PCA) is used to extract core features of camera operating parameters, such as the "frame rate-temperature" correlation feature. The amount of preprocessed data is compressed by 60%-80%, and only the core feature data is transmitted to the cloud, reducing the bandwidth burden on the cloud.
[0037] Preliminary anomaly identification: Based on the historical normal operating parameters of the equipment, a dynamic threshold model is established to make real-time judgments on the preprocessed equipment data. If the parameters exceed the dynamic threshold, they are marked as "suspected anomalies" and the suspected anomaly data and corresponding equipment status characteristics are uploaded to the cloud. If the parameters are normal, historical data is only stored at the edge, with a storage period of 7 days. Data is automatically cleaned up after the storage period and does not need to be uploaded to the cloud.
[0038] Deep analysis and integration on the cloud platform: The cloud platform receives suspected abnormal data and core characteristics uploaded from the edge device and performs the following processing: Cross-device data fusion is performed using the dynamic weight fusion method described above: based on road segment / regional datasets, the operating status of different devices is associated to eliminate abnormal misjudgments caused by false alarms from a single device.
[0039] Cross-time period data fusion: By comparing the historical data of suspected abnormal devices, such as the frame rate changes of the same camera in the same time period over the past 3 months, and the data of similar devices, such as the current frame rate of 3 other cameras of the same model in the same road segment, long-term deviations in device operating status, such as a continuous decline in frame rate, and individual deviations, such as a camera whose frame rate is significantly lower than that of similar devices, the accuracy of anomaly identification is improved.
[0040] The computational tasks of the aforementioned edge-cloud collaborative computing module are as follows: Real-time preprocessing and preliminary anomaly identification at the edge have been implemented, along with a hierarchical inference mechanism for edge-cloud collaboration. Edge computing units deployed on the roadside perform the following operations: Real-time filtering: for standardized data or global state vector Set dynamic threshold range Depending on the environment Adaptive adjustment, such as relaxing the RSU communication latency threshold during heavy rain, where... Indicates the lower threshold. This indicates a high threshold; data exceeding this range is considered suspicious and marked as "suspected anomaly". In the adaptive adjustment method for dynamic thresholds, the above thresholds are adjusted using the following scheme: Dynamic thresholds adjust the normal range of equipment operating parameters in real time based on environmental parameters:
[0041] in: Indicates the upper and lower bounds of the basic threshold; Represents an environmental parameter vector; Indicates the weight of environmental factors; This indicates the adjustment amount of the upper and lower bound thresholds.
[0042] The initial threshold is set using the normal distribution method to determine the upper and lower bounds of the basic threshold: The process of using the normal distribution method includes:
[0043] in, This represents the mean of standardized data. Here, denoted as variance, and n represents the number of standardized data points.
[0044] The upper and lower bound threshold adjustments are calculated by weighted summation of the contributions of each environmental factor:
[0045] in, This indicates the contribution of the threshold adjustment amount. Weighting based on contribution.
[0046] To assess the contribution of the threshold adjustment, the following methods are used: linear adjustment, piecewise linear adjustment, and exponential adjustment, or a weighted approach. For example, if RSU communication latency has a linear relationship with rainfall, a linear threshold adjustment is used; if there is a piecewise linear mapping between camera frame rate and temperature, a piecewise linear threshold adjustment is used; and if extreme high temperatures have an exponential impact on equipment failure rate or heavy rain has a non-linear impact on wireless signal attenuation, an exponential adjustment is used. Depending on the actual situation, one or more methods can be combined to calculate the contribution of the threshold adjustment process. Linear adjustment:
[0047] Piecewise linear adjustment:
[0048] Index Adjustment:
[0049] in, Represents the linear mapping coefficients. Represents an environment parameter vector. Represents the reference value of the environmental parameter vector. Indicates offset, Indicates the segmented boundary values; This represents the exponential scaling factor. This represents the exponential growth coefficient.
[0050] Regarding contribution weights, the weights are first initialized, and then relevance processing is performed using correlation weights and mutual information weights. The correlation weights are based on the Pearson correlation coefficient.
[0051]
[0052] in, This represents the Pearson correlation coefficient. This represents the mean of environmental parameters. This represents the average value of the operating status. This represents the relevance weight.
[0053] Mutual information weights are used to capture nonlinearity.
[0054]
[0055] in, Indicates mutual information, This represents the joint probability of observed environmental parameters and operating status. This represents the independent probability of environmental parameters and operating status. This indicates the possible values for environmental parameters and operating status.
[0056] Overall weight :
[0057]
[0058] in, and This indicates the corresponding weight.
[0059] In addition to threshold judgment, it also includes temporal mutation detection: Temporal abrupt change detection: A sliding window is used, with a window size of... k =5s, calculate state parameters First-order difference :
[0060] in, Denotes the normalization factor, if , ,based on In principle, the data is identified as a "potential anomaly" and then compressed before being uploaded to the cloud with a compression rate of ≥50%, retaining only the keyframes before and after the mutation. Local alarms: In case of emergency anomalies, such as device offline or no radar data, a level 1 alarm is triggered directly. Level 1 alarms do not require waiting for cloud confirmation.
[0061] 3. Anomaly detection module based on a hybrid model of time series prediction and unsupervised learning: This invention designs a hybrid anomaly detection model to replace existing single threshold or supervised learning models, specifically including: The time-series prediction sub-model employs a Long Short-Term Memory (LSTM) network to predict the normal operating parameter range for the next 12 hours based on the device's operating data from the past 12 hours, such as frame rate and temperature. If the device's current actual parameters exceed the predicted range, they are marked as "time-series anomalies," making it suitable for identifying sudden changes in the device's operating status.
[0062] Unsupervised learning sub-models: such as Figure 3 As shown, the Isolation Forest algorithm is used to perform cluster analysis on cross-device and cross-time period data after cloud fusion, automatically identifying the "normal mode" and "abnormal mode" of device operation. This sub-model does not require labeled samples, can adapt to different device abnormality types in different scenarios, and is marked as "mode abnormality".
[0063] Anomaly fusion judgment: If a device is simultaneously marked as "timing anomaly" and "mode anomaly," it is judged as "confirmed anomaly." If only one of these conditions is met, the process returns to the edge for secondary monitoring to avoid false positives. Simultaneously, based on the duration of the anomaly (e.g., anomalies lasting more than 5 minutes) and the scope of impact (e.g., affecting communication of 5 surrounding devices), an anomaly severity index is calculated by scoring the duration and scope of impact. The anomaly severity index ranges from 0 to 10, with higher indices indicating greater urgency for anomaly classification. Alternatively, anomaly classification can be calculated using health status evaluation indicators.
[0064] The computational content of the anomaly detection module of the hybrid model based on time series prediction and unsupervised learning is as follows: Deep anomaly detection on a cloud platform for a hybrid model combining time-series prediction and unsupervised learning: The cloud receives "suspicious data" and "potentially abnormal" data uploaded from the edge devices and performs in-depth analysis: Step 1: Normal Behavior Prediction Based on LSTM: To improve the accuracy of temporal anomaly detection, a multi-scale long short-term memory network architecture was designed. This architecture simultaneously captures the short-term, medium-term, and long-term dependencies of device operating parameters, significantly improving prediction accuracy and generalization ability. Equipment status Divided into three sequences according to time scale: (Short-term, such as 1 hour) (Mid-term, such as 6 hours) (Long-term, such as 12 hours), where d is the feature dimension. The hidden state calculation of LSTM at each scale is as follows:
[0065]
[0066]
[0067] Output the corresponding short-term, medium-term, and long-term size features for the above content. , , Input data for the next attention mechanism Multi-scale feature fusion is achieved through an attention mechanism, targeting the spliced sequences of different scales of the above outputs. Perform the following calculations:
[0068]
[0069]
[0070] in, Indicates learnable parameters, , , Represents a query, key, and value vector.
[0071]
[0072] Perform the following calculations for each individual sequence: Importance weights for each scale feature are assigned via query vectors. calculate:
[0073]
[0074] in, , , Indicates learnable parameters, , To represent different scale features This indicates that the length is consistent across short, medium, and long-term periods, padded with zeros. `q` represents the query vector of environmental parameters transformed through a linear mapping.
[0075] Features of different sizes are fused based on the importance weight of each scale feature mentioned above:
[0076] The different attention mechanisms mentioned above are then integrated:
[0077]
[0078]
[0079] in, This indicates the weights for later fusion of different sizes. Indicates the learnable weight parameters. Indicates the offset item. This indicates the calculation of the mean. Indicates the final characteristic.
[0080] The final predicted equipment operating status data is calculated using a mapping method. :
[0081] Calculate the prediction error:
[0082] like ( (The dynamic error threshold, which is dynamically updated based on historical prediction accuracy), is marked as "prediction deviation anomaly".
[0083] Step 2: Unsupervised anomaly clustering based on isolated forest To address the limitations of existing isolated forest algorithms in cross-device and cross-time period anomaly detection, this invention proposes a hierarchical isolated forest architecture. This architecture comprises three detection levels: device-level, road segment-level, and region-level. Different isolated forest models are used to perform anomaly detection on data at the device, road segment, and region levels, and the results are fused to generate a comprehensive anomaly score, achieving anomaly detection coverage from micro to macro levels.
[0084] Equipment-level anomaly detection focuses on the operational status of individual devices, and its anomaly score is calculated as follows:
[0085] in , For the sample Path length in an isolated tree For standardization factors, This represents the expected value of the path length among all trees in an isolated forest.
[0086] Road segment-level anomaly detection considers the correlation between devices within the same road segment, and its feature construction is as follows:
[0087] in The correlation coefficient between devices. This is to account for synchronization deviation between devices. This indicates the characteristics of the equipment's own operating status. This indicates the characteristics of related neighboring devices.
[0088] Road segment level anomaly score calculation:
[0089] Regional-level anomaly detection identifies cross-road segment anomaly patterns from a more macroscopic perspective, and the feature matrix is constructed as a spatiotemporal aggregation of road segment features:
[0090]
[0091]
[0092] Among them, aggregation operation This indicates the mean feature over the time dimension. Fluctuation characteristics in the time dimension spatial dimension correlation characteristics and characteristics of spatiotemporal propagation modes The aforementioned mean characteristics, fluctuation characteristics, correlation characteristics, and spatiotemporal propagation pattern characteristics are extracted through splicing using existing relevant statistical methods or neural network models. This represents the segment-level feature vector of the i-th road segment at time t'. The region contains the total number of road segments, T represents the time window length, and f represents the feature vector.
[0093] The final anomaly score is obtained through hierarchical fusion:
[0094] in, 、 、 Indicates the corresponding weight. Outputs anomaly scores. The closer it is to 1, the higher the probability of an anomaly.
[0095] Step 3: Calculation of Equipment Health Index By combining prediction bias and anomaly scores, a health index is defined:
[0096] in As weight, , This is determined to be an abnormal state.
[0097] 4. Automatic hierarchical alarm and maintenance strategy recommendation module: Tiered alert mechanism: Based on the severity index, anomalies are divided into three levels: Level 1 Alarm (Index 8-10): Emergency anomaly, such as complete communication interruption of RSU, radar inability to detect targets, which may lead to vehicle-road cooperation failure and missed traffic incidents. The system will immediately notify the operation and maintenance manager via SMS and telephone, and will also display a pop-up notification on the operation and maintenance platform, dispatching the nearest operation and maintenance personnel with backup equipment to arrive at the scene within 30 minutes.
[0098] Level 2 Alarm (Index 4-7): General anomalies, such as a decrease in camera frame rate but still meeting basic monitoring requirements, or slight fluctuations in RSU signal strength. The system pushes alarm information through the operation and maintenance platform, generates a scheduled maintenance order, and requires a repair response within 24 hours.
[0099] Level 3 alarm (index 0-3): Minor anomaly, such as equipment temperature slightly higher than the historical average but within the safe range. The system records the anomaly log, performs remote parameter optimization, such as restarting the equipment, directly adjusting the equipment parameters, and handles it during regular maintenance.
[0100] Intelligent recommendation of operation and maintenance strategies: Based on anomaly type, device location, and distribution of operation and maintenance resources, a strategy recommendation model is built. If it is a Level 1 alarm, the system will automatically query the location of the nearest maintenance personnel to the equipment, locate them through the maintenance personnel's APP, calculate the optimal route, and recommend the spare parts to carry. If it is a level 2 alarm, the system analyzes historical operation and maintenance data, determines the most likely cause of the fault, recommends maintenance actions, and schedules a maintenance time, prioritizing periods with low traffic flow. If it is a level 3 alarm, the system integrates all slightly abnormal devices in the same area, remotely optimizes parameters, generates a regular maintenance list, recommends batch maintenance solutions, and reduces operation and maintenance costs.
[0101] The calculations for the aforementioned automatic hierarchical alarm and operation and maintenance strategy recommendation module are as follows: Intelligent hierarchical alarm and operation and maintenance strategy generation to achieve dynamic priority-based operation and maintenance closed loop: Abnormality classification: based on health index The scope of influence is divided into three levels: Level 1 Alert: Or the equipment may completely fail, affecting the secure communication of the vehicle network; Level 2 Alarm: Performance degrades significantly; Level 3 Alert: Performance is slightly degraded.
[0102] Recommended automated operation and maintenance strategies: Based on a historical operations and maintenance database, which includes fault type, handling plan, and repair time, a collaborative filtering algorithm is used.
[0103] in The current fault characteristics are as follows: Characteristics of historical faults For feature similarity, For the plan Historical efficiency This indicates the score for the corresponding handling plan; in, Calculated using weighted mixed similarity:
[0104]
[0105]
[0106] in, and This represents numerical feature similarity and categorical feature similarity. This represents the observed values during equipment operation. This represents the set of category features, where the subscript i represents the current device and the subscript s represents the queried device. Represents a constant.
[0107] Choose the treatment option with the highest rating and use it.
[0108] The deficiencies of the prior art addressed by this invention include, or may include, the following: Existing road equipment, such as traffic cameras, roadside radars, and RSUs, mainly relies on the following methods for anomaly detection: Single device independent monitoring: Detecting faults through built-in sensors such as temperature sensors can only identify hardware damage such as power outages or offline status, but cannot detect performance degradation; Manual inspection + periodic calibration: Relies on on-site inspections by maintenance personnel, which is lagging and cannot quantify the health status of the equipment; Simple threshold judgment: By setting fixed thresholds, dynamic environmental changes are not considered, resulting in a high false alarm rate.
[0109] Existing technical shortcomings: Data silos: Data from each device is stored independently, failing to utilize the interrelationships between devices; Insufficient real-time performance: Reliance on centralized cloud processing and massive data transmission leads to excessive latency, failing to meet the low-latency requirements of vehicle networking; Limited anomaly modes: Only able to identify known faults, lacking the ability to detect new anomalies; Passive operation and maintenance: Alarms are only triggered after a fault occurs, lacking a predictive maintenance mechanism.
[0110] In summary, the technical problems to be solved are as follows: How to integrate data from multiple heterogeneous devices to achieve cross-device and cross-scenario anomaly correlation analysis; how to balance real-time performance and detection accuracy, quickly filtering normal data at the edge and uploading only suspicious data to the cloud; how to identify unknown anomaly patterns and quantify device health status, achieving an upgrade from "fault repair" to "predictive maintenance"; and how to automatically generate operation and maintenance strategies based on anomaly levels to improve handling efficiency.
[0111] Compared with the prior art, this invention has the following outstanding innovative features, and does not conflict with or resemble the prior art: A hierarchical construction scheme for a unified equipment status dataset: Existing technologies only collect data for a single equipment type. This invention solves the problem of fragmented data across multiple equipment by designing a cross-equipment data standardization protocol and constructing a three-level dataset of "equipment-road segment-region". This provides a foundation for cross-equipment and cross-time period fusion analysis. This dataset construction method has not been disclosed in existing patents.
[0112] The edge-cloud collaborative three-level computing architecture of "preprocessing-preliminary identification-deep fusion" is as follows: Existing edge computing only realizes single data filtering. This invention adds dynamic threshold preliminary anomaly identification at the edge, only uploading suspected abnormal data, while realizing cross-device / cross-time period data fusion in the cloud. This not only reduces the burden on the cloud and the amount of data transmission, but also improves the accuracy of anomaly identification. This collaborative architecture is fundamentally different from the existing technology's "simple edge filtering + full cloud computing" mode.
[0113] Hybrid anomaly detection model combining temporal prediction and unsupervised learning: Existing technologies rely on a single threshold or supervised learning. This invention improves LSTM temporal prediction to identify sudden anomalies and improves isolated forest unsupervised learning to identify patterned anomalies. Moreover, it does not require labeled samples, thus solving the problem of poor generalization ability caused by the scarcity of anomaly samples. This hybrid model design has not been applied in existing road equipment anomaly detection technologies.
[0114] A hierarchical alarm and intelligent strategy recommendation mechanism based on an anomaly severity index: Existing technologies only implement alarm functions. This invention divides alarm levels by an anomaly severity index and recommends customized operation and maintenance strategies based on device location, operation and maintenance resources, and historical data, realizing a closed loop of "detection-alarm-handling" and improving operation and maintenance efficiency. This mechanism fills the gap in the automatic recommendation of operation and maintenance strategies in existing technologies.
[0115] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A road equipment anomaly detection and operation method based on Internet of Vehicles, characterized in that, The method comprises the following steps: acquiring multi-modal operation data of a road device, performing standardization processing and dynamic weight fusion on the operation data, performing hierarchical integration on the standardization-processed data and the dynamic weight fusion result, and obtaining a device state data set; performing preliminary anomaly identification on the device state data set in an edge computing unit, and uploading the device state data set to a cloud end according to the preliminary anomaly identification result; performing anomaly identification on the device state data in the cloud end through a hybrid anomaly identification model, and performing fusion judgment according to the anomaly identification result to obtain a health degree index; performing anomaly grading judgment according to the health degree index, and performing automatic operation and maintenance strategy recommendation according to the anomaly grading judgment result to obtain an abnormal state operation and maintenance strategy.
2. The method of claim 1, wherein the operation data comprises device operation data, environment-related data, and interaction data, wherein the device operation data comprises operation data of different devices, the environment-related data comprises data of different environment parameters, and the interaction data comprises device interaction logs.
3. The method of claim 1, wherein the process of dynamic weight fusion comprises:
4. The method of claim 1, wherein the preliminary anomaly identification further comprises: performing preprocessing on the device state data set, wherein the preprocessing comprises data cleaning, data dimension reduction, and data compression. , wherein, is a global state vector, fusion weight , is a device physical distance, is a historical data correlation coefficient, denotes distance and correlation weight, ; n represents the total number of devices, and the fusion weight is calculated according to the device correlation; denotes a running data set.
5. The method of claim 1, wherein the process of preliminary anomaly identification comprises: performing judgment on the device state through a dynamic threshold to obtain a suspicious anomaly judgment result, wherein the dynamic threshold is adjusted through the environment-related data in the operation data; performing first-order difference calculation on the operation data through a sliding window, and performing judgment on the first-order difference calculation result to obtain a potential anomaly judgment result; wherein the process of obtaining the dynamic threshold comprises: setting an initial threshold through a normal distribution method according to a normal device state to obtain the initial threshold; calculating an environment parameter contribution degree through linear mapping or exponential mapping, calculating a correlation weight and a mutual information weight between the operation state and the environment parameter, calculating a comprehensive weight according to the correlation weight and the mutual information weight, adjusting the initial threshold according to the environment parameter contribution degree and the comprehensive weight, and obtaining the dynamic threshold.
6. The method of claim 1, wherein the hybrid anomaly identification model comprises a time series sub-model for detecting time series anomalies and an unsupervised learning sub-model for detecting pattern anomalies.
7. The method of claim 6, wherein in the hybrid anomaly identification model, the time series sub-model adopts an improved long short-term memory network, and the unsupervised learning sub-model adopts an isolation forest algorithm. The input and output of the time sequence sub-model are device state data of different scales, in the time sequence sub-model, different scale feature extraction is performed on the device state data of different scales through a long short-term memory network, self-attention mechanism is used to calculate the spliced different scale features to obtain self-attention features, query attention mechanism is used to calculate the different scale features respectively to obtain different scale importance weights, the different scale importance weights and the different scale features are weighted to obtain fusion features, the fusion features and the self-attention features are weighted to obtain time sequence prediction data; and a prediction error is calculated according to the time sequence prediction data; The device level, road section level and regional level device anomaly scores are obtained by calculating and judging the device state data and the prediction error of the device level, the road section level and the regional level through the hierarchical isolation forest algorithm, and the final anomaly score is obtained by weighting the device anomaly scores of the device level, the road section level and the regional level; in the judgment of the road section level, the input data of the isolation forest algorithm is the features of the road section level device itself and the associated devices, and in the judgment process of the regional level, the device state data and the prediction error of the regional level are spatiotemporally aggregated as the input data of the isolation forest algorithm.
8. The method of claim 1, wherein, The healthiness indicator The acquisition process comprises: ; wherein, , denote different weights, denotes a time series prediction bias of the hybrid anomaly recognition model output, denotes an anomaly score of the hybrid anomaly recognition model output.
9. The method of claim 1, wherein, The obtaining process of the abnormal state operation and maintenance strategy includes: The health degree index is subjected to abnormal grading judgment, the current fault feature is obtained according to the abnormal grading judgment result, and the operation and maintenance strategy is recommended according to the current fault feature through a recommendation algorithm based on a historical operation and maintenance database to obtain an abnormal state operation and maintenance strategy, wherein the historical operation and maintenance database includes associated fault types, processing schemes and repair times; The recommendation algorithm is: , wherein is a current failure feature, is a historical failure feature, is a feature similarity, is a scheme a historical efficiency, denotes a corresponding treatment scheme score, and the treatment scheme with the highest score is selected as an abnormal state operation and maintenance strategy for recommendation. 10.A road equipment anomaly detection and operation and maintenance system based on a vehicle-to-everything, characterized in that, A device for executing the method of any one of claims 1-9.
Citation Information
Patent Citations
Industrial internet security dynamic protection method and protection system
CN115550145A
Road traffic facility appearance anomaly detection method and device, electronic equipment and medium
CN116798006A
Cited By
Cloud edge collaboration-based service fault root cause analysis method and system
CN122293486A