Equipment anomaly detection method and device, equipment, storage medium and product

By acquiring multimodal data of the target device and comparing event graphs using anomaly detection and pattern recognition models, the problem of untimely device anomaly detection in existing technologies is solved, achieving highly accurate anomaly detection and prediction.

CN121935759APending Publication Date: 2026-04-28SUNGROW (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUNGROW (SHANGHAI) CO LTD
Filing Date
2024-10-25
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing technologies struggle to detect and track abnormal equipment behavior in a timely manner, primarily because monitoring methods relying on status indicators are not precise enough, resulting in unsatisfactory anomaly detection performance.

Method used

By acquiring multimodal data of the target device, anomaly detection is performed using a target anomaly detection model to generate a current event graph, which is then compared with historical event graphs carrying anomaly pattern labels to identify the device's anomaly patterns.

Benefits of technology

It enables timely detection and tracking of abnormal equipment performance, improves the accuracy of anomaly detection, and effectively predicts and detects abnormal events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121935759A_ABST
    Figure CN121935759A_ABST
Patent Text Reader

Abstract

The invention discloses an equipment anomaly detection method and device, equipment, a storage medium and a product. The method comprises the following steps: acquiring an anomaly detection task of target equipment and multi-modal data of a target component of the target equipment; based on the anomaly detection task and the modal type of the multi-modal data, calling a target anomaly detection model to perform anomaly detection on the multi-modal data to obtain a current anomaly detection result, and generating a current event atlas according to the current anomaly detection result; and calling a target abnormal mode recognition model based on the abnormal detection task to compare the current event atlas with the historical event atlas carrying the abnormal mode label, and obtaining the abnormal mode of the target equipment. The abnormal event can be effectively predicted and detected, the abnormal performance of the target equipment can be found and tracked in time, and the accuracy of abnormal detection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of equipment operation and maintenance technology, and in particular to a method, apparatus, equipment, storage medium and product for detecting equipment anomalies. Background Technology

[0002] Equipment malfunction typically refers to equipment being in an abnormal state, but this state does not necessarily mean that the equipment has completely lost its function or performance. Equipment malfunction is a precursor to equipment failure, an indication of decreased equipment performance or a change in its condition.

[0003] Equipment malfunctions exhibit relatively obvious symptoms, making them easy to detect and perceive. While numerous methods exist for fault detection, equipment anomalies are often more subtle and difficult to detect. Current anomaly detection methods primarily rely on monitoring equipment status indicators to determine malfunctions. However, the selection of these indicators directly impacts the detection results, leading to less than ideal detection outcomes and hindering timely discovery and tracking of abnormal equipment behavior. Summary of the Invention

[0004] This application provides a method, apparatus, device, storage medium, and product for detecting equipment anomalies, in order to solve the problem that it is difficult to detect and track abnormal equipment performance in a timely manner using status indicator monitoring methods.

[0005] In a first aspect, embodiments of this application provide a method for detecting device malfunctions, including:

[0006] Acquire anomaly detection tasks for the target device and multimodal data of the target components of the target device;

[0007] Based on the anomaly detection task and the modality type of the multimodal data, the target anomaly detection model is invoked to perform anomaly detection on the multimodal data, the current anomaly detection result is obtained, and the current event graph is generated based on the current anomaly detection result.

[0008] Based on the anomaly detection task, the target anomaly pattern recognition model is invoked to compare the current event graph with the historical event graph carrying anomaly pattern labels to obtain the anomaly pattern of the target device.

[0009] Secondly, embodiments of this application provide a device for detecting equipment malfunctions, comprising:

[0010] The task acquisition module is used to acquire the anomaly detection task of the target device and the multimodal data of the target components of the target device;

[0011] An anomaly detection module is used to call a target anomaly detection model to perform anomaly detection on the multimodal data based on the anomaly detection task and the modality type of the multimodal data, obtain the current anomaly detection result, and generate the current event graph based on the current anomaly detection result;

[0012] An anomaly pattern recognition module is used to call the target anomaly pattern recognition model based on the anomaly detection task to compare the current event map with the historical event map carrying anomaly pattern labels, so as to obtain the anomaly pattern of the target device.

[0013] Thirdly, embodiments of this application provide an electronic device, the electronic device comprising:

[0014] At least one processor; and

[0015] A memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the device anomaly detection method according to any embodiment of this application.

[0017] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the device anomaly detection method described in any embodiment of this application.

[0018] Fifthly, embodiments of this application provide a computer program product including a computer program, which, when executed by a processor, implements the device anomaly detection method described in any embodiment of this application.

[0019] The technical solution of this application embodiment acquires the anomaly detection task of the target device and the multimodal data of the target components of the target device; based on the modality type of the anomaly detection task and the multimodal data, it calls the target anomaly detection model to perform anomaly detection on the multimodal data, obtains the current anomaly detection result, and generates the current event graph based on the current anomaly detection result; based on the anomaly detection task, it calls the target anomaly pattern recognition model to compare the current event graph with the historical event graph carrying anomaly pattern labels to obtain the anomaly pattern of the target device. By constructing and comparing the historical event graph and the current event graph of anomaly events, the problem of difficulty in timely detection and tracking of abnormal device performance using status indicator monitoring methods is solved. It can effectively predict and detect anomaly events, timely detect and track the abnormal performance of the target device, and improve the accuracy of anomaly detection by calling the target anomaly detection model and the target anomaly pattern recognition model to detect and identify anomaly patterns in the multimodal data.

[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 A flowchart of a device anomaly detection method provided in Embodiment 1 of this application;

[0023] Figure 2 This is a schematic diagram of the structure of an equipment anomaly detection device provided in Embodiment 2 of this application;

[0024] Figure 3 A schematic diagram of the structure of an electronic device for implementing the device anomaly detection method of this application embodiment. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0026] It should be noted that the terms "first," "second," "third," and "fourth," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] Example 1

[0028] Figure 1 This is a flowchart of a device anomaly detection method provided in Embodiment 1 of this application. This embodiment can be applied to detecting whether there is an anomaly in the device during operation. The method can be executed by a device anomaly detection device, which can be implemented in hardware and / or software and can be configured in an electronic device.

[0029] like Figure 1 As shown, the method includes:

[0030] S110. Acquire the anomaly detection task of the target device and the multimodal data of the target components of the target device.

[0031] The target equipment can be understood as the equipment that needs to be detected for anomalies, such as photovoltaic power generation equipment, wind power generation equipment, energy storage equipment, electric vehicle charging equipment, and electrolysis hydrogen production equipment. The target equipment can be a standalone device or a relatively independent and complete operating unit within a standalone device. The target component can be understood as the component within the target device that needs to be tested, such as power converters like photovoltaic inverters, energy storage converters, and wind power converters, as well as photovoltaic modules, wind turbines, and energy storage batteries.

[0032] An anomaly detection task can be understood as a task used to instruct the detection of anomalies in the operating status of a target device. It can be input by maintenance personnel or automatically issued by the monitoring system. In this embodiment, the anomaly detection task may include: task content, task object, and task execution time, and can be represented using natural language such as voice and text. Multimodal data can be understood as operational data of different modalities generated by the target components of the target device during operation. Multimodal data can be sensor data collected within a preset time period.

[0033] For example, sensing data of the target device can be collected by different types of sensors placed at preset locations on the target device. Since the types of sensors differ, the modal types of the collected sensing data also differ. Sensors may include, for example, image sensors, voltage sensors, current sensors, sound sensors, temperature and humidity sensors, or pressure sensors. The sensing data collected by the sensors may involve images, audio, and signals, hence the term multimodal data. Multimodal data can also be acquired based on anomaly detection tasks by obtaining data from corresponding sensors. For example, if the anomaly detection task is "Please determine whether the valve of device A is abnormal based on the device's operating voltage, current, and monitoring data," then multimodal data collected by voltage sensors, current sensors, and monitoring devices around the valve of device A can be acquired.

[0034] S120. Based on the anomaly detection task and the modality type of the multimodal data, call the target anomaly detection model to perform anomaly detection on the multimodal data, obtain the current anomaly detection result, and generate the current event graph based on the current anomaly detection result.

[0035] The modal types of multimodal data can include images, audio, and signals. A target anomaly detection model can be understood as a model used for anomaly diagnosis analysis or prediction. In this embodiment, the target anomaly detection model can be a neural network model or a large language model. It is understood that different anomaly detection methods exist for different modal types of data and different anomaly detection tasks; therefore, multiple different target anomaly detection models can exist to perform anomaly detection on different modal types of data. For example, the target anomaly detection model can include: anomaly diagnosis and prediction models for image data, anomaly diagnosis and prediction models for audio data, and anomaly diagnosis and prediction models for signal data.

[0036] The current anomaly detection result can be understood as the detection result of whether the current operating state of each target component in the target device is abnormal, or the prediction result of whether there is a potential abnormal threat. The current event graph can be understood as an event graph based on the target device in its current operating state. An event graph can be understood as an event-centric knowledge representation form that constructs a knowledge network by describing event information and various relationships between events. The construction and application of the event graph involves several key technologies, including event extraction, event information completion, event relationship inference, and event prediction techniques, which will not be elaborated upon in this application. In the event graph, nodes represent events, and edges represent temporal, causal, sequential, and inclusion relationships between events.

[0037] Specifically, after acquiring the anomaly detection task and multimodal data, based on the task intent (anomaly diagnosis or anomaly prediction) and the multimodal data (images, audio, or signals), the corresponding target anomaly detection model is invoked to perform anomaly detection on each modality type of data, obtaining anomaly detection results. The events contained in the anomaly detection results are treated as nodes, and the relationships between nodes are treated as edges, constructing the current event graph.

[0038] S130. Based on the anomaly detection task, the target anomaly pattern recognition model is invoked to compare the current event graph with the historical event graph carrying anomaly pattern labels to obtain the anomaly pattern of the target device.

[0039] The target anomaly pattern recognition model can be understood as a model used to identify anomaly patterns of the target device. In this embodiment, the target anomaly pattern recognition model identifies anomaly patterns through graph comparison. The historical event graph can be considered as an event graph composed of anomaly events that occurred on the target device in the past, and each anomaly event carries a corresponding anomaly pattern label in the historical event graph. The anomaly pattern label is used to mark the anomaly pattern corresponding to the historical event graph; the anomaly pattern can be considered as an anomaly type defined based on the cause of the anomaly or the source of the anomaly, such as the component where the anomaly occurred.

[0040] Specifically, based on the task intent of the anomaly detection task, an appropriate target anomaly pattern recognition model is invoked. The target recognition model compares the current event map with the historical event map to determine the historical event map that matches the current event map. Based on the anomaly patterns corresponding to the historical event maps, the anomaly pattern of the target device is determined.

[0041] The technical solution of this application embodiment acquires the anomaly detection task of the target device and the multimodal data of the target components of the target device; based on the modality type of the anomaly detection task and the multimodal data, it calls the target anomaly detection model to perform anomaly detection on the multimodal data, obtains the current anomaly detection result, and generates the current event graph based on the current anomaly detection result; based on the anomaly detection task, it calls the target anomaly pattern recognition model to compare the current event graph with the historical event graph carrying anomaly pattern labels to obtain the anomaly pattern of the target device. By constructing and comparing the historical event graph and the current event graph of anomaly events, it is possible to effectively predict and detect anomaly events, and promptly discover and track the abnormal performance of the target device; and by calling the target anomaly detection model and the target anomaly pattern recognition model to detect and recognize anomaly patterns in the multimodal data, the accuracy of anomaly detection can be improved.

[0042] As an optional embodiment of this application, S120, the step of calling the target anomaly detection model to perform anomaly detection on the multimodal data based on the anomaly detection task and the modality type of the multimodal data, and obtaining the current anomaly detection result, includes:

[0043] S121. Based on the primary language model that serves as the intelligent agent for anomaly detection, a target anomaly detection model is matched from the anomaly detection model library according to the anomaly detection task and the modality type of the multimodal data.

[0044] The anomaly detection intelligent agent can be considered a proxy platform that uses artificial intelligence technology to identify and handle abnormal events in the workflow. Its main function is to match suitable target anomaly detection models for anomaly detection tasks. The anomaly detection model library can be considered a database used to store anomaly detection models. In this embodiment, the first major language model is used as the anomaly detection intelligent agent. It can be understood that the first major language model can be obtained by fine-tuning it with the training sample set of the corresponding anomaly detection model through anomaly detection tasks.

[0045] Specifically, a first prompt message is generated based on the anomaly detection task and the modality type of the multimodal data. The first prompt message is input into the first large language model, which is used as an intelligent agent for anomaly detection. A target anomaly detection model suitable for detecting each modality type of the input modality data is matched from multiple anomaly detection models stored in the anomaly detection model library.

[0046] S122. Call the target anomaly detection model to perform anomaly detection on the modal data corresponding to the modal type, and obtain the current anomaly detection result.

[0047] Specifically, based on the intelligent agent for anomaly detection, modal data of each modal type is input into the corresponding target anomaly detection model to obtain the current anomaly detection result output by each target anomaly detection model.

[0048] This application embodiment uses an anomaly detection intelligent agent to call the target anomaly detection model to perform anomaly detection on multimodal data. It can automatically monitor and analyze large amounts of data, quickly identify anomalies, reduce manual intervention, and improve the level of automation.

[0049] As an optional embodiment of this application, S130, the step of calling the target anomaly pattern recognition model based on the anomaly detection task to compare the current event map and the historical event map carrying anomaly pattern labels to obtain the anomaly pattern of the target device includes:

[0050] S131. Based on the second language model, which serves as an intelligent agent for anomaly pattern recognition, a target anomaly pattern recognition model is matched from the anomaly pattern recognition model library according to the anomaly detection task.

[0051] The anomaly pattern recognition intelligent agent can be considered a proxy platform that uses artificial intelligence technology to identify anomaly patterns in abnormal events. Its main function is to match suitable target anomaly pattern recognition models for anomaly detection tasks. The anomaly pattern recognition model library can be considered a database used to store anomaly pattern recognition models. In this embodiment, a second major language model is used as the anomaly detection intelligent agent. It is understood that the second major language model can be obtained by fine-tuning it using the training sample set of the anomaly detection task and the corresponding anomaly pattern recognition model.

[0052] Specifically, a second prompt message is generated based on the anomaly detection task. This second prompt message is then input into the second largest language model, which is used as an intelligent agent for anomaly pattern recognition. From multiple anomaly pattern recognition models stored in the anomaly pattern recognition model library, a target anomaly detection model suitable for identifying anomaly patterns in anomaly events is selected.

[0053] S132. Call the target anomaly pattern recognition model to calculate the graph similarity between the current event graph and the historical event graphs carrying anomaly pattern labels in the anomaly event graph library.

[0054] Specifically, the intelligent agent for anomaly pattern recognition calls the matched target anomaly pattern recognition model to calculate graph similarity for the current event graph and the historical event graphs in the anomaly event graph library that carry anomaly pattern labels.

[0055] For example, the graph similarity between the current event graph and the historical event graph can be calculated based on graph structure comparison, by comparing the number, type and connection method of nodes (events) and edges (relationships) between the current event graph and the historical event graph.

[0056] In an optional embodiment, the steps for constructing the anomaly event graph library include:

[0057] (1) Obtain multimodal failure timing data of the target device, wherein the multimodal failure timing data is sensing data of at least one target component of the target device collected during the historical failure process of the target device.

[0058] Specifically, multimodal failure data is collected from the target device or its surroundings as the device progresses from a normal state to a failure state over historical time using sensors. Since the failure process of the target device requires a certain amount of time, the multimodal failure data collected at each moment of the aging process constitutes multimodal failure time-series data.

[0059] (2) Based on the modality type of the multimodal failure time series data, call the anomaly detection model to perform anomaly detection on the multimodal failure time series data, and obtain the anomaly detection result time series data of the target device.

[0060] Among them, the anomaly detection result time series data can be considered as the time series data composed of the anomaly detection results of the single-modal data corresponding to the target component collected at each moment in the failure process of the target device.

[0061] Specifically, based on the modal type of the multimodal failure time series data, such as image, audio, or electrical signal, the corresponding anomaly detection model is called to perform anomaly detection on the failure time series data of each modal type, and the anomaly detection result time series data is composed of the anomaly detection results corresponding to the failure data of each modality at each time.

[0062] (3) Generate a historical event graph carrying anomaly pattern labels based on the anomaly detection result time series data; the event nodes in the historical event graph describe the attributes of the event, and the event node is the anomaly detection result of the target component at the node time; the edges between the event nodes represent the temporal and causal relationships between the event nodes.

[0063] Specifically, the anomaly detection result of each target component at each moment in the anomaly detection result time series data is taken as an event node. The edges between event nodes are formed according to the temporal and causal relationships between the anomaly detection results of different target components at different moments, thereby constructing a historical event graph. The historical event graph is then labeled with anomaly mode tags according to each anomaly mode of the target device.

[0064] (4) Construct an abnormal event graph library based on the historical event graph carrying abnormal pattern labels.

[0065] Specifically, after generating a historical event map with anomaly pattern labels for each abnormal event that occurred on the target device in the past, the map is written into the abnormal event map library.

[0066] This application embodiment constructs a historical event map using multimodal data collected from abnormal events that occur in the target device over a historical period. This allows for the intuitive presentation of the complex temporal and causal relationships between various components in abnormal events using an event map, thereby providing a reliable reference basis for the prediction and diagnosis of anomalies in the target device.

[0067] S133. The abnormal pattern corresponding to the historical event map with the highest graph similarity to the current event map and greater than the preset similarity threshold is determined as the abnormal pattern of the target device.

[0068] Among them, the preset similarity threshold is a pre-set similarity threshold that can be used to determine the abnormal patterns of the target device.

[0069] Specifically, the graph similarity between the current event graph and the historical event graph is compared with a preset similarity threshold. The historical event graph corresponding to the highest graph similarity among the preset similarity thresholds is determined as the historical event graph that matches the current event graph, and the abnormal pattern carried by the matched historical event graph is determined as the abnormal pattern of the target device.

[0070] Understandably, for the current event graph of an abnormal pattern, an abnormal pattern label can be generated based on the abnormal pattern, and the current event graph carrying the abnormal pattern label can be included in the historical event graph library as a historical event graph, so as to serve as an abnormal reference event for the prediction and diagnosis of abnormal patterns of the target device.

[0071] This embodiment compares the current event graph with the historical event graph carrying anomaly pattern labels to determine the anomaly pattern of the target device, enabling timely detection and prediction of anomalies in the target device.

[0072] In an optional embodiment of this application, step S110, which involves acquiring the anomaly detection task of the target device and multimodal data of at least one target component of the target device, includes:

[0073] S111. Based on the third language model as an interactive intelligent agent, the intent of the device health management task of the target device is identified to obtain the anomaly detection task.

[0074] The interactive intelligent agent can be considered as an agent platform that uses artificial intelligence technology to interact with external systems, primarily used for intent recognition of task instructions issued externally. In this embodiment, a third major language model is used as the interactive intelligent agent. It is understood that the third major language model can be obtained by fine-tuning a general-purpose large language model.

[0075] Health management tasks can be understood as tasks used to monitor, analyze, predict, diagnose, and maintain the operational status of target equipment. These tasks can be input by maintenance personnel or automatically issued by the PHM system. In this embodiment, equipment health management tasks may include: task content, task objects, and task execution time, and can be represented using natural language such as voice and text.

[0076] Specifically, upon receiving a device health management task, a fourth prompt is generated based on the task. The third prompt is then input into a third language model, which acts as an interactive intelligent agent to recognize the intent of the device health management task and identify an anomaly detection task requiring anomaly prediction or diagnosis of the target device. The anomaly detection task may include: the detection object, the detection content, and the detection indicators.

[0077] S112. Obtain multimodal data of the target component of the target device collected by the sensor according to the anomaly detection task.

[0078] Specifically, sensors collect real-time sensor data of target components of the target device for real-time monitoring. When acquiring anomaly detection tasks, multimodal data of the target components of the target device collected by the sensors are obtained based on the detection objects and content included in the anomaly detection task.

[0079] In an optional embodiment of this application, the method further includes:

[0080] Based on the fourth language model, which serves as an intelligent agent for report generation, a pre-built anomaly knowledge graph is retrieved according to the anomaly pattern to obtain anomaly knowledge information; and an anomaly diagnosis report containing anomaly detection results and solutions is generated based on the anomaly pattern and the anomaly knowledge information.

[0081] The report generation intelligent agent can be considered as a proxy platform that uses artificial intelligence technology to generate abnormal diagnostic reports. In this embodiment, a fourth major language model is used as the report generation intelligent agent. It can be understood that the fourth major language model can be obtained by fine-tuning a general large language model.

[0082] An anomaly knowledge graph can be understood as a network representing the relationships between knowledge such as the performance parameters, historical fault data, and common fault solutions of a target device in a graph structure. Anomaly knowledge information can be understood as the knowledge information in the anomaly knowledge graph that matches anomaly patterns. An anomaly diagnostic report can be considered as a diagnostic report generated based on anomaly knowledge information related to anomaly patterns, used to describe the anomaly detection results and provide solutions and related suggestions.

[0083] Specifically, a fourth prompt message is generated based on the anomaly pattern. This fourth prompt message is then input into the fourth language model, which serves as the intelligent agent for report generation. Anomaly knowledge graph is retrieved and constructed based on the anomaly pattern in the fourth prompt message to obtain anomaly knowledge information. Utilizing the processing capabilities of the fourth language model, a solution corresponding to the anomaly detection result is generated based on the anomaly pattern and anomaly knowledge information. Finally, an anomaly diagnosis report is generated based on the anomaly detection result and the solution.

[0084] This embodiment uses a large language model as an intelligent agent for report generation, which can improve the accuracy of anomaly diagnosis and resolution.

[0085] Example 2

[0086] Figure 2 This is a schematic diagram of a device for detecting equipment malfunctions according to Embodiment 2 of this application. Figure 2 As shown, the device includes: a task acquisition module 210, an anomaly detection module 220, and an anomaly pattern recognition module 230; wherein,

[0087] Task acquisition module 210 is used to acquire the anomaly detection task of the target device and the multimodal data of the target components of the target device;

[0088] Anomaly detection module 220 is used to call a target anomaly detection model to perform anomaly detection on the multimodal data based on the anomaly detection task and the modality type of the multimodal data, obtain the current anomaly detection result, and generate the current event graph based on the current anomaly detection result;

[0089] The anomaly pattern recognition module 230 is used to call the target anomaly pattern recognition model based on the anomaly detection task to compare the current event map and the historical event map carrying anomaly pattern labels to obtain the anomaly pattern of the target device.

[0090] The technical solution of this application embodiment acquires the anomaly detection task of the target device and the multimodal data of the target components of the target device; based on the modality type of the anomaly detection task and the multimodal data, it calls the target anomaly detection model to perform anomaly detection on the multimodal data, obtains the current anomaly detection result, and generates the current event graph based on the current anomaly detection result; based on the anomaly detection task, it calls the target anomaly pattern recognition model to compare the current event graph with the historical event graph carrying anomaly pattern labels to obtain the anomaly pattern of the target device. By constructing and comparing the historical event graph and the current event graph of anomaly events, it is possible to effectively predict and detect anomaly events, and promptly discover and track the abnormal performance of the target device; and by calling the target anomaly detection model and the target anomaly pattern recognition model to detect and recognize anomaly patterns in the multimodal data, the accuracy of anomaly detection can be improved.

[0091] Optionally, the anomaly detection module is specifically used for:

[0092] Based on the primary language model that serves as an intelligent agent for anomaly detection, a target anomaly detection model is matched from the anomaly detection model library according to the anomaly detection task and the modality type of the multimodal data.

[0093] The target anomaly detection model is invoked to perform anomaly detection on the modal data corresponding to the modal type, and the current anomaly detection result is obtained.

[0094] Optionally, the abnormal pattern recognition module 230 is specifically used for:

[0095] Based on the second language model, which serves as an intelligent agent for anomaly pattern recognition, a target anomaly pattern recognition model is matched from the anomaly pattern recognition model library according to the anomaly detection task and the current event graph.

[0096] The target anomaly pattern recognition model is invoked to calculate the graph similarity between the current event graph and the historical event graphs carrying anomaly pattern labels in the anomaly event graph library;

[0097] The abnormal pattern corresponding to the historical event graph that has the highest graph similarity to the current event graph and is greater than a preset similarity threshold is determined as the abnormal pattern of the target device.

[0098] Optionally, the steps for constructing the abnormal event graph library include:

[0099] Acquire multimodal failure time-series data of the target device, wherein the multimodal failure time-series data is sensor data of at least one target component of the target device collected during the historical failure process of the target device;

[0100] Based on the modality type of the multimodal failure time series data, an anomaly detection model is invoked to perform anomaly detection on the multimodal failure time series data, thereby obtaining the anomaly detection result time series data of the target device;

[0101] A historical event graph carrying anomaly pattern labels is generated based on the anomaly detection result time series data; the event nodes in the historical event graph describe the attributes of the events, and the event node is the anomaly detection result of the target component at the node time; the edges between the event nodes represent the temporal and causal relationships between the event nodes;

[0102] An abnormal event graph library is constructed based on the historical event graphs carrying abnormal pattern labels.

[0103] Optional, the task acquisition module 210 is specifically used for:

[0104] Based on the third language model, which serves as an interactive intelligent agent, intent recognition is performed on the device health management task of the target device to obtain an anomaly detection task.

[0105] The anomaly detection task acquires multimodal data of the target components of the target device collected by the sensors.

[0106] Optionally, the device further includes:

[0107] The report generation module is used to retrieve a pre-built anomaly knowledge graph based on the anomaly pattern, using the fourth language model as an intelligent agent for report generation, to obtain anomaly knowledge information; and to generate an anomaly diagnosis report containing anomaly detection results and solutions based on the anomaly pattern and the anomaly knowledge information.

[0108] The device anomaly detection apparatus provided in this application embodiment can execute the device anomaly detection method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects of executing the method.

[0109] Example 3

[0110] Figure 3 A schematic diagram of an electronic device 10, which can be used to implement embodiments of this application, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.

[0111] like Figure 3 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0112] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0113] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as device anomaly detection methods.

[0114] In some embodiments, the device anomaly detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the device anomaly detection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the device anomaly detection method by any other suitable means (e.g., by means of firmware).

[0115] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0116] In some embodiments, the device anomaly detection method may be implemented as a computer program, which is implicitly included in a computer program product. When executed by a processor, the computer program implements the device anomaly detection method of this application. The computer program product can be understood as a software product that primarily implements its solution through a computer program. The computer program used to implement the method of this application may be written in any combination of one or more programming languages. These computer programs may be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0117] In the context of this application, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0118] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0119] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0120] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0121] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this application can be achieved, and this is not limited herein.

[0122] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for detecting equipment malfunctions, characterized in that, include: Acquire anomaly detection tasks for the target device and multimodal data of the target components of the target device; Based on the anomaly detection task and the modality type of the multimodal data, the target anomaly detection model is invoked to perform anomaly detection on the multimodal data, the current anomaly detection result is obtained, and the current event graph is generated based on the current anomaly detection result; Based on the anomaly detection task, the target anomaly pattern recognition model is invoked to compare the current event graph with the historical event graph carrying anomaly pattern labels to obtain the anomaly pattern of the target device.

2. The equipment anomaly detection method according to claim 1, characterized in that, The step of invoking a target anomaly detection model to perform anomaly detection on the multimodal data based on the anomaly detection task and the modality type of the multimodal data, and obtaining the current anomaly detection result, includes: Based on the primary language model that serves as an intelligent agent for anomaly detection, a target anomaly detection model is matched from the anomaly detection model library according to the anomaly detection task and the modality type of the multimodal data. The target anomaly detection model is invoked to perform anomaly detection on the modal data corresponding to the modal type, and the current anomaly detection result is obtained.

3. The equipment anomaly detection method according to claim 1, characterized in that, The step of comparing the current event graph and the historical event graph carrying anomaly pattern labels based on the anomaly detection task to obtain the anomaly pattern of the target device includes: Based on the second language model, which serves as an intelligent agent for anomaly pattern recognition, a target anomaly pattern recognition model is matched from the anomaly pattern recognition model library according to the anomaly detection task and the current event graph. The target anomaly pattern recognition model is invoked to calculate the graph similarity between the current event graph and the historical event graphs carrying anomaly pattern labels in the anomaly event graph library; The abnormal pattern corresponding to the historical event graph that has the highest graph similarity to the current event graph and is greater than a preset similarity threshold is determined as the abnormal pattern of the target device.

4. The equipment anomaly detection method according to claim 3, characterized in that, The steps for constructing the abnormal event graph library include: Acquire multimodal failure time-series data of the target device, wherein the multimodal failure time-series data is sensor data of at least one target component of the target device collected during the historical failure process of the target device; Based on the modality type of the multimodal failure time series data, an anomaly detection model is invoked to perform anomaly detection on the multimodal failure time series data, thereby obtaining the anomaly detection result time series data of the target device; A historical event graph carrying anomaly pattern labels is generated based on the anomaly detection result time series data; the event nodes in the historical event graph describe the attributes of the events, and the event node is the anomaly detection result of the target component at the node time; the edges between the event nodes represent the temporal and causal relationships between the event nodes; An abnormal event graph library is constructed based on the historical event graphs carrying abnormal pattern labels.

5. The equipment anomaly detection method according to claim 1, characterized in that, The steps for acquiring anomaly detection task of target device and multimodal data of at least one target component of target device include: Based on the third language model, which acts as an interactive intelligent agent, intent recognition is performed on the device health management task of the target device to obtain an anomaly detection task; the third language model is compressed using large model compression technology and deployed in the edge server corresponding to the target device. The anomaly detection task acquires multimodal data of the target components of the target device collected by the sensors.

6. The equipment anomaly detection method according to any one of claims 1-5, characterized in that, Also includes: Based on the fourth language model, which serves as an intelligent agent for report generation, a pre-built anomaly knowledge graph is retrieved according to the anomaly pattern to obtain anomaly knowledge information. An anomaly diagnosis report containing anomaly detection results and solutions is generated based on the anomaly pattern and the anomaly knowledge information.

7. A device for detecting equipment malfunctions, characterized in that, The device includes: The task acquisition module is used to acquire the anomaly detection task of the target device and the multimodal data of the target components of the target device; An anomaly detection module is used to call a target anomaly detection model to perform anomaly detection on the multimodal data based on the anomaly detection task and the modality type of the multimodal data, obtain the current anomaly detection result, and generate the current event graph based on the current anomaly detection result; An anomaly pattern recognition module is used to call the target anomaly pattern recognition model based on the anomaly detection task to compare the current event map with the historical event map carrying anomaly pattern labels, so as to obtain the anomaly pattern of the target device.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the device anomaly detection method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the device anomaly detection method according to any one of claims 1-6.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the device anomaly detection method according to any one of claims 1-6.