Abnormality recognition method and system based on dimming level switching behavior
Patent Information
- Application Number
- CN202610687404.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-19
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2046-05-19
AI Technical Summary
然而,该类方法通常未能建立指令行为与执行器响应之间的结构性关联,尤其在存在网络抖动、缓存堆积或时钟偏移等情况下,容易将正常的链路波动误判为异常,从而产生大量伪异常结果
对行为特征数据进行行为承载状态提取,得到行为负载数据;
Smart Images

Figure CN122220853B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent lighting control technology, and in particular to an anomaly identification method and system based on dimming level switching behavior. Background Technology
[0002] In intelligent lighting systems and dimming control links, dimming commands are typically transmitted through multiple levels of devices and ultimately act on actuators, involving multiple clock domains at the control end, communication link, and actuator end. Due to differences in sampling frequency, transmission delay fluctuations, and device response differences among nodes, the timing data in the dimming link exhibits significant asynchronous characteristics. Against this backdrop, traditional anomaly detection methods based on a single time axis or local signals struggle to accurately represent the true behavioral relationships across devices. Existing technologies often employ threshold judgments or simple statistical analysis to identify dimming anomalies, such as detecting abnormal command frequencies, excessive response delays, or deviations in execution states. However, these methods typically fail to establish a structural correlation between command behavior and actuator response. Especially in the presence of network jitter, buffer buildup, or clock skew, normal link fluctuations are easily misjudged as anomalies, resulting in numerous false anomaly results. Furthermore, for genuine attack behaviors (such as illegal command injection, replay attacks, or tampering), the lack of analytical tools makes it difficult to effectively distinguish them from normal fluctuations. Summary of the Invention
[0003] To address the aforementioned technical problems, this invention proposes an anomaly identification method and system based on dimming level switching behavior, thereby resolving at least one of the aforementioned technical problems.
[0004] This application provides an anomaly identification method based on dimming level switching behavior, including the following steps: Acquire multi-source timing data of the dimming link, perform asynchronous phase self-consistent synchronization on the multi-source timing data, and obtain asynchronous command behavior data; Based on the asynchronous instruction behavior data, instruction interval features are extracted to obtain switching feature data; based on the asynchronous instruction behavior data, the executor trajectory is reconstructed to obtain behavior feature data. Instruction density data is constructed based on switching feature data and behavioral feature data; cross-clock verification is performed on the instruction density data to obtain cross-clock verification data. By separating pseudo-anomalies from real attacks in cross-clock verification data, anomaly identification data is obtained.
[0005] This invention constructs a multi-source timing data processing system for dimming command links. Through asynchronous phase self-consistent synchronization, it achieves unified alignment of clock differences and transmission delays between different acquisition terminals, effectively eliminating interference caused by traditional timestamp alignment errors. By extracting command interval features and reconstructing actuator behavior trajectories, dual-channel behavioral representations are established from the control and execution sides respectively, enabling the system to simultaneously perceive the coupling relationship between command generation patterns and physical response processes. By fusing switching features and behavioral features to construct a command density model and performing consistency checks across clock domains, it can effectively identify timing distortion phenomena caused by factors such as network congestion and cache accumulation, avoiding misjudging them as abnormal behavior. By separating and distinguishing between false anomalies and real attacks in the cross-clock check results, it achieves refined identification and attribution analysis of anomaly sources, thereby improving the accuracy and robustness of anomaly detection in dimming control systems in IoT environments, reducing false alarm rates, and enhancing the system's security protection capabilities.
[0006] Optionally, asynchronous phase self-consistent synchronization specifically refers to: Multi-source time series potential encoding is performed on multi-source time series data to obtain time series potential data; Cross-source anchor points are extracted based on time-series potential data to obtain cross-source anchor point data; By performing joint estimation of offset and drift on cross-source anchor point data, mapping function data is obtained; The asynchronous instruction behavior data is obtained by reconstructing the entire sequence based on the mapping function data.
[0007] This invention utilizes multi-source temporal potential encoding to convert the original asynchronous timestamps into potential representations with a unified reference, effectively mitigating the impact of clock drift and sampling bias between different acquisition sources. By extracting cross-source anchor points, a key alignment benchmark is established between data sources, enabling the system to achieve structural alignment even without a unified clock. Combined with joint estimation of offset and drift, a continuously varying mapping function is constructed, simultaneously compensating for fixed delays and dynamic jitter, thus avoiding the distortion problems caused by relying solely on static correction in traditional methods. Through full-sequence reconstruction, time-consistent and structurally self-consistent asynchronous instruction behavior data is obtained, allowing subsequent instruction interval analysis and behavior trajectory modeling to be based on a unified time benchmark. This improves data comparability and temporal consistency in network environments, enhancing the system's accuracy in identifying temporal spoofing and delay perturbations.
[0008] Optionally, the instruction interval feature extraction specifically involves: Adjacent instruction pairing is performed based on asynchronous instruction behavior data to obtain instruction interval data; Interval distribution analysis is performed on the instruction interval data to obtain interval statistical characteristic data; Quasi-periodic manifold extraction is performed on the instruction interval data to obtain quasi-periodic manifold data; Based on the instruction interval data, a switching amplitude coupling analysis is performed to obtain switching coupling characteristic data; Switching feature data is obtained by organizing switching features based on interval statistical feature data, quasi-periodic manifold data, and switching coupling feature data.
[0009] This invention constructs a refined instruction interval sequence by pairing adjacent instructions in asynchronous instruction behavior data. Combined with interval distribution analysis, statistical features reflecting the overall temporal rhythm and fluctuation characteristics are extracted, enabling the system to perceive the temporal distribution pattern of dimming instructions at a global level. Through quasi-periodic manifold extraction, the original interval sequence is mapped to a low-dimensional structural space, representing its potential periodicity and evolutionary trajectory, effectively identifying the difference between structural disturbances caused by network latency and natural control rhythms. Simultaneously, by combining switching amplitude coupling analysis, the time interval and dimming level change amplitude are jointly modeled, enhancing the perception of time-amplitude coordinated changes in abnormal behavior. Through the organization and fusion of multi-dimensional features, a switching feature representation with statistical, structural, and coupled characteristics is formed, enabling the system not only to identify simple abnormal fluctuations but also to distinguish between pseudo-anomalies and genuine abnormal behaviors in a given scene.
[0010] Optionally, the quasi-periodic manifold extraction specifically involves: Delayed embedding is performed based on the instruction interval data to obtain delayed embedded data; Locally tangent space alignment is performed on the delayed embedded data to obtain locally aligned data; The intrinsic behavior data is obtained by synchronizing the intrinsic evolution manifold behavior based on the local alignment data. Manifold constraint embedding is performed on intrinsic behavior data to obtain low-dimensional manifold data; Trajectory loop closure detection is performed based on low-dimensional manifold data to obtain quasi-periodic manifold data.
[0011] This invention reconstructs a one-dimensional time series into a high-dimensional state-space trajectory by delaying the embedding of instruction interval data, thus explicitly expressing the dynamic evolution patterns originally implicit in the time series. Local nonlinear distortions between different time segments are eliminated through local tangent space alignment, allowing similar dynamic patterns to be compared under a unified geometric structure. Evolutionary manifold behavior synchronization normalizes the evolutionary trends within different time periods, highlighting the system's inherent stable evolutionary characteristics. Manifold constraint embedding compresses complex high-dimensional trajectories into a low-dimensional manifold space, reducing noise interference while preserving key structural information, improving the compactness and discriminativeness of feature expression. Trajectory loop closure detection identifies recurring dynamic paths, enabling effective extraction of quasi-periodic behavioral structures. This allows the system to distinguish between random fluctuations caused by network disturbances and the inherent rhythms of the control strategy itself, thereby enhancing the structural awareness and stability of anomaly detection.
[0012] Optionally, the actuator trajectory reconstruction specifically includes: Based on the asynchronous instruction behavior data, instruction behavior fragments are associated to obtain behavior fragment data; Behavior segment data is analyzed to identify the start and end boundaries of behavior, resulting in behavior unit data. Behavioral trajectory data is obtained by parametric modeling of behavioral unit data. Based on the behavior trajectory data, cross-instruction trajectory splicing is performed to obtain continuous trajectory data; Constraint verification is performed on continuous trajectory data to obtain behavioral feature data.
[0013] This invention establishes a mapping relationship between discrete control commands and execution processes by associating asynchronous command behavior data with command behavior fragments, enabling previously isolated command information to form a traceable behavior sequence at the execution level. By identifying the start and end boundaries of behavior, it achieves fine segmentation of the response process, effectively eliminating boundary ambiguity caused by command superposition or delay. Through parameterized modeling of the behavior trajectory, key features such as the rate of change, response delay, and stable interval during execution are structurally expressed, transforming complex dynamic processes into an analyzable parameter space representation. By splicing across command trajectories, multiple local behavioral units are connected into a continuous trajectory, restoring the complete dynamic evolution path of the actuator in the time dimension. Simultaneously, a constraint verification mechanism verifies the physical consistency and control logic consistency of the trajectory, eliminating abnormal splicing or unreasonable responses. The resulting behavioral feature data accurately reflects the dynamic response characteristics of the actuator, providing a reliable basis for anomaly identification and improving the system's ability to distinguish between delay disturbances and abnormal behavior.
[0014] Optionally, the instruction density is constructed as follows: The time window is divided based on the switching feature data to obtain the switching window data; Perform instruction switching processing on the switching window data to obtain instruction switching data; Behavioral load data is obtained by extracting behavioral load state from behavioral feature data. Density distribution data is obtained by coupling and mapping instruction switching data and behavioral load data. Local peak shaping is performed on the density distribution data to obtain the command density data.
[0015] This invention divides time windows based on switching characteristics, reconstructing discrete and non-uniform instruction sequences into local analysis units with temporal semantics, enabling a stable representation of instruction activity levels at different time scales. By aggregating instruction switching behavior within the window, instruction switching data reflecting the frequency and intensity of dimming level changes is generated. Simultaneously, by combining execution-side behavioral features to extract behavioral load status, the actuator's response capability and load condition are incorporated into the modeling process, thus avoiding the bias caused by relying solely on control-side data. Through coupling and mapping instruction switching data and behavioral load data, the intensity of instruction occurrence and execution load capacity are uniformly represented as a density distribution, ensuring that density reflects not only the number of instructions but also the actual execution status. Through local peak shaping and continuity correction, the sudden accumulation effect and discontinuous jumps caused by network latency are effectively suppressed, resulting in smooth and physically consistent instruction density data.
[0016] Optionally, cross-clock verification specifically includes: Multi-clock domain density projection is performed based on instruction density data to obtain cross-domain density data. Trajectory manifold alignment is performed based on cross-domain density data to obtain time delay aligned data; The distribution divergence of the time-delay aligned data is measured to obtain the distribution divergence data; Based on the distribution divergence data, cross-clock residuals are constructed to obtain time-series residual data; Cross-clock verification data is obtained by performing cross-clock determination on the timing residual data.
[0017] This invention constructs a unified cross-domain density representation by projecting instruction density data onto multiple clock domains, making data that were originally affected by different sampling rhythms and transmission delays comparable within the same analytical framework. Structural matching of density evolution paths is achieved through trajectory manifold alignment, enabling the recovery of the true temporal correspondence between domains under conditions of non-uniform delay and local deformation. The alignment results are quantitatively evaluated using a distribution divergence metric, transforming density distribution differences from different sources into measurable statistical distances, thus avoiding the instability caused by single-time offset determinations. By constructing cross-clock residuals, structural deviations and distribution differences are uniformly expressed as temporal residual features, allowing for centralized characterization of anomalous information. Consistency analysis of the residuals is performed through cross-clock determinations, enabling effective identification of the sources of temporal anomalies.
[0018] Optionally, trajectory manifold alignment specifically includes: A density propagation conservation field is constructed based on cross-domain density data to obtain propagation constraint field data; Cross-domain propagation deformation modeling is performed on the propagation constraint field data to obtain propagation deformation function data; Density structure preservation mapping is performed based on the propagation deformation function data to obtain structure mapping data; Energy redistribution analysis of propagation energy is performed on the structure mapping data to obtain energy shift data; The time delay alignment data is obtained by solving the joint constraints based on the energy offset data and the propagation deformation function.
[0019] This invention constructs a density propagation conservation field, modeling the evolution of cross-domain command density as a constrained propagation system. This allows density changes between different nodes to be explained under a unified mechanism, effectively avoiding the problem of traditional methods relying solely on time alignment while ignoring propagation laws. Through cross-domain propagation deformation modeling, a nonlinear time deformation function continuously represents the delay stretching, compression, and local misalignment generated during network transmission, thus adapting to dynamic disturbances in complex network environments. Density structure preservation mapping retains peak structure, variation rhythm, and local continuity characteristics during alignment, preventing damage to the original structural information. Combined with propagation energy redistribution analysis, density changes are transformed into an energy distribution perspective, enabling the identification of abnormal energy accumulation or attenuation under abnormal conditions. Through joint constraint solving, the optimal time delay alignment result is determined under the premise of satisfying conservation, structural consistency, and deformation continuity, making the timing relationship across clock domains more realistic and reliable.
[0020] Optionally, the separation of pseudo-anomalies from real attacks is specifically as follows: Residual pattern parsing is performed based on cross-clock verification data to obtain residual structure data; Propagation closed-loop analysis was performed on the residual structure data to obtain propagation closed-loop data; Behavioral interpretability assessment is performed on the closed-loop propagation data to obtain behavioral interpretation data; Attribution judgment is performed based on residual structure data, propagation closed-loop data, and behavioral explanation data to obtain anomaly type data; Anomaly identification data is obtained by integrating anomaly type data.
[0021] This invention analyzes residual patterns in cross-clock verification results, transforming timing deviations from different sources into structurally characteristic residual expressions. This elevates anomalies beyond simple numerical deviations to analyzable pattern forms. Propagation loop analysis represents the transmission path and feedback relationships of residuals between system nodes, identifying the existence of closed-loop structures conforming to network propagation laws, thus distinguishing between systemic disturbances caused by link delays and external anomaly injection. Behavioral interpretability assessment verifies the causal consistency of the residual generation process, ensuring each anomaly has a traceable generation logic and avoiding the uncertainties of black-box judgment. By fusing residual structure, propagation loop, and behavioral explanation information for attribution discrimination, refined classification of anomaly sources is achieved, and structured results are output through anomaly identification.
[0022] Optionally, the anomaly identification system based on dimming level switching behavior, used to perform the anomaly identification method described above, includes: The asynchronous phase self-consistent synchronization module is used to acquire multi-source timing data of the dimming link, perform asynchronous phase self-consistent synchronization on the multi-source timing data, and obtain asynchronous command behavior data. The feature extraction module is used to extract instruction interval features from asynchronous instruction behavior data to obtain switching feature data; and to reconstruct the executor response trajectory from asynchronous instruction behavior data to obtain behavior feature data. The cross-clock verification module is used to construct instruction density data based on switching feature data and behavior feature data, and to obtain instruction density data; and to perform cross-clock verification based on instruction density data, and to obtain cross-clock verification data. The pseudo-anomaly and real attack separation module is used to separate pseudo-anomalies and real attacks based on cross-clock verification data to obtain anomaly identification data.
[0023] The beneficial effects of this invention are as follows: Through asynchronous phase self-consistent synchronization, structural alignment of multi-source time-series data is achieved under conditions without a unified clock, effectively eliminating the interference of clock drift and network jitter on subsequent analysis; combining instruction interval feature extraction and actuator response trajectory reconstruction, a collaborative representation is established from two dimensions: control-side rhythm and execution-side dynamics, enabling the system to simultaneously perceive the instruction generation logic and physical response process. Through instruction density construction, discrete events are transformed into a continuous density distribution, and behavioral carrying states are integrated to form a physically meaningful intensity expression; in the cross-clock verification stage, reliable alignment and difference quantification between multiple clock domains are achieved through density propagation consistency and nonlinear deformation constraints. Through residual structure analysis and propagation closed-loop analysis, interpretable attribution of anomaly sources is achieved, effectively distinguishing between pseudo-anomalies caused by network latency and malicious attack behavior. Attached Figure Description
[0024] Other features, objects, and advantages of this application will become more apparent from the following detailed description of the non-limiting embodiments, taken with reference to the accompanying drawings: Figure 1 A flowchart illustrating the steps of an anomaly identification method based on dimming level switching behavior according to one embodiment is shown. Figure 2 A flowchart illustrating the steps of an asynchronous phase self-consistent synchronization method according to one embodiment is shown. Figure 3 A flowchart illustrating the steps of an instruction interval feature extraction method according to an embodiment is shown. Figure 4 A flowchart illustrating the steps of an instruction density construction method according to one embodiment is shown. Figure 5 A flowchart illustrating the steps of a method for separating pseudo-anomalies from real attacks according to an embodiment is shown. Detailed Implementation
[0025] The technical method of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this invention.
[0026] Furthermore, the accompanying drawings are merely illustrative of the invention and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor methods and / or microcontroller methods.
[0027] It should be understood that although the terms "first," "second," etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are used merely to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0028] Please see Figures 1 to 5 This application provides an anomaly identification method based on dimming level switching behavior, including the following steps: S1. Obtain multi-source timing data of the dimming link, perform asynchronous phase self-consistent synchronization on the multi-source timing data, and obtain asynchronous command behavior data; In one embodiment, the system collects multi-source timing data from the dimming control terminal, network transmission node, and actuator side. The control terminal includes the command number, issuance time, target dimming level, and session identifier; the network side includes the reception time, forwarding time, buffer dwell time, and retransmission flag; and the actuator side includes the command reception time, output change time, brightness feedback time, and current feedback time. Based on the command number, device identifier (derived from the data records of each acquisition terminal; the control terminal carries the identifier of the control device or session initiating device, the network transmission node carries the identifier of the intermediate node or link node, and the actuator side carries the identifier of the specific execution device), and session identifier, a cross-source data association is established, merging data from different sources into the same command behavior set. The system performs time-series potential encoding on the time-series data from each source, converting the original time information into a sequence representation reflecting the chronological order and interval relationship of events. Within this sequence, it identifies recurring stable events in the multi-source data as anchor points, including level abrupt change points, continuous command termination points, and feedback change inflection points. (Level abrupt change points are determined by detecting the difference between the control values / target dimming levels of adjacent dimming commands; when the change exceeds a preset range. Continuous command termination points are obtained by identifying the end position of consecutive commands of the same direction or level. Feedback change inflection points are determined by trend analysis of actuator feedback signals (brightness, current, etc.); when the direction of change undergoes a significant reversal (from rising to leveling off or falling). The time-series potential encoding includes sorting the timestamp data from each source, converting the original absolute time into a relative sequence relationship; using the time interval between adjacent events as the basic metric, discretizing the time series into segments, and assigning each event a sequence number or interval label reflecting its relative position in the overall sequence; recording the interval change trend between adjacent events (such as increasing, decreasing, or stabilizing), thus forming a time-series potential representation that includes both chronological order and interval structure. Based on the relative positions of each anchor point, the system estimates the time offset and dynamic drift between different data sources and constructs a corresponding time mapping relationship. This maps all source data to the same reference time axis, thereby forming asynchronous instruction behavior data that covers the entire process of instruction generation, link transmission, execution, and feedback return.
[0029] S2. Extract instruction interval features from asynchronous instruction behavior data to obtain switching feature data; reconstruct the actuator trajectory from asynchronous instruction behavior data to obtain behavior feature data. In one embodiment, the system sorts dimming commands under the same control session based on a unified time axis and pairs adjacent commands to obtain the arrival interval, level change amplitude (such as target dimming level, brightness setting value, or dimming level), change direction, and number of consecutive reverse switching between adjacent commands, forming command interval data. The command intervals are segmented and statistically analyzed to obtain the proportion, average level, and dispersion of short, medium, and long intervals. Combined with the temporal evolution relationship of the interval sequence, its inherent structural features are extracted. For example, the system analyzes the changing trend of the interval sequence using a sliding time window as a unit, including whether it exhibits patterns such as continuous shortening, gradual lengthening, alternating fluctuations, or phased stability. Simultaneously, the sequence is structurally divided based on the change direction and continuity of adjacent intervals, thereby extracting structural features. The interval features are correlated with the corresponding level change amplitude. For example, within the same time window, the system aligns the interval features with the corresponding level change amplitude, analyzing whether short intervals are accompanied by large changes and whether long intervals correspond to small adjustments, thereby identifying high-frequency strong switching or low-frequency fine-tuning patterns. Based on the above, the system obtains switching feature data.
[0030] The system extracts execution segments based on actuator-side data, using the command reception and feedback times as boundaries. It determines the start and end boundaries of these segments by identifying abrupt changes in output, inflection points in brightness, and trend reversals in current. Within each segment, the system detects abrupt changes in the output signal (such as brightness or current) (points where the rate of change increases or decreases significantly), inflection points (points where the rate of change changes from increasing to leveling off or from leveling off to decreasing), and trend reversals (points where the overall direction of change changes), thus determining the start and end boundaries of the execution behavior within that segment. For each execution segment, the system extracts parameters such as response delay, rate of change, amplitude characteristics, stabilization duration (when the output rate of change decreases to near zero and the fluctuation amplitude remains within a small range for a period of time, it can be considered to have entered a stable phase; the system calculates the duration from entering this stable state until a significant change occurs again), and fluctuation degree. These parameters are then concatenated in chronological order to construct a continuous execution trajectory. Trajectory segments with abnormal rates of change, abnormal action cycles, or execution directions inconsistent with the command are marked to obtain behavioral feature data describing the actuator's dynamic characteristics.
[0031] S3. Construct instruction density based on switching feature data and behavioral feature data to obtain instruction density data; perform cross-clock verification on instruction density data to obtain cross-clock verification data. In one embodiment, the system adaptively divides a unified time axis based on the location of local mutations, interval compression sections, and level-reverse switching enhancement sections in the switching feature data. For example, a longer time window is used when the instruction interval changes smoothly, and the window length is shortened when short-term dense issuance or frequent round-trip switching is detected. The location of the local mutation can be determined by the location where the interval between adjacent instructions or the switching amplitude changes significantly in a short period of time. The interval compression section refers to the interval where the interval between multiple consecutive instructions is less than the historical average level. The level-reverse switching enhancement section refers to the section where instructions frequently change in opposite directions at adjacent times (such as rising and then falling rapidly) and the number of occurrences is higher than the normal level. Within each time window, the system statistically analyzes the number of instructions, the total number of level changes, the number of reverse switchings, the proportion of short intervals (the proportion of instruction intervals shorter than a preset baseline interval within the current time window to the total number of intervals), and the period deviation (by comparing the interval sequence within the current window with historical stable periods to determine whether there is period lengthening, shortening, or unstable fluctuation), forming the instruction switching intensity. Simultaneously, it extracts the state of the actuator within the corresponding window by combining behavioral feature data, including average response latency, execution overlap, stabilization time variation, and residual fluctuations, forming behavioral load data. The average response latency is obtained by averaging the difference between the time each instruction is issued and the corresponding actuator's response time. The execution overlap is obtained by statistically analyzing the number of times a new instruction has been triggered before execution is completed within the same time window, or the duration of overlap. The stabilization time variation refers to the time change trend experienced by the actuator from the start of response to entering a stable state. Residual fluctuations are characterized by the fluctuation amplitude and duration of the output signal after stabilization within a certain period. The system performs correlation analysis between command switching intensity and behavioral load according to a one-to-one correspondence within a time window. When both increase synchronously, it is identified as a high-density action zone. When the command intensity is high but the load does not change significantly, it is marked as a potential accumulation zone. For example, under a unified time window, the system fuses command switching intensity and behavioral load one-to-one, and the result is a density sequence representing the input intensity versus execution load per unit time. The output of the correlation analysis is the density value sequence. The system performs continuity correction and anomaly suppression on the density sequence, retaining continuous high-density segments and weakening isolated spikes to obtain command density data.
[0032] During the cross-clock verification process, the system maps the instruction density data (based on the instruction density data under a unified time axis, the system projects the density value of each time window to the local time axis of the corresponding device according to the source node identifier of the event and the original sampling time) to the clock domains of the control end, network transmission end and actuator end, forming a multi-domain density sequence, which is regarded as a density change process propagating along the dimming link. That is, the instruction density data represents the instruction action intensity and execution load intensity per unit time. This intensity is generated from the control end, transmitted through the network and finally acts on the actuator, with a clear causal link and time sequence relationship. The system establishes cross-domain propagation constraints, requiring that density changes in subsequent nodes can be explained by input changes in the preceding node within a reasonable time delay. For example, the system establishes window-level correspondences between adjacent nodes and searches for density change segments in subsequent nodes with similar shapes to the preceding window within a preset time delay. If the peak occurrence time, duration, and trend of the subsequent node can be explained by the preceding window through delay and smoothing changes, the propagation constraint is considered satisfied; otherwise, it is marked as an abnormal deviation. Simultaneously, through propagation deformation, the density sequence is allowed to undergo local stretching, compression, and slight misalignment during cross-domain processes, but its continuity, smoothness of change, and main peak order are constrained. That is, the system allows the density sequence to be aligned by stretching or compressing the time axis, i.e., moderately extending or shrinking the local window, while limiting the abrupt changes in the amplitude of adjacent windows and maintaining the order of the main peaks. Based on these constraints, the system aligns and compares instruction density data in different clock domains, analyzes peak positions, distribution widths, extension shapes, and local fluctuation differences, and generates residual information containing time offsets, amplitude changes, and structural differences. Based on the continuity of residual changes, the presence of abnormal isolated peaks, and whether the propagation order is disrupted, cross-domain consistency is determined. For example, when the time offset is continuous and changes smoothly, the structural differences are small and there are no isolated abnormal peaks, and the propagation order is consistent, it is determined to be consistent. When there are persistently high residuals, frequent isolated anomalies, or peak order reversals, it is determined to be inconsistent, and the corresponding window position and main abnormal characteristics are output. Based on the above, the system outputs cross-clock verification data.
[0033] S4. Separate pseudo-anomalies from real attacks in the cross-clock verification data to obtain anomaly identification data.
[0034] In one embodiment, the system analyzes the timing residual information in the cross-clock verification data and classifies it into continuous shift, local mutation, multi-peak misalignment, and reverse mismatch types according to the change pattern of the residuals. It also counts the duration, intensity level, and frequency of each type of residual in the current analysis period to characterize the basic pattern features of the anomaly. The continuous shift type refers to the fact that the peak values of each clock domain undergo approximately equal time shifts in multiple consecutive time windows, but the peak order relationship and structural morphology remain consistent. The local mutation type refers to the residuals suddenly increasing only in individual windows, manifested as isolated anomalies in the amplitude or position of density peaks, and discontinuity with the preceding and following windows. The multi-peak misalignment type refers to the disorder of the relative order or correspondence of multiple peak regions in different clock domains, such as the main peak and secondary peak positions intersecting or misaligning. The reverse mismatch type refers to the fact that the direction of density change in the subsequent clock domain is inconsistent with the direction of change of the preceding instruction, or there is a timing reversal phenomenon of response before input. The system performs propagation loop analysis based on the "control end—network end—actuator end" link structure. It checks whether density changes generated at the control end can be transmitted and reproduced at the network end and actuator end in a reasonable time sequence. Simultaneously, it verifies whether behavioral changes on the actuator side can correspond to preceding command inputs in reverse order. That is, it selects density change segments from the control end, searches for similar changes at the network end within the allowable time delay range, and then searches for response segments at the actuator end that are consistent with the previous two in terms of time sequence and structural form. It also checks whether behavioral changes at the actuator end can be traced back to the corresponding control command input in time. If the above matching relationship is valid at all nodes and the order is not reversed, it is determined that a propagation loop has been formed; otherwise, it is considered an incomplete loop. The system performs consistency evaluation based on actuator behavioral characteristics: when the residual exhibits smooth translation or continuous change, the link propagation relationship is complete, and the actuator response direction is consistent with the command, load changes are synchronized with density changes, and no unprovided action segments appear, this type of anomaly is judged as a pseudo-anomaly caused by network latency, buffer backlog, or congestion release. Conversely, when the residual exhibits abrupt changes, multi-peak misalignment, or local inversion characteristics, and there are density peaks that cannot be explained by preceding instructions, mismatches between executed actions and instructions, or breaks in the link propagation relationship, the system determines it to be a genuine attack caused by illegal injection, malicious replay, or instruction tampering. The anomaly identification data output by the system includes the anomaly type, the time range of occurrence, the involved link nodes, and the corresponding judgment criteria.
[0035] Optionally, asynchronous phase self-consistent synchronization specifically refers to: S11. Perform multi-source time series potential encoding on the multi-source time series data to obtain time series potential data; In one embodiment, the system acquires raw timing data from the control terminal, network nodes, and actuator side, and assigns corresponding tags to each record based on the event type. These tags include at least instruction generation, instruction forwarding, instruction arrival, execution initiation, and feedback return. Based on the order of events occurring within the same device, the system calculates the time interval between adjacent events and normalizes this time interval to form corresponding potential increments. During processing, for segments with sudden delays, longer time intervals are compressed using a segmented approach; for segments with densely occurring events, high distinguishability is maintained. The system associates the cumulative potential values of each event with the corresponding event tags to form timing potential data representing the sequence of events and their relative interval structure.
[0036] S12. Extract cross-source anchor points based on time series potential data to obtain cross-source anchor point data; In one embodiment, the system identifies event combinations with stable structural characteristics as candidate anchor points in the time-series potential sequences corresponding to each data source. These candidate anchor points include at least positions of significant level changes, the end positions of consecutive commands of the same level, positions of significant changes in actuator output, and feedback inflection points. The positions of significant level changes and the end positions of consecutive commands of the same level are obtained through change analysis based on the target dimming parameters carried in the commands. The system uses consistent event labels, similar potential interval structures, and consistent local order relationships as matching criteria to perform cross-source alignment and filtering of candidate anchor points from different data sources. When a candidate anchor point appears repeatedly in multiple consecutive time windows, and the changes in adjacent potential intervals remain within a preset fluctuation range, it is determined as a valid cross-source anchor point. Simultaneously, the anchor point's identification information, its data source, and its corresponding potential position are recorded to form cross-source anchor point data.
[0037] S13. Perform joint estimation of offset and drift on the cross-source anchor point data to obtain the mapping function data; In one embodiment, the system uses the temporal potential sequence at the control end as a unified reference to establish a correspondence between cross-source anchor points at the network and actuator ends, and calculates the potential differences between each corresponding anchor point. During the analysis, differences that remain relatively stable within the overall interval are extracted as fixed offsets, while differences that show a continuous trend over time are extracted as drift changes. The system uses a preset window to segment the anchor point sequence, establishing a mapping relationship between the reference potential and the target potential within each segment interval, and imposing continuity constraints on the changing trends between adjacent segments. The system generates mapping function data containing fixed offset information, drift change characteristics, and segment boundary divisions. The fixed offset represents the translation relationship of the overall time axis, the drift change represents the scaling or offset trend that gradually changes over time, and the segmentation process makes this relationship locally adaptable in different time intervals. Combining the above three parts forms a segmented continuous temporal correspondence rule, that is, for any input potential value, its output potential position can be determined by its segment and corresponding parameters, which is regarded as mapping function data.
[0038] S14. Reconstruct the entire sequence based on the mapping function data to obtain asynchronous instruction behavior data.
[0039] In one embodiment, the system, based on the mapping function, transforms the timing potential data from the network end and the actuator end point by point to a reference timing frame, and performs unified sorting of events from each data source. During the mapping process, for event segments with local sequence conflicts or time overlaps, adjustments are made first based on the business sequence relationship corresponding to the event tags to maintain the consistency of the order of instruction generation, forwarding, arrival, execution, and feedback; for segments not directly covered by anchor points, continuity compensation is performed using the boundary relationship of adjacent mapped segments. After completing the above processing, the system integrates the corresponding events from different data sources, constructs a unified event sequence, and generates asynchronous instruction behavior data containing instruction identifiers, unified timing positions, event types, and source node information.
[0040] Optionally, the instruction interval feature extraction specifically involves: S21. Perform adjacent instruction pairing processing based on asynchronous instruction behavior data to obtain instruction interval data; In one embodiment, the system sorts instruction events belonging to the same dimming link and control session based on a unified temporal location, and filters out records lacking instruction numbers or target level information. Adjacent instruction pairs are formed by the current instruction and its most recent valid successor, and the corresponding arrival time, dimming level, and event identifier are extracted. The system determines the time interval, level change magnitude, and direction of change between adjacent instructions, and judges whether there is a round-trip switching situation; for continuously repeated identical instructions, they are merged into a continuous instruction segment for processing. The system obtains instruction interval data containing time interval, level change characteristics, and direction information.
[0041] S22. Perform interval distribution analysis on the instruction interval data to obtain interval statistical characteristic data; In one embodiment, the system performs segmented statistical analysis on instruction interval data using preset time windows. Within each time window, it calculates statistical indicators such as the average level, median level, fluctuation degree, and value range of the interval. Based on preset division rules, the intervals are divided into three categories: short intervals, regular intervals, and long intervals. The proportion and consecutive occurrence of each type of interval are then statistically analyzed. For windows with a significant prevalence of long intervals, the concentration of intervals at the tail is recorded. For windows with a dense occurrence of short intervals, the degree of local compression and clustering characteristics are recorded. Through the above processing, statistical characteristic data of intervals representing the density distribution, fluctuation intensity, and abnormal concentration of instruction timing are obtained.
[0042] S23. Perform quasi-periodic manifold extraction on the instruction interval data to obtain quasi-periodic manifold data; In one embodiment, the system performs structural reconstruction processing on a continuous sequence of instruction intervals, converting it into a multidimensional state sequence according to a preset embedding length and time delay relationship. For example, starting from the current interval value, several subsequent interval values are selected sequentially with a fixed time delay, combined to form a multidimensional state vector, and the state sequence is generated by gradually sliding along the time sequence. Through this processing, the local dynamic relationships in the original time sequence are explicitly unfolded, so that the correlation structure between adjacent intervals can be reflected in the state space, thereby completing the structural reconstruction. Within this state space, a local neighborhood is constructed for each state, and the change direction of samples within the neighborhood is adjusted for consistency. For example, by comparing the change directions between adjacent states within the neighborhood, when there are opposite directions or large scale differences, their direction representations are unified, such as by agreeing on the same direction of change or normalizing the change amplitude, so that samples with similar evolutionary trends present a consistent change direction in the local space. While preserving the relative relationships within their neighborhoods, the multidimensional states are compressed into a low-dimensional representation space (by retaining the proximity relationships and relative distance structures between samples, high-dimensional states are mapped to low-dimensional coordinates, ensuring that similar states remain close in the low-dimensional space while states with different structures can be distinguished). Structural analysis is then performed on the sequence trajectories to identify features such as repeating paths, approximate loops, or repeated traversal of similar regions. When these structures consistently appear within multiple time windows and their intervals remain within a preset range, quasi-periodic manifold data is extracted.
[0043] S24. Perform switching amplitude coupling analysis based on instruction interval data to obtain switching coupling characteristic data; In one embodiment, the system uses adjacent instruction pairs as analysis units to correlate the corresponding time intervals with the magnitude of level changes. Significant level changes occurring within a short time interval are marked as high-intensity handovers; minor adjustments occurring after a longer time interval are marked as low-intensity handovers. Within a preset time window, the system statistically analyzes the proportion of high-intensity handovers, the frequency of alternating forward and reverse handovers, and the concentration of significant level changes within short intervals. When a pattern of short intervals accompanied by significant changes or frequent reverse handovers continuously appears in multiple consecutive windows, its coupling anomaly is enhanced and marked, thus forming handover coupling characteristic data.
[0044] S25. Based on the interval statistical characteristic data, quasi-periodic manifold data and switching coupling characteristic data, the switching characteristic data is organized to obtain the switching characteristic data.
[0045] In one embodiment, the system organizes interval statistical characteristic data, quasi-periodic manifold data, and switching coupling characteristic data in a unified time window, and integrates them according to the hierarchical relationship of statistical characteristics, structural characteristics, and coupling characteristics. The interval distribution, manifold structure, and switching coupling strength within each window are uniformly identified and aligned. When the statistical characteristics within a window are stable, the manifold structure exhibits regular loops, and the coupling strength is low, it is determined to be a stable switching state; when the proportion of short intervals increases, the manifold structure changes abnormally, and the coupling strength increases, it is marked as an abnormal switching candidate state. The system obtains switching characteristic data containing window identifiers, interval distribution characteristics, structural morphology identifiers, and coupling strength levels (mapped from the switching coupling characteristic data, for example, segmented according to their numerical range or relative level).
[0046] Optionally, the quasi-periodic manifold extraction specifically involves: Delayed embedding is performed based on the instruction interval data to obtain delayed embedded data; In one embodiment, the system extracts a continuous sequence of instruction intervals based on a unified temporal position and reconstructs them according to a preset embedding length and time delay relationship. Starting from the current interval value, several subsequent interval values are selected sequentially at fixed time intervals to form a multi-dimensional state vector; this vector is then gradually slid along the time sequence to generate a set of state vectors arranged in chronological order. For positions in the sequence with missing intervals, the system preferentially uses the average value of the nearest valid intervals to fill in the gaps; when the length of a continuous missing segment exceeds a preset range, the segment is marked as a low-confidence segment. Delayed embedding data is obtained through the above process.
[0047] Locally tangent space alignment is performed on the delayed embedded data to obtain locally aligned data; In one embodiment, the system constructs a local neighborhood by selecting several similar state vectors around each delayed embedding vector as the center. For each neighborhood, the main changing trend of the samples within it is analyzed, and the principal direction information representing the evolution direction of that neighborhood is extracted and used as the reference direction in the local space. The consistency of the principal directions between different neighborhoods is compared. For neighborhoods with large directional differences, their directional representations are adjusted to ensure that neighborhoods with similar evolutionary characteristics maintain a consistent orientation in the local space. For cases that are significantly affected by noise and whose directions are inconsistent with those of multiple surrounding neighborhoods, their weight in alignment is reduced. Through the above processing, local alignment data is obtained.
[0048] The intrinsic behavior data is obtained by synchronizing the intrinsic evolution manifold behavior based on the local alignment data. In one embodiment, the system analyzes the relationship between adjacent time points based on the locally aligned state vector sequence, obtains the evolution direction and intensity of change for each time period, and expresses them in a unified local space. Consistency processing is applied to continuous time segments: when the evolution direction of adjacent segments remains consistent or changes are small, they are merged into the same evolution segment; when there is a significant change in direction or a sudden increase in intensity, they are divided into new evolution segments. Segments with short duration and small change amplitude are considered local perturbations and are weakened. Through the above process, intrinsic behavior data is obtained.
[0049] Manifold constraint embedding is performed on intrinsic behavior data to obtain low-dimensional manifold data; In one embodiment, the system performs dimensionality reduction representation of high-dimensional state sequences based on segment connectivity, local proximity relationships, and temporal continuity constraints in intrinsic behavior data. During the embedding process, the relative distance relationship between adjacent samples is maintained first, so that the same evolving segment forms a continuous trajectory in the low-dimensional space; for locations where there are obvious directional changes between different segments, the corresponding turning features are preserved in the low-dimensional space. If the embedding result shows obvious distortion of neighborhood relationships or abnormal segmentation of continuous segments, the system adjusts the constraint weights during the embedding process (set to a preset ratio during initialization (e.g., equal weight for each constraint or allocated according to empirical ratio), and adjusts them according to the type of distortion when neighborhood distortion or segment breakage occurs in the embedding result, such as increasing the neighborhood preservation constraint to restore the local structure, or increasing the continuity constraint to repair the trajectory breakage), and re-executes the mapping until low-dimensional manifold data is obtained.
[0050] Trajectory loop closure detection is performed based on low-dimensional manifold data to obtain quasi-periodic manifold data.
[0051] In one embodiment, the system compares the spatial distribution of low-dimensional manifold trajectories across different time periods according to their temporal order, identifies instances of repeated entry into similar regions, and analyzes the distance relationships, directions of change, and dwell characteristics between corresponding trajectory segments. When multiple trajectory segments form approximately closed paths in low-dimensional space, and the spatial distance between segments is small while their directional changes remain consistent, they are marked as candidate loop structures. The system statistically analyzes the occurrence of these loop structures across multiple time windows, evaluating their repeatability and structural stability. When a loop structure appears multiple times and its shape remains stable, it is determined to be a quasi-periodic manifold; otherwise, it is considered an occasional disturbance and distinguished from other types. The system obtains quasi-periodic manifold data to describe the inherent periodic characteristics of the temporal series.
[0052] Optionally, the actuator trajectory reconstruction specifically includes: Based on the asynchronous instruction behavior data, instruction behavior fragments are associated to obtain behavior fragment data; In one embodiment, the system uses dimming commands under a unified time sequence as an index to retrieve output changes, brightness feedback, and current feedback records that are close to the command's time on the actuator side. Within a preset response time range after the command arrives, the system prioritizes the record showing the first significant change as a candidate association starting point. When multiple adjacent commands exist within the same time range, the system determines the attribution of the execution change segment by combining the command sequence, the consistency between the target level change direction and the actual change direction of the actuator. For cases where an execution change corresponds to multiple commands, the most recent preceding command corresponding to the change starting point is used as the primary association object, and the remaining commands are recorded as secondary associations. The system obtains behavioral segment data containing command identifiers, segment start and end positions, and feedback source information.
[0053] Behavior segment data is analyzed to identify the start and end boundaries of behavior, resulting in behavior unit data. In one embodiment, the system performs boundary identification processing on the actuator signals in each behavior segment. The moment when the output change accelerates significantly and exceeds a preset threshold is determined as the starting candidate position, and the moment when the signal change tends to stabilize and shows small changes within a consecutive number of sampling points is determined as the ending candidate position. For cases with overshoot, rebound, or local oscillations, the system does not use the first peak value as the ending point, but continues to track signal changes until the fluctuation amplitude converges to an allowable range before determining the termination boundary. When adjacent behavior segments have overlapping boundaries, the position with the smallest change between them is selected as the dividing point. Through the above processing, behavior unit data with clearly defined boundaries is obtained. Each behavior unit includes start and end times, associated instructions, and corresponding execution channel information.
[0054] Behavioral trajectory data is obtained by parametric modeling of behavioral unit data. In one embodiment, the system performs parametric modeling of the execution process of each behavioral unit, extracting indicators including response start delay, change duration, peak change amplitude, overall change rate, maximum instantaneous change intensity, stable holding time, and residual fluctuation degree. For behavioral units with multi-stage changes, the system divides them into several sub-stages based on change inflection points, and records the change direction and local change trend of each stage. The above parameters are organized according to a unified structure to form a trajectory representation representing the dynamic response characteristics of the actuator under a single instruction, thereby obtaining behavioral trajectory data.
[0055] Based on the behavior trajectory data, cross-instruction trajectory splicing is performed to obtain continuous trajectory data; In one embodiment, the system sequentially splices the behavioral trajectories corresponding to adjacent instructions based on the temporal order of the behavioral units to construct a continuous execution trajectory. When the starting position of a subsequent behavioral unit is earlier than the stable end of the preceding behavioral unit, the unconverged tail of the preceding trajectory is retained, and the two trajectories are connected in the order of occurrence within the overlapping temporal region to form a smooth transition. When there is a time interval between adjacent behavioral units, the end state of the preceding trajectory is continued to the starting position of the subsequent trajectory. For dense changes caused by the arrival of instructions in a concentrated manner, multiple close transitions are allowed in the same continuous trajectory. Through the above processing, continuous trajectory data representing the continuous dynamic change process of the actuator is obtained.
[0056] Constraint verification is performed on continuous trajectory data to obtain behavioral feature data.
[0057] In one embodiment, the system performs consistency verification on continuous trajectory data based on the physical characteristics and control rules of the actuator. It detects whether the trajectory change rate exceeds the device's allowable range, whether the minimum time interval requirement is met between adjacent actions, whether the overall trajectory change direction is consistent with the level change direction of the corresponding dimming command, and whether there are cases where there is a significant output change despite not corresponding to a command. Trajectory segments that meet the above constraints and are consistent with the command logic are marked as reliable behavior; trajectory segments with abnormal change rates, inconsistent directions, no command drive, or prolonged non-convergence are marked as abnormal behavior. The system obtains behavioral characteristic data including response latency, change rate, stability indicators, and consistency verification results.
[0058] Optionally, the instruction density is constructed as follows: S31. Divide the time window according to the switching feature data to obtain the switching window data; In one embodiment, the system divides the time series into windows based on switching feature data on a unified time axis. A basic window range and a minimum window limit are preset, and the distribution of short intervals, the frequency of level-based reverse switching, and the stability of structural changes within continuous time periods are detected. When the proportion of short intervals remains high or reverse switching increases in a short period, the corresponding segment is subdivided into shorter windows; when the interval distribution is relatively stable and structural changes are continuous, adjacent segments are merged to form longer windows. Each time window records its start and end times, corresponding instruction range, and main switching state characteristics, thus forming switching window data.
[0059] S32. Perform instruction switching processing on the switching window data to obtain instruction switching data; In one embodiment, the system statistically analyzes and aggregates instruction switching behavior within each switching window. It calculates the number of instructions, the total number of level changes, and the average magnitude of change within the window, and also counts the number of reverse switching, the duration of consecutive same-direction switching, and significant level changes occurring within short time intervals. For consecutively repeated instructions of the same level, they are merged into a single maintenance action for counting; for frequent back-and-forth ascending / descending switching within a short period, the system characterizes, integrates, and vectorizes the switching activity, directional bias, and local fluctuations within the window to form corresponding instruction switching data.
[0060] S33. Extract the behavioral load status from the behavioral feature data to obtain behavioral load data; In one embodiment, the system aligns the actuator's behavioral characteristic data to each switching window according to a uniform time. Within each window, it extracts relevant parameters characterizing the execution load state. These parameters include average response delay, the degree of overlap of consecutive actions, the duration of the stabilization process, the occurrence of near-maximum rate of change, and the persistence of residual fluctuations. The persistence of residual fluctuations is determined by the system analyzing the changing trends at the end of the behavioral units to identify whether fluctuations still exist after the stabilization phase, as well as the duration and attenuation of these fluctuations. When multiple overlapping behavioral units, prolonged stabilization processes, or increased cumulative fluctuations occur within a window, the load state of that window is determined to be high; when the response is relatively rapid, the actions converge quickly, and the fluctuations are small, the load state is determined to be low. Through the above, behavioral load data representing the actuator's load status within each time window is obtained.
[0061] S34. Couple and map the instruction switching data and behavior load data to obtain density distribution data; In one embodiment, the system uses switching windows as units, associating instruction switching data and behavioral load data within the same window to establish a coupling relationship between input intensity and execution load. When the instruction switching intensity is high and the behavioral load increases synchronously within a window, the window is assigned a high density level; when the instruction switching intensity is high but the behavioral load does not change significantly, it is marked as a segment with transmission lag; when the instruction switching intensity is low but the behavioral load increases abnormally, it is marked as a segment affected by delayed release. The system organizes the results of each window in chronological order and retains the change relationship between adjacent windows to obtain density distribution data, representing the degree of coupling between control input and execution load.
[0062] S35. Perform local peak shaping based on the density distribution data to obtain the command density data.
[0063] In one embodiment, the system performs shaping processing on local peaks in the density distribution data to distinguish between true high-density areas and occasional noise fluctuations. For isolated peaks that appear only within a single time window and differ significantly from adjacent windows, they are weakened by considering the switching trends between preceding and following windows and changes in behavioral load. For high-density segments formed by multiple consecutive windows, their peak positions and durations are preserved, and boundary regions are smoothly transitioned. When the interval between two adjacent peaks is short and the intermediate trough does not decrease significantly, they are merged into a continuous peak region. Through the above processing, instruction density data containing the density level, peak position, and peak region range of each window is obtained. The instruction density data represents the degree of aggregation and intensity distribution of instructions over time.
[0064] Optionally, cross-clock verification specifically includes: Multi-clock domain density projection is performed based on instruction density data to obtain cross-domain density data. In one embodiment, the system maps instruction density data obtained based on a unified time axis to the local clock domains of the control terminal, network node, and actuator terminal, respectively, according to the event source node and its original sampling time. Within each switching window, the system obtains the instruction switching intensity (e.g., number of instructions, level change amplitude, reverse switching frequency, etc.) representing the input side and the behavioral load (e.g., response latency, degree of overlapping execution, fluctuation, etc.) representing the execution side. The system normalizes these two types of data to place them under a unified dimension and combines them according to preset rules, such as through weighted superposition or hierarchical mapping, to transform the input activity level and execution load level into a scalar value, which is the density value of the time window. During the mapping process, the density value within the unified time window is allocated to the time intervals corresponding to each clock domain; when a density window spans multiple original sampling intervals, it is allocated according to its time proportion in each interval. For time segments with missing data, the trend of change of adjacent valid intervals is used to fill in the missing data. Through the above method, cross-domain density data that can be represented at different device local time scales is obtained.
[0065] Trajectory manifold alignment is performed based on cross-domain density data to obtain time delay aligned data; In one embodiment, the system organizes cross-domain density data in each clock domain into continuous density trajectory segments using a sliding window. Information characterizing the morphological features of each segment is extracted, including peak position, distribution width, upward and downward trends, and tail extension, forming a trajectory state description. Local neighborhood relationships are constructed in the state space corresponding to each clock domain, and different trajectory segments are constrained and matched based on the consistency of peak occurrence order and direction of change. Using the control-end trajectory as a reference, candidate segment paths with similar local structures and no reversal of peak order are searched in the network and execution ends. Under the conditions of preserving time order and structural continuity, the correspondence between clock domains is determined, thereby obtaining time delay alignment data representing the time differences across multiple clock domains.
[0066] The distribution divergence of the time-delay aligned data is measured to obtain the distribution divergence data; In one embodiment, the system performs statistical analysis on the density distribution characteristics of the control, network, and execution ends, using the corresponding time window after delay alignment as a unit. These characteristics include overall level, fluctuation degree, peak concentration, peak range, and sustained high density. The distribution patterns of each clock domain within the same window are compared to assess the degree of difference: when the peak positions of multiple clock domains largely overlap, their distribution ranges are similar, and the high-density area is consistently maintained, the difference is considered small; when peak misalignment, significantly inconsistent distribution ranges, or the presence of an independent peak in a single clock domain, the difference is considered large. Through this method, the degree of difference between each window is converted into distribution divergence data and organized chronologically. The distribution divergence data is an indexed result characterizing the differences in the density structure of multiple clock domains based on unified time-series alignment.
[0067] Based on the distribution divergence data, cross-clock residuals are constructed to obtain time-series residual data; In one embodiment, the system correlates and organizes the distribution divergence data with the time delay alignment results, constructing cross-clock residual information within the corresponding time window. The residuals include multiple aspects such as time alignment deviation, density peak difference, distribution width difference, and differences in the persistence of high-density areas. The system extracts these difference features within each window and concatenates them sequentially in time to form a residual sequence. During the analysis, when a certain type of residual shows a continuous increasing trend across multiple consecutive windows, its trend is recorded; when a window exhibits a significant anomaly and is discontinuous with its preceding and following changes, it is marked as an isolated anomalous segment. Time-series residual data is obtained through the above process.
[0068] Cross-clock verification data is obtained by performing cross-clock determination on the timing residual data.
[0069] In one embodiment, the system determines cross-clock consistency based on timing residual data. When the time alignment deviation is within acceptable limits and changes smoothly, all types of distribution differences are at acceptable levels, and no abnormal residuals appear in multiple consecutive windows, the cross-domain propagation relationship is determined to satisfy cross-clock consistency. When the residual sequence shows abnormal peak order, persistently large differences, repeated occurrences of local burst anomalies, or high-density areas cannot be reasonably corresponded to in subsequent clock domains, it is determined to be cross-clock inconsistent. The system outputs cross-clock verification data containing the consistency determination result, the location of the anomaly, the main residual types, and corresponding node information.
[0070] Optionally, trajectory manifold alignment specifically includes: A density propagation conservation field is constructed based on cross-domain density data to obtain propagation constraint field data; In one embodiment, the system maps the cross-domain density data of the control end, network end and execution end to the link propagation coordinate system, and uses the density change between adjacent time windows as the local flow manifestation of the propagation process. Within each time window, the output density of the previous node, the received density of the current node, and the density changes within that window are analyzed. Based on this, it is determined whether the changes can be explained by both the preceding input and the changes within the current window. For example, under a unified link coordinate system, the density sequences of the control end, network end, and execution end are aligned in units of time windows to obtain the density values of the same window on different nodes. The density value of the upstream node in that window is taken as the output density of the previous node, and the density value of the current node in that window is taken as the received density. The density changes of the current node between adjacent windows are calculated, i.e., the density difference between the current window and its preceding window is compared as the density change within the window. The system performs a consistency judgment: if the density change trend of the current node can be explained by the density input of the previous node in the preceding window after a reasonable time delay or slight diffusion, i.e., the density is sequentially shifted or smoothly transitioned on the time axis, then the change is considered to conform to the propagation logic; if there is a significant density increment in the current window, but no corresponding density source is found in the preceding node or the preceding window, or the magnitude of its change is significantly mismatched with the preceding input, then it is determined to be an abnormal change that cannot be explained by the input. When density changes form a continuous connection, it is determined to be a normal segment that satisfies the propagation constraints; when there are abnormal increments that cannot be explained by previous inputs, they are marked as propagation mismatch segments; for cases that only show overall delay or slight diffusion, they are retained as normal propagation processes. The system obtains propagation constraint field data containing normal propagation regions, abnormal mismatch regions, and propagation direction characteristics.
[0071] Cross-domain propagation deformation modeling is performed on the propagation constraint field data to obtain propagation deformation function data; In one embodiment, the system constructs a time mapping rule describing cross-domain propagation relationships, focusing on the density propagation process from the control end to the network end and from the network end to the execution end. This mapping reflects changes in the density sequence, such as time extension, compression, and overall offset, during propagation. Its input is the source time position, and its output is the target time position. During construction, the mapping relationship must maintain a consistent temporal order to avoid reversal. Simultaneously, the variation amplitude between adjacent time segments is limited to ensure a smooth and continuous overall change process. For segments with propagation anomalies, the local variation range can be appropriately relaxed, but it must be ensured that it smoothly connects with the preceding and following normal segments. Through the above processing, propagation deformation function data is formed to describe the temporal variation characteristics of cross-domain propagation. The propagation deformation function represents the correspondence between the source domain time axis and the target domain time axis, and its function value increases monotonically with the source time. Within normal propagation segments, the first-order change of the function remains smooth, representing continuous changes in propagation delay. Within abnormal segments, limited adjustments to the local slope are allowed, representing local stretching or compression, but this segment must be continuously connected with the preceding and following segments at the boundary. This function can be constructed using piecewise linear, piecewise spline, or other forms that satisfy monotonic continuous constraints.
[0072] Density structure preservation mapping is performed based on the propagation deformation function data to obtain structure mapping data; In one embodiment, the system maps the density sequence of the source domain to the time axis of the target domain based on a propagation deformation function, and imposes structural consistency constraints on the mapping results. During the mapping process, the continuity of structural features such as peak positions, distribution ranges, relative intervals between peaks, and tail-end variation trends is maintained. For continuously occurring high-density regions in the source domain, the sequential relationship between primary and secondary peaks is required to be maintained after mapping; when abnormal peak compression, splitting, or disordered order occurs in the mapping results, structural deviations are marked. For tail-end regions, a gradually weakening variation trend is required to be maintained in the target domain, avoiding reverse changes without corresponding evidence. The system obtains structural mapping data containing information such as the location of peak regions, peak order relationships, and the degree of structural preservation after mapping.
[0073] Energy redistribution analysis of propagation energy is performed on the structure mapping data to obtain energy shift data; In one embodiment, the system uses the density values corresponding to the structure mapping data as the intensity of the effect within each time window, compares and analyzes the peak regions before and after mapping, and extracts their overall change characteristics. The system evaluates the cumulative intensity level, concentration of the main peak, and changes in the expansion range of each peak region. When only a time position shift or moderate expansion leads to a decrease in peak value and an extension of the tail, it is determined to be a normal propagation change, and the overall intensity change is required to be within the allowable range. When there is an increase in intensity without a corresponding source, a significant decrease, or a local abnormal concentration, the region is marked as an abnormal shift region. Through the above, energy shift data containing intensity shift, expansion changes, concentration changes, and anomaly indicators are obtained.
[0074] The time delay alignment data is obtained by solving the joint constraints based on the energy offset data and the propagation deformation function.
[0075] In one embodiment, the system uses a propagation deformation function as a basis and energy offset data as a constraint to jointly optimize cross-domain time correspondences. Within each time window, candidate mapping relationships that simultaneously satisfy propagation continuity, structural consistency, and reasonable energy variation are selected, with priority given to alignment paths that maintain stable peak region correspondences and exhibit minimal energy variation. Paths that achieve time alignment but lead to peak region structural mismatch or abnormal energy concentration are discarded. The system progressively optimizes the time mapping relationships between clock domains through multiple rounds of window-level adjustments and continuity corrections. The system outputs time-delay alignment data containing time offset relationships, peak region correspondences, and alignment reliability.
[0076] Optionally, the separation of pseudo-anomalies from real attacks is specifically as follows: S41. Perform residual pattern parsing based on cross-clock check data to obtain residual structure data; In one embodiment, the system extracts various difference features based on residual information in cross-clock verification data, categorized by time window, including time position deviation, peak value variation difference, distribution width difference, and persistence difference. Using multiple consecutive time windows as analysis units, the system identifies residual change patterns, determining whether they exhibit characteristics such as overall shift, local abrupt changes, multi-peak misalignment, or alternating direction changes. When the same type of residual appears continuously in adjacent windows with a consistent trend, it is grouped into continuous residual pattern segments; cases that appear only in individual windows and lack continuity are marked as transient disturbances. Through the above, residual structure data containing residual type, persistence range, change intensity (determined based on the amplitude level of each residual component within the current window), and time position is obtained.
[0077] S42. Perform propagation closed-loop analysis on the residual structure data to obtain propagation closed-loop data; In one embodiment, the system performs propagation path analysis on each residual pattern segment in the residual structure data based on the link sequence of control end—network end—execution end. For each residual segment, it traces back along the link level by level, checking whether any abnormal changes occurring at the control end can be matched with corresponding segments in the network end and execution end, both in time sequence and structure. When the relevant changes show a sequential progression and correspond to each other at each node, the anomaly is determined to satisfy a closed-loop propagation relationship. When the anomaly exists only in local nodes, is missing in subsequent nodes, or exhibits inconsistent propagation order, the propagation loop is determined to be incomplete. The system also statistically analyzes the propagation coverage and sequential consistency of each residual segment, forming propagation closed-loop data representing the characteristics of the propagation loop.
[0078] S43. Conduct a behavioral interpretability assessment on the closed-loop propagation data to obtain behavioral interpretation data; In one embodiment, the system combines acquired behavioral feature data to perform interpretable evaluations of anomalous segments that meet or approach the propagation closed-loop conditions. The system checks whether the actuator's change direction during this period aligns with the corresponding dimming command's level change direction, whether the execution load change matches the density change trend, and whether there are instances of significant output changes occurring without a corresponding command. Anomalous segments are marked as interpretable segments when they can be explained by a continuous relationship of enhanced command changes, increased execution load, delayed or extended response processes; and are marked as uninterpretable segments when there are anomalous actions without command drive, inconsistent directions, or behavioral changes that cannot be correlated with preceding inputs. The system obtains behavioral interpretation data describing the interpretability of the anomalies.
[0079] S44. Attribution judgment is performed based on residual structure data, propagation closed-loop data, and behavioral interpretation data to obtain anomaly type data; In one embodiment, the system integrates residual structure data, propagation loop data, and behavioral interpretation data to determine the cause of anomalies. When the residuals mainly exhibit overall shifts or continuous changes, and a propagation relationship can be formed between nodes in the link, while the corresponding behavior can be reasonably explained by command changes, it is determined to be a pseudo-anomaly caused by network congestion, buffer backlog release, or link fluctuations. When the residuals exhibit local abrupt changes, multi-peak misalignment, or repeated changes in direction, and the propagation relationship is incomplete, while the behavioral changes cannot be explained by command input, it is determined to be an anomaly caused by illegal injection, replay, or tampering. For segments with insufficient features or uncertainties, they are marked as anomalies to be confirmed. The system outputs anomaly type data containing the anomaly category, judgment criteria, and corresponding time range.
[0080] S45. Based on the abnormality type data, perform abnormality identification and integration to obtain abnormality identification data.
[0081] In one embodiment, the system integrates and processes anomaly type data according to time sequence and link nodes to generate anomaly identification results. For cases determined to be pseudo-anomalies, the system records the occurrence time range, main affected nodes, corresponding residual patterns, and possible link congestion or delay segments; for cases determined to be anomalous attacks, the system records the occurrence window, suspected anomaly source location, main mismatch characteristics, and affected execution segments; for anomalies awaiting confirmation, the system includes relevant missing evidence information and corresponding confidence level descriptions. The system obtains anomaly identification data containing information such as anomaly category, occurrence time, involved nodes, and judgment criteria, which is used for alarm and analysis.
[0082] Optionally, the anomaly identification system based on dimming level switching behavior, used to perform the anomaly identification method described above, includes: The asynchronous phase self-consistent synchronization module is used to acquire multi-source timing data of the dimming link, perform asynchronous phase self-consistent synchronization on the multi-source timing data, and obtain asynchronous command behavior data. The feature extraction module is used to extract instruction interval features from asynchronous instruction behavior data to obtain switching feature data; and to reconstruct the executor response trajectory from asynchronous instruction behavior data to obtain behavior feature data. The cross-clock verification module is used to construct instruction density data based on switching feature data and behavior feature data, and to obtain instruction density data; and to perform cross-clock verification based on instruction density data, and to obtain cross-clock verification data. The pseudo-anomaly and real attack separation module is used to separate pseudo-anomalies and real attacks based on cross-clock verification data to obtain anomaly identification data.
[0083] Therefore, the embodiments should be regarded as exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended application documents rather than the foregoing description. Thus, it is intended that all variations falling within the meaning and scope of the equivalents of the application documents be incorporated into the invention.
[0084] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.
Claims
1. An anomaly identification method based on dimming level switching behavior, characterized in that, Includes the following steps: Acquire multi-source timing data of the dimming link, perform asynchronous phase self-consistent synchronization on the multi-source timing data, and obtain asynchronous command behavior data; Based on the asynchronous instruction behavior data, instruction interval features are extracted to obtain switching feature data; The executor trajectory is reconstructed based on the asynchronous instruction behavior data to obtain behavior feature data; The switching feature data is divided into time windows to obtain switching window data; the switching window data is processed by instruction switching to obtain instruction switching data; the behavior feature data is extracted by behavior carrying state to obtain behavior load data; the instruction switching data and behavior load data are coupled and mapped to obtain density distribution data; the density distribution data is shaped by local peaks to obtain instruction density data; and the instruction density data is checked across clocks to obtain cross-clock check data. By separating pseudo-anomalies from real attacks in cross-clock verification data, anomaly identification data is obtained.
2. The anomaly identification method based on dimming level switching behavior according to claim 1, characterized in that, Asynchronous phase self-consistent synchronization specifically refers to: Multi-source time-series data is encoded using multi-source time-series potential encoding to obtain time-series potential data: The system acquires raw time-series data from the control terminal, network nodes, and actuator side, and assigns corresponding tags to each record according to the event type. The tags include at least instruction generation, instruction forwarding, instruction arrival, execution initiation, and feedback return. Based on the occurrence order of events within the same device, the time interval between adjacent events is calculated and normalized to form the corresponding potential increment. The system associates the cumulative potential value of each event with the corresponding event tag to form time-series potential data. Cross-source anchor points are extracted based on time-series potential data to obtain cross-source anchor point data; By performing joint estimation of offset and drift on cross-source anchor point data, mapping function data is obtained; The asynchronous instruction behavior data is obtained by reconstructing the entire sequence based on the mapping function data.
3. The anomaly identification method based on dimming level switching behavior according to claim 1, characterized in that, The specific steps for extracting the instruction interval feature are as follows: Adjacent instruction pairing is performed based on asynchronous instruction behavior data to obtain instruction interval data; Interval distribution analysis is performed on the instruction interval data to obtain interval statistical characteristic data; Quasi-periodic manifold extraction is performed on the instruction interval data to obtain quasi-periodic manifold data; Based on the instruction interval data, a switching amplitude coupling analysis is performed to obtain switching coupling characteristic data; Switching feature data is obtained by organizing switching features based on interval statistical feature data, quasi-periodic manifold data, and switching coupling feature data.
4. The anomaly identification method based on dimming level switching behavior according to claim 3, characterized in that, Quasi-periodic manifold extraction specifically involves: Delayed embedding is performed based on the instruction interval data to obtain delayed embedded data; Locally tangent space alignment is performed on the delayed embedded data to obtain locally aligned data; The intrinsic evolutionary manifold behavior is synchronized based on locally aligned data to obtain intrinsic behavior data: The system analyzes the change relationship between adjacent time points based on the locally aligned state vector sequence, obtains the evolution direction and change intensity of each time period, and expresses them in a unified local space. Consistency processing is performed on continuous time segments to obtain intrinsic behavior data. Manifold constraint embedding is performed on intrinsic behavior data to obtain low-dimensional manifold data; Trajectory loop closure detection is performed based on low-dimensional manifold data to obtain quasi-periodic manifold data.
5. The anomaly identification method based on dimming level switching behavior according to claim 1, characterized in that, The actuator trajectory reconstruction is specifically as follows: Based on the asynchronous instruction behavior data, instruction behavior fragments are associated to obtain behavior fragment data; Behavior segment data is analyzed to identify the start and end boundaries of behavior, resulting in behavior unit data. Behavioral trajectory data is obtained by parametric modeling of behavioral unit data. Based on the behavior trajectory data, cross-instruction trajectory splicing is performed to obtain continuous trajectory data; Constraint verification is performed on continuous trajectory data to obtain behavioral feature data.
6. The anomaly identification method based on dimming level switching behavior according to claim 1, characterized in that, Cross-clock verification specifically refers to: Multi-clock domain density projection is performed based on instruction density data to obtain cross-domain density data. Trajectory manifold alignment is performed based on cross-domain density data to obtain time delay aligned data; The distribution divergence of the time-delay aligned data is measured to obtain the distribution divergence data; Based on the distribution divergence data, cross-clock residuals are constructed to obtain time-series residual data: The system associates and organizes the distribution divergence data with the time delay alignment results, and constructs cross-clock residual information within the corresponding time window. The residuals include time alignment deviation, density peak difference, distribution width difference, and high-density area persistence difference. The system extracts the above difference features in each window and splices them continuously in time order to obtain time-series residual data. Cross-clock verification data is obtained by performing cross-clock determination on the timing residual data.
7. The anomaly identification method based on dimming level switching behavior according to claim 6, characterized in that, Trajectory manifold alignment specifically refers to: A density propagation conservation field is constructed based on cross-domain density data to obtain propagation constraint field data; Cross-domain propagation deformation modeling is performed on the propagation constraint field data to obtain propagation deformation function data; Density structure preservation mapping is performed based on the propagation deformation function data to obtain structure mapping data; Energy redistribution analysis of propagation energy is performed on the structure mapping data to obtain energy shift data; The time delay alignment data is obtained by solving the joint constraints based on the energy offset data and the propagation deformation function.
8. The anomaly identification method based on dimming level switching behavior according to claim 1, characterized in that, The separation of pseudo-anomalies from real attacks is specifically as follows: Residual pattern parsing is performed based on cross-clock verification data to obtain residual structure data; Propagation closed-loop analysis was performed on the residual structure data to obtain propagation closed-loop data; Behavioral interpretability assessment is performed on the closed-loop propagation data to obtain behavioral interpretation data; Attribution judgment is performed based on residual structure data, propagation closed-loop data, and behavioral explanation data to obtain anomaly type data; Anomaly identification data is obtained by integrating anomaly type data.
9. An anomaly identification system based on dimming level switching behavior, characterized in that, For performing the anomaly identification method based on dimming level switching behavior as described in claim 1, the anomaly identification system based on dimming level switching behavior includes: The asynchronous phase self-consistent synchronization module is used to acquire multi-source timing data of the dimming link, perform asynchronous phase self-consistent synchronization on the multi-source timing data, and obtain asynchronous command behavior data. The feature extraction module is used to extract instruction interval features from asynchronous instruction behavior data to obtain switching feature data; and to reconstruct the executor response trajectory from asynchronous instruction behavior data to obtain behavior feature data. The cross-clock verification module is used to construct instruction density data based on switching feature data and behavior feature data, and to obtain instruction density data; and to perform cross-clock verification based on instruction density data, and to obtain cross-clock verification data. The pseudo-anomaly and real attack separation module is used to separate pseudo-anomalies and real attacks based on cross-clock verification data to obtain anomaly identification data.
Citation Information
Patent Citations
Edge calculation signal lamp control method and system based on traffic participant behavior analysis
CN120526475A
Abnormal process detection method based on multi-modal fusion
CN121705935A