An industrial intelligent control data security protection method, system and server

By performing unified time reference mapping and density sequence analysis on various control behaviors of industrial intelligent control devices, a time density baseline structure is constructed, which solves the negative impact of complex security strategies on control real-time performance and improves the accuracy and stability of anomaly identification and protection while ensuring data security.

CN122332816APending Publication Date: 2026-07-03HANXING TONGHENG TECH GRP CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANXING TONGHENG TECH GRP CO LTD
Filing Date
2026-05-09
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

In existing industrial intelligent control devices, complex security strategies, while improving data security, lead to a decrease in control real-time performance. Furthermore, attackers can exploit security mechanisms to interfere with the control process, causing control chain disorder and instability.

Method used

By mapping the control command trigger sequence, execution feedback transmission sequence, status update record sequence, and communication interaction sequence to a unified time base, a time density sequence set is constructed. Based on historical normal operation data, a time density baseline structure is constructed to generate a real-time time density sequence. Density expansion processing is performed to form an observation entropy sequence. Time structure anomalies are identified and rearranged to dynamically update security protection.

Benefits of technology

It enhances the ability to identify abnormal behavior, improves the accuracy and reliability of anomaly identification, avoids the negative impact of complex security strategies on real-time control, and ensures data security and the stability of the control process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122332816A_ABST
    Figure CN122332816A_ABST
Patent Text Reader

Abstract

This application provides a method, system, and server for data security protection in industrial intelligent control, relating to the field of data processing. The method acquires multiple types of time-series data from industrial intelligent control devices and maps them uniformly to the same time base, constructing a time density sequence set; forms a time density baseline structure based on historical normal operation data; generates real-time time density sequences and observation entropy sequences for real-time events; identifies time structure anomalies and determines the type of time disturbance by comparing them with the time density baseline structure; locates the source of time disturbance through time rearrangement; and dynamically updates the time density baseline structure and implements continuous security protection by combining time order evolution records. Implementing the technical solution provided in this application facilitates ensuring the data security of industrial intelligent control devices while avoiding the negative impact of complex security strategies on control real-time performance and preventing attackers from using security mechanisms to interfere with the control process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, specifically to a method, system, and server for protecting data security in industrial intelligent control. Background Technology

[0002] As industrial intelligent control devices gradually develop towards networking, distribution, and multi-source collaboration, the control command trigger sequence, execution feedback transmission sequence, status update record sequence, and communication interaction sequence exhibit highly coupled and rapidly iterating characteristics within the same control cycle, significantly increasing the system's time response requirements. Especially in high real-time scenarios such as power control, precision manufacturing, and process control, the control link typically relies on strict time constraints to complete closed-loop regulation. Once computational delays, scheduling blockages, or response lags occur, it may lead to a decrease in control accuracy or even trigger system instability.

[0003] To enhance the data security of industrial intelligent control devices, existing technologies typically incorporate encryption, authentication, and anomaly detection mechanisms into the control link to prevent data tampering, unauthorized access, and malicious attacks. However, these security strategies are mostly based on complex computational models or multi-round verification processes, inevitably introducing additional computational overhead and processing latency during execution. This is particularly true when performing deep detection or high-strength encryption on the control command trigger sequence and execution feedback return sequence, significantly increasing the processing time of the control path and lengthening the originally tight control cycle, thereby weakening the system's real-time response capability. Furthermore, in real-world operating environments, attackers can exploit the inherent contradiction between security strategies and real-time constraints by constructing specific forms of perturbation data or anomaly triggering conditions to induce the system to frequently activate high-overhead security strategies, such as triggering multi-level authentication processes or complex anomaly analysis processes, keeping the system continuously under high-load security processing. During this process, the processing rhythm of the control command trigger sequence and execution feedback return sequence is disrupted, delays and backlogs occur in the state update record sequence, and queuing and blocking occur in the communication interaction sequence, leading to disorder in the overall control link's timing structure and, in severe cases, even control instability.

[0004] Therefore, how to ensure the data security of industrial intelligent control devices while avoiding the negative impact of complex security strategies on the real-time performance of control, and preventing attackers from using security mechanisms to interfere with the control process, has become a key technical problem that urgently needs to be solved. Summary of the Invention

[0005] This application provides a method, system, and server for protecting data security in industrial intelligent control, which facilitates ensuring the data security of industrial intelligent control devices while avoiding the negative impact of complex security strategies on the real-time performance of control, and preventing attackers from using security mechanisms to interfere with the control process.

[0006] The first aspect of this application provides a method for protecting the security of industrial intelligent control data. The method includes: acquiring control command trigger sequences, execution feedback transmission sequences, status update record sequences, and communication interaction sequences of an industrial intelligent control device, and mapping them uniformly to the same time base to form a time density sequence set; performing merge analysis on the historical normal operation data of the industrial intelligent control device based on the time density sequence set to construct a time density baseline structure; mapping real-time event data of the industrial intelligent control device to the time density sequence set to generate a real-time time density sequence, and performing density expansion processing on the real-time time density sequence to form an observation entropy sequence; comparing the observation entropy sequence with the time density baseline structure to identify time structure anomaly regions, and tracing back the density evolution path of the time structure anomaly regions to obtain a time disturbance type identifier; performing time rearrangement processing on the time structure anomaly regions according to the time disturbance type identifier, and determining the time disturbance source based on the regression of the rearranged observation entropy sequence; dynamically updating the time density baseline structure based on the time order evolution record, and implementing continuous security protection processing on the time disturbance source.

[0007] A second aspect of this application provides an industrial intelligent control data security protection system. The system includes an acquisition module and a processing module. The acquisition module acquires control command trigger sequences, execution feedback transmission sequences, status update record sequences, and communication interaction sequences from an industrial intelligent control device, and maps them uniformly to the same time base to form a time density sequence set. The processing module performs merge analysis on the historical normal operation data of the industrial intelligent control device based on the time density sequence set to construct a time density baseline structure. The processing module also maps real-time event data of the industrial intelligent control device to the time density sequence set to generate real-time events. The processing module generates an observation entropy sequence by performing density expansion processing on the real-time temporal density sequence. The module further compares the observation entropy sequence with the temporal density baseline structure to identify temporal structure anomalies and traces the density evolution path of these anomalies to obtain a temporal disturbance type identifier. Based on the temporal disturbance type identifier, the module performs temporal rearrangement processing on the temporal structure anomalies and determines the temporal disturbance source based on the regression of the rearranged observation entropy sequence. Finally, the module dynamically updates the temporal density baseline structure based on the temporal order evolution record and implements continuous security protection processing for the temporal disturbance source.

[0008] A third aspect of this application provides a server comprising a processor, a memory, a user interface, and a network interface, wherein the memory is used to store instructions, the user interface and the network interface are both used to communicate with other devices, and the processor is used to execute the instructions stored in the memory to cause the server to perform the method described above.

[0009] A fourth aspect of this application provides a non-transitory computer-readable storage medium storing instructions that, when executed, perform the method described above.

[0010] In summary, one or more technical solutions provided in this application have at least the following technical effects or advantages: By mapping control command trigger sequences, execution feedback sequences, state update record sequences, and communication interaction sequences to a unified time base and constructing a set of time density sequences, the system can characterize the coordinated rhythms of multiple control behaviors under the same time coordinate. This avoids the one-sidedness caused by relying solely on a single data stream for judgment and improves the overall ability to identify abnormal behaviors in complex coupled scenarios. By constructing a time density baseline structure based on historical normal operation data, the system possesses a stable representation capability of normal time order. This time density baseline structure not only describes the distribution of various events within time unit intervals but also characterizes density stability intervals, density transition boundaries, and density propagation paths. This provides an evolution-constrained reference basis for subsequent real-time observations, facilitating consistency and interpretability of anomaly judgments under multiple operating conditions. By mapping real-time event data to generate real-time time density sequences and performing density expansion processing to form observation entropy sequences, the system can characterize the orderliness of the current operating state from the event distribution structure rather than single-point values. This allows for the identification of hidden anomalies at the time organization level while maintaining reasonable data values, effectively compensating for the difficulty of detecting low-amplitude disturbances using traditional threshold-based or statistical feature-based methods.

[0011] By comparing the observed entropy sequence with the temporal density baseline structure and tracing the density evolution path of the time structure anomaly region, anomaly identification is expanded from static boundary judgment to dynamic formation process analysis. This not only determines the location of the anomaly but also analyzes its formation path and expansion mode, providing clear causal evidence for subsequent processing. This helps distinguish between instantaneous fluctuations and continuous disturbances, improving the accuracy of anomaly identification. By performing time rearrangement based on the time disturbance type identifier and using the regression results of the rearranged observed entropy sequence to determine the time disturbance source, the system can verify whether the anomaly is caused by temporal disorder without changing the event content. This transforms anomaly localization from correlation judgment to causal verification, effectively improving the reliability of time disturbance source identification and avoiding misjudging non-critical events as the main attack source. By dynamically updating the temporal density baseline structure based on the time order evolution record, the system can absorb stable evolutionary characteristics and adjust the boundary range during long-term operation. This ensures safety judgment capabilities while adapting to changes in operating conditions, avoiding false alarms or missed alarms due to baseline rigidity, and improving the overall system robustness.

[0012] By implementing continuous security protection measures for time-based disturbance sources, the security mechanism shifts from one-time detection and response to continuous constraint and dynamic adjustment. This not only suppresses the re-influence of identified disturbance sources but also allows for the gradual optimization of protection strategies through hierarchical management and feedback mechanisms. This achieves a balance between security and performance while ensuring real-time control, preventing complex security strategies from overburdening the control chain. Therefore, it facilitates ensuring the data security of industrial intelligent control devices while avoiding the negative impact of complex security strategies on real-time control and preventing attackers from using security mechanisms to interfere with the control process. Attached Figure Description

[0013] Figure 1 A flowchart illustrating an industrial intelligent control data security protection method provided in this application embodiment; Figure 2 A schematic diagram of a module for an industrial intelligent control data security protection system provided in this application embodiment; Figure 3 This is a schematic diagram of the structure of a server provided in an embodiment of this application.

[0014] Explanation of reference numerals in the attached figures: 21. Acquisition module; 22. Processing module; 31. Processor; 32. Communication bus; 33. User interface; 34. Network interface; 35. Memory. Detailed Implementation

[0015] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.

[0016] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.

[0017] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0018] To address the aforementioned technical problems, this application provides a method for protecting data security in industrial intelligent control, referring to... Figure 1 , Figure 1 This is a flowchart illustrating an industrial intelligent control data security protection method provided in an embodiment of this application. The method is applied to a server and includes steps S110 to S160, as follows:

[0019] S110: Obtain the control command trigger sequence, execution feedback transmission sequence, status update record sequence, and communication interaction sequence of the industrial intelligent control device, and map them uniformly to the same time base to form a time density sequence set.

[0020] Specifically, after the server obtains the control command trigger sequence, execution feedback return sequence, status update record sequence, and communication interaction sequence from the industrial intelligent control device, it first performs event extraction processing to form a set of event units with a unified structure. The control command trigger sequence refers to the time-based triggering records of control actions such as start / stop, adjustment, switching, linkage, and strategy issuance issued by the industrial intelligent control device during operation. The execution feedback return sequence refers to the feedback records of the actuator's status confirmation, position return, action completion, and abnormal return in response to the control actions. The status update record sequence refers to the refresh records of the internal operating status, process status, mode status, and safety status of the industrial intelligent control device during operation. The communication interaction sequence refers to the interaction records between the industrial intelligent control device and edge nodes, upper-level nodes, collaborative nodes, or field terminals for message sending, message receiving, handshake confirmation, link maintenance, and abnormal retransmission. The purpose of event extraction processing is to unify the above-mentioned original records from different sources, in different formats, and with different refresh rates into event units. Each event unit includes at least an event category identifier, an event source identifier, an event target identifier, an original event timestamp, and an event content summary. The event category identifier distinguishes whether the current event is a control command event, execution feedback event, status update event, or communication interaction event; the event source identifier identifies whether the event originates from the control core, execution interface, status monitoring interface, or communication interface; the event target identifier identifies the control loop, execution component, status variable, or communication link associated with the event; the event original timestamp records the occurrence time of the event in the original data acquisition system; and the event content summary retains the event's key business information. To ensure consistent event unit structure, the following unified mapping expression can be used:

[0021]

[0022] in, Indicates the first One event unit; This indicates the event category identifier, which is divided into control instruction events, execution feedback events, status update events, and communication interaction events according to preset codes; This indicates the event source identifier, used to identify which type of interface or functional unit the event originated from; This represents the object to which the event applies, indicating which control object, execution object, state object, or communication object the event applies to. Represents the original timestamp of an event, used to characterize the recording time of the event in the original log, message, or sampling system; This represents a summary of the event content, used to retain the core business fields needed for subsequent merge analysis. The purpose of the above expression is to consolidate heterogeneous original records into a unified event unit structure, thereby providing a consistent processing object for subsequent unified time mapping.

[0023] After forming the event unit set, the server constructs a common time reference based on the control cycle of the industrial intelligent control device and maps each event unit to the same time reference to obtain a standard time stamp. The control cycle refers to the basic time length corresponding to the industrial intelligent control device completing one complete control perception, control calculation, and execution feedback closed loop; the common time reference refers to a unified time coordinate system established based on this control cycle, used to convert event units originally under different local clock, different buffer delay, and different link delay conditions into the same time reference frame; the standard time stamp refers to the time position re-obtained by the event unit under the same time reference. The key to this step is not simply modifying the timestamp, but eliminating the time deviation caused by queuing, buffering, transmission jitter, and local clock drift between different acquisition interfaces, so that the control command trigger sequence, execution feedback return sequence, status update record sequence, and communication interaction sequence can be aligned on the same time axis. The following standard time mapping expression can be used:

[0024]

[0025] in, Indicates the first Standard time stamp for each event unit; Indicates the first The original timestamp of each event unit; Indicates the unified start time of the current analysis window, used to shift all events to the same reference starting point; Indicates the first The time correction amount for each event unit is used to compensate for buffer latency, link jitter, queuing delay, and local clock skew. It represents the control cycle of an industrial intelligent control device, used to convert absolute time into a relative time position scaled by the control cycle.

[0026] After obtaining the standard timestamps, the server performs time slicing on the mapped event units to divide them into time unit intervals, and then performs time placeholder registration for each time unit interval. Time slicing refers to dividing the continuous time axis into discrete time intervals with consecutive beginnings and endings according to a preset time granularity; a time unit interval refers to each segmented discrete time segment; and time placeholder registration refers to assigning the event units to their corresponding time unit intervals according to the standard timestamps and recording the occurrence status of events within those time unit intervals. This step further transforms the continuous time mapping results into a statistically stable, merging, and comparable discrete time structure. To describe which time unit interval a given event unit belongs to, the following interval location expression can be used:

[0027]

[0028] in, Indicates the first The time interval number to which each event unit belongs; Indicates the first Standard time stamp for each event unit; The slice width represents the time unit interval and is used to determine the time range covered by each time unit interval; This represents the floor operation, used to map continuous time positions to discrete interval numbers. After completing the interval location, it is also necessary to perform time occupancy registration for each time unit interval. The number of occupancy slots for a certain type of event within a certain time unit interval can be represented by the following formula:

[0029]

[0030] in, Indicates the number is The category within the time unit interval is The number of event placeholders; This indicates the total number of event units in the current analysis window; This indicates an indicator function that takes the value 1 when the condition inside the parentheses is true, and 0 otherwise. Indicates the first The time interval number to which each event unit belongs; This indicates the target time unit interval number currently being counted; Indicates the first Event category identifier for each event unit; This indicates the category of target events currently being statistically analyzed. By registering time placeholders, we can not only determine whether a certain type of event occurs within a specific time interval, but also the degree of concentration of that type of event within that interval.

[0031] After completing time placeholder registration within each time unit interval, the server performs category merging processing on event units within each time unit interval to form a standardized time representation. Category merging processing refers to organizing event units belonging to the same event category and acting on the same event object within the same time unit interval into the same local subsequence; standardized time representation refers to a unified time series description result formed with the time unit interval as the horizontal axis and event category and event object as the organizational dimensions. The purpose of this step is to further organize the discrete placeholder statistics results from the previous step into a structured expression with clear business meaning and time sequence, so that subsequent time density construction processing no longer deals with isolated events, but with a time series structure that has been organized by category and object. The following merging expression can be used:

[0032]

[0033] in, The time unit interval number is Event category identifier The event target is identified as Local event merging groups; Indicates the first One event unit; Indicates the first The time interval number to which each event unit belongs; Indicates the first Event category identifier for each event unit; Indicates the first The event target identifier for each event unit; The union operation is used to merge sets of events that meet the conditions of the same time interval, the same event category, and the same object of action into the same merge group. Subsequently, local event merge groups from different time intervals can be connected chronologically to form a standardized time representation. The result preserves both the chronological order and the structural information of event categories and objects, facilitating subsequent analysis of the temporal coordination relationships between different control behaviors, execution behaviors, state behaviors, and communication behaviors.

[0034] After forming a standardized time expression, the server performs time density construction processing based on the standardized time expression to obtain the corresponding time density sequence, and then performs joint orchestration processing on each time density sequence to form a time density sequence set. Time density construction processing refers to calculating the event occupancy intensity, event clustering intensity, event continuity intensity, and event sparse distribution state for each type of standardized time expression in each time unit interval; a time density sequence refers to the density change trajectory formed by a certain type of event in a continuous time unit interval; joint orchestration processing refers to synchronously organizing the time density sequences corresponding to control command trigger sequences, execution feedback return sequences, state update record sequences, and communication interaction sequences according to the same time unit interval, thereby forming a multi-sequence parallel time density sequence set. An expression for the event occupancy intensity within a certain time unit interval can be defined first:

[0035]

[0036] in, Indicates the number is Event occupancy intensity within a time unit interval; Indicates the total number of event categories; Indicates the first The category weights of events are used to reflect the degree of influence of different event categories on time density, and are set according to the importance of control, the importance of feedback, the importance of state update and the importance of communication. Indicates the number is The category within the time unit interval is The number of event placeholders.

[0037] To further characterize the concentration of events within a local time frame, an expression for event clustering intensity can be constructed:

[0038] in, Indicates the number is The intensity of event clustering within a time unit interval; Indicates the first Category weights for class events; Indicates the number is The category within the time unit interval is The number of event placeholders; Indicates the number is The category within the time unit interval is The average time location of events is used to characterize the average distribution center of this type of event in that interval; Indicates the number is The midpoint time position of the time unit interval; It indicates the degree to which the average time position of an event deviates from the midpoint of the interval.

[0039] To characterize the stability of event continuation between adjacent time intervals, an expression for event continuity intensity can be constructed:

[0040] in, Indicates the number is The intensity of event continuity between time intervals relative to the previous time interval; Indicates the first Category weights for class events; Indicates the number is The category within the time unit interval is The number of event placeholders; Indicates the number is The category within the time unit interval is The number of event placeholders; This indicates the operation of taking the smaller value, used to characterize the scale of events that can actually form continuous support between two adjacent time unit intervals.

[0041] After obtaining the event occupancy intensity, event clustering intensity, and event continuity intensity, a comprehensive time density value can be constructed to form a time density sequence:

[0042] in, Indicates the number is The comprehensive time density value of the time unit interval; Indicates the intensity of event occupancy; Indicates the intensity of event clustering; Indicates the intensity of the continuity of an event; , , The combined weight parameters, representing the proportions of event occupancy intensity, event aggregation intensity, and event continuity intensity in the overall time density value, are non-negative and set according to the real-time requirements and business priorities of the industrial intelligent control device. Subsequently, the overall time density values ​​corresponding to all time unit intervals are arranged chronologically to form the corresponding time density sequences. Finally, the time density sequences corresponding to control command trigger sequences, execution feedback transmission sequences, status update record sequences, and communication interaction sequences are jointly arranged to synchronize multiple types of time density values ​​within the same time unit interval, forming a time density sequence set. This time density sequence set preserves both the temporal rhythm of individual events and the synchronization relationships between multiple events, providing a unified and complete analytical foundation for subsequently constructing a time density baseline structure based on historical normal operation data.

[0043] S120. Perform merge analysis on the historical normal operation data of industrial intelligent control devices based on the time density sequence set to construct a time density baseline structure.

[0044] Specifically, the server performs merge analysis on the historical normal operation data of industrial intelligent control devices based on the time density sequence set to construct a time density baseline structure. First, sample screening processing is performed on the historical normal operation data corresponding to the time density sequence set to form a historical normal sample set. Historical normal operation data refers to the time density sequence set recorded when the industrial intelligent control device did not experience abnormal phenomena such as control instability, execution anomalies, communication interruptions, or safety alarm failures during its past operation. The historical normal sample set refers to the sample set selected from all historical operation records that can truly reflect the characteristics of normal time order. The purpose of this step is to remove samples that are not representative of normal operation, such as fault conditions, switching shock conditions, debugging conditions, and abnormal communication conditions, before subsequent baseline construction, to avoid abnormal rhythms contaminating the baseline structure. To quantify whether a certain historical operation segment can enter the historical normal sample set, a normal sample scoring function can be constructed:

[0045]

[0046] in, Indicates the first Normal sample scores for a historical runtime segment; Indicates the first The stability of the control loop within a historical running segment is used to characterize whether a stable closed-loop relationship is maintained between the control command trigger sequence and the execution feedback return sequence. Its value falls within the range of 0 to 1 after normalization, and the larger the value, the more stable the control. Indicates the first The degree of continuity of execution feedback within a historical execution segment is used to characterize whether there is a large area of ​​missing or severe delay in the execution feedback return sequence, and its value falls within the range of 0 to 1. Indicates the first The degree of state update completeness within a historical running segment is used to characterize whether the state update record sequence is continuous, complete and without abnormal gaps, and its value falls within the range of 0 to 1; Indicates the first The stability of communication interaction within a historical segment is used to characterize whether there is severe blocking, continuous retransmission or long-term loss in the communication interaction sequence, and its value falls within the range of 0 to 1. , , , This represents the weight coefficient of the corresponding indicator. Each weight coefficient takes a non-negative value and their sum is 1. It is used to reflect the importance of different stability indicators in sample selection.

[0047] After forming the historical normal sample set, the server performs operating condition segmentation processing on the historical normal sample set to form multiple operating condition subsets. Operating condition segmentation processing refers to further dividing the historical normal sample set into multiple sample subsets with relatively consistent internal rhythms based on differences in operating load, control mode, communication activity level, status update cycle time, and execution intensity of industrial intelligent control devices. Operating condition subsets refer to historical normal sample sets with similar time density characteristics under the same type of operating conditions. The purpose of this step is to avoid forcibly mixing normal rhythms that already exhibit significant differences under different operating conditions, which could lead to an overly coarse or overly wide time density baseline structure. To describe the attribution of historical normal samples in the operating condition space, an operating condition feature vector can be constructed:

[0048]

[0049] in, Indicates the first The working condition feature vector of a historical normal sample; This represents the control load level, used to characterize the overall activity level of the control command trigger sequence within a unit of time. Its value falls within the range of 0 to 1 after normalization. It represents the level of communication activity and is used to characterize the frequency of communication interaction sequences per unit time. Its value falls within the range of 0 to 1. The control mode code is used to distinguish different control strategies or operating modes and can be obtained by numericalizing discrete identifiers. This represents the state update beat feature, used to characterize the update time structure of the state update record sequence; This represents the execution feedback intensity, used to characterize the feedback occupancy level of the execution feedback sequence per unit time. Based on the operating condition feature vector, a distance partitioning method can be used to form an operating condition subset, for example:

[0050]

[0051] in, Indicates the first The first historical normal sample and the first The working condition distance between historical normal samples; and These represent two historical normal samples at the 1st... Values ​​for each working condition characteristic; Indicates the first The distance weight of each working condition feature is used to reflect the degree of influence of each working condition feature on the segmentation result, and a non-negative value is taken.

[0052] After forming multiple work condition subsets, the server performs time unit alignment processing on the time density sequences within each subset to establish corresponding time unit intervals. Time unit alignment processing refers to realigning the time density sequences from different historical normal samples within the same work condition subset according to a unified time role. This allows time density sequences with different starting points, slightly different durations, or minor shifts in local beats to be merged within comparable time unit intervals. Corresponding time unit intervals refer to time intervals from different historical normal samples that, after alignment, have the same time role and the same analytical significance. The purpose of this step is to ensure that subsequent interval merging processing compares similar time positions, rather than mixtures of different time stages. To measure the alignment relationship between two samples in time units, an alignment mapping function can be defined:

[0053]

[0054] in, Indicates the first In the first historical normal sample The original time unit is numbered after alignment; Indicates the first In the first historical normal sample Original time unit number; Indicates the first The time offset of a historical normal sample relative to the reference rhythm of the current operating condition subset is used to compensate for differences such as starting position deviation, beat stretching or compression. This represents a time alignment mapping function used to convert the original time unit numbering into the corresponding time unit interval numbering. If linear alignment is used, it can be written as:

[0055]

[0056] in, Indicates the first A timescale adjustment coefficient for each historical normal sample is used to compensate for differences in time unit length, and it takes a positive value. Indicates the first The time shift of each historical normal sample is used to compensate for the initial position deviation.

[0057] After establishing the corresponding time unit intervals, the server performs interval merging processing on similar time density sequences within each interval to obtain a stable interval representation. Similar time density sequences refer to time density sequence fragments belonging to the same event category in different historical normal samples and falling within the same corresponding time unit interval after time unit alignment. Interval merging processing involves comprehensively extracting the statistical distribution of these similar time density sequence fragments within each corresponding time unit interval. A stable interval representation is a structured representation that characterizes the stable time density state of the corresponding time unit interval under normal operating conditions. The purpose of this step is to extract the normal density center, normal fluctuation range, and local variation trend of a specific time unit interval from multiple historical normal samples. The following interval stability expression can be used:

[0058]

[0059] in, Indicates the event category as The time density sequence in the corresponding time unit interval The interval is stable; This represents the mean temporal density of the event category within the corresponding time unit interval, used to characterize the normal density center. It indicates the degree of dispersion of the time density of the event category in the corresponding time unit interval, and is used to characterize the strength of normal fluctuations. It is the standard deviation or other dispersion measure. This indicates the lower boundary of the event category in the corresponding time unit interval, used to characterize the low-bit range allowed by normal time density; This represents the upper boundary of the event category within the corresponding time unit interval, used to characterize the high-order range allowed by normal time density. If the time density value is denoted as... Then the mean and dispersion can be written as:

[0060]

[0061]

[0062] in, Indicates the first The event category in the historical normal sample is: The time density sequence in the corresponding time unit interval The time density value on; Indicates the corresponding time unit interval The number of historical normal samples that participated in the merging.

[0063] After obtaining the interval stable representation, the server performs cooperative merging processing on the control command trigger sequence, execution feedback sequence, state update record sequence, and communication interaction sequence based on the interval stable representation to form cooperative density relationships. Cooperative merging processing means that instead of simply considering the stable states of the four types of time density sequences individually, it further analyzes their linkage strength and temporal coupling relationships within the same corresponding time unit interval. Cooperative density relationships refer to the time density cooperative patterns of control behavior, execution behavior, state behavior, and communication behavior under normal operating conditions. The purpose of this step is to elevate the normal range of a single sequence to a normal cooperative structure among multiple sequences, so that the time density baseline structure can characterize not only whether a single type of event is normal, but also whether cross-type linkage is normal. The cooperative relationship of a corresponding time unit interval can be represented by a cooperative density matrix:

[0064]

[0065] in, Indicates the corresponding time unit interval Synergistic density matrix on; Indicates event category Event Category In the corresponding time unit interval The coordination strength; event categories 1, 2, 3, and 4 correspond to the control command trigger sequence, execution feedback sequence, state update record sequence, and communication interaction sequence, respectively. If a normalized coordination correlation metric is used, it can be written as:

[0066]

[0067] in, Indicates the first The event category in the historical normal sample is: Time density value; Indicates the first The event category in the historical normal sample is: Time density value; and Representing event categories and event categories In the corresponding time unit interval The mean of time density.

[0068] After establishing the cooperative density relationship, the server performs boundary extraction processing on the interval stable representation and cooperative density relationship to obtain the density stable interval, density transition boundary, and density propagation path. Boundary extraction processing refers to further extracting structural boundary information that can be used for real-time determination from the interval stable representation and cooperative density relationship. The density stable interval refers to the allowable range within which the temporal density remains normal within a corresponding time unit interval. The density transition boundary refers to the upper and lower limits of normal density change between adjacent corresponding time unit intervals. The density propagation path refers to the path relationship of normal transmission and evolution of temporal density along continuous time unit intervals. The purpose of this step is to elevate the static interval statistical information and horizontal cooperative relationship into a boundary structure that can describe the temporal evolution logic. The density stable interval can be expressed as follows:

[0069]

[0070] in, Indicates the event category as The time density sequence in the corresponding time unit interval Density stability range above; This represents the average time density of the event category within the corresponding time interval; This indicates the degree of time density dispersion of the event category within the corresponding time unit interval; Indicates event category The stability interval scaling factor, used to control the width of the upper and lower boundaries, is taken as a positive value, and its magnitude is set according to the normal fluctuation tolerance of different event categories. The density transition boundary can be expressed by the difference between adjacent intervals:

[0071]

[0072]

[0073] in, Indicates the event category as The time density sequence from the corresponding time unit interval To the corresponding time unit interval Density transition boundary during transmission; It represents the difference in mean between two adjacent corresponding time intervals; and These represent the lower and upper bounds of a normal transition, respectively. The density propagation path can then be represented by a directed relation:

[0074]

[0075] in, Indicates the event category as The set of density transfer paths for time density sequences; Indicates from the corresponding time unit interval to the corresponding time unit interval The directed transitive relationship.

[0076] After obtaining the density stability interval, density transition boundary, and density transfer path, the server performs inter-layer merging processing on each operating condition subset to form the main baseline segment and the offset baseline segment. Inter-layer merging processing refers to continuing to compare and merge commonly stable temporal density features and local offset features that only exist under specific operating conditions across different operating condition subsets. The main baseline segment refers to the core temporal order segment that is stable across multiple operating condition subsets; the offset baseline segment refers to the rhythmic offset segment that exists only under one or several types of operating condition subsets but still falls within the normal operating range. The purpose of this step is to ensure that the temporal density baseline structure possesses both common stable features and operating condition adaptation features. If a certain operating condition subset is numbered... Then the local baseline segment under this subset of working conditions can be represented as:

[0077]

[0078] in, Represents a subset of operating conditions The corresponding local baseline segment; This represents the set of density-stable intervals under this subset of operating conditions; This represents the set of density transition boundaries under this subset of operating conditions; This represents the set of density transfer paths within this subset of operating conditions; This represents the set of collaborative density relationships within this subset of operating conditions. The common components across operating conditions can be extracted as the master baseline segment:

[0079]

[0080] in, Indicates the main baseline segment; Indicates the total number of subsets of operating conditions; This represents the intersection operation, used to extract the common, stable temporal density features across subsets of operating conditions. The operating condition-specific differences relative to the main baseline segment can be defined as the offset baseline segment.

[0081]

[0082] in, Represents a subset of operating conditions Offset baseline segment relative to the main baseline segment; the minus sign indicates that the shared portion of the main baseline segment is removed, retaining only the subset of operating conditions. A unique but still normal rhythm deviation.

[0083] After forming the main baseline segment and the offset baseline segment, the server performs a continuous weaving process on the main baseline segment and the offset baseline segment to form a time density baseline structure. Continuous weaving refers to reorganizing the dispersed main baseline segment and the offset baseline segment sequentially along the corresponding time unit intervals, and writing density stability intervals, density transition boundaries, density transfer paths, and cooperative density relationships into a unified continuous structure. The time density baseline structure refers to a unified baseline model that can completely describe the normal distribution, normal evolution, and normal cooperative relationships of multiple time density sequences under normal operating conditions of an industrial intelligent control device. The purpose of this step is to integrate all the local results obtained from the previous segmentation into an integrated reference structure that can be directly called upon for subsequent real-time judgment. The time density baseline structure can be represented as:

[0084]

[0085] in, Indicates the time density baseline structure; Indicates the corresponding time unit interval number; Indicates the corresponding time unit interval The set of density-stable intervals on; Indicates the corresponding time unit interval The set of density transition boundaries between its adjacent intervals; Indicates the corresponding time unit interval The associated density transfer path segment; Indicates the corresponding time unit interval The set of cooperative density relationships on; Indicates the corresponding time unit interval The segment source identifier is used to indicate whether the current interval is mainly supported by the main baseline segment or the offset baseline segment; This represents the total number of all corresponding time unit intervals. After continuous weaving, the time density baseline structure is no longer a collection of discrete statistical results, but a complete reference framework that can continuously express the normal rhythmic order on the time axis and adapt to changes in multiple operating conditions. This provides a direct basis for comparing real-time time density sequences with it, identifying time structure anomalies, tracing density evolution paths, and determining time disturbance types.

[0086] S130. Map the real-time event data of the industrial intelligent control device to a time density sequence set to generate a real-time time density sequence, and perform density expansion processing on the real-time time density sequence to form an observation entropy sequence.

[0087] Specifically, after constructing the time density baseline structure, the server maps the real-time event data of the industrial intelligent control device to a time density sequence set, generating a real-time time density sequence. It then performs density expansion processing on the real-time time density sequence to form an observation entropy sequence. This process begins with real-time event standardization processing of the real-time event data to form standard real-time event units. Real-time event data refers to the raw record set of control command trigger events, execution feedback events, status update record events, and communication interaction events continuously generated by the industrial intelligent control device during its current operating cycle. Real-time event standardization processing refers to unifying raw real-time events from different sources, formats, protocols, and caching methods into a standard expression with a consistent field structure. Standard real-time event units are the basic processing objects that, after unified processing, can directly participate in subsequent time mapping and density analysis. The purpose of this step is to ensure that various heterogeneous events collected at the current moment can use the unified event structure adopted when constructing the time density sequence set, thereby maintaining isomorphism between the real-time analysis chain and the historical analysis chain. The following real-time event standardization expression can be used:

[0088]

[0089] in, Indicates the first One standard real-time event unit; This indicates the event category identifier, used to distinguish whether the standard real-time event unit belongs to a control command trigger event, an execution feedback transmission event, a status update record event, or a communication interaction event. Its value is determined by a preset discrete code. This indicates the event source identifier, used to characterize whether the real-time event unit of this standard originates from the control core interface, execution feedback interface, status acquisition interface, or communication interaction interface. Indicates the object of the event, used to characterize the control loop, execution component, state variable or communication link corresponding to the standard real-time event unit; This represents the original real-time timestamp, used to record the local time position of the standard real-time event unit at the time of initial access; This represents a summary of the event content, used to retain key business fields of the standard real-time event unit; This indicates the real-time cycle identifier, used to characterize which real-time cycle the standard real-time event unit belongs to in the current analysis window; This indicates the real-time access location identifier, used to characterize which access channel or buffer location the real-time event unit of this standard originates from.

[0090] After forming a standard real-time event unit, the server performs real-time raw time correction processing on the standard real-time event unit to obtain a corrected time stamp. Real-time raw time correction processing refers to real-time compensation for time distortion caused by buffering, packet queuing, link jitter, interface forwarding, and local clock deviations within the current operating cycle. The corrected time stamp is a time stamp obtained after correcting the real-time raw time stamp, which more accurately reflects the actual occurrence sequence and real time position. The purpose of this step is to avoid misinterpreting time deviations introduced by the acquisition link itself as changes in the actual time structure within the industrial intelligent control device, thereby ensuring that subsequent real-time mapping processing is based on the most accurate possible time foundation. The following time correction expression can be used:

[0091]

[0092] in, Indicates the first Corrected time stamps for each standard real-time event unit; Indicates the first Real-time raw timestamps for each standard real-time event unit; This represents the cache latency correction amount, used to compensate for the dwell time of the standard real-time event unit in the local cache, message queue, or data buffer, and its value is non-negative. This represents the link transmission correction amount, used to compensate for the time consumption of the standard real-time event unit in the network transmission, forwarding queuing and protocol encapsulation process, and its value is non-negative. This represents the local clock correction amount, used to compensate for the offset between the clock of the current event access device and the unified time reference. Its value can be positive, negative, or zero. To improve the stability of the correction, the corrected time can also be subject to sequence constraints to ensure that the time on the same event object does not exhibit a reverse order that violates the control logic.

[0093] After obtaining the corrected timestamp, the server performs real-time mapping processing on the standard real-time event units based on the same time base and time unit interval, and assigns them to the corresponding time unit interval. The same time base refers to the unified time reference frame previously constructed based on the control cycle of the industrial intelligent control device; the time unit interval refers to the discrete time intervals previously divided under the unified time reference frame; real-time mapping processing refers to the process of converting the corrected standard real-time event units to the same time base and locating them within specific time unit intervals. The purpose of this step is to allow newly generated events within the current operating cycle to be directly embedded into the time frame corresponding to the existing time density sequence set, thereby making real-time events directly comparable to historical normal samples under the same time caliber. The following real-time mapping expression can be used:

[0094]

[0095]

[0096] in, Indicates the first The standard real-time position of each standard real-time event unit under the same time base; Indicates the first Corrected time stamps for each standard real-time event unit; Indicates the start time of the current real-time analysis window, used to unify the starting point of the position of all current real-time events; It indicates the control cycle of an industrial intelligent control device, used to convert absolute time into relative position under the control cycle; Indicates the first The time interval number to which each standard real-time event unit belongs; The slice width represents the time unit interval; This indicates the floor function.

[0097] After completing real-time mapping and assigning the events to their corresponding time intervals, the server performs real-time placeholder registration for the standard real-time event units within each time interval to form a real-time placeholder structure. Real-time placeholder registration refers to registering the distribution of standard real-time event units according to time intervals, recording the number, density, and time occupancy status of various events in each time interval. The real-time placeholder structure is a discrete structural expression reflecting the event occupancy status within each time interval of the current time window. The purpose of this step is to further transform the standard real-time event units that have already undergone unified mapping into a structural basis suitable for category merging and density writing. The following real-time placeholder expression can be used:

[0098]

[0099] in, Indicates the number is The category within the time unit interval is The number of real-time event placeholders; This indicates the total number of standard real-time event units within the current real-time analysis window; This indicates an indicator function that takes the value 1 when the condition inside the parentheses is true, and 0 otherwise. Indicates the first The time interval number to which each standard real-time event unit belongs; Indicates the target time unit interval number; Indicates the first Event category identifier for each standard real-time event unit; This indicates the target event category. Furthermore, the average entry position of events, the number of local concurrent events, and the continuity between adjacent time unit intervals can be registered in the real-time placeholder structure to support the subsequent calculation of aggregation intensity and continuity intensity.

[0100] After forming the real-time placeholder structure, the server performs real-time category merging processing based on the real-time placeholder structure to form real-time time density sequences corresponding to control command trigger sequences, execution feedback return sequences, status update record sequences, and communication interaction sequences. Real-time category merging processing refers to grouping standard real-time event units according to event category identifiers and event target identifiers within each time unit interval, and connecting them on continuous time unit intervals to form their own independent temporal expressions. The real-time time density sequence refers to the density change trajectory formed by a certain type of event unfolding along the time unit interval within the current running cycle. The purpose of this step is to organize the discrete placeholder results from the previous step into four real-time density skeletons that are completely consistent with the historical time density sequence set structure, thus providing a direct carrier for subsequent real-time density writing processing. The following merging expression can be used:

[0101]

[0102] in, The time unit interval number is Event category identifier The event target is identified as Real-time event merging groups; Indicates the first One standard real-time event unit; This indicates the time interval number to which the standard real-time event unit belongs; This indicates the event category identifier for the standard real-time event unit; This indicates the event target identifier of the standard real-time event unit; This indicates the union operation.

[0103] After forming four types of real-time time density sequences, the server performs real-time density writing processing on these sequences to obtain event occupancy intensity, event clustering intensity, event continuity intensity, and event sparse distribution state. Real-time density writing processing refers to converting the event distribution characteristics in the real-time merge group into quantifiable density characteristics for each time unit interval and writing them into the corresponding sequence position. Event occupancy intensity refers to the overall occupancy of a time position by real-time events within a certain time unit interval; event clustering intensity refers to the concentration of real-time events within a local time range within a certain time unit interval; event continuity intensity refers to the stability of the continued occurrence of real-time events between adjacent time unit intervals; and event sparse distribution state refers to the degree to which real-time events exhibit discontinuous distribution across continuous time unit intervals. The purpose of this step is to further elevate the four types of real-time time density sequences from a structural skeleton into a numerical expression with temporal rhythm characteristics. Real-time event occupancy intensity can be expressed as follows:

[0104]

[0105] in, Indicates the number is The intensity of real-time events within a time unit interval; Indicates the total number of event categories; Indicates the first The category weight of each event type is used to reflect the degree of contribution of different event types to the current time density, and takes a non-negative value; Indicates the number is The category within the time unit interval is The number of real-time event placeholders. The intensity of real-time event aggregation can be expressed by the following expression:

[0106]

[0107] in, Indicates the number is The intensity of real-time event aggregation within a time unit interval; Indicates the number is The category within the time unit interval is The average time position of real-time events is used to characterize the average landing point of this type of real-time event within the interval; Indicates the number is The midpoint time position of the time unit interval; the meanings of the other parameters are the same as before. The continuity intensity of real-time events can be expressed as follows: .in, Indicates the number is The continuity intensity of real-time events in a time unit interval relative to the previous time unit interval; Indicates the number is The category within the time unit interval is The number of real-time event placeholders. The sparse distribution of real-time events can be expressed by the following expression:

[0108]

[0109] in, Indicates the number is The sparse distribution of real-time events within a time unit interval; This indicates the degree of difference between the current time unit interval and the next time unit interval in the number of real-time events of a certain category. It indicates the degree of difference between the current time unit interval and the previous time unit interval in the number of real-time events of a certain category; the denominator 2 indicates that the difference between the two sides is averaged.

[0110] After obtaining the event occupancy intensity, event clustering intensity, event continuity intensity, and event sparse distribution state, the server performs baseline attachment processing on the real-time time density sequence and the time density baseline structure to form a real-time time density sequence with baseline reference. Baseline attachment processing refers to the locational correspondence and reference binding of the four types of real-time time density sequences obtained from the current real-time analysis with the time density baseline structure constructed from historical normal samples, under the same time unit interval, the same event category, and the same operating condition label. A real-time time density sequence with baseline reference means that each real-time sequence position is simultaneously associated with a corresponding density stability interval, density transition boundary, density transfer path, and cooperative density relationship. The purpose of this step is to transform the current real-time rhythm expression from an isolated result into a real-time expression closely compared with the normal historical order. The following baseline attachment expression can be used:

[0111]

[0112] in, Indicates the event category as And located within the time unit interval Location of real-time temporal density sequences with baseline reference; This indicates that the real-time density value at this location obtained from the current real-time analysis can be obtained by fusing the aforementioned occupancy intensity, aggregation intensity, continuous intensity, and sparse distribution state according to preset rules; This represents the density stability interval of this event category within the time unit interval in the time density baseline structure; This indicates the density transition boundary corresponding to this location; This indicates the density transfer path segment to which this location belongs; This represents the set of collaborative density relationships over the given time interval.

[0113] After generating a real-time temporal density sequence with baseline reference, the server performs density unrolling on the sequence to obtain local observation states. Density unrolling means that instead of treating the real-time density value within a given time unit interval as a single scalar, it further decomposes the components of the real-time density at that location into multiple observation dimensions to reveal the internal organization of that time position. Local observation states refer to the multidimensional local observation results formed within a given time unit interval under baseline reference constraints. The purpose of this step is to break down seemingly identical real-time density values ​​into state expressions with different internal structures, thereby avoiding the problem of being unable to distinguish different anomaly patterns based solely on the total density value. The local observation state can be represented as:

[0114]

[0115] in, Indicates the number is Local observation status within a time unit interval; This indicates the degree of distribution balance, which is used to characterize the degree of dispersion and balance of various real-time events within the time unit interval under the current baseline reference. Its value falls within the range of 0 to 1 after normalization. The larger the value, the more balanced the distribution. It indicates the degree of aggregation skew and is used to characterize whether a certain type of real-time event is over-stacking or offset at a local time location. Its value is non-negative. It indicates the degree of continuous support and is used to characterize whether the current time unit interval maintains a smooth rhythmic connection with the preceding and following time unit intervals. Its value falls within the range of 0 to 1. This indicates the degree of category coordination, characterizing whether the control command trigger sequence, execution feedback sequence, state update record sequence, and communication interaction sequence maintain baseline coordination within the given time unit interval. Its value falls within the range of 0 to 1. To extract these quantities from a real-time time density sequence with baseline reference, corresponding functions can be constructed, for example:

[0116]

[0117]

[0118]

[0119]

[0120] in, The function representing the degree of distribution balance is used to calculate the distribution balance of the time unit interval based on four types of real-time time density sequences with baseline reference. The function representing the degree of cluster skewness is used to identify whether there is abnormal clustering of one or more types of events based on four types of real-time time density sequences with baseline reference. The function representing the degree of continuous support is used to determine whether the current time position is continuous with the preceding and following rhythms based on the real-time time density sequence with baseline reference between adjacent time unit intervals. , , These represent the event categories as follows: The positional representation of the real-time temporal density sequence with baseline reference in the previous time unit interval, the current time unit interval, and the next time unit interval; The function representing the degree of synergy among categories is used to combine the synergy density matrix. The cooperative preservation state of the current time unit interval is extracted from four types of real-time time density sequences with baseline reference.

[0121] After obtaining the local observation state, the server performs observation structure extraction processing based on the local observation state and performs continuous concatenation processing according to the time unit interval to form an observation entropy sequence. Observation structure extraction processing refers to uniformly quantifying the local observation state in each time unit interval and extracting observations that can characterize the degree of organization and structural complexity at the current time position. Continuous concatenation processing refers to connecting the observations at each position from front to back in the time unit interval to form a sequence that unfolds along time. The observation entropy sequence is a sequence expression used to characterize the degree of organization of event distribution and the trend of temporal order changes in the industrial intelligent control device within the current operating cycle. The purpose of this step is to elevate the local observation state into a core judgment sequence that can directly participate in subsequent identification of time structure anomalies and backtracking of density evolution paths. The following observation entropy expression can be used:

[0122]

[0123] in, Indicates the number is The observed entropy value over a time unit interval; Indicates the local observation state at the th The normalized proportions of each observation dimension are used to reflect the relative contributions of distribution balance, cluster skewness, continuity support and class synergy in the current time unit interval. The value ranges from 0 to 1, and the sum of the normalized proportions of the four dimensions is 1. Let represent the natural logarithm function. In order to obtain... The following normalization expression can be used:

[0124]

[0125] in, Indicates the number is The local observation state in the time unit interval is in the first Values ​​in each observation dimension; Represents the first time unit interval. Each observation dimension has a numerical value. If the observed state within a certain time unit interval is too uniform, the observation entropy value is low, indicating that the organization at that time location is more concentrated; if the dimensions are relatively balanced, the observation entropy value is high, indicating that the organization at that time location is more dispersed and complex. Finally, the observation entropy values ​​of each time unit interval are arranged continuously in chronological order to obtain the observation entropy sequence:

[0126]

[0127] in, Represents the observed entropy sequence; These represent the intervals from the first time unit to the second time unit. The observed entropy value over a time unit interval; This indicates the total number of time unit intervals in the current real-time analysis window.

[0128] S140. Compare the observed entropy sequence with the temporal density baseline structure to identify temporal structure anomaly regions, and trace the density evolution path of the temporal structure anomaly regions to obtain the temporal perturbation type identifier.

[0129] Specifically, after obtaining the observation entropy sequence, the server first performs a synchronous attachment process between the observation entropy sequence and the time density baseline structure to establish a correspondence within the same time unit interval. This synchronous attachment process establishes a one-to-one reference mapping between the positions of each time unit interval in the observation entropy sequence and the corresponding density stability intervals, density transition boundaries, density transfer paths, and cooperative density relationships in the time density baseline structure. The correspondence within the same time unit interval means that time unit intervals with the same number share the same time coordinates, event category caliber, and operating condition caliber on both the real-time observation side and the historical baseline side. The purpose of this step is to ensure that all subsequent anomaly identifications occur at the same time location, rather than mixing and comparing observation results from different time roles with the baseline structure. The following synchronous attachment expression can be used:

[0130]

[0131] in, Indicates the number is The observation units attached to the time unit interval; This indicates that the observed entropy sequence is in the numbered sequence. The observed entropy value over a time unit interval; The time density baseline structure is indicated by the numbering The set of density-stable intervals over a time unit interval; The time density baseline structure is indicated by the numbering The set of density transition boundaries over time unit intervals; The time density baseline structure is indicated by the numbering Density transfer path segments within a time unit interval; The time density baseline structure is indicated by the numbering The set of collaborative density relationships over time unit intervals; This indicates the operating condition identifier or segment source identifier to which the time unit interval belongs.

[0132] After establishing the correspondence within the same time unit interval, the server performs segmentation processing on the observed entropy sequence to form observation segments to be compared. Segmentation processing means that the observed entropy sequence is no longer treated as a simple arrangement of individual time points, but rather divided into several continuous observation segments according to the local change trends, the continuity of reliable markers, and changes in operating condition boundaries within the continuous time unit interval. The observation segment to be compared is the smallest continuous analysis unit that will be compared segment by segment with the baseline reference segment. The purpose of this step is to transform the continuous time series into several segments with boundaries and local significance, thus elevating anomaly detection from single-point judgment to continuous structure judgment. The following segmentation expression can be used:

[0133]

[0134] in, Indicates the first One observation section to be compared; Indicates the time unit interval number; Indicates the first The starting time unit interval number of each observation segment to be compared; Indicates the first The end time unit interval number of each observation segment to be compared. To determine the segmentation boundary, local changes can be further defined: .in, Indicates the number is The magnitude of the change in observed entropy between time intervals relative to the previous time interval; This represents the observed entropy value for the current time unit interval; This represents the observed entropy value of the previous time unit interval.

[0135] After forming the observation segments to be compared, the server performs baseline correspondence processing on each observation segment based on the time density baseline structure to obtain the corresponding baseline reference segment. Baseline correspondence processing refers to selecting the most matching historical normal segment from the time density baseline structure as a reference based on the operating condition identifier, time range, event category combination state, and time transmission relationship of the observation segment to be compared. The corresponding baseline reference segment is the baseline segment most similar to a given observation segment in terms of time role and operating condition role. The purpose of this step is to avoid comparing real-time observation segments with incompatible baseline segments, which could lead to misjudgment. The following segment matching scoring function can be constructed:

[0136]

[0137] in, Indicates the first The observation segment to be compared with the first Matching scores between candidate baseline segments; Indicates temporal similarity, used to measure the degree of correspondence between two things in a time unit interval, and its value falls within the range of 0 to 1; This indicates the similarity of working conditions, which measures the degree of consistency between the working condition labels of two items. Its value falls within the range of 0 to 1. This represents the similarity of density propagation paths, used to measure the consistency of the temporal evolution paths of two entities, and its value falls within the range of 0 to 1. This represents the similarity of the collaborative density relationship, which measures the degree of consistency between two cross-category collaborative states, and its value falls within the range of 0 to 1; , , , This represents the weight coefficient of each similarity item, taking non-negative values ​​and summing to 1.

[0138] After obtaining the corresponding baseline reference segment, the server performs observation offset determination processing on each observation segment to be compared, in order to identify the observation offset. Observation offset refers to the deviation of the observation segment to be compared from the corresponding baseline reference segment in its internal organizational state, specifically including distribution balance offset, clustering skew offset, continuity support offset, and category coordination offset. Distribution balance offset refers to the deviation of the distribution balance of various events within the current segment from the historical normal balance; clustering skew offset refers to the abnormal stacking or abnormal clustering of one or several types of events at a local time position; continuity support offset refers to the deviation of the connection relationship between the current segment and the preceding and following time unit intervals from the normal rhythmic continuity; category coordination offset refers to the imbalance of the normal coordination relationship between the control command trigger sequence, execution feedback return sequence, state update record sequence, and communication interaction sequence. The following observation offset expression can be used:

[0139]

[0140]

[0141]

[0142]

[0143] in, Indicates the first The distribution balance shift of each observation segment to be compared; Indicates the first Clustering skewness shift of each observation segment to be compared; Indicates the first Continuous support migration of each observation segment to be compared; Indicates the first Category co-occurrence shift of each observation segment to be compared; Indicates the first The number of time unit intervals covered by each observation segment to be compared; This indicates that the time intervals within the specified segment are summed. , , , These represent the local observation state components in each time unit interval of the current observation segment to be compared; , , , These represent the baseline observation state components of the corresponding baseline reference segment within the same time unit interval.

[0144] After identifying the observation offset, the server performs anomaly concatenation processing on the observation segments to be compared that show consecutive observation offsets within adjacent time unit intervals, in order to form candidate anomaly segments. Anomaly concatenation processing refers to connecting observation segments to be compared that are sequential in time, consistent in offset direction, and similar in offset level along the time axis to form a longer-range continuous anomaly segment; candidate anomaly segments refer to anomaly candidate segments that already possess continuous offset characteristics but have not yet undergone confidence constraint screening. The purpose of this step is to elevate individual local offsets from discrete segments to a continuous structure, filtering out instantaneous deviations caused by isolated jitter. The following concatenation judgment expression can be used:

[0145]

[0146] in, Indicates the first The observation segment to be compared with the first Whether the abnormal connection conditions are met between the observation segments to be compared; Indicates an indicator function; Indicates the first The starting time unit interval number of each observation segment to be compared; Indicates the first The end time unit interval number of each observation segment to be compared; Indicates the first The main offset type of the observation segment to be compared is used to indicate which type of offset it is mainly dominated by; Indicates the first The main offset type of the observation segment to be compared; Indicates the first The overall migration intensity of each observation segment to be compared; Indicates the first The overall migration intensity of each observation segment to be compared; This represents the offset strength tolerance threshold, used to control the allowable range of differences between adjacent segments at the offset level.

[0147] After candidate anomalous segments are formed, the server performs a credibility constraint screening process to identify time structure anomalies. Credibility constraint screening involves combining the credibility marker status, acquisition integrity status, and operational continuity status of the corresponding time unit interval of the candidate anomalous segment to exclude false offsets and low-credibility segments. Time structure anomalies are those segments confirmed to be out of balance in the actual time order after credibility constraint screening. This step prevents acquisition link problems, temporary gaps, or low-credibility observations from being misjudged as genuine anomalies. A credibility score can be defined for candidate anomalous segments.

[0148]

[0149] in, Indicates the first Confidential scores for each candidate anomalous segment; This indicates the coverage ratio of the trusted markers for the candidate anomaly segment, used to characterize the proportion of the high-confidence time unit intervals, and its value falls within the range of 0 to 1. This indicates the completeness of the data collection for the candidate anomaly segment, used to characterize whether there are time gaps, category mismatches, or anomaly compressions within it, and its value falls within the range of 0 to 1; This indicates the degree of continuity of the operating conditions of the candidate abnormal section, and is used to characterize whether the section has experienced a sudden change in operating conditions. Its value falls within the range of 0 to 1. , , This represents the weighting coefficient, which takes non-negative values ​​and sums to 1.

[0150] After identifying the time structure anomaly region, the server performs anomaly boundary convergence processing to obtain the anomaly initiation time unit interval, the anomaly expansion time unit interval, and the anomaly decay time unit interval. Anomaly boundary convergence processing refers to further refining the boundary structure and evolution stages of the anomaly within the already identified time structure anomaly region. The anomaly initiation time unit interval refers to the time position when the anomaly first moves from within the normal boundary to outside the anomaly boundary; the anomaly expansion time unit interval refers to the set of time positions where the anomaly offset continues to deepen or spread outward on the time axis; and the anomaly decay time unit interval refers to the set of time positions where the anomaly offset gradually falls back on the time axis and approaches the normal boundary. The purpose of this step is to further divide a broad anomaly segment into sub-intervals with evolutionary roles, providing the starting point, expansion segment, and fallback segment for subsequent density evolution backtracking processing. The following boundary determination expression can be used:

[0151]

[0152]

[0153] in, Indicates the interval number of the abnormal starting time unit of the time structure anomaly region; Indicates the interval number of the abnormal termination time unit in the time structure anomaly region; This represents the set of all time unit intervals covered by the current time structure anomaly region; Indicates the number is Comprehensive offset intensity over the time unit interval; This represents the abnormal boundary threshold, used to distinguish between normal and abnormal states.

[0154] After obtaining the time unit intervals for the anomaly's initiation, expansion, and decay, the server performs density evolution backtracking on the time structure anomaly region and evolutionary stratification on the backtracking path to form a leading disturbance layer, anomaly clustering layer, anomaly diffusion layer, and anomaly stabilization layer. Density evolution backtracking refers to tracing the changes in the previous time density state and local observation state backward along the time axis from the anomaly's initiation time unit interval to identify how the anomaly gradually evolved from the normal rhythm. The backtracking path refers to the sequence of continuous time unit intervals traversed during this backward tracing process. Evolutionary stratification refers to dividing different stages into a leading disturbance layer, anomaly clustering layer, anomaly diffusion layer, and anomaly stabilization layer based on changes in offset intensity, clustering characteristics, and diffusion range along the backtracking path. The leading disturbance layer refers to the early segment where a slight deviation has already occurred before the anomaly formally forms; the anomaly aggregation layer refers to the segment where event density rapidly accumulates within a local time range, driving the formation of the anomaly; the anomaly diffusion layer refers to the segment where the anomaly expands from the local segment to surrounding segments; and the anomaly stabilization layer refers to the segment where the anomaly maintains a continuous deviation across multiple consecutive time unit intervals. A state vector can be defined on the backtracking path:

[0155]

[0156] in, Indicates the number is The evolutionary state vector of the time unit interval on the backtracking path; Indicates the overall offset strength; This indicates the degree of aggregation enhancement and is used to characterize whether local stacking is increasing; its value is non-negative. This indicates the diffusion range, used to characterize whether the abnormal impact extends from the current time unit interval to the adjacent intervals before and after it, and its value is non-negative. It represents the degree of stability and is used to characterize the ability of an abnormal state to be maintained over a continuous interval. Its value is non-negative.

[0157] After forming the leading perturbation layer, anomaly aggregation layer, anomaly diffusion layer, and anomaly stabilization layer, the server performs pattern classification processing based on these layers to obtain initial pattern classification results, including compressed time perturbations, diffused time perturbations, and pseudo-periodic time perturbations. Pattern classification processing refers to identifying the primary perturbation pattern of the current time structure anomaly region based on the distribution pattern, sequence of action, and characteristic combinations of the four types of evolution layers along the time axis. Compressed time perturbations refer to the rapid compression and stacking of a large number of events within a short time interval, resulting in compressed time organization. Diffuse time perturbations refer to the gradual expansion of anomalies from local time intervals to a wider time range, resulting in fragmented time organization. Pseudo-periodic time perturbations refer to anomalies repeating at fixed or approximately fixed intervals, forming anomalies disguised as periodic fluctuations. The following pattern scoring function can be constructed:

[0158]

[0159]

[0160]

[0161] in, Indicates the first The time structure anomaly region is attributed to the mode score of compressed time perturbation; Indicates the first The time structure anomaly region is attributed to the pattern score of diffused time perturbation; Indicates the first The time structure anomaly region is attributed to the pattern score of pseudo-periodic time perturbation; This represents the proportion of the leading perturbation layer, used to characterize the proportion of minor perturbations in the entire anomaly evolution, and its value falls within the range of 0 to 1; This indicates the proportion of the abnormal clustering layer, used to characterize the proportion of the local abnormal stacking stage in the entire abnormal evolution; This indicates the proportion of the anomalous diffusion layer, used to characterize the proportion of the diffusion stage in the entire anomalous evolution; This indicates the proportion of the stable layer of anomalies, used to characterize the proportion of the continuous anomaly stage in the entire anomaly evolution; Indicates the degree of repetition, used to characterize whether an abnormal segment recurs at multiple time points; It indicates the degree of periodic consistency and is used to characterize whether the time interval between abnormal repetitions is close to a fixed period; , , , , , , , This represents the weighting coefficient, and takes a non-negative value.

[0162] After obtaining the initial pattern classification results, the server performs perturbation consistency verification on these results to form a temporal perturbation type identifier. Perturbation consistency verification involves cross-validating the initial pattern classification results with the offset distribution, cooperative density relationship changes, and density transfer path imbalances in the control command trigger sequence, execution feedback return sequence, state update record sequence, and communication interaction sequence. The temporal perturbation type identifier is the perturbation pattern label finally assigned to the current temporal structure anomaly region after cross-category, cross-path, and cross-segment consistency confirmation. This step aims to prevent the pattern classification results derived solely from the evolutionary layer ratio from being affected by accidental perturbations or local distortions, thereby improving the reliability of perturbation type identification. The following perturbation consistency scoring function can be constructed:

[0163]

[0164] in, Indicates the first Consistency score of perturbations in each temporal structural anomaly region; It represents cross-event category consistency and is used to characterize whether the initial pattern classification result is supported in the control instruction trigger sequence, execution feedback return sequence, state update record sequence and communication interaction sequence. Its value falls within the range of 0 to 1. It represents the consistency of cross-density propagation paths and is used to characterize whether the initial pattern classification result is consistent with the way the anomaly is propagated along the path. Its value falls within the range of 0 to 1. This indicates consistency across collaborative density relationships and is used to characterize whether the initial pattern classification result is accompanied by changes in the corresponding collaborative relationships. Its value falls within the range of 0 to 1. , , This represents the weighting coefficient, which takes non-negative values ​​and sums to 1. After this processing, the server finally obtains the time disturbance type identifier and associates it with the abnormal start time unit interval, abnormal expansion time unit interval, abnormal decay time unit interval, and density evolution path for storage. This information is used to perform time rearrangement processing on the time structure abnormal area based on the time disturbance type identifier and to further determine the time disturbance source.

[0165] S150. Based on the time disturbance type identifier, perform time rearrangement processing on the time structure anomaly region, and determine the time disturbance source based on the regression of the rearranged observation entropy sequence.

[0166] Specifically, after obtaining the time disturbance type identifier, the server does not directly statically mask the time structure anomaly region. Instead, it performs rearrangement preparation processing on the time structure anomaly region to form a group of events to be rearranged. Rearrangement preparation processing refers to extracting and stratifying all standard real-time event units covered by the time structure anomaly region from the original real-time time density sequence according to the anomaly start time unit interval, anomaly expansion time unit interval, and anomaly decay time unit interval. The group of events to be rearranged refers to the set of events that have been removed from the original time arrangement but still retain event category identifiers, event source identifiers, event target identifiers, standard time positions, and their respective anomaly layer information. The purpose of this step is to transform the originally continuously embedded anomaly events in the time series into independently operable rearrangement objects, avoiding interference with unrelated normal events during subsequent rearrangement. The following expression can be used to construct the group of events to be rearranged:

[0167]

[0168] in, Indicates the event group to be rearranged; This represents the set of time unit intervals corresponding to the current time structure anomaly region; Indicates the first One standard real-time event unit; Indicates the first The time interval number to which each standard real-time event unit belongs; This indicates that only standard real-time event units falling within the current time structure anomaly region are extracted. To further preserve the role of anomaly evolution, a layer identifier can be written for each standard real-time event unit, such as a leading perturbation layer identifier, anomaly aggregation layer identifier, anomaly diffusion layer identifier, and anomaly stabilization layer identifier, for subsequent differentiated rearrangement.

[0169] After forming the event group to be rearranged, the server performs rearrangement strategy matching processing based on the time perturbation type identifier to generate a corresponding time rearrangement strategy. Rearrangement strategy matching processing refers to selecting a rearrangement rule that matches the current anomaly mechanism based on the time disorder characteristics corresponding to compressed, diffused, or pseudo-periodic time perturbations. The time rearrangement strategy is a set of operational constraints that specify how the event group to be rearranged moves, disperses, recycles, and breaks up repetitive rhythms along the time axis. The purpose of this step is to ensure that the time rearrangement process is no longer indiscriminate trial and error, but rather maintains a strict correspondence with the previously identified time perturbation type. A matching function between the time perturbation type and the time rearrangement strategy can be defined:

[0170]

[0171] in, Indicates the time rearrangement strategy; This represents the strategy matching function, used to select the corresponding set of rearrangement rules based on the time perturbation type identifier; This indicates the type of time perturbation, which can be either compressed, diffuse, or pseudo-periodic. If the time perturbation type is compressed, the time rearrangement strategy prioritizes dispersing locally high-density stacked events outward along adjacent idle time unit intervals to restore the event distribution width. If the time perturbation type is diffuse, the time rearrangement strategy prioritizes retrieving outward-spreading events and pushing them back onto the original normal propagation path. If the time perturbation type is pseudo-periodic, the time rearrangement strategy prioritizes breaking up fixed or approximately fixed repetition intervals to make events conform to the normal density propagation path again.

[0172] After obtaining the corresponding time reordering strategy, the server performs constraint loading processing on the event group to be reordered. This introduces the density stability interval, density transition boundary, density propagation path, and cooperative density relationship from the time density baseline structure, forming a constrained event group to be reordered. Constraint loading processing involves writing the time order boundary information formed by historical normal operation into the event group to be reordered, ensuring that subsequent time position adjustments are always within the range allowed by normal time organization. A constrained event group to be reordered refers to a set of events that already possesses both the original event attributes and the baseline boundary constraint attributes. The purpose of this step is to prevent the time reordering process from eliminating local anomalies but moving events to new abnormal time positions, thus causing secondary distortion. The following expression can be used for a constrained event group to be reordered:

[0173]

[0174] in, This represents a group of events with constraints to be rearranged. Indicates the first One standard real-time event unit; Indicates the event category as And located within the time unit interval The density stability interval is used to define the normal density range into which such events can fall; Indicates the event category as And located within the time unit interval The density transition boundary is used to limit the allowable range of change between adjacent time unit intervals; This indicates the density transfer path segment corresponding to this location, used to define the normal flow direction after event rearrangement; This represents the set of collaborative density relationships over the given time interval, used to define the normal linkage relationships between different event categories after rearrangement.

[0175] After forming a constrained event group to be rearranged, the server performs time position probing adjustment processing on the constrained event group and simultaneously performs real-time mapping backfilling processing to form a rearranged real-time time density sequence. Time position probing adjustment processing refers to adjusting the standard time position of each or layer-by-layer standard real-time event unit in the constrained event group without changing the event content, event category, or the object of the event, and checking whether the baseline constraints are still met after each adjustment step. Real-time mapping backfilling processing refers to rewriting the standard real-time event units whose time positions have been probing and adjusted back to the unified time base and time unit interval system to generate a new real-time time density sequence. The purpose of this step is to verify whether the current anomaly is mainly caused by time disorder through constrained time position reconstruction. The first step can be defined as... The trial time adjustment expression for a standard real-time event unit:

[0176]

[0177] in, Indicates the first The standard time position of each standard real-time event unit after trial and error adjustment; Indicates the first The original standard real-time position of each standard real-time event unit; Indicates the first The time rearrangement increment of a standard real-time event unit characterizes the magnitude of the event's adjustment forward or backward on the timeline; its value can be positive, negative, or zero. This adjustment must satisfy constraints, such as:

[0178]

[0179] in, This indicates that the event category after the trial adjustment is... Time density series in time unit interval The new density value; This represents the baseline density mean of the event category over the given time interval. This represents the scaling factor of the stability interval for this event category; This indicates the degree of dispersion of the baseline density of the event category within that time unit interval. After adjustment, the time unit interval assignment is recalculated based on the adjusted time position.

[0180]

[0181] in, Indicates the first Each standard real-time event unit is numbered within a time unit interval after trial and adjustment; This indicates the slice width of the time unit interval. Then, all adjusted standard real-time event units are backfilled into the new time unit interval to form the rearranged real-time time density sequence.

[0182] After generating the rearranged real-time temporal density sequence, the server performs density unpacking, observation structure extraction, and concatenation processing based on the rearranged real-time temporal density sequence to generate the rearranged observation entropy sequence. The density unpacking, observation structure extraction, and concatenation processing follow the same rules as when constructing the observation entropy sequence from the original real-time temporal density sequence. The rearranged observation entropy sequence refers to the sequence representation reflecting the current degree of orderliness of the time organization, recalculated after the temporal rearrangement process. The purpose of this step is to allow the results before and after the temporal rearrangement to be compared under the same judgment criteria, thereby determining whether the temporal rearrangement is effective. If the local observation state is denoted as... Then the rearranged observation entropy value can be expressed as:

[0183]

[0184]

[0185] in, Indicates the number is The observed entropy value of the time unit interval after time rearrangement; This indicates the local observation state after rearrangement at the [number]th ...]. Normalization percentage across each observation dimension; This indicates that the numbering after rearrangement is The time unit interval in the first Local observation state values ​​in each observation dimension; Let represent the natural logarithm function. Arranging the rearranged observation entropy values ​​across all time intervals in chronological order yields the rearranged observation entropy sequence.

[0186] After obtaining the rearranged observation entropy sequence, the server performs regression evaluation on it to obtain regression results. Regression evaluation involves comparing the rearranged observation entropy sequence with the temporal density baseline structure again and measuring whether the original temporal structure anomaly regions have converged in terms of offset intensity, offset range, and offset continuity. The regression results are a structured assessment of the effectiveness of the time rearrangement process, including complete regression, partial regression, and no regression. This step serves to quantify whether the time rearrangement process has truly eliminated or alleviated temporal disorder. A regression score for the original anomaly region can be defined:

[0187]

[0188] in, Indicates the regression score; This represents the total overall offset intensity of the original anomaly region before time rearrangement. This represents the total overall offset intensity of the corresponding segment after time rearrangement. This indicates the number of time intervals covered by the original outlier region before time rearrangement. This indicates the number of time intervals that remain in an abnormal state after time rearrangement. Indicates the degree of continuity of anomalies in the original anomaly region before time rearrangement; Indicates the degree of continuity of consecutive anomalies remaining in the anomaly region after time rearrangement. , , This represents the weighting coefficients, which are non-negative and sum to 1. If the regression score is higher than the high threshold, it is considered a complete regression; if the regression score is between the middle thresholds, it is considered a partial regression; if the regression score is lower than the low threshold, it is considered a non-regression.

[0189] After obtaining the regression results, the server performs perturbation contribution decomposition processing on the standard real-time event units within the temporal structure anomaly region based on the regression results, to form high-contribution perturbation events, medium-contribution perturbation events, and low-contribution events. Perturbation contribution decomposition processing refers to evaluating the actual impact of each standard real-time event unit on the regression effect before and after temporal rearrangement. High-contribution perturbation events are those whose temporal position, after rearrangement, significantly promotes the regression of the observed entropy sequence towards the baseline; medium-contribution perturbation events are those whose temporal position, after rearrangement, helps the local regression but has a moderate impact on the overall anomaly region; low-contribution events are those whose temporal position changes have little or almost no impact on the overall regression effect. The purpose of this step is to further refine the overall anomaly regression results to the specific event level, providing a basis for subsequent source merging processing. The first... The disturbance contribution value of each standard real-time event unit:

[0190]

[0191] in, Indicates the first The disturbance contribution value of a standard real-time event unit; This represents the regression score obtained when all events to be rearranged participate in the time rearrangement process. Indicates removing the first The regression score is obtained by re-executing local time rearrangement after standard real-time event units. Based on the relationship between the disturbance contribution value and the preset threshold, events can be divided into high-contribution disturbance events, medium-contribution disturbance events, and low-contribution events.

[0192] After high-contribution, medium-contribution, and low-contribution disturbance events are generated, the server performs source merging processing on the high-contribution disturbance events to form a candidate disturbance source set. Source merging processing refers to aggregating multiple high-contribution disturbance events to a higher-level source entity based on the event source identifier, the event's affected object identifier, the communication path attribution, and the control point's endpoint. The candidate disturbance source set refers to a set of source objects that may constitute the true root cause of time disturbances. The purpose of this step is to avoid mistakenly interpreting time disturbance sources as single, isolated events, but rather to elevate them to the source units that truly and continuously output high-contribution disturbance events. The following source merging expression can be used:

[0193]

[0194] in, The source identifier is The set of candidate perturbation sources; A set of indices representing all high-contribution perturbation events; Indicates the first A standard real-time event unit corresponding to a high-contribution disturbance event; This indicates the event source identifier of the standard real-time event unit; This indicates the event target identifier of the standard real-time event unit; This indicates the access location or path identifier of the standard real-time event unit; Represents a logical OR relationship.

[0195] After forming a set of candidate disturbance sources, the server performs a rearrangement response consistency check on the candidate disturbance source set to determine the temporal disturbance source. The rearrangement response consistency check involves conducting individual or grouped temporal rearrangement experiments on each candidate disturbance source set, comparing whether their impact on the observed entropy sequence regression results, offset point contraction, and anomaly path regression remains stable and consistent. A temporal disturbance source refers to the true source object that, after rearrangement verification, can consistently and stably explain the formation of the current temporal structure anomaly. The purpose of this step is to eliminate candidate disturbance sources that are highly correlated but not the root cause through further verification, retaining only the sources that truly dominate the formation of the temporal structure anomaly. We can define the first... Consistency score of rearrangement response for each set of candidate perturbation sources:

[0196]

[0197] in, Indicates the first Consistency score of rearranged response for each set of candidate disturbance sources; This indicates the stability of the contribution of the candidate perturbation source set to the overall regression score when participating in time rearrangement. It is used to characterize whether the regression effect is consistent under different trial batches, and its value falls within the range of 0 to 1. This indicates the consistency of the contribution of the candidate perturbation source set to the backsliding of the abnormal path when participating in the temporal rearrangement. It is used to characterize whether it continues to drive the shortening or backsliding of the density evolution path. Its value falls within the range of 0 to 1. This indicates the consistency of the contribution of the candidate perturbation source set to the shrinkage of the offset landing point when participating in the time rearrangement. It is used to characterize whether it continuously reduces the number of high offset time unit intervals, and its value falls within the range of 0 to 1. , , This represents the weighting coefficient, which takes non-negative values ​​and sums to 1. When the reordered response consistency score is higher than a preset threshold, the candidate disturbance source set is identified as a time disturbance source. If multiple candidate disturbance source sets simultaneously meet the conditions, they can be sorted by score to determine the primary and secondary time disturbance sources. After this processing, the server finally determines the time disturbance source and stores it in association with the time disturbance type identifier, the anomaly start time unit interval, the anomaly extension time unit interval, the anomaly decay time unit interval, and the regression results, providing a direct object and accurate basis for subsequent continuous security protection processing.

[0198] S160. The temporal density baseline structure is dynamically updated based on the temporal order evolution record, and continuous security protection is implemented for temporal disturbance sources.

[0199] Specifically, after identifying the time disturbance source, the server dynamically updates the time density baseline structure based on the time order evolution record and implements continuous security protection for the time disturbance source. First, it performs evolutionary segment extraction processing on the time order evolution record to form stable operation segments, boundary fluctuation segments, and disturbance impact segments. The time order evolution record refers to the comprehensive record accumulated by the industrial intelligent control device over multiple consecutive operating cycles, including the time density sequence set, observation entropy sequence, time structure anomaly region, density evolution path, time disturbance type identifier, time disturbance source attributes, and the regression results of the rearranged observation entropy sequence. Evolutionary segment extraction processing involves dividing the time order evolution record into continuous time segments with different attributes according to the consistency and offset of the time unit intervals across multiple operating cycles. Stable operation segments are time segments that maintain normal time density relationships and normal coordination relationships throughout multiple consecutive operating cycles. Boundary fluctuation segments are time segments that are close to the time density baseline structure boundary but have not yet formed a time structure anomaly region. Disturbance impact segments are time segments that have been affected by time disturbance sources and have formed real abnormal propagation traces. To quantify the evolutionary properties of a specific time interval across multiple operating cycles, a segment attribute scoring vector can be constructed:

[0200]

[0201] in, Indicates the number is The segment attribute rating vector of a time unit interval in the time order evolution record; The stability score is used to characterize the degree to which the time unit interval maintains a normal rhythm and low offset state across multiple operating cycles. Its value falls within the range of 0 to 1 after normalization, and the larger the value, the more stable it is. The boundary fluctuation score is used to characterize the degree to which the time unit interval is close to the baseline boundary but has not yet crossed the boundary and become unstable. Its value falls within the range of 0 to 1. The disturbance impact score represents the degree to which the time unit interval is associated with the time disturbance source and exhibits abnormal expansion, abnormal clustering, or abnormal stability. Its value falls within the range of 0 to 1.

[0202] After forming stable operating segments, the server performs stability enhancement processing on these segments and writes them into the main baseline segment of the time density baseline structure. Stability enhancement processing refers to increasing the statistical weight and structural reliability of time unit intervals that have long-term stable performance and are unaffected by time disturbances, making them the core support for subsequent baseline updates. The main baseline segment refers to the core segment of normal time order that remains valid across multiple operating conditions, multiple operating cycles, and multiple observation windows. The purpose of this step is to continuously strengthen the stable part of the time density baseline structure through long-term normal operation, rather than remaining statically represented by the initial historical samples. The following stability enhancement update expression can be used:

[0203]

[0204]

[0205] in, Indicates the event category as Time density series in time unit interval The updated baseline mean; This represents the baseline mean before the update; This represents the stable average density value of this event category within this time unit interval in a stable running segment; The stable reinforcement memory coefficient is used to control the fusion ratio of old baseline information and new stable sample information. Its value ranges from 0 to 1. The larger the value, the more conservatively the old baseline is preserved. Indicates the degree of dispersion of the updated baseline; Indicates the degree of dispersion of the baseline before the update; This represents the statistical value indicating the degree of dispersion of this event category within the time unit interval in a stable running segment.

[0206] After the boundary fluctuation segments are formed, the server performs boundary adjustment processing on them to update the density stable intervals and density transition boundaries in the time density baseline structure. Boundary adjustment processing refers to slightly correcting the allowable fluctuation range and normal transition boundaries between adjacent intervals for time unit intervals that have been located near the baseline boundary for a long time, have slight offsets, but have not formed a true anomaly extension. The density stable interval refers to the allowable normal time density range for a certain event category in a certain time unit interval; the density transition boundary refers to the upper and lower bounds of the allowable change when the time density between adjacent time unit intervals undergoes normal changes. The purpose of this step is to enable the time density baseline structure to adapt to slow rhythm drift caused by changes in operating conditions, avoiding the continuous misjudgment of new normal rhythms that are reasonable for a long time but have slight offsets as anomalies. The following boundary adjustment expression can be used:

[0207]

[0208]

[0209]

[0210] in, Indicates the event category as Time density series in time unit interval The updated density stability range; and These represent the updated baseline mean and the updated baseline dispersion, respectively. This represents the updated stability interval scaling factor, used to control the boundary width, and its value is positive. This represents the scaling factor of the stability interval before the update; This represents the boundary adjustment step size coefficient, used to control the magnitude of each update; its value is a positive value less than 1. It represents the boundary offset of the event category in the time unit interval within the boundary fluctuation segment, used to characterize the degree to which the new normal rhythm is closer to the old boundary; Indicates from time unit interval To time unit interval The updated density transition boundary; This represents the difference in mean between adjacent time intervals after the update; This indicates the updated transition tolerance, used to limit the range of fluctuations in normal changes between adjacent intervals.

[0211] After the perturbation impact segments are formed, the server performs perturbation isolation processing on these segments to remove time unit intervals associated with the time perturbation source and form a subset of perturbation records. Perturbation isolation processing refers to removing time unit intervals, offset paths, and anomalous landing points that have been verified to have a direct propagation relationship with the time perturbation source from the baseline update candidate range, preventing anomalous structures from being mistakenly absorbed as normal structures. The subset of perturbation records is a separate set of records specifically storing these removed segments and their perturbation attributes. The purpose of this step is to ensure that the dynamic update of the time density baseline structure only absorbs true normal rhythms and acceptable boundary drifts, and not any distorted rhythms shaped by the time perturbation source. The following removal expression can be used:

[0212]

[0213]

[0214] in, This represents the set of time unit intervals that need to be removed from the baseline update candidate set; Indicates the time unit interval number; This represents the set of identified time disturbance sources; Represents time unit interval With time disturbance source The correlation determination function between time unit intervals The value is 1 when it is located within the density evolution path, offset landing point range, or anomalous propagation boundary of the time disturbance source; otherwise, the value is 0. Represents a subset of perturbation records; Indicates the source of the time disturbance; Indicates the source of time disturbance The corresponding time disturbance type identifier; Represents time unit interval The overall offset strength.

[0215] After completing the disturbance isolation process, the server performs cross-period consistency analysis on the time order evolution record to identify persistent trend shifts within time unit intervals and mark high-sensitivity areas. Cross-period consistency analysis involves comparing the temporal density changes, observational entropy changes, anomaly frequency, and anomaly regression effects of the same time unit interval across multiple operating cycles to identify whether a long-term, stable, and consistent shift trend exists. A persistent trend shift refers to a time structure change in which a certain time unit interval slowly moves in the same direction across multiple operating cycles and is not an occasional anomaly. High-sensitivity areas are those time unit intervals that frequently approach anomaly boundaries, frequently associate with time disturbance sources, or frequently trigger anomaly warnings across multiple operating cycles. The purpose of this step is to incorporate long-term evolution trends into dynamic update decisions and to mark time locations requiring key constraints for subsequent continuous security protection processing. The following trend shift expression can be used:

[0216]

[0217]

[0218]

[0219] in, Represents time unit interval Average trend offset over multiple operating cycles; This indicates the total number of runtimes included in the analysis; Indicates the first Time unit interval in each operating cycle The time density value or corresponding comprehensive observation value; Represents time unit interval The baseline reference mean; Represents time unit interval The degree of fluctuation between adjacent operating cycles is used to characterize whether the trend deviation is smooth and stable. Represents time unit interval Sensitive rating; , , This represents the weighting coefficients, which are non-negative and sum to 1. This represents the absolute value of the trend offset; Represents time unit interval The proportion of times an anomaly is identified across multiple operating cycles, with a value ranging from 0 to 1; Represents time unit interval The frequency proportion associated with time disturbance sources, with values ​​ranging from 0 to 1.

[0220] After completing the cross-cycle consistency analysis, the server performs structural reweaving on the updated master baseline segments, density stability intervals, density transition boundaries, and density transfer paths to form an updated temporal density baseline structure. Structural reweaving involves reassembling the local update results obtained after the aforementioned stability enhancement, boundary adjustment, and perturbation isolation processes along the temporal unit intervals, and re-verifying cross-category synergies and path continuity to form a new continuous baseline. The updated temporal density baseline structure refers to a unified temporal baseline model that has absorbed real stable evolution and eliminated perturbation contamination. The purpose of this step is to reintegrate the update results scattered across different processing modules into a complete baseline that can be directly accessed in the next round of real-time analysis. The structural reweaving expression can be used as follows:

[0221]

[0222] in, This represents the updated temporal density baseline structure; Indicates the time unit interval number; Represents time unit interval The updated set of density-stable intervals; Represents time unit interval The updated set of density transition boundaries; Represents time unit interval The updated density transfer path fragment; Represents time unit interval The updated set of collaborative density relationships; Represents time unit interval Updated source identifier for the clip; This represents the total number of all time unit intervals.

[0223] After establishing the updated time density baseline structure, the server performs source behavior constraint processing, rhythm reshaping processing, and collaborative restriction processing based on the time disturbance source to implement continuous security protection. Source behavior constraint processing limits the number of events entering the time disturbance source within a unit time interval, the event entry frequency, and the event entry window. Rhythm reshaping processing adjusts the distribution of the time disturbance source's output events on the time axis, ensuring it conforms to the normal density propagation path defined by the updated time density baseline structure. Collaborative restriction processing limits the time disturbance source from creating abnormal linkage amplification effects between control command trigger sequences, execution feedback return sequences, state update record sequences, and communication interaction sequences. This step transforms the time disturbance source from an identified object into a continuously constrained and corrected control object, thereby preventing it from creating time structure anomalies again. The following source behavior constraint expression can be used:

[0224]

[0225]

[0226] in, Indicates the source of time disturbance In time unit interval The number of events that can be retained within the specified range; Indicates the source of time disturbance In time unit interval The number of events originally generated within the system; Indicates the source of time disturbance The constraint coefficient is used to control the allowable retention ratio, and its value ranges from 0 to 1; This indicates the number of references allowed for this source in the updated time density baseline structure over the specified time interval; Indicates the source of time disturbance The The remodeled time interval between each retained event and the previous retained event; This indicates the minimum event interval that the time disturbance source must meet during continuous security protection processing.

[0227] After implementing continuous security protection, the server performs protection effect feedback processing on the time disturbance source and writes the feedback results into the time order evolution record. Protection effect feedback processing refers to continuously observing the changes in event occupancy intensity, entropy sequence regression, anomaly re-triggering, and collaborative imbalance recovery of the time disturbance source in subsequent operating cycles, and writing these results back into the time order evolution record; the feedback results refer to structured data that characterizes the actual effect of the current continuous security protection processing. The purpose of this step is to create a self-verifying closed loop for continuous security protection, preventing the protection strategy from remaining fixed in the long term and failing to adjust to changes in source behavior. The following protection effect scoring expression can be used:

[0228]

[0229] in, Indicates the source of time disturbance The protective effect score; , , This represents the weighting coefficients, which are non-negative and sum to 1. It represents the degree of regression of the observation entropy sequence of the corresponding segment of the time disturbance source under continuous security protection processing. Its value falls within the range of 0 to 1, and the larger the value, the more complete the regression. This indicates the degree to which abnormal paths caused by time disturbances are suppressed and shortened, and its value falls within the range of 0 to 1; This indicates the frequency of time disturbance sources triggering anomalies again after continuous security protection processing, and its value falls within the range of 0 to 1.

[0230] After obtaining feedback on the protection effect, the server performs hierarchical management of time-related disturbance sources to form a hierarchical control structure of latent risk sources, intermediate-level constraint sources, and high-risk sources. Hierarchical management refers to applying different levels of continuous security protection strategies to different time-related disturbance sources based on their historical recurrence frequency, current disturbance contribution level, protection effect score, and coupling degree with high-sensitivity areas. Latent risk sources are those whose current disturbance behavior has significantly weakened, have not triggered anomalies again in the short term, but still require basic monitoring. Intermediate-level constraint sources are those that still have some disturbance activity, require continuous constraint, but have not yet reached a strong isolation level. High-risk sources are those that repeatedly trigger anomalies, significantly affect high-sensitivity areas and key control rhythms, and require focused suppression and strong constraint. The purpose of this step is to transform the continuous security protection process from a single fixed strategy into a layered, hierarchical, and dynamically adjustable control structure. The following hierarchical scoring expression can be used:

[0231]

[0232] in, Indicates the source of time disturbance Risk level rating; , , , This represents the weighting coefficients, which are non-negative and sum to 1. Indicates the source of time disturbance The abnormal recurrence frequency, whose value falls within the range of 0 to 1; Indicates the source of time disturbance The average disturbance contribution value corresponding to high-contribution disturbance events falls within the range of 0 to 1; This indicates the protection effectiveness score against the disturbance source at that time. This indicates the coupling strength between the time-based disturbance source and the highly sensitive area, with a value ranging from 0 to 1. If the anomaly recurrence frequency is high, the average disturbance contribution value is high, the protection effect is poor, and it is highly coupled with the highly sensitive area, then the risk level score of the time-based disturbance source is high, and it should be classified as a high-risk source. If the above indicators are in the middle range, it is classified as a medium-level constraint source. If the above indicators are consistently low and the protection effect is stable, it is classified as a latent risk source. The resulting hierarchical control structure can correspond to the basic monitoring strategy, the continuous constraint strategy, and the strong isolation strategy, respectively, thus making the entire dynamic update and continuous security protection mechanism closed-loop, progressive, and adaptively evolving.

[0233] This application also provides an industrial intelligent control data security protection system, referring to... Figure 2 , Figure 2This is a schematic diagram of a data security protection system for industrial intelligent control provided in an embodiment of this application. The system is a server, which includes an acquisition module 21 and a processing module 22. The acquisition module 21 is used to acquire the control command trigger sequence, execution feedback transmission sequence, status update record sequence, and communication interaction sequence of the industrial intelligent control device, and uniformly map them to the same time base to form a time density sequence set. The processing module 22 is used to perform merge analysis on the historical normal operation data of the industrial intelligent control device based on the time density sequence set to construct a time density baseline structure. The processing module 22 is also used to map the real-time event data of the industrial intelligent control device to the time density. In the sequence set, a real-time temporal density sequence is generated, and density expansion processing is performed on the real-time temporal density sequence to form an observation entropy sequence. The processing module 22 is also used to compare the observation entropy sequence with the temporal density baseline structure to identify the temporal structure anomaly region, and to trace back the density evolution path of the temporal structure anomaly region to obtain the temporal disturbance type identifier. The processing module 22 is also used to perform temporal rearrangement processing on the temporal structure anomaly region according to the temporal disturbance type identifier, and to determine the temporal disturbance source based on the regression of the rearranged observation entropy sequence. The processing module 22 is also used to dynamically update the temporal density baseline structure based on the temporal order evolution record, and to implement continuous security protection processing for the temporal disturbance source.

[0234] This application also provides a server, as shown in the reference. Figure 3 , Figure 3 This is a schematic diagram of a server provided in an embodiment of this application. The server may include: at least one processor 31, at least one network interface 34, a user interface 33, a memory 35, and at least one communication bus 32.

[0235] The communication bus 32 is used to enable communication between these components.

[0236] The user interface 33 may include a display screen and a camera. Optionally, the user interface 33 may also include a standard wired interface and a wireless interface.

[0237] The network interface 34 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).

[0238] The processor 31 may include one or more processing cores. The processor 31 connects to various parts of the server via various interfaces and lines, executing instructions, programs, code sets, or instruction sets stored in the memory 35, and calling data stored in the memory 35 to perform various server functions and process data. Optionally, the processor 31 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 31 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed on the screen; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 31 and may be implemented as a separate chip.

[0239] The memory 35 may include random access memory (RAM) or read-only memory. Optionally, the memory 35 may include a non-transitory computer-readable storage medium. The memory 35 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 35 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 35 may also be at least one storage device located remotely from the aforementioned processor 31. Figure 3 As shown, the memory 35, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for an industrial intelligent control data security protection method.

[0240] exist Figure 3In the server shown, the user interface 33 is mainly used to provide an input interface for the user and obtain the user input data; while the processor 31 can be used to call the application program stored in the memory 35, which is an industrial intelligent control data security protection method. When executed by one or more processors, the server executes one or more methods as described in the above embodiments.

[0241] This application also provides a non-transitory computer-readable storage medium storing instructions. When executed by one or more processors, these instructions cause a server to perform one or more of the methods described in the above embodiments.

[0242] The foregoing description is merely an exemplary embodiment of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Those skilled in the art will readily conceive of other embodiments of this disclosure upon considering the specification and the disclosure of practical truth. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure. The specification and embodiments are considered exemplary only, and the scope and spirit of this disclosure are defined by the claims.

Claims

1. An industrial intelligent control data security protection method, characterized in that, The method includes: The control command trigger sequence, execution feedback transmission sequence, status update record sequence, and communication interaction sequence of the industrial intelligent control device are acquired and uniformly mapped to the same time base to form a time density sequence set. Based on the time density sequence set, a merge analysis is performed on the historical normal operation data of the industrial intelligent control device to construct a time density baseline structure; The real-time event data of the industrial intelligent control device is mapped to the time density sequence set to generate a real-time time density sequence, and density expansion processing is performed on the real-time time density sequence to form an observation entropy sequence. The observed entropy sequence is compared with the time density baseline structure to identify time structure anomaly regions, and the density evolution path of the time structure anomaly regions is traced back to obtain the time perturbation type identifier. Based on the time disturbance type identifier, time rearrangement is performed on the time structure anomaly region, and the time disturbance source is determined based on the regression of the rearranged observation entropy sequence. The time density baseline structure is dynamically updated based on the time order evolution record, and continuous security protection is implemented for the time disturbance source.

2. The industrial intelligent control data security protection method of claim 1, wherein, The acquisition of the control command trigger sequence, execution feedback transmission sequence, status update record sequence, and communication interaction sequence of the industrial intelligent control device, and mapping them uniformly to the same time base to form a time density sequence set, specifically includes: The control command trigger sequence, execution feedback transmission sequence, status update record sequence, and communication interaction sequence of the industrial intelligent control device are subjected to event extraction processing to form a set of event units with a unified structure. Based on the control cycle of the industrial intelligent control device, a common time reference is constructed, and each event unit is mapped to the same time reference to obtain a standard time mark. Perform time slicing on the mapped event units to divide them into time unit intervals, and perform time placeholder registration on each time unit interval; Within each time unit interval, event units are categorized and merged to form a standardized time representation; Based on the standardized time representation, a time density construction process is performed to obtain the corresponding time density sequence, and the time density sequences are jointly arranged to form the time density sequence set.

3. The industrial intelligent control data security protection method of claim 1, wherein, The process of performing a merge analysis on the historical normal operation data of the industrial intelligent control device based on the time density sequence set to construct a time density baseline structure specifically includes: Perform sample filtering processing on the historical normal operation data corresponding to the time density sequence set to form a historical normal sample set; The historical normal sample set is processed by operating condition segmentation to form multiple operating condition subsets; Time unit alignment processing is performed on the time density sequence of each of the aforementioned working condition subsets to establish corresponding time unit intervals; Within the corresponding time unit interval, interval merging is performed on similar time density sequences to obtain interval stable representation; Based on the aforementioned interval stable expression, a collaborative merging process is performed on the control command trigger sequence, execution feedback return sequence, state update record sequence, and communication interaction sequence to form a collaborative density relationship; Boundary extraction processing is performed on the interval stable expression and the cooperative density relationship to obtain the density stable interval, density transition boundary and density transfer path; Perform inter-layer merging processing on each of the aforementioned work condition subsets to form main baseline segments and offset baseline segments; The main baseline segment and the offset baseline segment are subjected to a continuous weaving process to form a time-density baseline structure.

4. The industrial intelligent control data security protection method of claim 1, wherein, The step of mapping the real-time event data of the industrial intelligent control device to the time density sequence set to generate a real-time time density sequence, and performing density expansion processing on the real-time time density sequence to form an observation entropy sequence, specifically includes: The real-time event data is subjected to real-time event standardization processing to form standard real-time event units; Perform real-time raw time correction processing on the standard real-time event unit to obtain the corrected time stamp; Based on the same time reference and time unit interval, the standard real-time event unit is subjected to real-time mapping processing and assigned to the corresponding time unit interval; Real-time placeholder registration processing is performed on the standard real-time event units within each time unit interval to form a real-time placeholder structure; Based on the real-time placeholder structure, real-time category merging processing is performed to form a real-time time density sequence corresponding to the control instruction trigger sequence, a real-time time density sequence corresponding to the execution feedback transmission sequence, a real-time time density sequence corresponding to the state update record sequence, and a real-time time density sequence corresponding to the communication interaction sequence. Real-time density writing processing is performed on the real-time time density sequence to obtain event occupancy intensity, event clustering intensity, event continuity intensity, and event sparse distribution state; The real-time time density sequence is coupled to the time density baseline structure to form a real-time time density sequence with a baseline reference. Density unrolling is performed on the real-time temporal density sequence with baseline reference to obtain the local observation state; Based on the local observation state, the observation structure is extracted and continuously concatenated according to the time unit interval to form the observation entropy sequence.

5. The industrial intelligent control data security protection method of claim 1, wherein, The step of comparing the observed entropy sequence with the temporal density baseline structure to identify temporal structure anomaly regions and tracing back the density evolution path of the temporal structure anomaly regions to obtain a temporal perturbation type identifier specifically includes: The observed entropy sequence and the time density baseline structure are synchronously coupled to form a correspondence within the same time unit interval; The observed entropy sequence is segmented to form observation segments to be compared; Based on the time density baseline structure, baseline correspondence processing is performed on each of the observation segments to be compared to obtain the corresponding baseline reference segments; Observation offset determination processing is performed on each of the observation segments to be compared in order to identify observation offsets, including distribution balance offset, cluster skew offset, continuous support offset, and category coordination offset. For observation segments to be compared that show consecutive observation shifts within adjacent time unit intervals, anomaly concatenation processing is performed to form candidate anomaly segments; The candidate anomalous segments are subjected to a confidence constraint screening process to determine the time structure anomalous regions; Anomaly boundary convergence processing is performed on the time structure anomaly region to obtain anomaly start time unit interval, anomaly expansion time unit interval, and anomaly decay time unit interval; Density evolution backtracking is performed on the time structure anomaly region, and evolution layering is performed on the backtracking path to form a leading perturbation layer, anomaly aggregation layer, anomaly diffusion layer and anomaly stabilization layer. The pattern classification process is performed based on the leading perturbation layer, the abnormal aggregation layer, the abnormal diffusion layer, and the abnormal stabilization layer to obtain the initial pattern classification results, including compressed time perturbation, diffused time perturbation, and pseudo-periodic time perturbation. The initial pattern classification result is subjected to a perturbation consistency check to form the time perturbation type identifier.

6. The industrial intelligent control data security protection method of claim 1, wherein, The step of performing time rearrangement processing on the time structure anomaly region according to the time perturbation type identifier, and determining the time perturbation source based on the regression of the rearranged observation entropy sequence, specifically includes: Perform rearrangement preparation processing on the aforementioned time structure aberration region to form a group of events to be rearranged; Based on the time perturbation type identifier, the event group to be rearranged is subjected to rearrangement strategy matching processing to generate a corresponding time rearrangement strategy. Constraint loading is performed on the event group to be rearranged to introduce the density stability interval, density transition boundary, density propagation path and cooperative density relationship in the time density baseline structure to form a constrained event group to be rearranged. The time position trial adjustment process is performed on the constrained event group to be rearranged, and the real-time mapping backfilling process is performed simultaneously to form a real-time time density sequence after rearrangement; Based on the rearranged real-time time density sequence, density expansion processing, observation structure extraction processing, and continuous concatenation processing are performed to form the rearranged observation entropy sequence. Regression determination processing is performed on the rearranged observation entropy sequence to obtain regression results; Based on the regression results, the standard real-time event units within the time structure anomaly region are subjected to perturbation contribution decomposition processing to form high-contribution perturbation events, medium-contribution perturbation events, and low-contribution events. The high-contribution perturbation events are subjected to source merging processing to form a candidate perturbation source set; Perform a rearrangement response consistency check on the candidate perturbation source set to determine the time perturbation source.

7. The industrial intelligent control data security protection method of claim 1, wherein, The dynamic updating of the temporal density baseline structure based on the temporal order evolution record and the continuous security protection of the temporal disturbance source specifically include: The time-order evolution record is processed to extract evolution segments to form stable operation segments, boundary fluctuation segments, and disturbance impact segments. The stable running segment is subjected to stabilization enhancement processing and written into the main baseline segment of the time density baseline structure; Boundary adjustment processing is performed on the boundary fluctuation segment to update the density stability interval and density transition boundary in the time density baseline structure; The disturbance-affected segments are subjected to disturbance isolation processing to remove time unit intervals associated with the time disturbance source and form a disturbance record subset; Cross-period consistency analysis is performed on the time order evolution record to identify persistent trend shifts in time unit intervals and mark high-sensitivity areas; The updated main baseline segment, the density stable interval, the density transition boundary, and the density transfer path are subjected to structural reweaving to form the updated temporal density baseline structure. Based on the aforementioned time disturbance source, source behavior constraint processing, rhythm reshaping processing, and collaborative restriction processing are implemented to carry out continuous security protection processing; The protection effect feedback process is performed on the time disturbance source, and the feedback result is written into the time order evolution record; The time disturbance sources are subjected to hierarchical management processing to form a hierarchical control structure of latent risk sources, intermediate constraint sources, and high-risk sources.

8. An industrial intelligent control data security protection system, characterized in that, The system is used to execute the industrial intelligent control data security protection method as described in any one of claims 1 to 7, wherein the system includes an acquisition module and a processing module, wherein... The acquisition module is used to acquire the control command trigger sequence, execution feedback transmission sequence, status update record sequence and communication interaction sequence of the industrial intelligent control device, and uniformly map them to the same time base to form a time density sequence set. The processing module is used to perform a merge analysis on the historical normal operation data of the industrial intelligent control device based on the time density sequence set, so as to construct a time density baseline structure. The processing module is further configured to map the real-time event data of the industrial intelligent control device to the time density sequence set, generate a real-time time density sequence, and perform density expansion processing on the real-time time density sequence to form an observation entropy sequence. The processing module is also used to compare the observed entropy sequence with the time density baseline structure to identify time structure anomalous regions, and to trace back the density evolution path of the time structure anomalous regions to obtain a time perturbation type identifier. The processing module is further configured to perform time rearrangement processing on the time structure anomaly region according to the time disturbance type identifier, and determine the time disturbance source based on the regression of the rearranged observation entropy sequence; The processing module is also used to dynamically update the time density baseline structure based on the time order evolution record, and to implement continuous security protection processing for the time disturbance source.

9. A server, characterized by The server includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions. The user interface and the network interface are both used to communicate with other devices. The processor is used to execute the instructions stored in the memory to cause the server to perform the method as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium, comprising: The non-transitory computer-readable storage medium stores instructions that, when executed, perform the method as described in any one of claims 1 to 7.