Intelligent connected vehicle anomaly detection system and method based on big data analysis
Patent Information
- Application Number
- CN202610794861.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-03
- Publication Date
- 2026-09-11
AI Technical Summary
[0003]现有智能网联汽车异常检测通常以单车运行或单一通信状态为主要判断依据,车辆运营状态、网联协同状态和道路运营场景之间缺少连续时空关联;在复杂运营场景下,历史运营基线难以随场景和运行阶段动态更新,跨域偏离难以被连续确认,导致异常来源回溯、风险分级处置和运营记录留存之间承接不足,影响异常检测准确性和处置可追溯性
1、本发明中,首先通过构建多源运营数据的运营时空连续关联机制,将车辆运营状态、网联协同状态和道路运营场景在同一车辆运营过程、运营任务、时间片和路段位置下形成连续对应关系,提高了异常检测前端数据的时空对齐精度,减少了多源数据错位导致的异常误判,为智能网联汽车复杂运营过程中的异常识别提供了一致、稳定的数据基础;通过构建面向运营场景和运行阶段的动态基线自适应构建机制,使当前运营时空关联数据能够与车队历史运营数据在场景、阶段、时间片和路段位置维度形成对应关系,并据此形成分场景动态运营基线,提高了异常检测基准对不同道路环境、不同运行阶段和不同协同状态的适配能力,增强了检测稳定性和异常识别灵敏度。
Smart Images

Figure CN122736306A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of anomaly detection technology for connected vehicles, and in particular to an intelligent connected vehicle anomaly detection system and method based on big data analysis. Background Technology
[0002] Intelligent connected vehicles continuously generate data related to vehicle operation status, network connectivity status, and road operation scenarios during operation. Existing anomaly detection systems typically collect relevant data through on-board terminals, roadside equipment, and operation platforms, and combine this data with vehicle operation processes, communication interaction processes, and road traffic environment to perform status analysis in order to identify abnormal changes in vehicle operation and provide data support for safety supervision, operation scheduling, and handling records.
[0003] Current intelligent connected vehicle anomaly detection methods typically rely on single-vehicle operation or single communication status as the primary basis for judgment, lacking continuous spatiotemporal correlation between vehicle operating status, network collaboration status, and road operation scenarios. In complex operating scenarios, historical operating baselines are difficult to update dynamically with different scenarios and operating phases, and cross-domain deviations are difficult to continuously confirm. This results in insufficient connection between anomaly source tracing, risk classification and handling, and operational record retention, affecting the accuracy of anomaly detection and the traceability of handling. Summary of the Invention
[0004] The purpose of this invention is to address the shortcomings of existing technologies by proposing an intelligent connected vehicle anomaly detection system and method based on big data analysis.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: an intelligent connected vehicle anomaly detection system and method based on big data analysis, comprising: The vehicle operation data access module performs multi-source operation access and consolidation processing on vehicle operation status data, network connectivity and collaboration status data and road operation scenario data to generate multi-source operation basic data. The spatiotemporal correlation module performs unified spatiotemporal correlation processing on multi-source basic operational data to generate spatiotemporal correlated data. The scenario baseline construction module performs scenario-specific dynamic baseline construction processing on the spatiotemporal correlation data of operations and the historical operation data of the fleet, and generates scenario-specific dynamic operation baselines. The cross-domain consistency detection module performs COPOD algorithm processing on the spatiotemporal correlation data of operation and the dynamic operation baseline of each scenario based on Page-Hinkley residual confirmation to generate cross-domain anomaly detection data. The anomaly source tracing module performs anomaly source tracing and aggregation processing on cross-domain anomaly detection data to generate anomaly source data. The risk classification and handling module performs operational risk classification and handling on abnormal source data and cross-domain anomaly detection data, and generates anomaly detection results. The operation record retention module performs abnormal operation record retention processing on the abnormal detection results and abnormal source data, and generates abnormal retention records.
[0006] As a further description of the above technical solution: The vehicle operation data access module generates multi-source basic operation data, including: The access order of vehicle operation status data, network connectivity collaboration status data and road operation scenario data is sorted out. The three types of data are arranged according to the order of collection, receipt and recording in the same vehicle operation process to generate operation access order data. The corresponding content is collected for the operation access sequence data. The corresponding content of vehicle operation status data, network connectivity collaboration status data, and road operation scenario data are grouped into the continuous data position under the same vehicle operation process to generate operation corresponding collection data. Perform network-connected collaborative data processing on the collected operational data, continuously match the corresponding content of vehicle operation status data with the corresponding content of network-connected collaborative status data, and connect the corresponding content of road operation scenario data to the same corresponding location to generate collaborative scenario data. Time-slice processing is performed on the data corresponding to collaborative scenarios. The corresponding content of vehicle operation status data, network collaboration status data and road operation scenario data within the same time slice are merged, and the corresponding content between different time slices is arranged continuously according to the time sequence to generate time-slice processed data. The time-slice data is processed to perform road segment location mapping. The corresponding content within the same time slice is merged according to the road segment location relationship, and the corresponding content between different road segment locations is arranged continuously according to the passage sequence during vehicle operation to generate road segment location mapping data. Multi-source operation access and consolidation processing is performed on the data corresponding to road segment locations. The content corresponding to vehicle operation status data, network connectivity collaboration status data, and road operation scenario data is uniformly consolidated according to time slice relationships and road segment location relationships to generate multi-source operation basic data.
[0007] As a further description of the above technical solution: The operational spatiotemporal correlation module generates operational spatiotemporal correlation data including: Perform operation object merging processing on multi-source operation basic data, read the corresponding content under the same vehicle operation process in the multi-source operation basic data, and group the corresponding content under the same vehicle operation process into continuous associated positions to generate operation object merged data; Perform corresponding processing on the merged data of the operation objects. According to the correspondence between the vehicle operation process and the operation task, the corresponding content in the merged data of the operation objects is assigned to the continuous data position under the same operation task, and the corresponding data of the operation task is generated. Perform continuous time-slice processing on the data corresponding to the operational tasks, arrange the corresponding content of different time slices under the same operational task in a continuous manner according to the time sequence, and merge the corresponding content within the same time slice to generate continuous time-slice processing data. The continuous processing of time-slice data is performed to continuously correspond to road segment locations. The corresponding content within the same time slice is merged according to the road segment location relationship, and the corresponding content between different road segment locations is continuously arranged according to the passage sequence during vehicle operation to generate continuous road segment location correspondence data. Perform spatiotemporal cross-organization processing on the continuous corresponding data of road segment locations, cross-merge the corresponding content under the same operation task, the same time slice and the same road segment location, and maintain the continuous and consistent arrangement relationship between different operation tasks, different time slices and different road segment locations to generate spatiotemporal cross-organized data. The spatiotemporal cross-organized operational data is processed by unified spatiotemporal association, which links the corresponding content of vehicle operation status data, network connectivity collaboration status data, and road operation scenario data according to the continuous correspondence between operational tasks, time slices, and road segment locations, generating spatiotemporal associated operational data.
[0008] As a further description of the above technical solution: The scenario baseline construction module generates scenario-specific dynamic operation baselines, including: Perform scenario-based processing on the spatiotemporal correlation data of operations, read the corresponding content under the same operational task, the same time slice and the same road segment location, and classify the corresponding content of vehicle operation status data, network connectivity collaboration status data and road operation scenario data into the same scenario corresponding position to generate operation scenario corresponding data; The data corresponding to the operation scenario is continuously processed and organized during the operation phase. According to the sequence of vehicle operation, the corresponding content under the same operation scenario is arranged by continuous time slices and continuous road segment locations. The arranged corresponding content is then classified into the same operation phase to generate operation phase organized data. The historical corresponding segment extraction process is performed on the data compiled during the operation phase and the historical operation data of the fleet. According to the correspondence between operation scenarios and operation phases, the historical operation content that continuously corresponds to the data compiled during the operation phase is extracted from the historical operation data of the fleet to generate historical operation segment data. Historical state merging processing is performed on historical operation segment data. Historical operation content under the same operation scenario and the same operation stage is merged according to the correspondence between vehicle operation status, network connectivity status and road operation scenario, while maintaining the continuity and consistency of time slice order and road segment location order among historical operation content, and generating historical state merged data. The historical status merged data and the operational phase organized data are processed to perform scenario difference sorting. The corresponding content under the current operation scenario is matched with the historical operation content item by item, and the differences between vehicle operation status, network collaboration status and road operation scenario under the same operational phase are sorted to generate scenario difference sorting data. Dynamic baseline processing is performed on the scenario difference data. According to the correspondence of operational scenarios, operational phases, and historical operational content, stable corresponding content in the scenario difference data is merged, and deviating content is separated and processed to generate dynamic baseline data. The dynamic baseline data is processed by scenario-based dynamic baseline construction. The dynamic baseline data under the same operation scenario and the same operation phase are uniformly organized according to time slice relationship, road segment location relationship and historical operation content correspondence to generate scenario-based dynamic operation baselines.
[0009] As a further description of the above technical solution: The cross-domain consistency detection module generates cross-domain anomaly detection data including: The spatiotemporal correlation data and the dynamic operational baselines for different scenarios are processed by algorithm input. The spatiotemporal correlation data and the dynamic operational baselines for different scenarios are arranged according to the same operational task, the same time slice and the same road segment location to generate the processed algorithm input data. The baseline corresponding sample processing is performed on the algorithm input data. Based on the corresponding arrangement relationship in the algorithm input data, the corresponding content of the operation spatiotemporal correlation data and the corresponding content of the dynamic operation baseline in different scenarios are extracted. The extracted corresponding content is then merged in the same arrangement order to generate baseline corresponding sample data. Cross-domain residual processing is performed on the baseline corresponding sample data. The content corresponding to the operation spatiotemporal correlation data in the baseline corresponding sample data is sorted out with the content corresponding to the dynamic operation baseline in different scenarios. The results of the sorting out of differences are merged according to the same operation task, the same time slice and the same road segment location to generate cross-domain residual data. Local detection subspace construction processing is performed on cross-domain residual data. Based on the continuous difference sorting results in the cross-domain residual data, detection dimensions that maintain correspondence with the spatiotemporal correlation data of operation and the dynamic operation baseline of sub-scenario are extracted, and the detection dimensions are organized in the original order to generate local detection subspace data. Cross-domain detection sample construction processing is performed on local detection subspace data and operational spatiotemporal correlation data. According to the detection dimension in the local detection subspace data, the corresponding content is extracted from the operational spatiotemporal correlation data. The extracted corresponding content is then merged according to the same operational task, the same time slice, and the same road segment location to generate cross-domain detection sample data. Local experience Copula distribution construction processing is performed on cross-domain detection sample data and scenario-based dynamic operation baselines. According to the corresponding arrangement relationship in the scenario-based dynamic operation baselines, the cross-domain detection sample data is sorted by edge experience distribution and joint sorting to generate local experience Copula distribution data. Tail probability calculation is performed on local empirical Copula distribution data and cross-domain detection sample data. Tail probability is sorted on cross-domain detection sample data based on local empirical Copula distribution data, and the tail probability results corresponding to each detection dimension are jointly merged to generate tail probability data. Perform residual confirmation sequence generation processing on the tail probability data and cross-domain residual data, and arrange the tail probability data and cross-domain residual data continuously according to the same operational task, continuous time slice and the same road segment location to generate residual confirmation sequence data; Perform residual mean update processing on the residual confirmation sequence data. Read the corresponding content in the residual confirmation sequence data in the order of continuous time slices, and perform mean update and fallback adjustment on the corresponding content of the current time slice and the corresponding content of the previous time slice to generate residual mean update data. The cumulative residual deviation processing is performed on the residual mean update data. The corresponding content that changes in the same direction within consecutive time slices in the residual mean update data is accumulated and processed, and the corresponding content that does not maintain continuous change in the same direction is separated and processed to generate cumulative residual deviation data. Perform scenario-corresponding deviation confirmation processing on the cumulative residual deviation data and the scenario-based dynamic operation baseline. Compare the cumulative residual deviation data with the corresponding content in the scenario-based dynamic operation baseline, and retain the content that maintains a continuous correspondence with both the tail probability data and the cross-domain residual data to generate residual confirmation data. Feedback correction processing is performed on the residual confirmation data and the local detection subspace data. The detection dimensions that are continuously corresponding in the residual confirmation data are written back to the local detection subspace data. The detection dimensions of subsequent time slices are arranged according to the correspondence after writing back, and the corrected local detection subspace data is generated. The tail probability data, residual confirmation data, and corrected local detection subspace data are merged. The tail probability data, residual confirmation data, and corrected local detection subspace data are merged in a unified manner according to the same operation task, the same time slice, and the same road segment location to generate cross-domain anomaly detection data.
[0010] As a further description of the above technical solution: The anomaly source backtracking module generates anomaly source data including: Perform anomaly location sorting processing on cross-domain anomaly detection data, read the corresponding content under the same operation task, the same time slice and the same road segment in the cross-domain anomaly detection data, and merge the corresponding content according to the continuous arrangement relationship in the vehicle operation process to generate anomaly location data; Anomaly trigger relationship processing is performed on the data corresponding to the anomaly location. The corresponding content of consecutive time slices before and after the anomaly location data is compared sequentially, and the content that forms the anomaly correspondence for the first time is separated and processed with the subsequent anomaly correspondence to generate anomaly trigger relationship data. Perform anomaly persistence relationship processing on the anomaly trigger relationship data. Merge the contents that maintain the same anomaly correspondence within consecutive time slices in the anomaly trigger relationship data, and separate and organize the contents that do not maintain a continuous relationship to generate anomaly persistence relationship data. Perform anomaly association content back-checking on the abnormal persistent relationship data. Based on the correspondence between operational tasks, time slices and road segment locations in the abnormal persistent relationship data, back-check the content in the cross-domain anomaly detection data that continuously corresponds to the abnormal persistent relationship data, and generate anomaly association back-checking data. Cross-domain source correspondence processing is performed on the abnormal correlation back lookup data. The content that is continuously related to the vehicle operation status data, the network collaboration status data, and the road operation scenario data in the abnormal correlation back lookup data is merged separately, while maintaining the correspondence under the same operation task, the same time slice, and the same road segment location, to generate cross-domain source correspondence data. Anomaly source aggregation processing is performed on cross-domain source corresponding data. Contents that continuously point to the same source relationship in cross-domain source corresponding data are merged, and the corresponding content between different source relationships are arranged according to the chronological relationship in the vehicle operation process to generate anomaly source aggregation data. Anomaly source data is processed by backtracking and aggregating the anomaly source data. The anomaly source data is then uniformly organized according to the operational tasks, time slices, road segment locations, and cross-domain source correspondence to generate anomaly source data.
[0011] As a further description of the above technical solution: The risk classification and handling module generates anomaly detection results including: Perform corresponding processing on abnormal source data and cross-domain abnormal detection data. Read the corresponding content of the same operation task, the same time slice and the same road segment in the abnormal source data, and classify the content that corresponds to the abnormal source data in the cross-domain abnormal detection data into the same processing input position to generate corresponding processing input data. The abnormal impact range data is sorted and processed by performing anomaly impact range sorting on the corresponding data of the disposal input. The corresponding contents of the corresponding data of the disposal input that maintain the same abnormal source relationship within consecutive time slices and consecutive road segments are merged, and the impact contents corresponding to different abnormal source relationships are arranged according to the chronological relationship of the vehicle operation process to generate abnormal impact range data. Perform anomaly persistence status processing on the anomaly impact range data, merge the continuous anomaly impact content that occurs continuously under the same operational task in the anomaly impact range data, and separate and process the anomaly impact content that occurs interrupted, to generate anomaly persistence status data. Risk correspondence processing is performed on the continuous abnormal status data and cross-domain anomaly detection data. The continuous abnormal impact content in the continuous abnormal status data is merged with the corresponding content in the cross-domain anomaly detection data item by item, while maintaining the correspondence under the same operational task, the same time slice and the same road segment location, to generate risk correspondence processing data. The risk correspondence data is processed by classifying operational risk levels. According to the correspondence of abnormal source data, the correspondence of abnormal impact scope data, and the correspondence of abnormal duration data, the corresponding content in the risk correspondence data is merged into levels, and the corresponding content of different levels is arranged according to the chronological relationship in the vehicle operation process to generate operational risk level data. The operational risk level data is mapped to the corresponding content of the same level in the operational risk level data and the corresponding content of the anomaly source data and cross-domain anomaly detection data. The mapping results of different levels are merged according to the arrangement relationship in the operational risk level data to generate the handling strategy mapping data. Operational risk classification and handling are performed on the handling strategy mapping data, operational risk level data and anomaly source data. The corresponding content in the handling strategy mapping data, the level corresponding content in the operational risk level data and the source corresponding content in the anomaly source data are uniformly organized according to the same operational task, the same time slice and the same road segment location to generate anomaly detection results.
[0012] As a further description of the above technical solution: The operations record retention module generates abnormal retention records including: Perform retention input correspondence processing on anomaly detection results and anomaly source data, read the corresponding content under the same operation task, the same time slice and the same road segment location in the anomaly detection results, and classify the content that continuously corresponds to the anomaly detection results in the anomaly source data into the same retention input location to generate retention input correspondence data; The source result correspondence processing is performed on the retained input data. The abnormal source data in the retained input data is matched with the abnormal detection result, and the matched content is arranged according to the chronological relationship in the vehicle operation process to generate source result correspondence data. Perform anomaly record association processing on the source result corresponding data, merge the corresponding content under the same operation task, the same time slice and the same road segment location in the source result corresponding data, and organize the corresponding content under different time slices and different road segment locations according to the continuous arrangement relationship to generate anomaly record association data; The process of handling the associated data of abnormal records is processed and organized. The content that corresponds continuously to the abnormal detection results in the associated data of abnormal records is read and arranged according to the correspondence of abnormal source data and the chronological relationship in the vehicle operation process to generate the handling process record data. Anomaly review and marking processing is performed on the data recorded during the handling process. Contents in the data recorded during the handling process that are continuously corresponding to the source data of the anomaly are merged according to the same operational task, the same time slice, and the same road segment location. The merged content is then marked and organized according to the source correspondence in the source data of the anomaly, generating anomaly review and marking data. Perform retention order sorting on the abnormal review mark data and abnormal record associated data, fill the corresponding content in the abnormal review mark data back into the consecutive record positions in the abnormal record associated data, and form a retention arrangement relationship according to the chronological relationship in the vehicle operation process to generate retention order sorting data; The data for the retention order is processed to retain abnormal operation records. The data for the retention order is uniformly organized according to the correspondence between abnormal detection results, abnormal source data, and handling process records, and abnormal retention records are generated.
[0013] As a further description of the above technical solution: Anomaly detection methods for intelligent connected vehicles based on big data analytics include: Acquire vehicle operation status data, network connectivity collaboration status data, and road operation scenario data; perform multi-source operation access and consolidation processing on the vehicle operation status data, network connectivity collaboration status data, and road operation scenario data to generate multi-source operation basic data. Perform unified spatiotemporal correlation processing on multi-source operational basic data to generate spatiotemporal correlated operational data; Acquire historical operational data of the fleet, perform scenario-based dynamic baseline construction processing on the spatiotemporal correlation data of operations and historical operational data of the fleet, and generate scenario-based dynamic operational baselines; The operation spatiotemporal correlation data and scenario-based dynamic operation baselines are processed using the scenario-based dynamic baseline feedback COPOD algorithm based on Page-Hinkley residual confirmation to generate cross-domain anomaly detection data. Perform anomaly source tracing and aggregation processing on cross-domain anomaly detection data to generate anomaly source data; Perform operational risk-based classification and handling of abnormal source data and cross-domain anomaly detection data, and generate anomaly detection results; Perform abnormal operation record retention processing on abnormal detection results and abnormal source data to generate abnormal retention records.
[0014] The present invention has the following beneficial effects: 1. In this invention, firstly, by constructing a continuous spatiotemporal correlation mechanism for multi-source operational data, a continuous correspondence is formed between vehicle operational status, network-connected collaborative status, and road operational scenarios under the same vehicle operation process, operational task, time slice, and road segment location. This improves the spatiotemporal alignment accuracy of anomaly detection front-end data, reduces misjudgments of anomalies caused by misalignment of multi-source data, and provides a consistent and stable data foundation for anomaly identification in the complex operation process of intelligent connected vehicles. Secondly, by constructing a dynamic baseline adaptive construction mechanism oriented towards operational scenarios and operational stages, the current spatiotemporal correlation data can form a correspondence with the fleet's historical operational data in the dimensions of scenario, stage, time slice, and road segment location. Based on this, a scenario-specific dynamic operational baseline is formed, improving the adaptability of the anomaly detection benchmark to different road environments, different operational stages, and different collaborative states, and enhancing detection stability and anomaly identification sensitivity.
[0015] 2. In this invention, a cross-domain consistency detection mechanism coupling tail probability detection and continuous residual confirmation is constructed. This mechanism coordinates the tail probability judgment formed by the COPOD algorithm with the Page-Hinkley residual confirmation process. Furthermore, by correcting the local detection subspace to achieve feedback updates of the detection dimension, the accuracy and repeatability of cross-domain anomaly detection are improved. This enhances the ability to identify persistent deviations, early anomalies, and complex collaborative anomalies, while reducing false positives and false negatives. Additionally, by constructing a trigger-persistence-source backtracking mechanism for cross-domain anomalies, the anomaly location, triggering relationship, persistence relationship, and associated backtracking content in the cross-domain anomaly detection data are uniformly collected into a single mechanism. By incorporating vehicle operating status, network connectivity status, and road operation scenarios, the system enhances the ability to locate anomalies and improves the interpretability of detection results. This enables anomaly detection results to support causal analysis, operational review, and subsequent handling decisions. By constructing a risk-based classification and traceability retention mechanism driven by anomaly detection results, the system continuously maps anomaly sources, impact ranges, duration of anomalies, operational risk levels, handling strategies, and anomaly retention records. This improves the consistency and coordinated control capabilities of anomaly handling, allowing for traceable records of the anomaly handling process, source relationships, and review markers. This provides auxiliary decision support for the safe operation management of intelligent connected vehicles. Attached Figure Description
[0016] Figure 1 This is a system architecture diagram of the present invention; Figure 2 This is a diagram illustrating the method steps of the present invention. Detailed Implementation
[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0018] Reference Figure 1-2 The present invention provides an embodiment of an intelligent connected vehicle anomaly detection system and method based on big data analysis, comprising: The vehicle operation data access module performs multi-source operation access and consolidation processing on vehicle operation status data, network connectivity and collaboration status data and road operation scenario data to generate multi-source operation basic data. The spatiotemporal correlation module performs unified spatiotemporal correlation processing on multi-source basic operational data to generate spatiotemporal correlated data. The scenario baseline construction module performs scenario-specific dynamic baseline construction processing on the spatiotemporal correlation data of operations and the historical operation data of the fleet, and generates scenario-specific dynamic operation baselines. The cross-domain consistency detection module performs COPOD algorithm processing on the spatiotemporal correlation data of operation and the dynamic operation baseline of each scenario based on Page-Hinkley residual confirmation to generate cross-domain anomaly detection data. The anomaly source tracing module performs anomaly source tracing and aggregation processing on cross-domain anomaly detection data to generate anomaly source data. The risk classification and handling module performs operational risk classification and handling on abnormal source data and cross-domain anomaly detection data, and generates anomaly detection results. The operation record retention module performs abnormal operation record retention processing on the abnormal detection results and abnormal source data, and generates abnormal retention records.
[0019] Anomaly detection methods for intelligent connected vehicles based on big data analytics include: Acquire vehicle operation status data, network connectivity collaboration status data, and road operation scenario data; perform multi-source operation access and consolidation processing on the vehicle operation status data, network connectivity collaboration status data, and road operation scenario data to generate multi-source operation basic data. Perform unified spatiotemporal correlation processing on multi-source operational basic data to generate spatiotemporal correlated operational data; Acquire historical operational data of the fleet, perform scenario-based dynamic baseline construction processing on the spatiotemporal correlation data of operations and historical operational data of the fleet, and generate scenario-based dynamic operational baselines; The operation spatiotemporal correlation data and scenario-based dynamic operation baselines are processed using the scenario-based dynamic baseline feedback COPOD algorithm based on Page-Hinkley residual confirmation to generate cross-domain anomaly detection data. Perform anomaly source tracing and aggregation processing on cross-domain anomaly detection data to generate anomaly source data; Perform operational risk-based classification and handling of abnormal source data and cross-domain anomaly detection data, and generate anomaly detection results; Perform abnormal operation record retention processing on abnormal detection results and abnormal source data to generate abnormal retention records.
[0020] In this embodiment, the vehicle operation data access module receives vehicle operation status data, network connectivity collaboration status data, and road operation scenario data. First, it reads the corresponding content of the vehicle operation status data according to the same vehicle operation process. Then, it reads the corresponding content of the network connectivity collaboration status data according to the order of receipt. Finally, it reads the corresponding content of the road operation scenario data according to the order of recording. After reading, the corresponding content is arranged in order according to the order of collection, receipt, and recording. The arranged corresponding content is then connected to the continuous data position of the same vehicle operation process to generate operation access order data.
[0021] After the operation access sequence data enters the corresponding content collection step, the continuous arrangement of the same vehicle operation process in the operation access sequence data is read first. Then, the data is merged item by item according to the original arrangement relationship between the corresponding content of vehicle operation status data, the corresponding content of network connectivity collaboration status data, and the corresponding content of road operation scenario data. During the merging process, the corresponding content belonging to the same vehicle operation process is connected to the same continuous data position, and the corresponding content under different vehicle operation processes is organized separately according to their respective arrangement order to generate operation corresponding collection data.
[0022] After the operation-related collected data enters the network-connected collaborative data processing step, the corresponding content of vehicle operation status data in the operation-related collected data is read first, and then the corresponding content of network-connected collaborative status data under the same vehicle operation process is read. The two are then established in a sequential correspondence relationship according to their consecutive positions. After the sequential correspondence relationship is formed, the corresponding content of road operation scenario data under the same vehicle operation process is read, and the corresponding content of road operation scenario data is connected to the same corresponding position that has been formed by the corresponding content of vehicle operation status data and network-connected collaborative status data to generate collaborative scenario corresponding data.
[0023] After the collaborative scenario data enters the time-slice processing step, the collaborative scenario data within the same time slice is first read according to the chronological order. Then, the vehicle operation status data, network-connected collaborative status data, and road operation scenario data within the same time slice are merged. After merging within the same time slice, the corresponding content between different time slices is arranged continuously according to the chronological order, ensuring that the corresponding content within each time slice does not deviate from the original vehicle operation process, thus generating time-slice processed data.
[0024] After the time-slice data processing enters the road segment location correspondence step, it first reads the corresponding content that has been merged within the same time slice, and then merges the corresponding content belonging to the same road segment location within the same time slice according to the road segment location relationship; after the merging of the same road segment location is completed, the corresponding content between different road segment locations is arranged continuously according to the traffic order during vehicle operation, while keeping the time sequence in the time-slice data processing unchanged, to generate road segment location correspondence data.
[0025] After the road segment location data enters the multi-source operation access and consolidation step, the continuous arrangement of the same vehicle operation process in the road segment location data is read first. Then, the corresponding content of vehicle operation status data, network connectivity collaboration status data, and road operation scenario data are uniformly consolidated according to the time slice relationship and road segment location relationship. During the uniform consolidation process, the corresponding content under the same time slice and the same road segment location is grouped into the same basic operation location, and the corresponding content under different time slices and different road segment locations is connected according to the chronological relationship in the vehicle operation process to generate multi-source basic operation data.
[0026] In this embodiment, after receiving multi-source operational basic data, the operation spatiotemporal association module first reads the corresponding content under the same vehicle operation process in the multi-source operational basic data, then organizes the read corresponding content in order according to the continuous arrangement relationship in the vehicle operation process, and writes the corresponding content under the same vehicle operation process into the continuous association position to generate operation object merging data.
[0027] After the data of the merged operation objects enters the corresponding steps of the operation tasks, the corresponding content that has been assigned to the continuous associated positions in the merged operation object data is read first. Then, the assignment position is determined item by item according to the correspondence between the vehicle operation process and the operation tasks. The corresponding content belonging to the same operation task is connected to the continuous data positions under the same operation task to generate the corresponding data of the operation task.
[0028] After the data corresponding to the operational tasks enters the time-slice continuous processing step, the corresponding content under the same operational task is read first, and then the corresponding content is arranged continuously according to the time sequence between different time slices. The corresponding content within the same time slice is then grouped into the same time slice position to generate time-slice continuous processing data.
[0029] After the time-slice continuous data processing enters the road segment location continuous correspondence step, it first reads the corresponding content that has been merged within the same time slice, then merges the corresponding content belonging to the same road segment location within the same time slice according to the road segment location relationship, and connects the corresponding content between different road segment locations according to the passage sequence during vehicle operation to generate road segment location continuous correspondence data.
[0030] After the continuous corresponding data of road segment locations enters the operation spatiotemporal cross-organization step, the corresponding content under the same operation task, the same time slice and the same road segment location is read first. Then, the read corresponding content is merged according to the cross relationship between operation task, time slice and road segment location, and the arrangement relationship between different operation tasks, different time slices and different road segment locations is kept continuous and consistent to generate operation spatiotemporal cross-organization data.
[0031] After the operational spatiotemporal cross-organized data enters the operational spatiotemporal unified association step, the corresponding content under the same operational task, the same time slice, and the same road segment location in the operational spatiotemporal cross-organized data is first read. Then, the corresponding content of vehicle operation status data, network connectivity collaboration status data, and road operation scenario data are uniformly connected according to the continuous correspondence between operational tasks, time slices, and road segment locations. The connected corresponding content is then assigned to the same operational spatiotemporal associated location to generate operational spatiotemporal associated data.
[0032] In this embodiment, after receiving the spatiotemporal correlation data of operation, the scenario baseline construction module first reads the corresponding content under the same operation task in the spatiotemporal correlation data of operation, and then organizes the read corresponding content in sequence according to the same time slice and the same road segment location. After the sequential organization is completed, the corresponding content of vehicle operation status data, the corresponding content of network connectivity collaboration status data, and the corresponding content of road operation scenario data are grouped into the same scene corresponding position, and the arrangement relationship between different operation tasks, different time slices, and different road segment locations is kept continuous and consistent to generate operation scenario corresponding data.
[0033] After the data corresponding to the operation scenario enters the continuous processing step of the operation phase, the corresponding content under the same operation scenario is read first. Then, the corresponding content is arranged according to the sequence of vehicle operation. The arranged corresponding content is then connected according to the location of continuous road segments. After the connection is completed, the corresponding content under the continuous time slice and the continuous road segment location is included in the same operation phase to generate the operation phase processing data.
[0034] After the operational phase data and fleet historical operation data enter the historical segment extraction step, the corresponding content under the same operational scenario and the same operational phase in the operational phase data is first read. Then, the continuously corresponding historical operation content in the fleet historical operation data is read according to the operational scenario correspondence and the operational phase correspondence. After reading, the historical operation content is organized according to the arrangement order in the operational phase data, and the historical operation content that cannot form a continuous correspondence with the operational phase data is separated to generate historical operation segment data.
[0035] After the historical operation segment data enters the historical state merging step, the historical operation content under the same operation scenario and the same operation stage in the historical operation segment data is first read. Then, the historical operation content is merged item by item according to the correspondence between vehicle operation status, network connectivity status and road operation scenario. During the merging process, the time slice order and road segment location order between the historical operation content are kept continuous and consistent. The merged historical operation content is then connected to the continuous location under the same operation stage to generate historical state merged data.
[0036] After the historical status merged data and the operational phase organized data enter the scenario difference sorting step, the corresponding content under the current operational scenario in the operational phase organized data is read first. Then, the historical operational content under the same operational scenario and the same operational phase in the historical status merged data is read, and each item is matched according to the correspondence between vehicle operational status, network connectivity collaborative status and road operational scenario. After the item-by-item matching is completed, the difference relationship between the corresponding content under the current operational scenario and the historical operational content is sorted out, and the difference relationship is merged according to the time slice relationship and the road segment location relationship to generate scenario difference sorting data.
[0037] After the scenario difference data enters the dynamic baseline data processing step, the corresponding content under the same operating scenario and the same operating phase in the scenario difference data is first read. Then, the stable corresponding content in the scenario difference data is merged according to the corresponding relationship of operating scenario, corresponding relationship of operating phase and corresponding relationship of historical operating content. After the stable corresponding content is merged, the deviating corresponding content is separated from the same merged position, and the separated corresponding content is kept to continuously correspond with the original time slice relationship and road segment position relationship, thus generating dynamic baseline data.
[0038] After the dynamic baseline data enters the scenario-specific dynamic baseline construction step, the corresponding content under the same operating scenario and the same operating phase in the dynamic baseline data is first read. Then, the read corresponding content is uniformly organized according to the time slice relationship, road segment location relationship and historical operating content correspondence. During the uniform organization process, the dynamic baseline data under the same operating scenario, the same operating phase, the same time slice and the same road segment location are grouped into the same baseline position, and the corresponding content under different operating scenarios and different operating phases is arranged continuously according to the chronological relationship in the vehicle operation process to generate scenario-specific dynamic operating baselines.
[0039] In this embodiment, after receiving the operational spatiotemporal correlation data and the scenario-specific dynamic operational baseline, the cross-domain consistency detection module first reads the corresponding content under the same operational task in the operational spatiotemporal correlation data, and then reads the corresponding content continuously corresponding to the operational task in the scenario-specific dynamic operational baseline. The two types of corresponding content are then arranged sequentially according to the same operational task, the same time slice, and the same road segment location. After the arrangement is completed, the corresponding content of the operational spatiotemporal correlation data and the corresponding content of the scenario-specific dynamic operational baseline are written into the same arrangement position to generate the algorithm input processing data. The algorithm input processing formula is as follows: , ; Operational task index Time slice index Road segment location index The sequence number is formed according to the same operational task, the same time slot, and the same road segment location. A sorting function that generates sequence numbers based on the continuous correspondence between operational tasks, time slices, and road segment locations. : Vectors formed by the spatiotemporal correlation data of operations under corresponding operational tasks, time slices, and road segment locations. : The vector formed by the dynamic operation baseline for each scenario under the corresponding operation task, time slice, and road segment location. The algorithm inputs sorted data into sequence numbers. The corresponding input processing results.
[0040] After the algorithm input data enters the baseline corresponding sample processing step, it first reads the corresponding arrangement relationship in the algorithm input data, and then extracts the corresponding content of the operational spatiotemporal correlation data and the corresponding content of the dynamic operational baseline for different scenarios according to the corresponding arrangement relationship. After extraction, the two types of corresponding content are merged item by item according to the same arrangement order, and the merged corresponding content is connected to the continuous positions under the same operational task, the same time slice, and the same road segment location to generate baseline corresponding sample data. Baseline corresponding sample processing formula: , , Operational task index Time slice index Road segment location index : Detection dimension index The set of detection dimensions under the same operational task, the same time slice, and the same road segment location. Operational spatiotemporal correlation data in the detection dimension The corresponding content value below, : Dynamic operational baselines for different scenarios in the detection dimension The corresponding content value below, Detection Dimensions The baseline corresponds to the sample unit. Baseline corresponding sample data formed under the same operational task, the same time slice, and the same road segment location.
[0041] After the baseline-corresponding sample data enters the cross-domain residual processing step, the corresponding content of the operational spatiotemporal correlation data in the baseline-corresponding sample data is first read, and then the corresponding content of the dynamic operational baseline for each continuous scenario is read. The differences between the two types of corresponding content are then read according to the same operational task, the same time slice, and the same road segment location. After the difference reading is completed, the difference processing results are merged according to the original sorting order, and the merged difference processing results are connected to the continuous difference positions to generate cross-domain residual data. Cross-domain residual processing formula: , ; Operational task index Time slice index Road segment location index : Detection dimension index Operational spatiotemporal correlation data in the detection dimension The corresponding content value below, : Dynamic operational baselines for different scenarios in the detection dimension The corresponding content value below, Directed residuals in cross-domain residual data : Residual magnitude in cross-domain residual data.
[0042] After the cross-domain residual data enters the local detection subspace construction step, the continuous difference processing results in the cross-domain residual data are first read. Then, according to the position of the continuous difference processing results in the original arrangement order, detection dimensions that maintain a corresponding relationship with the operational spatiotemporal correlation data and the dynamic operational baseline of each scenario are extracted. After the detection dimensions are extracted, they are organized according to the original arrangement order, and the organized detection dimensions are connected to the continuous detection positions under the same operational task, the same time slice, and the same road segment location to generate local detection subspace data. Local detection subspace construction processing formula: , ; Operational task index Time slice index Road segment location index : Detection dimension index The set of detection dimensions under the same operational task, the same time slice, and the same road segment location. Detection Dimensions The residual amplitude below, Detection Dimensions The directed residual below, The set of detection dimensions in the local detection subspace data. Local detection subspace data formed from the results of continuous difference processing.
[0043] After the local detection subspace data and operational spatiotemporal correlation data enter the cross-domain detection sample construction step, the detection dimensions in the local detection subspace data are first read. Then, according to the order of the detection dimensions in the local detection subspace data, the corresponding content is read continuously from the operational spatiotemporal correlation data. After reading, the read corresponding content is merged according to the same operational task, the same time slice, and the same road segment location, while maintaining the consistency of the arrangement relationship between the corresponding content and the detection dimensions, thus generating cross-domain detection sample data. The cross-domain detection sample construction processing formula is as follows: , , ; Operational task index Time slice index Road segment location index : Detection dimension index The set of detection dimensions in the local detection subspace data. Operational spatiotemporal correlation data in the detection dimension The corresponding content value below, Cross-domain detection sample data in the detection dimension The sample values below, Cross-domain detection sample data generated under the same operational task, the same time slice, and the same road segment location.
[0044] After the cross-domain detection sample data and the scenario-specific dynamic operation baseline enter the local experience Copula distribution construction step, the corresponding arrangement relationship in the scenario-specific dynamic operation baseline is first read. Then, the corresponding content in the cross-domain detection sample data is read according to this arrangement relationship, and the corresponding content in the cross-domain detection sample data is processed by edge experience distribution. After the edge experience distribution is processed, it is jointly sorted according to the arrangement order between detection dimensions, and the corresponding content after edge experience distribution processing and the corresponding content after joint sorting are grouped into the same joint distribution position to generate local experience Copula distribution data. The formula for constructing the local experience Copula distribution is as follows:
[0045]
[0046] Operational task index Time slice index Road segment location index : Detection dimension index : Index of operational tasks in a localized experience sample. Time slice index in local empirical samples : Road segment location index in local empirical samples The set of detection dimensions in the local detection subspace data. Cross-domain detection sample data in the detection dimension The sample values below, Local empirical samples in the detection dimension The sample values below, : Continuously corresponds to the dynamic operation baseline for different scenarios and is used for detection dimensions The set of local empirical sample indexes A set of local experience sample indexes that continuously correspond to the dynamic operation baseline for different scenarios and are used for joint sorting and organization. : Medium sample size : Medium sample size Detection Dimensions The corresponding marginal empirical distribution function, Quantitative values formed after cross-domain detection sample data is processed using the marginal empirical distribution. : A joint ranking vector composed of the quantile values of each detection dimension. Local empirical Copula distribution data.
[0047] After the local empirical Copula distribution data and cross-domain detection sample data enter the tail probability calculation step, the distribution positions in the local empirical Copula distribution data that continuously correspond to the cross-domain detection sample data are first read. Then, the corresponding content in the cross-domain detection sample data is read according to the order of detection dimensions, and the corresponding content is mapped to the corresponding distribution positions in the local empirical Copula distribution data. After the mapping is completed, the tail probabilities corresponding to each detection dimension are sorted, and the tail probability results corresponding to each detection dimension are jointly merged according to the same operational task, the same time slice, and the same road segment location to generate tail probability data. Tail probability calculation processing formula: , , , ; Operational task index Time slice index Road segment location index : Detection dimension index The set of detection dimensions in the local detection subspace data. Detection Dimensions The quantile value below, Detection Dimensions The corresponding number of local empirical samples, Detection Dimensions The probability of the left tail below, Detection Dimensions The probability of the right tail below, Detection Dimensions The probability of the tail is below. The combined tail probability under the same operational task, the same time slice, and the same road segment location. : Local empirical Copula distribution function.
[0048] After the tail probability data and cross-domain residual data enter the residual confirmation sequence generation step, the corresponding content under the same operational task in the tail probability data is read first, and then the corresponding content continuously corresponding to the tail probability data in the cross-domain residual data is read. The two types of corresponding content are then arranged sequentially according to consecutive time slices and the same road segment location. After the sequential arrangement is completed, the corresponding content of the tail probability data and the corresponding content of the cross-domain residual data are inserted into the same sequence position, maintaining the continuous arrangement relationship between different time slices, to generate the residual confirmation sequence data. The residual confirmation sequence generation processing formula is as follows: , ; Operational task index Time slice index Road segment location index : Detection dimension index Operational tasks and road section location The following is a set of consecutive time slices. Detection Dimensions The probability of the tail is below. Detection Dimensions The directed residual below, : Residual confirmation sequence units composed of tail probabilities and cross-domain residuals in the same time slice Residual confirmation sequence data arranged in sequential order of consecutive time slices. Arranged in ascending order of time slices.
[0049] After the residual confirmation sequence data enters the residual mean update step, the corresponding content in the residual confirmation sequence data is first read in the order of consecutive time slices. Then, the corresponding content of the current time slice is compared item by item with the corresponding content of the previous time slice, and the mean is updated according to the continuous change relationship obtained from the comparison. During the mean update process, the corresponding content that maintains continuous change is added to the update position, and the corresponding content that does not maintain continuous change is adjusted back. The updated corresponding content and the adjusted corresponding content are merged in the order of time slices to generate the residual mean update data. Residual mean update processing formula: , ; Operational task index Time slice index Road segment location index : Detection dimension index Detection Dimensions The directed residual below, Mean of residuals after updating from the previous time slice. : The mean of the residuals after the current time slice update : The cumulative sequence number of the current time slice entering the mean update. The deviation of the current time slice residual from the updated mean.
[0050] After the residual mean update data enters the cumulative residual deviation cleanup step, the corresponding content that changes in the same direction within consecutive time slices is first read from the residual mean update data. Then, the corresponding content that changes in the same direction is accumulated and cleaned according to the time slice order, and the accumulated and cleaned corresponding content is entered into the same accumulation position. After the accumulation and cleanup is completed, the corresponding content that does not maintain continuous same-direction change is separated from the same accumulation position, and the separated corresponding content is arranged according to the original time slice order to generate the cumulative residual deviation data. The cumulative residual deviation cleanup formula is as follows: , , ; Operational task index Time slice index Road segment location index : Detection dimension index The deviation of the current time slice residuals from the updated mean. The amount of pullback and consolidation formed by residual confirmation sequence data. : Positive cumulative residual deviation of the preceding time slice : Deviation of the backward cumulative residual of the preceding time slice The positive cumulative residual deviation of the current time slice. : Deviation of the reverse cumulative residual for the current time slice : The overall deviation in the cumulative residual deviation data.
[0051] After the cumulative residual deviation data and the scenario-specific dynamic operational baseline enter the scenario-corresponding deviation confirmation step, the corresponding content under the same operational task, the same time slice, and the same road segment location in the cumulative residual deviation data is first read. Then, the corresponding content continuously corresponding to the cumulative residual deviation data in the scenario-specific dynamic operational baseline is read, and a comparison is made according to the continuous correspondence between the two types of corresponding content. After the comparison is completed, the content that maintains a continuous correspondence with both the tail probability data and the cross-domain residual data is retained. The retained content is then merged according to the same operational task, the same time slice, and the same road segment location to generate residual confirmation data. Scenario-corresponding deviation confirmation processing formula: , , Operational task index Time slice index Road segment location index : Detection dimension index The set of detection dimensions in the local detection subspace data. The overall deviation in the cumulative residual deviation data. : The cumulative deviation confirmation boundary value formed by the content corresponding to the dynamic operation baseline for each scenario. Detection Dimensions The probability of the tail is below. The tail probability confirmation boundary value is formed by the content corresponding to the dynamic operation baseline of each scenario. Detection Dimensions The residual amplitude below, The boundary value is confirmed by the residual amplitude formed by the content corresponding to the dynamic operation baseline of each scenario. Detection Dimensions The residual confirmation result is set to 1 to indicate retention and 0 to indicate separation. Residual confirmation data generated under the same operational task, the same time slice, and the same road segment location.
[0052] After the residual confirmation data and local detection subspace data enter the feedback correction step, the continuously corresponding detection dimensions in the residual confirmation data are read first, and then the corresponding content in the local detection subspace data that is in the same arrangement position as the detection dimension is read. The detection dimensions in the residual confirmation data are then written back to the corresponding positions in the local detection subspace data. After the write-back is completed, the detection dimensions of subsequent time slices are arranged according to the written-back correspondence, and the arranged detection dimensions are connected to the continuously corrected positions to generate corrected local detection subspace data. Feedback correction processing formula: , ; Operational task index Time slice index Road segment location index : Detection dimension index : The set of detection dimensions in the local detection subspace data before feedback correction. Detection Dimensions The residual confirmation results are as follows. The set of detection dimensions that need to be written back in the residual confirmation data. : The set of detection dimensions in the local detection subspace data used for correction in subsequent time slices after feedback correction.
[0053] After the tail probability data, residual confirmation data, and corrected local detection subspace data enter the result merging step, the corresponding content under the same operational task, time slice, and road segment location in the tail probability data is read first. Then, the corresponding content continuously corresponding to the tail probability data in the residual confirmation data and corrected local detection subspace data is read, and unified merging is performed according to the continuous correspondence between the three types of data. After unified merging, the merged corresponding content is connected to the same cross-domain anomaly detection location, maintaining the continuous and consistent arrangement relationship between different operational tasks, different time slices, and different road segment locations, to generate cross-domain anomaly detection data. Result merging processing formula: ; Operational task index Time slice index Road segment location index The combined tail probability under the same operational task, the same time slice, and the same road segment location. Residual confirmation data generated under the same operational task, the same time slice, and the same road segment location. : Correct the set of detection dimensions in the local detection subspace data. Cross-domain anomaly detection data formed after result merging.
[0054] In this embodiment, after receiving cross-domain anomaly detection data, the anomaly source tracing module first reads the corresponding content under the same operational task in the cross-domain anomaly detection data, and then organizes the read corresponding content in sequence according to the same time slice and the same road segment location. After the sequential organization is completed, the corresponding content is assigned to the same anomaly corresponding position according to the continuous arrangement relationship in the vehicle operation process, and the arrangement relationship between different operational tasks, different time slices and different road segment locations is kept continuous and consistent, generating anomaly corresponding position data.
[0055] After the abnormal location data enters the abnormal trigger relationship sorting step, the corresponding content of consecutive time slices in the abnormal location data is first read, and then the adjacent corresponding content is compared in sequence according to the time slice sequence. During the sequential comparison, the content that forms the abnormal correspondence for the first time is written into the trigger start position, and the subsequent continuous abnormal correspondence is written into the trigger continuation position. The trigger start position and the trigger continuation position are connected according to the sequence of the vehicle operation process to generate abnormal trigger relationship data.
[0056] After the abnormal trigger relationship data enters the abnormal persistence relationship sorting step, the corresponding content within the continuous time slice in the abnormal trigger relationship data is first read, and then the corresponding content read is checked for continuity according to the same abnormal correspondence. After the continuity check is completed, the corresponding content that maintains the same abnormal correspondence is grouped into the same persistence relationship position, and the corresponding content that does not maintain the continuity relationship is separated from the same persistence relationship position. The separated corresponding content is then arranged in the original time slice order to generate abnormal persistence relationship data.
[0057] After the abnormal persistent relationship data enters the abnormal associated content review step, the corresponding relationship between the operation task, time slice and road segment location in the abnormal persistent relationship data is read first. Then, the corresponding content in the cross-domain anomaly detection data is reviewed according to the corresponding relationship. After the review is completed, the corresponding content obtained in the review is merged according to the sorting order in the abnormal persistent relationship data, and the merged corresponding content is connected to the same abnormal associated location to generate abnormal associated review data.
[0058] After the abnormal correlation review data enters the cross-domain source correspondence step, it first reads the content that is continuously related to the vehicle operation status data in the abnormal correlation review data, then reads the content that is continuously related to the network connectivity collaboration status data, and continues to read the content that is continuously related to the road operation scenario data. After reading, the three types of continuously related content are respectively assigned to the corresponding source positions, and the corresponding relationship is maintained according to the same operation task, the same time slice, and the same road segment position to generate cross-domain source correspondence data.
[0059] After cross-domain source data enters the abnormal source aggregation step, the corresponding content that continuously points to the same source relationship in the cross-domain source data is first read, and then the corresponding content under the same source relationship is merged according to the sequence of vehicle operation. After the merging is completed, the corresponding content between different source relationships is arranged according to the sequence of vehicle operation, and the correspondence between different source relationships and the original operation tasks, time slices and road segment locations is maintained to generate abnormal source aggregation data.
[0060] After the abnormal source data enters the abnormal source backtracking and collection step, the corresponding content under the same operational task, the same time slice, and the same road segment location in the abnormal source data is first read. Then, the read corresponding content is uniformly organized according to the cross-domain source correspondence. After the uniform organization is completed, the corresponding content under the same source relationship is assigned to the same abnormal source location, and the corresponding content under different source relationships is arranged continuously according to the chronological relationship in the vehicle operation process to generate abnormal source data.
[0061] In this embodiment, after receiving the abnormal source data and cross-domain abnormal detection data, the risk classification and handling module first reads the corresponding content under the same operation task, the same time slot, and the same road segment location in the abnormal source data, and then reads the content that continuously corresponds to the abnormal source data in the cross-domain abnormal detection data. The modules then arrange the abnormal source data and the cross-domain abnormal detection data according to the continuous correspondence between them. After the arrangement is completed, the two types of corresponding content are assigned to the same handling input position, and the arrangement relationship between different operation tasks, different time slots, and different road segment locations is kept continuous and consistent, thus generating corresponding handling input data.
[0062] After the corresponding data for handling input enters the abnormal impact range sorting step, firstly, the corresponding content that maintains the same abnormal source relationship within consecutive time slices in the corresponding data for handling input is read. Then, the impact content that continuously corresponds to the abnormal source relationship is read according to the location of consecutive road segments, and the read corresponding content is merged according to the chronological relationship during vehicle operation. After merging, the impact content corresponding to different abnormal source relationships is arranged into their respective consecutive positions, while maintaining the chronological relationship between each consecutive position, to generate abnormal impact range data.
[0063] After the abnormal impact range data enters the abnormal persistence state sorting step, firstly, read the abnormal impact content that appears continuously under the same operational task in the abnormal impact range data, then merge the continuous abnormal impact content according to the time slice order, and put the merged content into the same persistence state position; after the persistence relationship is merged, the abnormal impact content that appears interrupted is separated from the same persistence state position, and the separated content is arranged according to the original time slice order to generate abnormal persistence state data.
[0064] After the persistent anomaly status data and cross-domain anomaly detection data enter the risk correspondence processing step, the continuously corresponding anomaly impact content in the persistent anomaly status data is read first, and then the corresponding content in the cross-domain anomaly detection data that is in the same operational task, the same time slot, and the same road segment location as the anomaly impact content is read. The two types of corresponding content are then merged according to the item-by-item relationship. After the item-by-item merging is completed, the merged corresponding content is connected to the same risk correspondence position, and the arrangement relationship between different risk correspondence positions is kept continuous and consistent to generate risk correspondence processing data.
[0065] After the risk correspondence data enters the operational risk level classification step, the corresponding content under the same operational task in the risk correspondence data is first read. Then, the read corresponding content is leveled and merged according to the correspondence of abnormal source data, abnormal impact scope data, and abnormal persistence status data, and the corresponding content of the same level is placed in the same level position. After the level merging is completed, the corresponding content of different levels is arranged according to the chronological relationship in the vehicle operation process, and the correspondence of each level position is kept continuous and consistent with the correspondence in the risk correspondence data to generate operational risk level data.
[0066] After the operational risk level data enters the handling strategy mapping step, the corresponding content of the same level in the operational risk level data is read first. Then, the content that corresponds to the corresponding content of the same level in the anomaly source data and cross-domain anomaly detection data is read. The corresponding content read is then organized according to the arrangement relationship in the operational risk level data. After the organization is completed, the organization results corresponding to different levels are assigned to their respective mapping positions. The mapping positions are then merged according to the arrangement relationship in the operational risk level data to generate handling strategy mapping data.
[0067] After the handling strategy mapping data, operational risk level data, and anomaly source data enter the operational risk classification and handling step, the corresponding content in the handling strategy mapping data is read first, followed by the level-corresponding content in the operational risk level data and the source-corresponding content in the anomaly source data. The three types of corresponding content are then uniformly organized according to the same operational task, the same time slice, and the same road segment location. After the uniform organization is completed, the organized corresponding content is connected to the same anomaly detection result location, while maintaining the sequential relationship of vehicle operation processes between different anomaly detection result locations, to generate anomaly detection results.
[0068] In this embodiment, after receiving the anomaly detection results and anomaly source data, the operation record retention module first reads the corresponding content under the same operation task, the same time slot, and the same road segment location in the anomaly detection results, and then reads the content that continuously corresponds to the anomaly detection results in the anomaly source data. The two types of corresponding content are then arranged in a sequential order according to the continuous correspondence between the anomaly detection results and the anomaly source data. After the sequential order is completed, the two types of corresponding content are grouped into the same retention input position, and the arrangement relationship between different operation tasks, different time slots, and different road segment locations is kept continuous and consistent, thus generating the corresponding retention input data.
[0069] After the retained input data enters the source result correspondence processing step, the abnormal source data corresponding content in the retained input data is read first, and then the abnormal detection result corresponding content in the same retained input position as the abnormal source data corresponding content is read. Then, the corresponding content is matched item by item according to the same operation task, the same time slice, and the same road segment location. After the item-by-item matching is completed, the matched content is arranged continuously according to the chronological relationship in the vehicle operation process, and the arranged content is connected to the same source result corresponding position to generate source result corresponding data.
[0070] After the source result data enters the abnormal record association step, the corresponding content under the same operation task, the same time slice, and the same road segment location in the source result data is first read. Then, the read corresponding content is merged according to the time slice order and road segment location order under the same operation task. After merging, the corresponding content under different time slices and different road segment locations is organized in a continuous arrangement relationship, and the organized corresponding content is written into the continuous abnormal record location to generate abnormal record association data.
[0071] After the abnormal record associated data enters the handling process record organization step, the content that continuously corresponds to the abnormal detection result in the abnormal record associated data is first read. Then, the read content is arranged in order according to the correspondence of the abnormal source data, and the arranged content is merged according to the chronological relationship in the vehicle operation process. After merging, the content that continuously corresponds to the abnormal detection result is connected to the same handling process record position, and the chronological relationship between different handling process record positions is maintained to generate handling process record data.
[0072] After the data recorded during the handling process enters the anomaly review and marking process, the content that continuously corresponds to the anomaly source data in the data recorded during the handling process is first read. Then, the read content is merged according to the same operational task, the same time slice, and the same road segment location. The merged content is then marked and organized according to the source correspondence in the anomaly source data. After the marking and organization is completed, the marked corresponding content is connected to the same anomaly review mark position, and the arrangement relationship between different anomaly review mark positions is kept continuous and consistent to generate anomaly review mark data.
[0073] After the anomaly review marker data and anomaly record association data enter the retention order sorting step, the corresponding content in the anomaly review marker data is read first, and then the continuous record positions in the anomaly record association data that are continuously corresponding to the anomaly review marker data are read. The corresponding content in the anomaly review marker data is then backfilled into the continuous record positions in the anomaly record association data. After backfilling is completed, the backfilled corresponding content is arranged according to the chronological relationship in the vehicle operation process, and the arranged corresponding content is connected to the same retention order position to generate retention order sorting data.
[0074] After the data retention order sorting enters the abnormal operation record retention step, the corresponding content under the same operation task, the same time slice, and the same road segment location in the retention order sorting data is first read. Then, the read corresponding content is uniformly sorted according to the correspondence of abnormal detection results, the correspondence of abnormal source data, and the correspondence of handling process records. After the uniform sorting is completed, the sorted corresponding content is written to the same abnormal retention location, and the sequential relationship of vehicle operation process between different abnormal retention locations is maintained to generate abnormal retention records.
[0075] In this embodiment, after receiving the anomaly detection results and anomaly source data, the operation record retention module first reads the corresponding content under the same operation task, the same time slot, and the same road segment location in the anomaly detection results, and then reads the content that continuously corresponds to the anomaly detection results in the anomaly source data. The two types of corresponding content are then arranged in a sequential order according to the continuous correspondence between the anomaly detection results and the anomaly source data. After the sequential order is completed, the two types of corresponding content are grouped into the same retention input position, and the arrangement relationship between different operation tasks, different time slots, and different road segment locations is kept continuous and consistent, thus generating the corresponding retention input data.
[0076] After the retained input data enters the source result correspondence processing step, the abnormal source data corresponding content in the retained input data is read first, and then the abnormal detection result corresponding content in the same retained input position as the abnormal source data corresponding content is read. Then, the corresponding content is matched item by item according to the same operation task, the same time slice, and the same road segment location. After the item-by-item matching is completed, the matched content is arranged continuously according to the chronological relationship in the vehicle operation process, and the arranged content is connected to the same source result corresponding position to generate source result corresponding data.
[0077] After the source result data enters the abnormal record association step, the corresponding content under the same operation task, the same time slice, and the same road segment location in the source result data is first read. Then, the read corresponding content is merged according to the time slice order and road segment location order under the same operation task. After merging, the corresponding content under different time slices and different road segment locations is organized in a continuous arrangement relationship, and the organized corresponding content is written into the continuous abnormal record location to generate abnormal record association data.
[0078] After the abnormal record associated data enters the handling process record organization step, the content that continuously corresponds to the abnormal detection result in the abnormal record associated data is first read. Then, the read content is arranged in order according to the correspondence of the abnormal source data, and the arranged content is merged according to the chronological relationship in the vehicle operation process. After merging, the content that continuously corresponds to the abnormal detection result is connected to the same handling process record position, and the chronological relationship between different handling process record positions is maintained to generate handling process record data.
[0079] After the data recorded during the handling process enters the anomaly review and marking process, the content that continuously corresponds to the anomaly source data in the data recorded during the handling process is first read. Then, the read content is merged according to the same operational task, the same time slice, and the same road segment location. The merged content is then marked and organized according to the source correspondence in the anomaly source data. After the marking and organization is completed, the marked corresponding content is connected to the same anomaly review mark position, and the arrangement relationship between different anomaly review mark positions is kept continuous and consistent to generate anomaly review mark data.
[0080] After the anomaly review marker data and anomaly record association data enter the retention order sorting step, the corresponding content in the anomaly review marker data is read first, and then the continuous record positions in the anomaly record association data that are continuously corresponding to the anomaly review marker data are read. The corresponding content in the anomaly review marker data is then backfilled into the continuous record positions in the anomaly record association data. After backfilling is completed, the backfilled corresponding content is arranged according to the chronological relationship in the vehicle operation process, and the arranged corresponding content is connected to the same retention order position to generate retention order sorting data.
[0081] After the data retention order sorting enters the abnormal operation record retention step, the corresponding content under the same operation task, the same time slice, and the same road segment location in the retention order sorting data is first read. Then, the read corresponding content is uniformly sorted according to the correspondence of abnormal detection results, the correspondence of abnormal source data, and the correspondence of handling process records. After the uniform sorting is completed, the sorted corresponding content is written to the same abnormal retention location, and the sequential relationship of vehicle operation process between different abnormal retention locations is maintained to generate abnormal retention records.
[0082] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An intelligent connected vehicle anomaly detection system based on big data analysis, characterized in that: include: The vehicle operation data access module performs multi-source operation access and consolidation processing on vehicle operation status data, network connectivity and collaboration status data and road operation scenario data to generate multi-source operation basic data. The spatiotemporal correlation module performs unified spatiotemporal correlation processing on multi-source basic operational data to generate spatiotemporal correlated data. The scenario baseline construction module performs scenario-specific dynamic baseline construction processing on the spatiotemporal correlation data of operations and the historical operation data of the fleet, and generates scenario-specific dynamic operation baselines. The cross-domain consistency detection module performs COPOD algorithm processing on the spatiotemporal correlation data of operation and the dynamic operation baseline of each scenario based on Page-Hinkley residual confirmation to generate cross-domain anomaly detection data. The anomaly source backtracking module performs anomaly source backtracking and aggregation processing on cross-domain anomaly detection data to generate anomaly source data. The risk classification and handling module performs operational risk classification and handling on abnormal source data and cross-domain anomaly detection data, and generates anomaly detection results. The operation record retention module performs abnormal operation record retention processing on the abnormal detection results and abnormal source data, and generates abnormal retention records.
2. The intelligent connected vehicle anomaly detection system based on big data analysis according to claim 1, characterized in that: The vehicle operation data access module generates multi-source basic operation data, including: The access order of vehicle operation status data, network connectivity collaboration status data and road operation scenario data is sorted out. The three types of data are arranged according to the order of collection, receipt and recording in the same vehicle operation process to generate operation access order data. The corresponding content is collected for the operation access sequence data. The corresponding content of vehicle operation status data, network connectivity collaboration status data, and road operation scenario data are grouped into the continuous data position under the same vehicle operation process to generate operation corresponding collection data. Perform network-connected collaborative data processing on the collected operational data, continuously match the corresponding content of vehicle operation status data with the corresponding content of network-connected collaborative status data, and connect the corresponding content of road operation scenario data to the same corresponding location to generate collaborative scenario data. Time-slice processing is performed on the data corresponding to collaborative scenarios. The corresponding content of vehicle operation status data, network collaboration status data and road operation scenario data within the same time slice are merged, and the corresponding content between different time slices is arranged continuously according to the time sequence to generate time-slice processed data. The time-slice data is processed to perform road segment location mapping. The corresponding content within the same time slice is merged according to the road segment location relationship, and the corresponding content between different road segment locations is arranged continuously according to the passage sequence during vehicle operation to generate road segment location mapping data. Multi-source operation access and consolidation processing is performed on the data corresponding to road segment locations. The content corresponding to vehicle operation status data, network connectivity collaboration status data, and road operation scenario data is uniformly consolidated according to time slice relationships and road segment location relationships to generate multi-source operation basic data.
3. The intelligent connected vehicle anomaly detection system based on big data analysis according to claim 1, characterized in that: The operational spatiotemporal correlation module generates operational spatiotemporal correlation data including: Perform operation object merging processing on multi-source operation basic data, read the corresponding content under the same vehicle operation process in the multi-source operation basic data, and group the corresponding content under the same vehicle operation process into continuous associated positions to generate operation object merged data; Perform corresponding processing on the merged data of the operation objects. According to the correspondence between the vehicle operation process and the operation task, the corresponding content in the merged data of the operation objects is assigned to the continuous data position under the same operation task, and the corresponding data of the operation task is generated. Perform continuous time-slice processing on the data corresponding to the operational tasks, arrange the corresponding content of different time slices under the same operational task in a continuous manner according to the time sequence, and merge the corresponding content within the same time slice to generate continuous time-slice processing data. The continuous processing of time-slice data is performed to continuously correspond to road segment locations. The corresponding content within the same time slice is merged according to the road segment location relationship, and the corresponding content between different road segment locations is continuously arranged according to the passage sequence during vehicle operation to generate continuous road segment location correspondence data. Perform spatiotemporal cross-organization processing on the continuous corresponding data of road segment locations, cross-merge the corresponding content under the same operation task, the same time slice and the same road segment location, and maintain the continuous and consistent arrangement relationship between different operation tasks, different time slices and different road segment locations to generate spatiotemporal cross-organized data. The spatiotemporal cross-organized operational data is processed by unified spatiotemporal association, which links the corresponding content of vehicle operation status data, network connectivity collaboration status data, and road operation scenario data according to the continuous correspondence between operational tasks, time slices, and road segment locations, generating spatiotemporal associated operational data.
4. The intelligent connected vehicle anomaly detection system based on big data analysis according to claim 1, characterized in that: The scenario baseline construction module generates scenario-specific dynamic operation baselines, including: Perform scenario-based processing on the spatiotemporal correlation data of operations, read the corresponding content under the same operational task, the same time slice and the same road segment location, and classify the corresponding content of vehicle operation status data, network connectivity collaboration status data and road operation scenario data into the same scenario corresponding position to generate operation scenario corresponding data; The data corresponding to the operation scenario is continuously processed and organized during the operation phase. According to the sequence of vehicle operation, the corresponding content under the same operation scenario is arranged by continuous time slices and continuous road segment locations. The arranged corresponding content is then classified into the same operation phase to generate operation phase organized data. The historical corresponding segment extraction process is performed on the data compiled during the operation phase and the historical operation data of the fleet. According to the correspondence between operation scenarios and operation phases, the historical operation content that continuously corresponds to the data compiled during the operation phase is extracted from the historical operation data of the fleet to generate historical operation segment data. Historical state merging processing is performed on historical operation segment data. Historical operation content under the same operation scenario and the same operation stage is merged according to the correspondence between vehicle operation status, network connectivity status and road operation scenario, while maintaining the continuity and consistency of time slice order and road segment location order among historical operation content, and generating historical state merged data. The historical status merged data and the operational phase organized data are processed to perform scenario difference sorting. The corresponding content under the current operation scenario is matched with the historical operation content item by item, and the differences between vehicle operation status, network collaboration status and road operation scenario under the same operational phase are sorted to generate scenario difference sorting data. Dynamic baseline processing is performed on the scenario difference data. According to the correspondence of operational scenarios, operational phases, and historical operational content, stable corresponding content in the scenario difference data is merged, and deviating content is separated and processed to generate dynamic baseline data. The dynamic baseline data is processed by scenario-based dynamic baseline construction. The dynamic baseline data under the same operation scenario and the same operation phase are uniformly organized according to time slice relationship, road segment location relationship and historical operation content correspondence to generate scenario-based dynamic operation baselines.
5. The intelligent connected vehicle anomaly detection system based on big data analysis according to claim 1, characterized in that: The cross-domain consistency detection module generates cross-domain anomaly detection data including: The spatiotemporal correlation data and the dynamic operational baselines for different scenarios are processed by algorithm input. The spatiotemporal correlation data and the dynamic operational baselines for different scenarios are arranged according to the same operational task, the same time slice and the same road segment location to generate the processed algorithm input data. The baseline corresponding sample processing is performed on the algorithm input data. Based on the corresponding arrangement relationship in the algorithm input data, the corresponding content of the operation spatiotemporal correlation data and the corresponding content of the dynamic operation baseline in different scenarios are extracted. The extracted corresponding content is then merged in the same arrangement order to generate baseline corresponding sample data. Cross-domain residual processing is performed on the baseline corresponding sample data. The content corresponding to the operation spatiotemporal correlation data in the baseline corresponding sample data is sorted out with the content corresponding to the dynamic operation baseline in different scenarios. The results of the sorting out of differences are merged according to the same operation task, the same time slice and the same road segment location to generate cross-domain residual data. Local detection subspace construction processing is performed on cross-domain residual data. Based on the continuous difference sorting results in the cross-domain residual data, detection dimensions that maintain correspondence with the spatiotemporal correlation data of operation and the dynamic operation baseline of sub-scenario are extracted, and the detection dimensions are organized in the original order to generate local detection subspace data. Cross-domain detection sample construction processing is performed on local detection subspace data and operational spatiotemporal correlation data. According to the detection dimension in the local detection subspace data, the corresponding content is extracted from the operational spatiotemporal correlation data. The extracted corresponding content is then merged according to the same operational task, the same time slice, and the same road segment location to generate cross-domain detection sample data. Local experience Copula distribution construction processing is performed on cross-domain detection sample data and scenario-based dynamic operation baselines. According to the corresponding arrangement relationship in the scenario-based dynamic operation baselines, the cross-domain detection sample data is sorted by edge experience distribution and joint sorting to generate local experience Copula distribution data. Tail probability calculation is performed on local empirical Copula distribution data and cross-domain detection sample data. Tail probability is sorted on cross-domain detection sample data based on local empirical Copula distribution data, and the tail probability results corresponding to each detection dimension are jointly merged to generate tail probability data. Perform residual confirmation sequence generation processing on the tail probability data and cross-domain residual data, and arrange the tail probability data and cross-domain residual data continuously according to the same operational task, continuous time slice and the same road segment location to generate residual confirmation sequence data; Perform residual mean update processing on the residual confirmation sequence data. Read the corresponding content in the residual confirmation sequence data in the order of continuous time slices, and perform mean update and fallback adjustment on the corresponding content of the current time slice and the corresponding content of the previous time slice to generate residual mean update data. The cumulative residual deviation processing is performed on the residual mean update data. The corresponding content that changes in the same direction within consecutive time slices in the residual mean update data is accumulated and processed, and the corresponding content that does not maintain continuous change in the same direction is separated and processed to generate cumulative residual deviation data. Perform scenario-corresponding deviation confirmation processing on the cumulative residual deviation data and the scenario-based dynamic operation baseline. Compare the cumulative residual deviation data with the corresponding content in the scenario-based dynamic operation baseline, and retain the content that maintains a continuous correspondence with both the tail probability data and the cross-domain residual data to generate residual confirmation data. Feedback correction processing is performed on the residual confirmation data and the local detection subspace data. The detection dimensions that are continuously corresponding in the residual confirmation data are written back to the local detection subspace data. The detection dimensions of subsequent time slices are arranged according to the correspondence after writing back, and the corrected local detection subspace data is generated. The tail probability data, residual confirmation data, and corrected local detection subspace data are merged. The tail probability data, residual confirmation data, and corrected local detection subspace data are merged in a unified manner according to the same operation task, the same time slice, and the same road segment location to generate cross-domain anomaly detection data.
6. The intelligent connected vehicle anomaly detection system based on big data analysis according to claim 1, characterized in that: The anomaly source backtracking module generates anomaly source data including: Perform anomaly location sorting processing on cross-domain anomaly detection data, read the corresponding content under the same operation task, the same time slice and the same road segment in the cross-domain anomaly detection data, and merge the corresponding content according to the continuous arrangement relationship in the vehicle operation process to generate anomaly location data; Anomaly trigger relationship processing is performed on the data corresponding to the anomaly location. The corresponding content of consecutive time slices before and after the anomaly location data is compared sequentially, and the content that forms the anomaly correspondence for the first time is separated and processed with the subsequent anomaly correspondence to generate anomaly trigger relationship data. Perform anomaly persistence relationship processing on the anomaly trigger relationship data. Merge the contents that maintain the same anomaly correspondence within consecutive time slices in the anomaly trigger relationship data, and separate and organize the contents that do not maintain a continuous relationship to generate anomaly persistence relationship data. Perform anomaly association content back-checking on the abnormal persistent relationship data. Based on the correspondence between operational tasks, time slices and road segment locations in the abnormal persistent relationship data, back-check the content in the cross-domain anomaly detection data that continuously corresponds to the abnormal persistent relationship data, and generate anomaly association back-checking data. Cross-domain source correspondence processing is performed on the abnormal correlation back lookup data. The content that is continuously related to the vehicle operation status data, the network collaboration status data, and the road operation scenario data in the abnormal correlation back lookup data is merged separately, while maintaining the correspondence under the same operation task, the same time slice, and the same road segment location, to generate cross-domain source correspondence data. Anomaly source aggregation processing is performed on cross-domain source corresponding data. Contents that continuously point to the same source relationship in cross-domain source corresponding data are merged, and the corresponding content between different source relationships are arranged according to the chronological relationship in the vehicle operation process to generate anomaly source aggregation data. Anomaly source data is processed by backtracking and aggregating the anomaly source data. The anomaly source data is then uniformly organized according to the operational tasks, time slices, road segment locations, and cross-domain source correspondence to generate anomaly source data.
7. The intelligent connected vehicle anomaly detection system based on big data analysis according to claim 1, characterized in that: The risk classification and handling module generates anomaly detection results including: Perform corresponding processing on abnormal source data and cross-domain abnormal detection data. Read the corresponding content of the same operation task, the same time slice and the same road segment in the abnormal source data, and classify the content that corresponds to the abnormal source data in the cross-domain abnormal detection data into the same processing input position to generate corresponding processing input data. The abnormal impact range data is sorted and processed by performing anomaly impact range sorting on the corresponding data of the disposal input. The corresponding contents of the corresponding data of the disposal input that maintain the same abnormal source relationship within consecutive time slices and consecutive road segments are merged, and the impact contents corresponding to different abnormal source relationships are arranged according to the chronological relationship of the vehicle operation process to generate abnormal impact range data. Perform anomaly persistence status processing on the anomaly impact range data, merge the continuous anomaly impact content that occurs continuously under the same operational task in the anomaly impact range data, and separate and process the anomaly impact content that occurs interrupted, to generate anomaly persistence status data. Risk correspondence processing is performed on the continuous abnormal status data and cross-domain anomaly detection data. The continuous abnormal impact content in the continuous abnormal status data is merged with the corresponding content in the cross-domain anomaly detection data item by item, while maintaining the correspondence under the same operational task, the same time slice and the same road segment location, to generate risk correspondence processing data. The risk correspondence data is processed by classifying operational risk levels. According to the correspondence of abnormal source data, the correspondence of abnormal impact scope data, and the correspondence of abnormal duration data, the corresponding content in the risk correspondence data is merged into levels, and the corresponding content of different levels is arranged according to the chronological relationship in the vehicle operation process to generate operational risk level data. The operational risk level data is mapped to the corresponding content of the same level in the operational risk level data and the corresponding content of the anomaly source data and cross-domain anomaly detection data. The mapping results of different levels are merged according to the arrangement relationship in the operational risk level data to generate the handling strategy mapping data. Operational risk classification and handling are performed on the handling strategy mapping data, operational risk level data and anomaly source data. The corresponding content in the handling strategy mapping data, the level corresponding content in the operational risk level data and the source corresponding content in the anomaly source data are uniformly organized according to the same operational task, the same time slice and the same road segment location to generate anomaly detection results.
8. The intelligent connected vehicle anomaly detection system based on big data analysis according to claim 1, characterized in that: The operations record retention module generates abnormal retention records including: Perform retention input correspondence processing on anomaly detection results and anomaly source data, read the corresponding content under the same operation task, the same time slice and the same road segment location in the anomaly detection results, and classify the content that continuously corresponds to the anomaly detection results in the anomaly source data into the same retention input location to generate retention input correspondence data; The source result correspondence processing is performed on the retained input data. The abnormal source data in the retained input data is matched with the abnormal detection result, and the matched content is arranged according to the chronological relationship in the vehicle operation process to generate source result correspondence data. Perform anomaly record association processing on the source result corresponding data, merge the corresponding content under the same operation task, the same time slice and the same road segment location in the source result corresponding data, and organize the corresponding content under different time slices and different road segment locations according to the continuous arrangement relationship to generate anomaly record association data; The process of handling the associated data of abnormal records is processed and organized. The content that corresponds continuously to the abnormal detection results in the associated data of abnormal records is read and arranged according to the correspondence of abnormal source data and the chronological relationship in the vehicle operation process to generate the handling process record data. Anomaly review and marking processing is performed on the data recorded during the handling process. Contents in the data recorded during the handling process that are continuously corresponding to the source data of the anomaly are merged according to the same operational task, the same time slice, and the same road segment location. The merged content is then marked and organized according to the source correspondence in the source data of the anomaly, generating anomaly review and marking data. Perform retention order sorting on the abnormal review mark data and abnormal record associated data, fill the corresponding content in the abnormal review mark data back into the consecutive record positions in the abnormal record associated data, and form a retention arrangement relationship according to the chronological relationship in the vehicle operation process to generate retention order sorting data; The data for the retention order is processed to retain abnormal operation records. The data for the retention order is uniformly organized according to the correspondence between abnormal detection results, abnormal source data, and handling process records, and abnormal retention records are generated.
9. An anomaly detection method for intelligent connected vehicles based on big data analysis, characterized in that, include: Acquire vehicle operation status data, network connectivity collaboration status data, and road operation scenario data; perform multi-source operation access and consolidation processing on the vehicle operation status data, network connectivity collaboration status data, and road operation scenario data to generate multi-source operation basic data. Perform unified spatiotemporal correlation processing on multi-source operational basic data to generate spatiotemporal correlated operational data; Acquire historical operational data of the fleet, perform scenario-based dynamic baseline construction processing on the spatiotemporal correlation data of operations and historical operational data of the fleet, and generate scenario-based dynamic operational baselines; The operation spatiotemporal correlation data and scenario-based dynamic operation baselines are processed using the scenario-based dynamic baseline feedback COPOD algorithm based on Page-Hinkley residual confirmation to generate cross-domain anomaly detection data. Perform anomaly source tracing and aggregation processing on cross-domain anomaly detection data to generate anomaly source data; Perform operational risk-based classification and handling of abnormal source data and cross-domain anomaly detection data, and generate anomaly detection results; Perform abnormal operation record retention processing on abnormal detection results and abnormal source data to generate abnormal retention records.