An intelligent system for detecting anomalies in IOT networks using edge computing and deep learning

DE202025102503U1Active Publication Date: 2025-07-17BHARGAVI MOKASHI DR BENGALURU +7
View PDF 0 Cites 9 Cited by

Patent Information

Application Number
DE202025102503
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-17
Estimated Expiration
2035-05-31

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An intelligent anomaly detection system (100) for IoT networks using edge computing and deep learning, comprising: (a) a data collection and pre-processing module configured to collect data from a variety of heterogeneous IoT devices and perform pre-processing operations, including normalization, denoising, and feature extraction; b) an edge intelligence and model deployment module configured to deploy deep learning models optimized for edge devices to perform local data analysis; (c) an anomaly detection and classification module configured to identify abnormal behavior in the processed data using deep neural networks and to classify the anomalies into predefined threat categories; (d) an adaptive learning and model update module configured to update the deployed models through incremental or federated learning mechanisms without transmitting raw data to a centralised server; (e) an alert and response management module configured to generate alerts and execute predefined mitigation actions based on the type and severity of the detected anomalies; f) and a system monitoring and visualization module configured to display real-time insights, alerts and system analysis through a user interface, g) the system operates in a decentralised manner using edge computing to achieve scalable and privacy-preserving anomaly detection in IoT environments in real time.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to the field of network security and anomaly detection in Internet of Things (IoT) environments. More specifically, the invention relates to an intelligent system and method for anomaly detection in IoT networks using edge computing and deep learning techniques.

[0002] The exponential growth of the Internet of Things (IoT) has led to the deployment of billions of connected devices in diverse areas such as smart homes, healthcare, manufacturing, and critical infrastructure. While these systems enhance automation and real-time monitoring, they also create a vast and complex attack surface for cyber threats. Traditional centralized security solutions often struggle to handle the massive, heterogeneous, and latency-sensitive data generated by IoT devices, resulting in delayed detection and response to security breaches. This creates an urgent need for intelligent and scalable security mechanisms tailored to the unique characteristics of IoT networks.

[0003] Existing anomaly detection methods largely rely on cloud-based processing, which introduces significant latency, bandwidth consumption, and data privacy concerns. Furthermore, many traditional methods rely on signature-based detection models that are ineffective against zero-day attacks and novel intrusions. These limitations make timely and accurate real-time anomaly detection difficult, especially in resource-constrained environments where constant cloud connectivity cannot be guaranteed. Therefore, there is a critical need for localized, adaptive, and intelligent systems that can monitor and analyze data at the edge, close to the source of generation.

[0004] To address these challenges, the present invention proposes an intelligent anomaly detection system that integrates edge computing with deep learning models specifically optimized for IoT networks. By deploying lightweight yet powerful neural network architectures on edge devices, the system enables real-time detection of anomalous behavior with minimal latency and without compromising data privacy. This approach not only reduces dependence on cloud infrastructure but also improves scalability and responsiveness, making it ideal for decentralized and dynamic IoT ecosystems. The invention thus provides a novel and efficient solution to the shortcomings of existing security systems in protecting IoT networks from evolving cyber threats.

[0005] One goal of this disclosure is to enable real-time anomaly detection with minimal latency through edge computing.

[0006] Another objective of the present disclosure is to reduce network bandwidth consumption by local data processing.

[0007] Another objective of this disclosure is to protect data privacy by avoiding the transfer of sensitive information to the cloud.

[0008] Another goal of this disclosure is to adapt to new threats through continuous learning and model updates.

[0009] Another subject of this disclosure is the detection of known and unknown attacks using deep learning techniques.

[0010] Another goal of this disclosure is easy scaling across different IoT applications and infrastructures.

[0011] Another objective of this disclosure is to minimize false alarms through intelligent classification of anomalies.

[0012] Another objective of this disclosure is to provide actionable insights through a user-friendly monitoring dashboard.

[0013] Further objects and advantages of the present disclosure will become apparent from the following description, which is not intended to limit the scope of the present disclosure.

[0014] The present invention generally relates to a decentralized approach that performs anomaly detection directly at the edge of the IoT network. This reduces latency, saves bandwidth, and preserves data privacy by minimizing dependence on the cloud.

[0015] One embodiment of the present invention is that the system consists of several specialized modules ranging from data acquisition to alarm management, ensuring scalability, maintainability, and adaptability in various IoT applications and environments.

[0016] Another embodiment of the invention involves using advanced deep learning models, such as LSTM and CNN, for real-time anomaly detection and classification. These models are optimized for edge execution through compression and quantization.

[0017] Another embodiment of the invention is that the system processes various data types from different IoT devices, including time series, numeric, and categorical data. This flexibility makes it suitable for use in smart homes, healthcare, and industrial IoT networks.

[0018] Another embodiment of the invention is that the system continuously evolves to address new threats through adaptive learning mechanisms, including federated updates. This enables collaborative intelligence across distributed edge nodes without the need to exchange raw data.

[0019] Another embodiment of the invention is that the system triggers automatic responses such as alerts, node isolation, or logging upon detection of anomalies. This proactive defense mechanism increases the resilience and security of the network.

[0020] Another embodiment of the invention is a dedicated dashboard module that provides real-time insights into anomaly trends, network status, and device behavior. This visual layer enables administrators to monitor and respond effectively to threats.

[0021] Another embodiment of the invention is that the system is designed to be application-independent and thus adaptable to various areas such as smart cities, logistics, agriculture, and critical infrastructure. Its modular and intelligent architecture ensures broad utility.

[0022] The present invention relates to an intelligent anomaly detection system (100) for IoT networks that uses edge computing and deep learning. The present invention relates to an intelligent anomaly detection system specifically designed for IoT networks that integrates edge computing and deep learning for real-time threat detection. The system consists of several key modules, including a data acquisition and preprocessing module for collecting and preparing IoT data and an edge intelligence and model deployment module that locally executes optimized deep learning models. An anomaly detection and classification module identifies abnormal behavior, while the adaptive learning module ensures continuous model improvement without compromising data privacy.The alert and response module provides immediate notification and damage control, and a visualization module provides real-time insights via a graphical dashboard. Together, these modules form a decentralized, adaptive, and responsive security solution for modern IoT environments. Module for data acquisition and preprocessing

[0023] This module is responsible for collecting raw data generated by various IoT devices, such as sensors, actuators, and smart devices. The data is acquired via secure communication channels and preprocessed at the edge nodes. Preprocessing includes noise reduction, normalization, data transformation, and feature extraction to ensure compatibility with deep learning models. The module is designed to handle heterogeneous data types, including time series, categorical, and numeric inputs, which are common in IoT networks. Lightweight preprocessing ensures minimal resource consumption on constrained edge devices. Edge Intelligence and Model Deployment Module

[0024] This module facilitates the deployment of deep learning models directly on edge nodes such as gateways or embedded computing platforms (e.g., Raspberry Pi, NVIDIA Jetson). Models trained offline with labeled datasets are optimized for edge execution using model compression, quantization, or pruning techniques. These models are capable of detecting temporal and spatial anomalies in incoming IoT data streams. Edge-based inference enables low-latency detection and reduced dependence on cloud infrastructure, preserving data privacy and network bandwidth. Anomaly detection and classification module

[0025] At the heart of the invention, this module performs real-time analysis of the processed data using deep learning algorithms such as LSTM (Long Short-Term Memory), CNN (Convolutional Neural Networks), or hybrid architectures. The system identifies deviations from normal behavior patterns and classifies anomalies into categories such as DoS attacks, data spoofing, malfunctioning sensors, or unknown intruders. Thanks to the classification function, the system can react context-dependently, thus improving the relevance and timeliness of alerts and decisions. Adaptive learning and model update module

[0026] This module ensures the system adapts to evolving data patterns and emerging threats. It supports incremental or federated learning, where edge devices update their models using local data and periodically synchronize with a central server (or among peers) without sharing raw data. This approach enables collaborative learning across distributed nodes while preserving privacy. The module can also include feedback mechanisms where user-labeled results or expert comments improve model accuracy over time. Warning and response management module

[0027] Once an anomaly is detected, this module generates alerts and initiates predefined response protocols depending on the type and severity of the threat. Responses include logging the event, notifying administrators, isolating affected nodes, or triggering automatic remediation actions. The module supports customizable policies to tailor responses for different use cases, such as smart cities, healthcare, or industrial IoT. Integration with existing SIEM (Security Information and Event Management) tools is also supported for centralized monitoring. System monitoring and visualization module

[0028] This module provides a user-friendly dashboard for real-time monitoring of network health, detected anomalies, and system performance. It offers visual analytics such as anomaly trends, device activity maps, and threat classification statistics. The interface can be accessed locally or remotely, depending on user preferences and security settings. This module provides administrators with actionable insights for proactively managing their IoT infrastructure.

[0029] The invention is explained again below with reference to the figure. It shows: Fig. : an illustration of an intelligent anomaly detection system(100) for IOT networks using edge computing and deep learning

[0030] The operation of the intelligent anomaly detection system begins with the data collection and preprocessing module, which collects heterogeneous data from various IoT devices distributed across the network, including sensors, actuators, and embedded systems. This module filters and processes the data at the edge by performing normalization, denoising, and extracting relevant features to prepare it for real-time analysis. The preprocessed data is then forwarded to the edge intelligence and model deployment module, where lightweight, pre-trained deep learning models—optimized by compression and pruning—are deployed directly to edge computing devices. These models enable localized, low-latency processing without the need to transfer sensitive data to the cloud.The anomaly detection and classification module actively monitors incoming data streams using deep neural network architectures such as LSTM or CNN to detect unusual patterns or deviations from normal behavior.

[0031] When anomalies are detected, they are automatically classified into known categories, such as denial-of-service (DoS) attacks, device tampering, or emerging threats. The system's adaptability is enhanced by the adaptive learning and model update module, which uses techniques such as federated learning or incremental updates, allowing the system to learn from new data in real time without compromising data privacy. When an anomaly is confirmed, the alert and response management module is triggered to generate intelligent alerts and perform context-dependent response actions, such as notifying system administrators, isolating suspicious nodes, or logging the event for forensic analysis.At the same time, the system monitoring and visualization module provides an intuitive user interface that displays real-time network activity, detected anomalies, system diagnostics, and threat patterns through dashboards and graphical reports, allowing users to keep an eye on the situation and respond proactively.

Claims

[1] An intelligent anomaly detection system (100) for IoT networks using edge computing and deep learning, comprising: (a) a data collection and pre-processing module configured to collect data from a variety of heterogeneous IoT devices and perform pre-processing operations, including normalization, denoising, and feature extraction; b) an edge intelligence and model deployment module configured to deploy deep learning models optimized for edge devices to perform local data analysis; (c) an anomaly detection and classification module configured to identify abnormal behavior in the processed data using deep neural networks and to classify the anomalies into predefined threat categories; (d) an adaptive learning and model update module configured to update the deployed models through incremental or federated learning mechanisms without transmitting raw data to a centralised server; (e) an alert and response management module configured to generate alerts and execute predefined mitigation actions based on the type and severity of the detected anomalies; f) and a system monitoring and visualization module configured to display real-time insights, alerts and system analysis through a user interface, g) the system operates in a decentralised manner using edge computing to achieve scalable and privacy-preserving anomaly detection in IoT environments in real time. [2] The system (100) of claim 1, wherein the deep learning models employed comprise Long Short-Term Memory (LSTM), Convolutional Neural Networks (CNN), or a mixture of both for accurate temporal and spatial anomaly detection. [3] The system (100) of claim 1, wherein the edge computing devices comprise low-power embedded systems such as Raspberry Pi, NVIDIA Jetson, or similar processors with local inference capabilities. [4] The system (100) of claim 1, wherein the adaptive learning and model update module uses federated learning to enable distributed model updates without central data aggregation. [5] The system (100) of claim 1, wherein the alert and response management module supports customizable rule-based and intelligent AI-driven policies for automatic threat mitigation. [6] The system (100) of claim 1, wherein the data acquisition and preprocessing module supports integration with multiple communication protocols and formats, including MQTT, CoAP, and HTTP. [7] The system (100) of claim 1, wherein the system monitoring and visualization module provides an interactive dashboard accessible via web and mobile interfaces for remote anomaly tracking and analysis. [8] The system (100) of claim 1, wherein the anomaly detection and classification module further incorporates user feedback and expert input for continuous performance improvement and accuracy refinement.

Citation Information

Cited By

  • Edge heterogeneous Internet of Things operation and maintenance chassis data processing method and system

    CN120602309A

  • Portable WiFi multi-band adjusting system based on deep learning and edge computing

    CN120897268A

  • Marine monitoring data real-time processing method and system based on edge calculation

    CN121078090A

  • Terminal data security processing method and system

    CN121126325A

  • Multi-access-control lightweight anomaly detection method, system and device based on edge calculation

    CN121170933A