DETECTION OF ANOMALIES IN AN ENVIRONMENT OR SYSTEM
The method simplifies anomaly detection by using an information filter that converges to a limit value, enabling intuitive threshold setting for reliable and efficient magnetic anomaly detection.
Patent Information
- Application Number
- FR2024006090
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-10
- Publication Date
- 2025-12-12
AI Technical Summary
Existing anomaly detection methods face challenges in determining an adequate threshold for magnetic anomaly detection due to the unknown optimal value of the threshold being influenced by the sliding window and discretization step, requiring a tedious trial-and-error process.
A method and device for anomaly detection that establishes an information filter based on probability density, which converges to a limit value for normal signals and increases with anomalies, allowing for a threshold determination based on this convergence limit value, simplifying the selection of the detection threshold.
Ensures high reliability and ease of implementation by intuitively defining the threshold, balancing accurate anomaly detection with minimized false alarms.
Smart Images

Figure 00000018_0000 
Figure 00000019_0000 
Figure 00000020_0000
Abstract
Description
Title of the invention: DETECTION OF ANOMALIES IN AN ENVIRONMENT OR SYSTEM technical field
[0001] The present invention relates to the field of anomaly detection and, more particularly, it aims to identify behaviors that deviate from standard or ambient behavior. PREVIOUS STATE OF THE ART
[0002] Anomaly detection encompasses a variety of techniques and finds applications in many industrial sectors.
[0003] For example, the detection of a ferromagnetic target, which induces a magnetic anomaly in the environment, illustrates one of the many possible applications of these techniques. Numerous applications take advantage of the magnetic field for the detection, localization, and tracking of objects, offering precise solutions in visually demanding contexts.
[0004] Such a method is described by Sheinker et al. in the article “Magnetic Anomaly Detection Using an Entropy Filter”, published in Measurement Science and Technology, vol. 19, no. 045205. Available online: https: / / doi.org / 10.1088 / 0957-0233 / 19 / 4 / 045205.
[0005] This method suggests modeling the normal behavior of the environment using a continuous probability density function, denoted f. A sliding window, Wj, which contains N samples (where N is generally equal to 30), is defined as follows:
[0006] [Math.l] Wj-— | •••' -*7-}. A}
[0007] A discretization step, denoted A, is also established. Subsequently, a filter is applied to the window W) and it is calculated as follows:
[0008] [Math.2] Ml (Xi) =- 7LXk£Wi A / (¾¼ ( A )
[0009] The presence of a magnetic anomaly is detected when the filter value falls below a certain threshold -S;
[0010] [Math.3]
[0011] The main challenge of this method lies in the difficulty of establishing an adequate threshold for two main reasons. First, the optimal value of the threshold is not known a priori. Secondly, the threshold is influenced both by the length of the sliding window, N, and the degree of discretization, A.
[0012] In particular, it is crucial to emphasize that the appropriate choice of A is critical to the detector's effectiveness. For example, an oversized value of A could lead the filter to react counterintuitively, increasing instead of decreasing in the presence of an anomaly, and in this case, the anomaly would never be detected.
[0013] Another method was described by Zhou et al. in the article entitled “Magnetic anomaly detection via a combination approach of minimum entropy and gradient orthogonal functions”, published in ISA Transactions, volume 134, pages 548-560. Available online: https: / / doi.org / 10.1016 / jjsatra.2022.08.026.
[0014] Zhou's method uses the same approach as Sheinker, and defines a filter as follows:
[0015] [Math.4]
[0016] The presence of a magnetic anomaly is detected when the filter value falls below a certain threshold S;
[0017] [Math.5] M2(Xi)
[0018] The method proposed by Zhou offers the advantage of eliminating the need for a discretization step A for signal processing. However, as with the previous approach, determining a suitable threshold proves complex, since its optimal value is not known a priori and is also affected by the size of the sliding window N. Adjusting the threshold based on the length of the sliding window proves particularly tedious, given that the window size can vary. Consequently, traditional methods often require a tedious trial-and-error process to determine the appropriate threshold.
[0019] The object of the present invention is to propose a device and a method for detecting anomalies which remedy the aforementioned drawbacks, by significantly simplifying the definition of the detection threshold. Description of the invention
[0020] This objective is achieved with a method for detecting anomalies within an environment or system, comprising the following steps:
[0021] - acquire a normal signal reflecting the normal state of the environment or system,
[0022] - determine from said normal signal, a probability density, denoted f, which models a state of normal behavior of the environment or system,
[0023] - establish an information filter based on said probability density, said an information filter configured to converge to a limit value when applied to samples of a normal signal, while increasing its value in response to the detection of an anomaly,
[0024] - establish a threshold value based on said convergence limit value,
[0025] - acquire a current signal reflecting the current behavioral state of the environment or system,
[0026] - to sample said current signal into a current series of N samples in using a determined Wi sliding window,
[0027] - calculate a result of applying the information filter to said current series of N samples,
[0028] - compare said result with said threshold value, an anomaly being detected if said The result exceeds the said threshold value.
[0029] This method significantly improves anomaly detection, ensuring high reliability, while being extremely simple to implement. Indeed, determining the threshold is intuitive and easy, as it is based on the limit value, which is intrinsically defined.
[0030] Advantageously, said threshold value is equal to said convergence limit value, plus an increase value chosen according to a compromise sought between reliable detection and minimization of the number of false alarms.
[0031] This facilitates the simplified selection of the detection threshold according to the degree of accuracy and reliability desired for the identification of anomalies.
[0032] According to a first embodiment, the information filter corresponds to a first filter li designed such that, when applied to samples of a normal signal, it converges to a limiting value which corresponds to the entropy of the probability density associated with this normal signal.
[0033] This first filter ensures the automatic establishment of the entropy of the probability density associated with the normal signal as a lower bound for the threshold.
[0034] Advantageously, the application of said first filter on said current series of a determined number N of samples consists of calculating the natural logarithm of the value of the probability density f for each of the samples XK, then summing these logarithms, and multiplying the result of this summation by the negative factor corresponding to the inverse of said determined number N of samples, according to the following formula:
[0035] [Math.6]
[0036] Advantageously, said threshold value S is equal to the value of the entropy H(f) of the probability density f, plus a value s within an interval from 1% to 20% of the absolute value of said entropy, according to the following formula:
[0037] [Math.7] S = H(f)+e
[0038] The added value chosen for the markup is carefully determined in order to achieve an optimal balance between the ability to reliably detect real anomalies and minimizing the risk of generating incorrect alerts, i.e. false alarms.
[0039] According to a first example, said increase value is defined in a range between 10% and 20% of the absolute value of the entropy, with the aim of achieving a very low probability of false alarms, between 10⁴ and 10³.
[0040] According to a second example, said markup value is defined in a range between 1% and 10% of the absolute value of the entropy, to promote the probability of correct detection.
[0041] According to a second embodiment, the information filter corresponds to a second filter which is based on said first filter described above, and uses a continuous function, denoted g, which represents an approximation of the data probability density of the current signal Sc over a predetermined sliding window Wi.
[0042] Applying said second filter to said current series of a determined number N of samples consists of calculating the natural logarithm of the value of the continuous function for each of the samples, calculating the average of the results obtained for these natural logarithms, and adding the result of said average to the result of applying the first filter to the same current series of samples, according to the following formula:
[0043] [Math. 8] Ki = + li
[0044] The invention also relates to a device for detecting anomalies within an environment or system, comprising:
[0045] - an acquisition module configured to acquire a current signal reflecting the state of current behavior of the environment or system,
[0046] - a processor configured for:
[0047] - to sample said current signal into a current series of N samples in using a determined Wi sliding window,
[0048] - to calculate a result of applying an information filter to said current series of N samples, said information filter being based on a probability density modeling a normal behavioral state of the environment or system, said an information filter configured to converge to a limit value when applied to samples of a normal signal, while increasing its value in response to the detection of an anomaly,
[0049] - compare said result with a threshold value based on said convergence limit value, an anomaly being detected if said result exceeds said threshold value, and
[0050] - an output interface configured to indicate the detection of an anomaly.
[0051] According to a first application, the device includes a magnetometer configured to generate said current signal by capturing an ambient magnetic field, including the Earth's field as well as various magnetic disturbances.
[0052] According to a second application, the device includes an accelerometer (or a vibration sensor) configured to generate the current signal by capturing vibrations emanating from a machine to be monitored.
[0053] According to a third application, the device includes a counter configured to generate the current signal by measuring the volume of data exchanged at a specific node of a computer network to be monitored.
[0054] According to a fourth application, the device includes an eddy current probe configured to produce the current signal by measuring the thickness of a pipeline under surveillance. Brief description of the drawings
[0055] The present invention will be better understood upon reading the description of exemplary embodiments given by way of illustration only and in no way limiting, with reference to the accompanying drawings in which:
[0056] Fig. 1 schematically illustrates a device for detecting anomalies within an environment or technical system, according to one embodiment of the invention;
[0057] Figure 2 schematically illustrates a method for detecting anomalies within an environment or technical system, according to one embodiment of the invention;
[0058] Fig. 3 schematically illustrates a method for detecting anomalies within an environment or technical system, according to a first preferred embodiment of the invention;
[0059] Figures [Fig. 4A], [Fig. 4B] and [Fig. 5A], [Fig. 5B], [Fig. 5C], [Fig. 5D], [Fig. 5E], [Fig. 5F] show the application of the present invention in the detection of anomalies by exploiting the data collected by a sensor, according to a specific implementation of the invention; and
[0060] Figure 6 schematically illustrates a method for detecting anomalies within an environment or technical system, according to a first preferred embodiment of the invention.
[0061] DETAILED DESCRIPTION OF SPECIFIC EMBODIMENTS
[0062] The concept behind the invention is to propose a detection technique where the threshold is determined intuitively from a predefined value known in advance.
[0063] Fig. 1 schematically illustrates a device for detecting anomalies within an environment or technical system, according to one embodiment of the invention.
[0064] The anomaly detection device 1 includes an acquisition module 3, a processor 5 which can be a microcontroller, a central processor or a microprocessor, a dedicated memory 7, as well as input / output interfaces 9.
[0065] The detection device 1 is adapted to acquire signals that can be of different types depending on the problem under consideration. For example, it can capture magnetic signals via a magnetometer to identify ferromagnetic targets, vibration signals from a vibration sensor to monitor the condition of a machine, or acoustic signals to check the integrity of a pipeline, among other applications. Consequently, the device 1 is designed to be equipped with or combined with a suitable sensor 11, according to the specific requirements of the intended application.
[0066] The detection device 1 is specifically designed to implement a detection method detailed in the diagram of [Fig.2].
[0067] Indeed, [Fig.2] schematically illustrates a method for detecting anomalies within an environment or technical system, according to an embodiment of the invention.
[0068] The process is structured around two phases: an initial calibration phase, described by steps E1 to E4, and an operational phase, devoted to the active detection of anomalies, detailed in steps E5 to E8.
[0069] In step El, the acquisition module 3 is configured to acquire a normal signal SN reflecting the normal state of the environment or system. An example is represented by the time signal in the graph of [Fig. 4A].
[0070] In step E2, the processor 5 is configured to determine a probability density, denoted f, which models a normal behavioral state of the environment or the system under study. An example of a probability density is given in the graph in [Fig. 4B].
[0071] In step E3, the processor 5 is configured to establish an information filter F based on the probability density function f. The information filter F is established in taking into account the probability density function f and the window size N. It can also integrate a continuous function constructed from a current signal. (For the inventor: here, the information filter 'F' is a filter that generalizes the two filters 'li' and 'Ki'. Moreover, without this generalization, we would face an objection related to the lack of unity of invention).
[0072] The information filter F(xk) converges to a predefined limit value L when applied to samples of a normal signal SN. Thus, it suffices to use samples of a normal signal SN to determine this limit value L. According to the example of a first embodiment, explained in relation to Fig. 3, the limit value L corresponds to the entropy of the probability density characterizing the normal state of the system or environment. According to the example of a second embodiment described in relation to Fig. 6, the limit value L corresponds to zero. Furthermore, the information filter F(xk) is characterized by an increase in its value in response to the detection of an anomaly 'A'.
[0073] In step E4, the processor 5 is configured to establish a threshold value S based on the convergence limit value L. Since the information filter F(xk) naturally tends towards a well-defined limit value L when analyzing a normal signal SN, and conversely, it exhibits an increase in the case of an anomaly, the definition of the threshold value S becomes intuitive: it is set slightly above L so that, during operation, any filter value exceeding L signals an anomaly. For illustrative purposes, the threshold S can be modeled as an affine function of L, according to the equation S - aL + e, where a is a positive or zero adjustment factor and e is a small, constant, positive upper bound, ensuring a margin above the limit value L for reliable anomaly detection.
[0074] Advantageously, the threshold value S can simply be equal to the limit value L, plus a constant upper bound value £. This upper bound value £ is chosen based on a desired compromise between reliable detection and minimizing the number of false alarms.
[0075] Within the detection device 1, the memory 7 stores the probability density function f, the information filter F, the convergence limit value L, and the threshold value $ for effective recall during detection operations.
[0076] Steps E1 to E4 define the initial calibration phase which, once completed, does not require to be repeated at each new anomaly detection sequence.
[0077] Active anomaly detection begins at step E5, during which the processor 5 is configured to acquire a current signal Sc reflecting the current behavioral state of the environment or system to be monitored.
[0078] At step E6, the processor 5 is configured to sample the current signal Sc into an initial series of N samples using a determined sliding window Wi.
[0079] It should be emphasized that the size of the selected window is adjustable. This ability to adjust the window size is explained by the fact that, according to the present invention, the threshold value S is not related to the size of the window adopted. The same threshold value $ is applied, which guarantees the uniformity of the detection criterion.
[0080] At step E7, the processor 5 is configured to calculate a result F( Wj) of the application of the information filter on the current series Sc of N samples.
[0081] At step E8, the processor 5 is configured to compare this result F^W^ with the threshold value S. An anomaly is detected if the result F exceeds the threshold value 5. The detection of an anomaly can be signaled by the output interface 9 of the detection device 1.
[0082] Figure 3 schematically illustrates a method for detecting anomalies within an environment or technical system, according to a first preferred embodiment of the invention.
[0083] In order to clarify the presentation of this process, it is explained by referring to the examples illustrated by figures 4A to 5F.
[0084] Figs. 4A to 5F demonstrate the application of the present invention in the detection of anomalies by exploiting the data collected by a sensor, according to a specific implementation.
[0085] According to this example, the detection device 1 is associated with a magnetometer 11 configured to generate the current signal by detecting an ambient magnetic field, including the Earth's magnetic field as well as various magnetic disturbances. The magnetometer 11 is, for example, positioned on the Earth's surface to detect variations in the local magnetic field. The recorded signal reflects the natural Earth's magnetic field, while also including various interferences and background noise, such as the noise inherent in the magnetometer 11 and external geomagnetic disturbances.
[0086] Figure 4A illustrates the standard magnetic field profile as measured in the absence of interference. By introducing a ferromagnetic object, such as a vehicle, into this environment, the magnetometer 11 will detect variations superimposed on the basic signal. These variations or disturbances are referred to as anomalies. The main objective of the detection device 1 is to accurately identify such anomalies.
[0087] In accordance with what has been previously established, the calibration phase, which extends from steps E1 to E14, is dedicated to defining the probability density function, the information filter, the convergence limit value as well as the threshold value.
[0088] In step El 1, the acquisition module 3 is configured to acquire a normal signal SN reflecting the normal state of the environment or system.
[0089] Such an SN signal is illustrated in [Fig.4A]. This figure more precisely shows a graph of the magnetic signal recorded over a period of 1000 minutes which serves as the basis for establishing the standard model of the behavior of the local magnetic field.
[0090] At step E12, the processor 5 is configured to determine the probability density / which models the normal behavioral state of the environment or system under study.
[0091] By way of example, Fig. 4B shows a diagram representing a Gaussian probability density function f. The function f is constructed by calculating the mean and variance from the normal signal shown in [Fig. 4A]. These calculations are based on the following formulas:
[0092] [Math.9] P = ilLXkSWxk And [Math.9]
[0093] Based on these parameters, the probability density function f can be expressed as follows:
[0094] [Math. 10] f(xk) = ~^S~ ]
[0095] Consider, for example, the normal signal of the Earth's magnetic field, observed over a period of 1000 minutes as illustrated in Figure 4A. For this signal, it has been determined that the mean is μ = 2.72 x 10^16 and the standard deviation μ = 1.15 x 10^n.
[0096] It should be noted that the probability density function f representing the normal behavior of a signal can be represented either by a continuous function or by a histogram, depending on the specific nature of the signal studied.
[0097] In step E13, the processor 5 is configured to establish an average information filter I, called the 'first filter', which is based on the probability density function f. This first filter is designed such that, when applied to a normal signal SN, it converges to a limiting value which corresponds to the entropy of the probability density f associated with this normal signal.
[0098] The first filter on an initial or current series of a determined number A of samples consists of calculating the natural logarithm of the value of the probability density function f for each of the samples xk in the set of A samples. The sum of these logarithms is then obtained, and the total is multiplied by the opposite of the inverse of the number N of samples, according to the following formula:
[0099] [Math. 11]
[0100] The value towards which the output of the first filter tends, when the number of samples of the normal signal SN increases indefinitely, corresponds to the entropy of the probability density, denoted by This relationship is described by the following formula:
[0101] [Math. 12] = - J / (x)*log( / (x) )dx x^X
[0102] where X corresponds to the set of possible values for x.
[0103] At step E14, processor 5 is configured to establish the threshold value $ based on the value H( f) of the entropy of the probability density f associated with the normal signal SN.
[0104] Advantageously, the threshold value S is equal to the value of the entropy of the probability density f, plus a value s within an interval from 1% to 20% of the absolute value of the entropy H(f), according to the following formula:
[0105] [Math. 13] S = H(f)+e
[0106] Thus, the choice of the threshold $ is very simple to make; it suffices to calculate the entropy H( f} of the probability density f, and to take as the threshold value, this entropy plus a small value s.
[0107] It should be noted that increasing the boost value e reduces the number of false alarms, but this can also reduce detection sensitivity and reliability. Conversely, lowering the boost value e improves reliability through increased sensitivity, but at the cost of an increase in false alarms. Therefore, this value s can be adjusted to strike a balance between the correct detection rate and the risk of false alarms, depending on the specific requirements of each application.
[0108] According to a first example, the markup value £ is defined in a range between 10% and 20% of the absolute value of the entropy, with the aim of achieving a very low probability of false alarms, between 10⁴ and 10³.
[0109] According to another example, the markup value is defined in a range between 1% and 10% of the absolute value of the entropy, to promote the achievement of maximum reliability in anomaly detection.
[0110] For illustrative purposes, let us take the calculated entropy for the probability density f shown in Fig. 4B, which is H(f) = -23.77. In order to promote detection sensitivity while accepting a higher rate of False alarms, it is possible to adopt a deliberately low threshold value e. By setting e at 1.47, or approximately 6% of the absolute value of H(f), we establish the detection threshold $ at -22.3, which translates to the sum of H(f) and s, i.e. S = -23.77+1.47 = -22.3.
[0111] Steps El 1 to E14 are dedicated to the initial calibration phase. Once this phase is completed, operational anomaly detection is initiated, starting at step El5.
[0112] The description continues in Figures 5A to 5F, which are based on the same case study as Figures 4A and 4B. Figures 5A, 5C, and 5E illustrate the results obtained for a signal considered normal. In parallel, Figures 5B, 5D, and 5F show the data corresponding to an 'abnormal' situation, such as the presence of a vehicle near the sensor. More specifically, Figures 5A and 5B respectively show the recordings of a normal signal SN and a current signal Sc affected by an anomaly. Figures 5C and 5D reveal the probability density profiles associated with the data in Figures 5A and 5B, respectively. Finally, Figures 5E and 5F compare the filter results of the data in Figures 5A and 5B with the established threshold value, thus highlighting the presence or absence of anomalies. The values of entropy H(f) = - 23.77 and of threshold value S = - 22.3 are represented by the horizontal lines in figures 5E and 5F.
[0113] In step E15, the processor 5 is configured to acquire a current signal Sc reflecting the current behavioral state of the environment or system to be monitored. This current signal Sc is shown in [Fig. 5A] if it is a normal signal without anomalies, or in [Fig. 5B] if it contains anomalies.
[0114] At step E16, the processor 5 is configured to sample the current signal Sc into a series of N samples using a determined sliding window Wi.
[0115] [Math.l] Wi= KzV+P Xi-N^ •••> Xi-L
[0116] At step E17, processor 5 is configured to calculate the result of The application of the first information filter to the current series of N samples. Indeed, processor 5 first evaluates the probability density function f for the data from the current signal Sc illustrated in Fig. 5B. The curve f(xk) Oui, representing this probability density function as a function of time, is shown in Fig. 5D. Processor 5 is then configured to calculate, giving rise to the curve corresponding represented in Fig. 5F. Finally, processor 5 performs the summation of the logarithms of f(x^ for AT of samples, with N = 30 in this context. This sum is then multiplied by the opposite of the inverse of N, according to the formula stated previously. The result of the filter j _ ^jyj is
[0117]
[0118]
[0119]
[0120]
[0121]
[0122]
[0123]
[0124]
[0125]
[0126]
[0127] presented as a time curve in [Fig.5F]. At step E18, processor 5 is configured to compare this result with the threshold value 5'. An anomaly is detected if the result j^yy j exceeds the threshold value S: [Math. 14] Awj >s Figure 5E illustrates that, for a normal signal SN, the time curve corresponding to the filter j remains systematically below the threshold value set at >5 = -22.3. In contrast, Figure 5F reveals intervals where the time curve of the filter / (W.) associated with the current signal Sc rises above this threshold value. This exceedance indicates the presence of an anomaly. Figure 6 schematically illustrates a method for detecting anomalies within an environment or technical system, according to a second preferred embodiment of the invention. This method differs from that presented in [Fig.3] primarily by the introduction of a filter, distinct from the first filter. According to this second embodiment, the information filter corresponds to a second filter which relies on the first filter described in [Fig.3]. At step E21, acquisition module 3 is configured to acquire a normal signal SN reflecting the normal state of the environment or system. At step E22, processor 5 is configured to determine from the normal signal SN the probability density f which models the normal behavior state of the environment or system under study. At step E23, processor 5 is configured to acquire a current signal Sc reflecting the current behavioral state of the environment or system to be monitored. At step E24, processor 5 is configured to sample the current signal Sc to obtain a series of N samples, using a predefined sliding window Wi. [Math.l] Wj— {, Xj-N+2' •••' Xj j At step E25, processor 5 is configured to approximate the probability density of the current signal data Sc over this sliding window by a continuous probability density s. The estimation of the probability density Σ can be performed using a histogram or by the non-parametric estimation approach. Kernel Density Estimation (KDE) uses functions called kernels to assign local weights, allowing for smoothing of data from a finite set of samples. This technique is particularly useful when the number of samples, N, is limited.
[0128] According to this second embodiment, the application of the second filter, designated on an initial calibration series or a current series of a determined number Processing N samples using processor 5 involves first calculating the natural logarithm of the value of the continuous function Σ for each sample. Then, processor 5 calculates the arithmetic mean of the results obtained for these natural logarithms. This mean is then added to the result of applying the first filter to the same series of samples. The formula used by processor 5 is as follows:
[0129] [Math.8]
[0130] When this second filter is applied to the samples of the normal signal SN, its value converges to zero. Moreover, the value of the second filter increases in the presence of an anomaly, as was the case for the first embodiment.
[0131] At step E26, processor 5 is configured to establish the threshold value, which is simply expressed according to the following formula:
[0132] [Math. 15] S=0 + £
[0133] Consequently, determining the threshold '5 is even simpler than in the first embodiment. It is not necessary to calculate the entropy H(f) since it suffices to take a small fixed value e. This value must always be adjusted according to a compromise between the probability of correct detection and the probability of a false alarm.
[0134] At step E27, processor 5 is configured to calculate the value which results from applying the second information filter to the current series of N samples.
[0135] Finally, at step E28, processor 5 is configured to compare the value previously obtained with the threshold 5'. The detection of an anomaly is confirmed if j exceeds the threshold value S:
[0136] [Math. 16] k(w) >s
[0137] It should be noted that the present invention, illustrated by a detailed example associated with Figures 4A-4B and 5A-5F for an application case involving a magnetic signal and the detection of a ferromagnetic object, is suitable for implementation in other applications.
[0138] A first example of application is the detection of attacks in a computer network. For this situation, a relevant time series, denoted Xt,T (where 'f refers to time), records the amount of data, measured in bytes or bits, passing through a node of the network over the time interval [t; t+T]. The sensor used is then a counter configured to generate the current signal by measuring the volume of data exchanged at a specific node of the computer network that one wishes to monitor.
[0139] A second example concerns the detection of anomalies in machines. For this purpose, the appropriate sensor could be an accelerometer or an acoustic sensor, both configured to create the current signal by detecting the vibrations emitted by the machine being monitored.
[0140] A third example is the non-destructive testing of metallic pipelines. In this situation, a suitable sensor is an eddy current probe, which is configured to generate the current signal by measuring the thickness of a pipeline being monitored.
Claims
Demands
1. A method for detecting anomalies within an environment or system, comprising the following steps: - acquiring (E1) a normal signal (NS) reflecting the normal state of the environment or system, - determining from the normal signal (NS) a probability density function f that models a normal behavioral state of the environment or system, - establishing (E3) an information filter based on said probability density function f, said information filter being configured to converge to a limiting value L when applied to samples of a normal signal, while increasing its value in response to the detection of an anomaly, - establishing (E4) a threshold value $ based on said convergence limiting value, - acquiring (E5) a current signal (Sc) reflecting the current behavioral state of the environment or system, - sampling (E6) said current signal (Sc) in a current series of N samples,- calculate (E7) a result of applying the information filter to the current series of N samples, - compare (E8) said result with said threshold value, an anomaly being detected if said result exceeds said threshold value.
2. A method according to claim 1, characterized in that said threshold value is equal to said limit value E, plus a value s of increase chosen according to a compromise sought between reliable detection and minimization of the number of false alarms.
3. A method according to claim 1 or 2, characterized in that the information filter corresponds to a first filter designed such that, when applied to samples of a normal signal, it converges to a limiting value which corresponds to the entropy of the probability density associated with this normal signal.
4. The method according to claim 3, characterized in that applying said first filter to said current series of a determined number of samples consists of calculating the natural logarithm of the value of the probability density function f for each of the samples, then summing these logarithms, and multiplying the result by this summation by the negative factor corresponding to the inverse of the said determined number N of samples, according to the following formula: [Math.6]
5. A method according to claim 3 or 4, characterized in that said threshold value is equal to the entropy value H(f) of the probability density function σ, plus a value e within a range of 1% to 20% of the absolute value of said entropy, according to the following formula: [Math.7] S = H(f) + e
6. A method according to claim 5, characterized in that said increase value is defined in a range between 10% and 20% of the absolute value of entropy, with the aim of achieving a very low probability of false alarms, between 10⁴ and 10³.
7. A method according to claim 5, characterized in that said increase value is defined in a range between 1% and 10% of the absolute value of the entropy, to promote the achievement of maximum reliability in anomaly detection.
8. A method according to claim 1, characterized in that the information filter corresponds to a second filter which is based on said first filter described in claims 3 or 4, and uses a continuous function which represents an approximation of the data probability density of the current signal (Sc) over a predetermined sliding window Wi.
9. A method according to claim 8, characterized in that the application of said second filter to said current series of a determined number N of samples consists of calculating the natural logarithm of the value of the continuous function for each of the samples, calculating the average of the results obtained for these natural logarithms, and adding the result of said average to the result of the application of the first filter to the same current series of samples, according to the following formula: [Math.8]
10. Anomaly detection device within an environment or system, comprising: - an acquisition module (3) configured to acquire a current signal reflecting the current behavioral state of the environment or system, - a processor (5) configured to: - sample said current signal into a current series of N samples, - calculate a result of the application of an information filter on said current series of N samples, said information filter being based on a probability density modeling a normal behavioral state of the environment or system, said information filter being configured to converge to a limit value when applied to samples of a normal signal, while increasing its value in response to the detection of an anomaly, - compare said result with a threshold value based on said convergence limit value, an anomaly being detected if said result exceeds said threshold value, and - an output interface (9) configured to indicate the detection of an anomaly.
11. A detection device according to claim 10, characterized in that it comprises a magnetometer (11) configured to generate said current signal by capturing an ambient magnetic field, including the Earth's field as well as various magnetic disturbances.
12. Detection device according to claim 10, characterized in that it comprises an accelerometer configured to generate the current signal by capturing vibrations emanating from a machine to be monitored.
13. Detection device according to claim 10, characterized in that it comprises a counter configured to generate the current signal by measuring the volume of data exchanged at the level of a specific node of a computer network to be monitored.
14. Detection device according to claim 10, characterized in that it comprises an eddy current probe configured to produce the current signal by measuring the thickness of a pipeline under surveillance.
Citation Information
Patent Citations
Tramp metal detection
US20170031049A1