Abnormality detection device, abnormality detection system, and abnormality detection method
The abnormality detection system addresses the challenge of identifying abnormality causes in machine detection systems by using a combination of outlier calculations, factor analysis, target narrowing, and cause identification units, resulting in efficient and timely cause identification and reduced calculation load.
Patent Information
- Application Number
- JP2023183856
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-26
- Publication Date
- 2025-05-13
AI Technical Summary
Existing abnormality detection systems for machines, such as gas turbines, can only detect abnormalities but fail to identify their causes effectively, leading to difficulties in grasping the underlying issues promptly.
An abnormality detection system that includes an abnormality detection unit, a factor analysis unit, a target narrowing unit, and a cause identification unit, which calculates outlier values for data sequences, determines their importance, narrows down the relevant data sequences, and identifies the cause of the abnormality within a predefined range.
This system enables quick identification of abnormality causes, allowing for early and appropriate responses to machine issues while reducing the calculation load by pre-limiting the abnormality and data values.
Smart Images

Figure 2025073250000001_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to machine anomaly detection. [Background technology]
[0002] For example, in industrial machines such as gas turbines, in order to avoid downtime due to sudden failures, it is necessary to detect abnormalities before a failure occurs and take action in advance. In consideration of this need, data collected from sensors attached to the machines is diagnosed by statistical methods or machine learning to detect abnormalities.
[0003] For example, a conventional anomaly detection method has been proposed in which operation data of a facility to be monitored is collected in a learning phase, and an anomaly detection model is constructed from the operation data.In the monitoring phase, an anomaly score is calculated for each piece of operation data from the operation data and the anomaly detection model, and if the anomaly score exceeds a threshold, it is determined that an anomaly has occurred.
[0004] In the case of an anomaly detection method that calculates an anomaly score for one monitoring item such as temperature or pressure included in the operation data and judges the anomaly score based on a threshold, it is possible to detect an anomaly that can be determined from the instantaneous value of the monitoring item. However, for example, depending on the operating state of the equipment, the value of the monitoring item may exceed the threshold even if no anomaly has occurred. Therefore, if an anomaly of one monitoring item is judged by focusing only on one anomaly score, the accuracy of anomaly detection will decrease.
[0005] The above problem is also pointed out in Patent Document 1, and in response to this problem, Patent Document 1 proposes the following anomaly detection system. This anomaly detection system includes a data acquisition unit, a score calculation unit, and an anomaly detection unit. The data acquisition unit acquires parameters that are operation data of a monitored device. The score calculation unit calculates multiple probabilities of observing a measured value of the monitored device included in the operation data, using different methods. The data acquisition unit calculates a score indicating the degree of anomaly for each of the multiple types of calculated probabilities. The anomaly detection unit determines whether or not each of the multiple scores is abnormal, based on the multiple scores and a determination model, and detects an anomaly in the device based on the results of the multiple determinations.
[0006] In Patent Document 1, four different scores indicating the degree of anomaly are calculated for the parameters acquired by the data acquisition unit. The anomaly detection system in Patent Document 1 detects anomalies based on the four scores, that is, four indicators occurring in the behavior of the parameters to be monitored. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Patent Publication No. 2022-84435 Summary of the Invention [Problem to be solved by the invention]
[0008] In order to respond appropriately to an abnormality that occurs in a machine, it is essential to correctly identify the cause. However, Patent Document 1 only detects the abnormality and does not disclose how to identify the cause of the abnormality. Therefore, even if the configuration of Patent Document 1 allows an operator to know the occurrence of an abnormality early, it is difficult for the operator to grasp the cause of the abnormality early.
[0009] The present disclosure has been made in consideration of the above circumstances, and has an object to provide an anomaly detection system that can detect an anomaly and identify the cause of the anomaly with a small amount of calculation. [Means for solving the problem]
[0010] The problem to be solved by the present disclosure is as described above. Next, the means for solving this problem and the effects thereof will be described.
[0011] According to a first aspect of the present disclosure, there is provided an anomaly detection device for detecting anomalies in a machine, having the following configuration. That is, the anomaly detection device includes an anomaly detection unit, a factor analysis unit, a target selection unit, and a cause identification unit. The anomaly detection unit inputs a plurality of data series, each of which is a string of data values representing the state of the machine, calculates an anomaly value representing the degree of anomaly of the data value based on a predetermined anomaly determination method, and determines the presence or absence of an anomaly based on the anomaly value. The factor analysis unit calculates an importance indicating the degree to which the data value contributes to the anomaly value for each of the plurality of data series. The target selection unit narrows down anomalies and data series to be targets for which the cause is to be identified from a plurality of predetermined anomalies and a plurality of the data series, based on the anomaly value acquired by the anomaly detection unit and the importance of each of the data series acquired by the factor analysis unit. The cause identification unit identifies the cause of an anomaly occurring in the machine within the range of the anomalies and the data series narrowed down by the target selection unit.
[0012] According to a second aspect of the present disclosure, there is provided an anomaly detection system for detecting anomalies in a machine, the anomaly detection system being configured as follows. That is, the anomaly detection system includes an anomaly detection unit, a factor analysis unit, a target selection unit, and a cause identification unit. The anomaly detection unit receives input of a plurality of data series, each of which is a string of data values representing the state of the machine, calculates an anomaly value representing the degree of anomaly of the data value based on a predetermined anomaly determination method, and determines the presence or absence of an anomaly based on the anomaly value. The factor analysis unit calculates an importance indicating the degree to which the data value contributes to the anomaly value for each of the plurality of data series. The target selection unit narrows down anomalies and data series, the cause of which is to be identified, from a plurality of predetermined anomalies and a plurality of the data series, based on the anomaly value acquired by the anomaly detection unit and the importance of each of the data series acquired by the factor analysis unit. The cause identification unit identifies the cause of an anomaly occurring in the machine within the range of the anomalies and the data series narrowed down by the target selection unit.
[0013] According to a third aspect of the present disclosure, there is provided an anomaly detection method for detecting an anomaly in a machine, as follows: That is, this detection method includes inputting a plurality of data series, each of which is a string of data values representing a state of the machine, calculating an anomaly value representing the degree of anomaly of the data values based on a predetermined anomaly determination method, determining the presence or absence of an anomaly based on the anomaly value, calculating an importance indicating the degree to which a data value contributes to the anomaly value for each of the plurality of data series, narrowing down anomalies and data series, the cause of which are to be identified, from a plurality of predetermined anomalies and a plurality of the data series based on the anomaly value and the importance of each of the data series, and identifying the cause of an anomaly occurring in the machine within the narrowed down range of the anomalies and the data series.
[0014] This allows an operator to know the cause of an anomaly very soon after it is detected. Therefore, based on the identified cause, an operator can take an early and appropriate action to deal with the anomaly. In addition, because the cause is identified within a range of anomalies and data values narrowed down in advance, the calculation load can be effectively reduced. Effect of the Invention
[0015] According to the present disclosure, it is possible to provide an anomaly detection system that can detect an anomaly and identify the cause of the anomaly with a small amount of calculation. [Brief description of the drawings]
[0016] [Figure 1] 1 is a schematic diagram showing an overall configuration of a condition diagnosis system according to an embodiment of the present disclosure; [Diagram 2] FIG. 4 is a block diagram of a status diagnosis server. [Diagram 3] 4 is a graph for explaining an abnormality detected by the abnormality determination method. [Figure 4] FIG. 4 is a schematic diagram for explaining settings of a status diagnosis server. [Diagram 5] FIG. 11 is a flow diagram illustrating the process flow of anomaly determination, factor analysis, narrowing down of analysis targets, and cause identification in the status diagnosis server. [Figure 6] FIG. 11 is a flow diagram illustrating a process performed on a data value before an abnormality is determined. [Figure 7] FIG. 1 is a schematic diagram illustrating a fault tree. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0017] Next, an embodiment of the present disclosure will be described with reference to the drawings. Fig. 1 is a schematic diagram showing an overall configuration of a condition diagnosis system (anomaly detection system) 150 according to an embodiment of the present disclosure. Fig. 2 is a block diagram of a condition diagnosis server 30. Fig. 3 is a graph that illustrates an anomaly detected by an anomaly determination method.
[0018] 1 performs a condition diagnosis of a machine 100. The machine 100 can also be referred to as equipment. The machine 100 can be, for example, a gas turbine in a power plant, but is not limited to this.
[0019] In this embodiment, the condition diagnosis is realized by sequentially performing three steps: abnormality detection, factor analysis, and cause identification.
[0020] In this specification, an abnormality refers to a phenomenon in which the behavior of data obtained about the machine 100 is different from data accumulated in the past. An abnormality can be understood as a sign of a malfunction occurring in the machine 100. A malfunction refers to a state in which the machine 100 is unable to achieve a required function, regardless of whether the machine 100 is able to operate.
[0021] Anomaly detection refers to detecting the above-mentioned anomaly from data obtained regarding the machine 100. Cause analysis refers to identifying the data that is the cause of the detected anomaly. Cause identification refers to analyzing the data that is the cause of the anomaly in the machine 100 and identifying the part of the machine 100 that is causing the anomaly. Only one part may be identified as the cause of the anomaly, or multiple parts that have a certain degree of possibility may be identified.
[0022] The condition diagnosis system 150 includes a condition diagnosis server (anomaly detection device) 30. The condition diagnosis server 30 acquires data obtained by observing the machine 100 with a plurality of sensors 10 via a data collection device 20. At least one of the sensors 10 and the data collection device 20 may be included in the condition diagnosis system 150.
[0023] A large number of sensors 10 are attached to the machine 100 to be diagnosed. The sensors 10 detect the state of the machine 100 and repeatedly output data values. The number of sensors 10 is arbitrary, and can be, for example, several hundred. The state quantity detected by each sensor 10 is arbitrary, and can be, for example, temperature, pressure, flow rate, vibration, current, power amount, rotation speed, etc. The sensor 10 may output, as a data value, a value appropriately calculated from the detected value, instead of the obtained detected value.
[0024] Each sensor 10 functions as a data source for the condition diagnosis server 30. In the following, for example, a sequence of data values repeatedly output by one sensor 10 may be referred to as a data series. A data series can be considered as a unit of data monitoring performed in the condition diagnosis system 150. Instead of a sequence of data values output by a sensor 10, a data series may be a sequence of data values calculated by the data collection device 20 or the condition diagnosis server 30 based on the data values.
[0025] Each sensor 10 is connected to a data collection device 20 by wire or wirelessly. The data collection device 20 is a known computer including a CPU, a ROM, a RAM, etc. The data values acquired by the sensors 10 are stored in the data collection device 20 together with the time of acquisition.
[0026] The condition diagnosis server 30 is communicably connected to the data collection device 20. The communication can be performed by any method including a WAN, a LAN, etc. The condition diagnosis server 30 acquires the detection value acquired by the sensor 10 from the data collection device 20.
[0027] As described above, the condition diagnosis server 30 detects anomalies, analyzes factors, and identifies causes, and outputs the results. For example, a client computer 90 that enables an operator to perform monitoring work is connected to the condition diagnosis server 30. The condition diagnosis server 30 generates diagnosis result data and transmits it to the client computer 90. The client computer 90 outputs a diagnosis result report to a display (not shown) based on the diagnosis result data.
[0028] As shown in FIG. 2, the condition diagnosis server 30 includes a communication unit 31, a memory unit 32, an abnormality detection unit 33, a factor analysis unit 39, a target narrowing down unit 45, a setting unit 46, a learning unit 47, a model memory unit 48, a cause identification unit 49, a report data creation unit 50, and an output unit 51.
[0029] Specifically, the condition diagnosis server 30 is a known computer including a CPU, a ROM, a RAM, an auxiliary storage device, etc. In order to perform anomaly detection, a program for performing statistical processing, machine learning processing, etc., for implementing the anomaly detection method of the present disclosure is pre-installed in the condition diagnosis server 30. This hardware and software can cooperate to cause the condition diagnosis server 30 to function as a communication unit 31, a storage unit 32, an anomaly detection unit 33, a factor analysis unit 39, a target narrowing-down unit 45, a setting unit 46, a learning unit 47, a model storage unit 48, a cause identification unit 49, a report data creation unit 50, and an output unit 51.
[0030] The communication unit 31 is configured as, for example, a communication interface. The communication unit 31 communicates with the data collecting device 20 to obtain the data value and the data acquisition time obtained by the sensor 10.
[0031] The storage unit 32 is configured as, for example, a database. The storage unit 32 can accumulate data values acquired by the sensors 10 regarding the machine 100 and the times at which the data was acquired.
[0032] The anomaly detection unit 33 reads out the data values stored in the storage unit 32 together with the acquisition time, and judges whether or not an anomaly exists. The anomaly detection unit 33 calculates the degree of anomaly when each of a plurality of predetermined anomaly judgment methods is applied. The presence or absence of an anomaly is judged based on the result of comparing these anomaly degrees with a threshold value.
[0033] The abnormality detection unit 33 includes a normal space deviation detection unit 34, a correlation breakdown detection unit 35, a sudden change detection unit 36, a non-steady change detection unit 37, and a level change detection unit 38 in response to a plurality of abnormality determination methods.
[0034] A deviation from normal space means that a data value belonging to one data series deviates from a predetermined range, or a set of data values belonging to two or more data series deviates from a predetermined range in a multi-dimensional space. Deviation from normal space includes a case where a data value irregularly deviates from a range that should normally be taken, as shown in graph G1 of FIG. 3, and a case where the level of a data value changes each time a machine is repeatedly started and stopped, and eventually deviates from a predetermined range, as shown in graph G2. The normal space deviation detection unit 34 detects deviation from normal space by a known method such as LOF. LOF is an abbreviation for Local outlier Factor, and is a method for detecting outliers from a set of data. In LOF, an LOF score is calculated based on the data density of the data of interest and the data density of data in the vicinity of the data of interest, to determine whether the data is an outlier. This LOF score can be considered as a kind of abnormality. The presence or absence of an abnormality in deviation from normal space can be determined by comparing the LOF score with a predetermined threshold. Detection of deviation from normal space can also be achieved by a method other than LOF, for example, OCSVM. OCSVM is an abbreviation for One Class SVM.
[0035] Correlation breakdown means that the correlation between data values belonging to two data series is broken, as shown in graph G3. The correlation breakdown detection unit 35 detects correlation breakdown by a known method such as LOF, OCSVM, or MTS. MTS is an abbreviation for Mahanobis-Taguchi System.
[0036] A sudden change means that, as shown in graph G4, a data value belonging to one data series is within the normal space described above, but exhibits a sudden change over time. The sudden change detection unit 36 detects a sudden change, for example, by monitoring the time series of the data value. The sudden change detection unit 36 performs known pattern recognition on the time transition of the data value, and calculates the degree of difference from a normal time transition pattern. This degree of difference can be considered as a kind of abnormality. The presence or absence of a sudden abnormality can be determined by comparing the degree of difference with a predetermined threshold. The presence or absence of an abnormality may be determined by calculating a time change rate from the transition of the data value, and using the ratio obtained by dividing this time change rate by the normal time change rate.
[0037] An unsteady change means that a change different from the steady change that should normally occur occurs in a data value belonging to one data series, as shown in graph G5. The unsteady change detection unit 37 detects an unsteady change, for example, by monitoring the time series of the data value.
[0038] A level change, as shown in graph G6, means that the data values belonging to one data series show discontinuous changes even when the machine is not operating / stopping, etc. The level change detection unit 38 detects the level change, for example, by monitoring the time series of the data values.
[0039] The factor analysis unit 39 shown in FIG. 2 calculates, for each anomaly determination method used by the anomaly detection unit 33, a value indicating whether or not the data value (data series) on which the anomaly detection unit 33 calculates the degree of anomaly contributes strongly to the degree of anomaly (hereinafter, referred to as importance).
[0040] The factor analysis unit 39 includes a normal space deviation factor analysis unit 40, a correlation breakdown factor analysis unit 41, a sudden change factor analysis unit 42, a non-steady change factor analysis unit 43, and a level change factor analysis unit 44 to correspond to a plurality of abnormality determination methods.
[0041] For example, the correlation collapse factor analysis unit 41 obtains the importance of each data value (data series) with respect to the degree of anomaly calculated by the correlation collapse detection unit 35. The importance can be calculated, for example, by decomposing the vector of the degree of anomaly into the vector of each data series and calculating the length of the decomposed vector. The importance of each data series can also be calculated by methods such as SHAP and LIME. SHAP is a method that applies the Shapley value used in cooperative game theory to machine learning and quantitatively expresses the contribution of each feature to the prediction made by the machine learning model. LIME is a method that separately constructs a simple model that outputs a prediction result that is locally approximate to the prediction result of the machine learning model, and examines the feature that strongly contributes to the prediction based on this model. SHAP and LIME are one of the methods called explainable AI.
[0042] The normal space deviation factor analysis unit 40, the sudden change factor analysis unit 42, the non-stationary change factor analysis unit 43, and the level change factor analysis unit 44 also obtain the importance of each data series with respect to the degree of abnormality by calculation.
[0043] The target narrowing down unit 45 narrows down the anomalies and data series that are to be analyzed by the cause identification unit 49 for cause identification, based on the degree of anomaly output by the anomaly detection unit 33 and the importance output by the factor analysis unit 39. The specific processing performed by the target narrowing down unit 45 will be described later.
[0044] The setting unit 46 receives settings related to the processing in the abnormality detection unit 33, the learning unit 47, and the cause identification unit 49.
[0045] The learning unit 47 performs processing equivalent to the training phase of machine learning to create a machine learning model to be used in the anomaly detection unit 33. This machine learning model can be a model that inputs data read from the storage unit 32 and outputs an anomaly degree.
[0046] The machine learning model is constructed when one or more anomaly determination methods used in the anomaly detection unit 33 utilize machine learning. A machine learning model is constructed for each anomaly to be detected. An example of the machine learning model to be constructed is the model that performs LOF described in the explanation of the normal space deviation detection unit 34. The machine learning model is constructed by learning data values when the machine 100 is operating in a normal state in a training phase.
[0047] The model storage unit 48 stores the machine learning model constructed by the learning unit 47. The machine learning model stored in the model storage unit 48 is used in the anomaly detection unit 33 and the cause identification unit 49.
[0048] The cause identification unit 49 analyzes the data that is determined by the factor analysis unit 39 to have caused the abnormality, and identifies the part of the machine 100 that caused the abnormality. Although it is possible that the abnormal behavior of the data is due to a false detection by the sensor 10 or the like, the cause identification unit 49 can also determine whether or not there is an abnormality in the sensor 10. The specific processing performed by the cause identification unit 49 will be described later.
[0049] The report data creation unit 50 creates diagnostic result data based on the processing results of the abnormality detection unit 33, the factor analysis unit 39, the cause identification unit 49, and the like.
[0050] The output unit 51 is configured as, for example, a communication interface. The output unit 51 communicates with the client computer 90 to transmit the diagnostic result data created by the report data creation unit 50 to the client computer 90.
[0051] Next, the process performed by the condition diagnosis server 30 of this embodiment will be specifically described.
[0052] For the condition diagnosis server 30 to perform fault diagnosis, at least settings are required for the process performed by the anomaly detection unit 33 and the process performed by the cause identification unit 49. These settings are realized by the setting unit 46. The settings can be realized, for example, by an administrator connecting to the condition diagnosis server 30 using a computer and performing appropriate operations.
[0053] The settings related to the processing performed by the anomaly detection unit 33 include information on the application target data series, information on the operating condition thresholds, information on the normal period, and information on the warning thresholds.
[0054] The information on the target data series is information describing, for each of a number of anomaly determination methods, one or more data series to which the method is to be applied, as shown in table T1 in Fig. 4. Hereinafter, one or more data series determined as the target of a certain anomaly determination method may be referred to as a group.
[0055] For example, consider a case where the machine 100 is a gas turbine, and the multiple sensors 10 include a pressure sensor provided in a discharge pipe of an air compressor and a NOx sensor provided in an exhaust pipe. A data series of pressure values detected by the pressure sensor corresponds to data series C in table T1 of FIG. 4. When this data series C is to be monitored for deviation from normal space by the normal space deviation detection unit 34, information identifying the data series C is set as one group in the setting unit 46 ("group 1" in table T1). The format of the information identifying each data series is arbitrary, but may be, for example, an ID assigned to uniquely identify the data series.
[0056] The data series of the NOx gas concentration detected by the NOx sensor corresponds to data series E in table T1. When this data series E is to be monitored for deviation from normal space, information specifying the data series E is set as one group in the setting unit 46 ("group 2" in table T1).
[0057] Regarding the determination of correlation collapse, instead of monitoring only one combination of data sequences, multiple combinations may be monitored. In this case, for each combination (group) for which the correlation collapse detection unit 35 monitors correlation, information for identifying the data sequences belonging to the combination is set in the setting unit 46 ("Group 3" and "Group 4" in table T1).
[0058] The information on the operating condition threshold values shown in Table T2 is information that defines a group, an anomaly determination method, and a threshold value for determining whether the machine 100 is operating if the degree of anomaly calculated based on a predetermined anomaly determination method for a predetermined group satisfies a predetermined condition, and whether the machine 100 is not operating if the degree of anomaly does not satisfy the predetermined condition. The operating data of the machine 100 used for anomaly detection is acquired on the condition that the operating conditions are satisfied. This makes it possible to perform anomaly detection by excluding situations in which the data values contain a lot of noise.
[0059] The information on the normal period is information that defines a period during which the machine 100 is normal with respect to a predetermined group and with respect to a predetermined abnormality determination method. Data values of the operation data acquired during the period during which the machine 100 is normal are used in the learning unit 47 to construct a machine learning model.
[0060] The information on the warning threshold is information that defines a group, an abnormality determination method, and a warning generation condition when the calculated abnormality degree for a certain group and a certain abnormality determination method satisfies a certain condition and the condition diagnosis server 30 generates a warning. The threshold of the warning generation condition may be the same as or different from the threshold for the abnormality detection unit 33 to determine the presence or absence of an abnormality.
[0061] Regarding the process performed by the cause identification unit 49, for example, a formula for calculating a score related to a fault tree, which will be described later, is set.
[0062] Next, mainly with reference to FIG. 5, the processes performed by the anomaly detection unit 33, the factor analysis unit 39, the target selection unit 45, and the cause identification unit 49 will be described in detail in relation to the above settings.
[0063] The normal space deviation detection unit 34 provided in the abnormality detection unit 33 reads data values from the memory unit 32 and calculates the degree of abnormality for each of the groups defined in the setting unit 46 corresponding to the deviation from the normal space ("Group 1" and "Group 2" in table T1).
[0064] Before the abnormality detection unit 33 calculates the degree of abnormality, the data values are subjected to pre-processing shown in steps S101 to S107 in Fig. 6. The steps will be described below in order.
[0065] In step S101, for a particular data series, a difference, an average, etc. are calculated for data values obtained from the database in the storage unit 32, thereby creating another data series.
[0066] In step S102, a screening process is performed on the acquired data values in accordance with the settings of the operating condition thresholds shown in table T2 of Fig. 4. This allows only data values obtained when the machine 100 is operating to be obtained.
[0067] In step S103, a filter process is performed using an appropriate method for the purpose of removing noise, etc.
[0068] In step S104, a process of calculating a regression error or the like is performed as necessary.
[0069] In step S105, in accordance with the settings shown in table T1 in FIG. 4, only the data series included in the group corresponding to the abnormality determination method (deviation from normal space in the case of normal space deviation detection unit 34) is extracted.
[0070] In step S106, a dummy sequence is added as necessary.
[0071] In step S107, a known normalization process is performed on the data values.
[0072] The series of processes shown in the above-mentioned steps S101 to S107 is performed for each combination of the abnormality determination method and group set in the table T1 of FIG.
[0073] 5, for each of "group 1" and "group 2", the degree of anomaly obtained by normal space deviation detection unit 34 is compared with a predetermined threshold, and the presence or absence of an anomaly is determined based on the comparison result. For each of "group 1" and "group 2", normal space deviation detection unit 34 outputs the determination result regarding the presence or absence of an anomaly to target selection unit 45. The correlation breakdown detection unit 35, sudden change detection unit 36, non-steady change detection unit 37, and level change detection unit 38 also perform the same processing as that of normal space deviation detection unit 34 for the groups set in table T1.
[0074] The normal space deviation factor analysis unit 40 included in the factor analysis unit 39 calculates a value indicating the degree to which each data series (data value) belonging to the group contributes to the abnormality level for "group 1". Hereinafter, the value indicating the degree of contribution to the abnormality level may be referred to as importance. The normal space deviation factor analysis unit 40 outputs the obtained importance for each data series (data value) belonging to the group to the target narrowing down unit 45. The normal space deviation factor analysis unit 40 performs the same processing for "group 2". The correlation breakdown factor analysis unit 41, the sudden change factor analysis unit 42, the non-steady change factor analysis unit 43, and the level change factor analysis unit 44 also perform the same processing as the normal space deviation factor analysis unit 40.
[0075] The target narrowing down unit 45 receives the degrees of anomaly calculated for the target group by the normal space deviation detection unit 34, correlation collapse detection unit 35, sudden change detection unit 36, non-steady change detection unit 37, and level change detection unit 38 provided in the anomaly detection unit 33. Furthermore, the target narrowing down unit receives the importance calculated for the data series included in the target group by the normal space deviation factor analysis unit 40, correlation collapse factor analysis unit 41, sudden change factor analysis unit 42, non-steady change factor analysis unit 43, and level change factor analysis unit 44 provided in the factor analysis unit 39.
[0076] When the anomaly detection unit 33 determines that an anomaly has occurred in the machine 100 by one or more of the multiple anomaly determination methods, the target narrowing down unit 45 narrows down the anomalies whose causes are to be identified and the data series used to identify the causes of the anomalies. The narrowing down is performed based on the degree of anomaly and the importance obtained for each combination of the anomaly determination method and group. Information indicating the narrowed down anomalies and data series is output to the cause identification unit 49.
[0077] For example, in table T1 of Fig. 4, three data series included in "group 3" are defined. Assume that correlation collapse detection unit 35 detects an anomaly with respect to the data values of group 3, and correlation collapse cause analysis unit 41 calculates the importance of data series B to be 0.7, the importance of data series D to be 0.2, and the importance of data series E to be 0.1. In this case, target narrowing-down unit 45 selects two data series from the three data series in descending order of importance. As a result, the data series used by cause identification unit 49 to identify the cause of the anomaly are narrowed down to two, data series B and data series D. The extent to which the data series are reduced by narrowing-down can be determined arbitrarily.
[0078] The cause identification unit 49 identifies the cause of the abnormality that has occurred in the machine 100 based on the abnormalities and data series that have been narrowed down by the target narrowing down unit 45.
[0079] Specifically, the cause identification unit 49 reads out data values for the data series narrowed down by the target selection unit 45 for cause identification from the storage unit 32, and recalculates the degree of anomaly for the anomaly narrowed down by the target selection unit 45. The calculated degree of anomaly is compared with a predetermined threshold value to determine the presence or absence of an anomaly. This process of the cause identification unit 49 is substantially similar to that of the anomaly detection unit 33.
[0080] In order to identify the cause of an anomaly, a tree diagram is created in advance for each anomaly, in which the anomaly is treated as a fundamental event and the causes of the anomaly are hierarchically broken down into primary, secondary, ... This tree diagram is sometimes called a fault tree. The fault tree is stored in an appropriate storage unit of the condition diagnosis server 30.
[0081] For example, consider a case where the machine 100 is a gas turbine having a gas generator, and the sensor 10 includes a position sensor attached near the main shaft of the gas generator. As shown in FIG. 7, for example, when the root event is "vibration of the gas generator main shaft," the fault tree includes a tree in which the primary causes are "change in bearing," "change in rotating body," "change in lubrication state," ... Causes (secondary causes) of "change in bearing" include "abnormality of bearing." Causes (secondary causes) of "change in rotating body" include "abnormality of rotating body." Causes (tertiary causes) of "abnormality of rotating body" include "damage to rotating body parts."
[0082] The cause identification unit 49 stores a predetermined formula for calculating a score for each of the terminal causes included in the fault tree FT1 of FIG. 7. The score indicates the probability that the cause is the cause of the abnormality that has occurred this time. For example, in the above-mentioned "bearing abnormality," the formula for calculating the score can be a sum of conditional raw scores that are determined in advance, such as point A when there is a change in the detection value of the temperature sensor that detects the bearing metal temperature, point B when the differential pressure calculated from the detection value of the pressure sensor upstream of the lubricating oil filter of the bearing and the detection value of the pressure sensor downstream of the bearing is increased compared to a predetermined period before, etc. Each raw score is set to be high when the corresponding condition strongly suggests the cause of the abnormality. The raw scores may be set in consideration of the seriousness of the situation expected in the future when the condition is satisfied.
[0083] The position sensor, temperature sensor, and pressure sensor described in the above calculation explanation are all included in the above-mentioned sensor 10. Therefore, the detection value of each sensor constitutes any one of the above-mentioned data series.
[0084] By monitoring the differential data values derived from the above-mentioned position sensor and using, for example, a method for detecting anomalies that deviate from normal space, an anomaly in the "spindle vibration" can be detected. When an anomaly in the "spindle vibration" is detected, the cause identification unit 49 calculates the above-mentioned score for all end causes included in the fault tree FT1 that has the anomaly as its root event. However, data series (data values) that belong to a group that has been removed by the target narrowing down unit 45 are not taken into consideration in the score calculation, and are considered to not satisfy the condition for the conditional raw score. This makes it possible to reduce the calculation load for identifying the cause.
[0085] When the configuration of the machine 100 is complex and the number of sensors 10 is large, the number of terminal causes included in the fault tree is large, and the amount of calculation required to calculate each score is also large. In particular, in a gas turbine, the data values that can usually be taken vary greatly depending on operating conditions such as the intake air temperature or the rotation speed, so that anomaly judgment tends to be complicated. If tens of types of anomalies are detected for each of hundreds of data series, the number of raw score conditions included in all the fault trees may be tens of thousands or more. In this regard, in the present embodiment, the calculation for identifying the cause is performed in a form that is narrowed down in advance from the viewpoint of the anomaly judgment method and the group as described above, so that the effect of reducing the calculation load is remarkable.
[0086] When the scores are calculated for all the end causes, the cause identification unit 49 creates cause analysis data including the end causes and the scores obtained for the causes. This allows the identification of the cause. This cause analysis data is used when the report data creation unit 50 creates report data. Based on this report data, the client computer 90 displays the end causes on the display, for example, in descending order of score. This allows the operator to correctly understand the cause of the abnormality and take appropriate action.
[0087] As described above, the condition diagnosis server 30 of the present embodiment detects an abnormality of the machine 100. The condition diagnosis server 30 includes an abnormality detection unit 33, a factor analysis unit 39, a target selection unit 45, and a cause identification unit 49. The abnormality detection unit 33 inputs a plurality of data series, each of which is a string of data values that represents the state of the machine 100, calculates an abnormal value that represents the degree of abnormality of the data value based on a predetermined abnormality determination method, and determines the presence or absence of an abnormality based on the abnormal value. The factor analysis unit 39 calculates an importance that indicates the degree to which the data value contributes to the abnormal value for each of the plurality of data series. The target selection unit 45 narrows down the abnormality and data series, the cause of which is to be identified, from a plurality of predetermined abnormalities and a plurality of data series, based on the abnormal value acquired by the abnormality detection unit 33 and the importance of each data series acquired by the factor analysis unit 39. The cause identification unit 49 identifies the cause of the abnormality that occurred in the machine 100 within the range of the abnormality and data series narrowed down by the target selection unit 45.
[0088] This allows an operator to know the cause of an anomaly very soon after it is detected. Therefore, based on the identified cause, an operator can take an early and appropriate action to deal with the anomaly. In addition, because the cause is identified within a range of anomalies and data values narrowed down in advance, the calculation load can be effectively reduced.
[0089] In the condition diagnosis server 30 of this embodiment, a fault tree FT1 for identifying the cause of an abnormality is determined in advance for each abnormality. The cause identification unit 49 identifies the cause of the abnormality according to the fault tree FT1 within the range of the data series narrowed down by the target narrowing down unit 45.
[0090] This makes it possible to appropriately identify the cause of a detected abnormality while reducing the calculation load.
[0091] In the condition diagnosis server 30 of this embodiment, the target selection unit 45 narrows down the data series by selecting some data series from a plurality of data series in descending order of importance.
[0092] This allows the cause of the anomaly to be identified without using data from a data series with a relatively low level of importance, thereby reducing the calculation load and enabling the cause of the anomaly to be identified with high accuracy.
[0093] In the condition diagnosis server 30 of this embodiment, a screening process is performed on the data values constituting the data series to extract data values corresponding to the period during which the machine 100 is in operation (step S102 in FIG. 6). The anomaly detection unit 33 performs anomaly detection on the data values after the screening process.
[0094] This allows abnormality detection to be performed based on data values during the operation time of the machine 100.
[0095] In the condition diagnosis server 30 of this embodiment, the anomaly detection unit 33 calculates an anomaly value based on a change over time in the data value in the data series.
[0096] This makes it possible to detect changes in data values over time as anomalies, enabling a wide range of types of anomalies to be detected and their causes identified.
[0097] Although the preferred embodiment of the present disclosure has been described above, the above configuration can be modified, for example, as follows. A single modification may be made, or multiple modifications may be made in any combination.
[0098] The condition diagnosis server 30 may include the sensor 10 and the data collection device 20 .
[0099] Some of the abnormality detection unit 33, the factor analysis unit 39, the target selection unit 45, and the cause identification unit 49 may be realized by hardware different from that of the condition diagnosis server 30.
[0100] The types of abnormalities detected by the abnormality detection unit 33 are not limited to those shown in Fig. 3, and can be changed to detect various types of abnormalities. The same applies to the cause analysis performed by the cause analysis unit 39 and the identification of the cause of the abnormality performed by the cause identification unit 49.
[0101] The derivation, screening, filtering, and the like of the data series described in FIG. 6 can also be performed at a stage before the data values are stored in the storage unit 32 (database).
[0102] As long as information relating the event (anomaly) to its cause is used, the cause of the anomaly may be identified using a method other than fault tree analysis.
[0103] The screening process shown in step S102 in FIG. 6 may be omitted.
[0104] The functions of the elements disclosed herein can be performed using circuits or processing circuits, including general purpose processors, special purpose processors, integrated circuits, Application Specific Integrated Circuits (ASICs), conventional circuits, and / or combinations thereof, configured or programmed to perform the disclosed functions. Processors are considered processing circuits or circuits because they include transistors and other circuits. In this disclosure, a circuit, unit, or means is hardware that performs the recited functions or hardware that is programmed to perform the recited functions. The hardware may be hardware disclosed herein or other known hardware that is programmed or configured to perform the recited functions. Where the hardware is a processor, which is considered a type of circuit, the circuit, means, or unit is a combination of hardware and software, and the software is used to configure the hardware and / or the processor. [Explanation of symbols]
[0105] 30 Status diagnosis server (anomaly detection device) 33 Anomaly detection unit 39 Factor Analysis Department 45 Target Selection Section 49 Cause identification department 100 machines 150 Condition diagnosis system (abnormality detection system) FT1 Fault Tree
Claims
1. An abnormality detection device that detects an abnormality in a machine, an anomaly detection unit that receives input of a plurality of data series, each of which is a string of data values that represent a state of the machine, calculates an anomaly value that represents the degree of anomaly in the data values based on a predetermined anomaly determination method, and determines the presence or absence of an anomaly based on the anomaly value; a factor analysis unit that calculates a degree of importance indicating a degree to which a data value contributes to the abnormal value for each of a plurality of data series; a target narrowing-down unit that narrows down anomalies and data series whose causes are to be identified from a plurality of predetermined anomalies and a plurality of the data series based on the abnormal value acquired by the anomaly detection unit and the importance of each of the data series acquired by the factor analysis unit; a cause identification unit that identifies a cause of the abnormality occurring in the machine within the range of the abnormality and the data series narrowed down by the target narrowing down unit; An anomaly detection device comprising:
2. The anomaly detection device according to claim 1 , a fault tree for identifying a cause of the abnormality is determined in advance according to the abnormality; The cause identification unit identifies a cause of the abnormality according to the fault tree within the range of the data series narrowed down by the target narrowing down unit.
3. The anomaly detection device according to claim 1 , The anomaly detection device, wherein the target narrowing down of the data series by the target narrowing down unit is performed by selecting a portion of the data series from the plurality of data series in descending order of importance.
4. The anomaly detection device according to claim 1 , a screening process is performed on the data values constituting the data series to extract data values corresponding to a period during which the machine is in operation; The anomaly detection unit detects anomalies in the data values after the screening process.
5. The anomaly detection device according to claim 1 , The anomaly detection device, wherein the anomaly detection unit calculates the anomaly value based on a temporal change in the data value in the data series.
6. An anomaly detection system for detecting an anomaly in a machine, comprising: an anomaly detection unit that receives input of a plurality of data series, each of which is a string of data values that represent a state of the machine, calculates an anomaly value that represents the degree of anomaly in the data values based on a predetermined anomaly determination method, and determines the presence or absence of an anomaly based on the anomaly value; a factor analysis unit that calculates a degree of importance indicating a degree to which a data value contributes to the abnormal value for each of a plurality of data series; a target narrowing-down unit that narrows down anomalies and data series whose causes are to be identified from a plurality of predetermined anomalies and a plurality of the data series based on the abnormal value acquired by the anomaly detection unit and the importance of each of the data series acquired by the factor analysis unit; a cause identification unit that identifies a cause of the abnormality occurring in the machine within the range of the abnormality and the data series narrowed down by the target narrowing down unit; An anomaly detection system comprising:
7. 1. A method for detecting an abnormality in a machine, comprising: inputting a plurality of data series, each of which is a string of data values representing a state of the machine, calculating an abnormality value representing the degree of abnormality of the data values based on a predetermined abnormality determination method, and determining the presence or absence of an abnormality based on the abnormality value; calculating a significance level indicating the degree to which a data value contributes to the abnormal value for each of a plurality of data series; narrowing down anomalies and data series whose causes are to be identified from a plurality of predetermined anomalies and a plurality of predetermined data series based on the abnormal values and the importance of each of the data series; An anomaly detection method for identifying a cause of an anomaly occurring in the machine within the narrowed-down range of the anomaly and the data series.
Citation Information
Patent Citations
Abnormality detection system, abnormality detection method, and program
JP2022084435A