Anomaly detection and fault isolation for vehicle sub-systems

By identifying and analyzing redundant subsystems within complex systems, the method effectively detects anomalies and isolates faults, addressing the challenges of deterioration detection in dynamic and sensor-data-rich environments.

JP2025087588APending Publication Date: 2025-06-10THE BOEING CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024182425
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-20
Filing Date
2024-10-18
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Deterioration detection and fault isolation in complex systems, such as aircraft, are challenging due to the difficulty in identifying signs of correlated deterioration from sensor data, which can vary widely under dynamic operating conditions and be masked by controller actions.

Method used

The method involves identifying three or more redundant subsystems, forming combinations of these subsystems, identifying the combination with the smallest variation, calculating nominal values for parameters within the first subsystem of this combination, and detecting anomalies based on these nominal values.

Benefits of technology

This approach enables accurate and computationally efficient detection of signs of degradation and failure in complex systems by leveraging redundant subsystems to establish baseline nominal values, thereby isolating anomalies and identifying their causes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025087588000001_ABST
    Figure 2025087588000001_ABST
Patent Text Reader

Abstract

To provide anomaly detection for complex systems such as vehicles.SOLUTION: An anomaly detection method includes: identifying a plurality of three or more redundant sub-systems in a system; forming 402 a plurality of combinations of the redundant sub-systems, each combination relating to a subset of the plurality of redundant sub-systems; identifying 404 a first combination with the least variability among sub-systems, from among the plurality of combinations of redundant sub-systems; computing 406 one or more nominal values for one or more parameters of a first sub-system, of the plurality of sub-systems, using the first combination; and detecting 410 an anomaly in the first sub-system based on the computed one or more nominal values.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Some aspects of the present disclosure relate to anomaly detection in complex systems such as vehicles.

Background Art

[0002] Deterioration detection and fault isolation in complex systems (e.g., aircraft and other vehicles, or other complex systems) are very difficult. For example, anomalies in a particular aircraft subsystem can be detected before failure by identifying signs of correlated deterioration as features. However, signs of deterioration are not always reflected in direct sensor measurements. In addition, identifying anomalies typically requires characterizing and deriving the normal behavior of components under various operating conditions, which is very difficult because sensor data can vary widely under dynamic operating conditions and because the associated controller can operate to cancel out deterioration. The difficulty is further increased by limited sensor data or few sample data.

Summary of the Invention

[0003] Aspects of the invention include a method. The method includes identifying three or more redundant subsystems in a system. The method further includes forming a plurality of combinations of the redundant subsystems, each combination being a subset of the redundant subsystems. The method further includes identifying a first combination having the smallest variation between subsystems among the plurality of combinations of the redundant subsystems. The method further includes calculating one or more nominal values of one or more parameters for a first subsystem of the plurality of subsystems using the first combination, and detecting an anomaly in the first subsystem based on the calculated one or more nominal values.

[0004] The inventive aspect further includes a system, the system including one or more processors and one or more memories storing a program, the program causing processing to be executed in any combination of the one or more processors. The processing includes identifying three or more redundant subsystems in the system. The processing further includes forming a plurality of combinations of the plurality of redundant subsystems, each combination being a subset of the plurality of redundant subsystems. The processing further includes identifying a first combination among the plurality of combinations of the redundant subsystems that has the smallest variation among the subsystems. The processing further includes, for a first subsystem among the plurality of subsystems, calculating one or more nominal values of one or more parameters using the first combination, and detecting an anomaly in the first subsystem based on the calculated one or more nominal values.

[0005] The inventive aspect further includes a computer program product including a computer-readable non-transitory storage medium having computer-readable program code incorporated therein, the computer-readable program code being executable by one or more computer processors to thereby cause processing to be executed. The processing includes identifying three or more redundant subsystems in the system. The processing further includes forming a plurality of combinations of the plurality of redundant subsystems, each combination being a subset of the plurality of redundant subsystems. The processing further includes identifying a first combination among the plurality of combinations of the redundant subsystems that has the smallest variation among the subsystems. The processing further includes, for a first subsystem among the plurality of subsystems, calculating one or more nominal values of one or more parameters using the first combination, and detecting an anomaly in the first subsystem based on the calculated one or more nominal values.

[0006] In any of the above-described aspects of the invention, further, the system is an aircraft, and the three or more redundant subsystems are redundant subsystems in the aircraft.

[0007] In any of the above-described aspects of the invention, further, identifying the first combination having the smallest variation is based on sensor values measured for one or more subsystems and at least one of (i) physical-based parameters calculated for the one or more subsystems or (ii) parameters from a digital twin for the one or more subsystems.

[0008] In any of the above-described aspects of the invention, further, identifying the first combination having the smallest variation is based on both physical-based parameters calculated for the one or more subsystems and parameters from the digital twin for the one or more subsystems.

[0009] In any of the above-described aspects of the invention, further, for the first subsystem among the plurality of subsystems, calculating the one or more nominal values of the one or more parameters using the first combination includes averaging each of the one or more parameters across all of the subsystems in the first combination.

[0010] In any of the above-described aspects of the invention, further, identifying the first combination having the smallest variation among the plurality of combinations of the redundant subsystems further includes identifying one or more outliers excluded from the first combination.

[0011] In any of the above-described aspects of the invention, further, detecting an abnormality in the first subsystem based on the calculated one or more nominal values includes determining a health index of the subsystem by calculating at least one of a cosine similarity or an Euclidean distance between the calculated one or more nominal values and a plurality of parameters in the first subsystem.

[0012] In any of the above-described aspects of the invention, further, determining the health index of the first subsystem is based on calculating both the cosine similarity and the Euclidean distance between the calculated one or more nominal values and the plurality of parameters in the subsystem.

[0013] In any of the above-described aspects of the invention, further, the method or process further includes identifying a first component that is at least a partial cause of the abnormality in the first subsystem.

[0014] In any of the above-described aspects of the invention, further, identifying a first component that is at least a partial cause of the abnormality in the first subsystem further includes using an inference algorithm to identify the first component based on the abnormality.

[0015] In any of the above-described aspects of the invention, further, the inference algorithm is a Bayesian network trained based on historical data related to the operation of the aircraft.

Brief Description of the Drawings

[0016] For a more detailed understanding of the above features, the above summary will be described more specifically with reference to exemplary aspects. Some of these exemplary aspects are shown in the accompanying drawings.

[0017]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Embodiments for Carrying Out the Invention

[0018] One or more aspects of the present disclosure provide anomaly detection and advanced fault isolation for complex systems (such as aircraft and other vehicles). In one aspect, the complex system has multiply redundant subsystems. Relative or comparative features can be calculated based on the nominal value of each feature, and the nominal value can be dynamically estimated for each data sample (e.g., an aircraft flight leg or flight segment, or each sample time). This approach is particularly suitable for subsystems that are more redundant than dual (e.g., triple or more redundant), which is very common in aircraft.

[0019] In one aspect, initial features are calculated from direct sensor measurements, physics based features are calculated, and parameters are estimated from a digital twin. The nominal value of each feature can be dynamically calculated by averaging the features of two or more subsystems that exhibit similar behavior for each operating segment (e.g., an aircraft flight leg). The similarity between subsystems can be calculated using a similarity score or any other suitable technique.

[0020] In one aspect, next, a more advanced feature amount is calculated from the differences obtained by comparing the initial feature amounts with their respective nominal values, and statistical feature amounts of these differences are derived based on time-series data spanning multiple operation segments (for example, multiple flight legs). The health index of each subsystem can be estimated based on the calculation of Euclidean distance and cosine similarity (or any other suitable technique). By comparing the health indices of multiple consecutive operation intervals (for example, flight legs), a subsystem with degradation can be isolated. Next, the degradation data across multiple operation intervals (for example, flight legs) is associated with a fault label based on historical data obtained in fleet operation before triggering a fault event (for example, a maintenance message). The labeled historical data is used for training an inference algorithm (for example, a Bayesian network or other suitable machine learning (ML) model), which is used for detecting the degradation location and isolating the degraded subsystem components. Details of this will be described later in relation to FIGS. 1 and 3-6.

[0021] Note that the techniques described above or later in relation to FIGS. 3-6 are suitable for systems including multiple redundant subsystems, but additional techniques can be used to identify nominal values in anomaly detection that do not require redundant subsystems. For example, the nominal value of a specific subsystem (for example, a subsystem of a specific aircraft tail) can be identified using the historical data of the subsystem, and this nominal value can be used to perform anomaly detection and fault isolation. Details of this will be described later in relation to FIGS. 1 and 7-8. In another example, the nominal value of the subsystems included in a fleet can be identified using the historical data of the subsystems in a group of systems (for example, a group of aircraft (fleet)), and this nominal value can be used to perform anomaly detection and fault isolation. Details of this will be described later in relation to FIGS. 1 and 7-10.

[0022] In one aspect, one or more of these technologies have significant advantages over the prior art. For example, the progression of degradation is often very slow, making it extremely difficult to identify changes over time and resulting in a high computational load. Additionally, since automated systems can counteract degradation, it becomes even more difficult to detect signs of failure. By using one or more of the technologies described herein, it is possible to detect signs of degradation and failure in an accurate and computationally efficient manner.

[0023] FIG. 1 is a diagram showing one aspect of anomaly detection and fault isolation of subsystems with different levels of redundancy. Computer environment 100 uses a plurality of input values to perform either or both of anomaly detection and fault isolation of subsystems in a complex system (e.g., an aircraft or other vehicle, or any other suitable complex system). As shown, the inputs include sensor values 102, physics-based features 104, and digital twin values 106. Note that these are merely examples, and any subset of these values may be used, or other additional values may be used (e.g., instead of or in addition to any combination of sensor values 102, physics-based features 104, and digital twin values 106). For example, if the physics-based features 104 are sufficiently robust, the digital twin values 106 are not required (and vice versa).

[0024] In one aspect, the sensor values 102 are measurement values (e.g., directly measured values) related to the operation of the target subsystem. The physics-based features 104 are values calculated from underlying data (e.g., based on the measured sensor values 102). For example, if the subsystem is a capacitor, the heat transfer rate during operation is calculated using sensor data and is not directly measured. Note that this is merely an example, and any suitable physics-based features can be used. The digital twin values 106 are values generated using a model that replicates the target physical subsystem. For example, the target physical subsystem can be modeled to generate a digital twin, and various digital twin values 106 can be generated using this. Details of these values will be described later in relation to FIG. 6.

[0025] In one aspect, in block 112, sensor value 102, physical - based feature 104, and digital twin value are combined. These values are compared with nominal feature values 122 generated in block 120 by comparator 150, and comparative features and feature errors 154 are generated. Then, the comparative features and feature errors 154 are used to identify a fault 156 separated from the detected anomaly.

[0026] In one aspect, any of several different techniques can be used to generate the nominal feature values 122 in block 120. For example, a system includes a plurality of redundant subsystems. As an example, an aircraft includes a plurality of redundant cabin air - compression subsystems. These subsystems can be monitored using an aircraft condition monitoring system (ACMS). In block 130, if the target subsystem includes more than two (e.g., three or more) redundant subsystems, the nominal value is calculated using redundancy in block 132. Details of this will be described later in relation to FIGS. 3 - 6.

[0027] In one aspect, if the redundancy of the target subsystem is two or less, the nominal value is calculated either in block 142 or block 144. For example, in block 142, the nominal value is calculated for a particular subsystem (e.g., a subsystem of a particular aircraft tail) using the aircraft's historical data. Details of this will be described later in relation to FIGS. 7 - 8. In other examples, in block 144, the nominal value is calculated at the fleet level (e.g., across an entire aircraft fleet) for a particular subsystem in all aircraft in a given aircraft fleet. Details of this will be described later in relation to FIGS. 9 - 10.

[0028] Figure 2 is a diagram showing one aspect of the controller 200 for detecting abnormalities and isolating faults in a subsystem. In one aspect, the controller 200 can be used for one or more aspects of detecting abnormalities and isolating faults as shown in the computer environment 100 of FIG. 1. The controller 200 includes a processor 202, a memory 210, and a network component 220. The processor 202 generally acquires and executes program instructions stored in the memory 210. The illustrated processor 202 represents, for example, a single central processing unit (CPU), multiple CPUs, a single CPU including multiple processing cores, a graphics processing unit (GPU) having multiple execution paths, and the like.

[0029] The network component 220 includes components necessary for the controller 200 to interact with components on the network (see, for example, FIG. 1). For example, the controller 200 can use the network component 220 to interact with remote storage or computer nodes (e.g., inside or outside the computer environment 100).

[0030] The controller 200 can interact with other elements in the system via a local area network (LAN) such as a corporate network, a wide area network (WAN), the Internet, or any other suitable network. The network component 220 includes interface components and related software for each of the wired, WiFi, or cellular networks, enabling communication between the controller 200 and the communication network.

[0031] Note that, in the illustration, the memory 210 is shown as a single entity, but the memory 210 may include one or more memory devices having a plurality of memory blocks associated with physical addresses, such as, for example, random access memory (RAM), read only memory (ROM), flash memory, or other types of volatile and non-volatile memory. The memory 210 generally includes program code for performing various functions related to the use of the controller 200. The program code is, in a general description, various functional “applications” and “services” included in the memory 210, but in alternative embodiments may include different functions or combinations of functions. In the memory 210, the anomaly detection service 212 performs anomaly detection of subsystems (e.g., within an aircraft, vehicle, or other suitable system). The fault isolation service 214 facilitates the isolation of faults in a subsystem (e.g., the subsystem in which an anomaly has been detected using the anomaly detection service 212). Details of this will be described below with reference to the drawings.

[0032] In FIG. 2, the anomaly detection service 212 and the fault isolation service 214 are shown as being included in the memory 210, but this is merely an example for illustrative purposes. More generally, the controller 200 includes one or more computer platforms, such as a computer server, for example, which may be installed in the same location or may constitute a distributed system interconnected with each other. Examples of distributed systems include cloud-based systems (e.g., public cloud, private cloud, hybrid cloud, or any other suitable cloud-based system). In this case, the processor 202 and the memory 210 may correspond to processor resources and memory resources distributed in a computer environment.

[0033] FIG. 3 illustrates one aspect of anomaly detection and fault isolation using redundancy. In one aspect, a system 300 (e.g., an aircraft or other vehicle, or any other suitable system) includes a plurality of redundant subsystems. For example, an aircraft includes a left cabin air compressor 310 and a right cabin air compressor 320. The cabin air compressors 310 and 320 can each include a plurality of redundant air compression subsystems. For example, the left cabin air compressor 310 can include an air compression subsystem 312 and a redundant air compression subsystem 314. The right cabin air compressor 320 can include an air compression subsystem 322 and a redundant air compression subsystem 324.

[0034] In one aspect, the air compression subsystems 312, 314, 322, and 324 perform overlapping operations with each other. That is, the system 300 includes four redundant subsystems, and the nominal values for anomaly detection can be calculated using these redundant subsystems (see, e.g., the above description related to block 132 in FIG. 1). For example, a combination of subsystems with the least variability can be identified. Further, combinations of redundant subsystems can be formed and used for detecting nominal values. The local nominal value can be calculated by averaging each parameter across the identified combination, thereby determining a health index for each subsystem. The health index can be used for anomaly detection and for identifying the subsystem containing the anomaly, and then a reasoning algorithm can be trained and used for identifying the component that is the cause of the degradation. This will be described in more detail below with reference to FIG. 4.

[0035] FIG. 4 is a flowchart 400 showing one aspect of anomaly detection and fault isolation using redundancy. At block 402, an anomaly detection service (e.g., anomaly detection service 212 of FIG. 2) forms combinations of redundant subsystems. Note that the system includes more than two subsystems (see, e.g., FIG. 3). In one aspect, the anomaly detection service forms combinations by selecting combinations of subsets of redundant subsystems. For example, if the system in question includes three redundant subsystems A, B, and C, the anomaly detection service will form pairs of "A and B", "A and C", and "B and C". As another example, the system 300 shown in FIG. 3 includes four redundant pneumatic compression subsystems 312, 314, 322, and 324. In this case, the anomaly detection service can form multiple combinations of two subsystems (e.g., "312, 314", "312, 322", "312, 324", "314, 322", "314, 324", "322, 324"). Alternatively, multiple combinations of three subsystems can also be formed (e.g., "312, 314, 322", "312, 314, 324", "312, 322, 324", "314, 322, 324").

[0036] At block 404, the anomaly detection service identifies the combination of subsystems with the least variation (e.g., the combination with the least average variation across the entire combination). As described above, in one aspect, the system includes more than two redundant subsystems. The anomaly detection service can calculate the variation for each combination of subsystems (see, e.g., the above description related to block 402). The combination with the least variation can be used to identify anomalies (e.g., outliers). For example, the system shown in FIG. 3 includes four redundant pneumatic compression subsystems 312, 314, 322, and 324. Among these, if the variation in the combination of "312, 314, 322" (e.g., the variation between the subsystems included in the combination) is the least, the remaining subsystem (e.g., subsystem 324) is an outlier and is suggested to be anomalous.

[0037] In one aspect, the anomaly detection service can identify the combination of subsystems with the least variation using any combination of sensor values (e.g., sensor value 102 shown in FIG. 1), calculated physics-based feature quantities (e.g., physics-based feature quantity 104 shown in FIG. 1), and digital twin values (e.g., digital twin value 106 shown in FIG. 1). For example, all of the sensor value, the calculated physics-based feature quantity, and the digital twin value may be used to identify the variation in operation between subsystems. Alternatively, any suitable subset of the sensor value, the calculated physics-based feature quantity, and the digital twin value may be used. Details of this will be described later in relation to FIG. 6.

[0038] In block 406, the anomaly detection service can calculate the local nominal value (e.g., mean value) of each parameter by taking the average of the entire identified combination. In one aspect, the anomaly detection service uses the combination of redundant subsystems identified in block 404 described above. The anomaly detection service averages various parameters (e.g., detected sensor values) for each subsystem across all subsystems in the identified combination. This can generate a local nominal value while avoiding including outliers.

[0039] For example, as described above, assume that the combination of "312, 314, 322" is the combination with the least variation between subsystems and is identified in block 404. In this case, the anomaly detection service averages the sensor data points in all three of these subsystems "312, 314, 322" to identify the local nominal value of each parameter. This can exclude subsystem 324, which is likely to be an outlier.

[0040] In block 408, the anomaly detection service determines the health indicators of each redundant subsystem. For example, the anomaly detection service calculates either or both of the cosine similarity and Euclidean distance for all parameters of each subsystem using the local nominal values calculated in block 406. By using this, the health indicator of each subsystem can be calculated.

[0041] In block 410, the anomaly detection service detects anomalies and identifies the subsystem containing the anomaly. For example, the anomaly detection service can compare the behavior of a subsystem across multiple operating cycles (e.g., multiple flight legs of an aircraft) by calculating the health indicator of the subsystem for each of the multiple operating cycles. If a particular subsystem consistently shows a low health indicator (e.g., the lowest health indicator among the redundant subsystems included in the system), that subsystem is likely to contain an anomaly.

[0042] For example, as shown in FIG. 3, assume that an aircraft includes redundant pneumatic subsystems 312, 314, 322, and 324. Using the above-described technique related to block 408, the health indicators of these subsystems are calculated over three flight legs for each flight leg. If subsystem 314 continuously shows the lowest health indicator in all three flight legs, it can be identified that this subsystem has an anomaly.

[0043] In one aspect, numerous actions can be taken based on the detection of an anomaly. For example, a warning indicating the anomaly can be generated to prompt the maintenance personnel to inspect and repair the subsystem (e.g., before a failure occurs). In other examples, a process of automatically disabling or repairing the subsystem (e.g., automatic correction of software or hardware) can be executed. Note that these are merely examples, and any appropriate action is possible.

[0044] In block 412, the anomaly detection service executes training of an inference algorithm (e.g., a Bayesian network). For example, historical data spanning multiple flight legs can be used for training the Bayesian network, thereby enabling identification of components that are the cause of a failure among subsystems containing anomalies. This training may include associating degradation labels with a discretized feature set. Note that the Bayesian network is merely an example, and any suitable inference algorithm (e.g., a suitable machine learning (ML) model) can be used. Details of this will be described later in relation to FIG. 5.

[0045] In block 414, the anomaly detection service separates the component that is the cause of the failure using the inference algorithm. For example, the anomaly detection service can use the operation data of the subsystem containing the anomaly to estimate, by means of the inference algorithm, the component that is the cause of the failure.

[0046] In one aspect, the separation of the component can be used for a number of actions. For example, a warning indicating an anomaly can be generated to prompt the maintenance staff to inspect the component that is the cause of the failure (e.g., before the occurrence of a failure). In other examples, a process of automatically disabling or repairing the component (e.g., automatic correction of software or hardware) can be executed. Note that these are merely examples, and any suitable actions are possible.

[0047] FIG. 5 shows an example embodiment of generating labeled data for fault isolation based on an inference network. Graph 510 shows zones of sensor data, which includes a fail zone 512 and a degradation zone 514. Further, graph 510 also shows region A and region B. In one embodiment, region A represents a nominal zone and region B represents a degradation zone. For example, graph 510 shows a flight leg that is continuous from left to right. In the first region A indicated by reference numeral 516A, the sensor values are normal. This suggests that the subsystem is likely operating normally. In the degradation zone B indicated by reference numeral 514, the sensor values of the subsystem suggest degradation, and then it transitions to the fail zone 512 and eventually fails. The subsystem is then repaired (e.g., a failed component or part is repaired or replaced) and shows normal operation again in the second region A indicated by reference numeral 516B.

[0048] Table 520 shows the association of a discretized feature set used in an inference network (e.g., a Bayesian network). In one embodiment, table 520 shows an example of the association of features of sensor data spanning multiple flight legs, as shown in graph 510. Each column 522A - 522N of the table contains degradation data, and each row corresponds to one flight leg (e.g., of an aircraft). This table shows the history of degradation data and can be used for training an inference algorithm for fault isolation.

[0049] In one aspect, for each feature of a flight phase (e.g., ground taxi, takeoff, cruise, or any other suitable flight phase) in one flight leg, aggregated features (e.g., mean, standard deviation, z - score, or other aggregated features) are calculated. The calculated aggregated features are classified into various state categories (e.g., "high", "low", "healthy", "deteriorated", or other suitable state categories) corresponding to the nominal values of each aggregated feature. A table (e.g., Table 520) is created for all flight legs in the fleet. In the deterioration stage, the component failure mode is associated with the adjacent historical ground truth replacement for each row of the table. Once this data is created for the entire fleet, various techniques such as multi - class classification, inference algorithms (e.g., Bayesian network), or pattern recognition approaches can be applied to identify the deteriorated components.

[0050] Figure 6 is a flowchart showing one aspect of an initial set of absolute features. In one aspect, Figure 6 corresponds to block 404 of Figure 4. As described above, the anomaly detection service in one aspect (e.g., the anomaly detection service 212 shown in Figure 2) uses any combination of sensor values (e.g., the sensor values 102 shown in Figure 1), calculated physics - based features (e.g., the physics - based features 104 shown in Figure 1), and digital twin values (e.g., the digital twin values 106 shown in Figure 1) to identify the average variation in a selected combination of subsystems (e.g., the combination selected as described above in relation to block 402 of Figure 4).

[0051] In block 602, the anomaly detection service identifies the measured sensor parameters. In one aspect, one or more sensors can be used to measure various sensor values for one subsystem. These sensor parameters represent the directly measured state of the subsystem.

[0052] In block 604, the anomaly detection service calculates one or more physics-based parameters. In one aspect, the physics-based parameters are not directly measured values. The physics-based parameters are values calculated using sensor data. For example, the heat transfer rate of an air compression subsystem (e.g., the air compression subsystems 312, 314, 322, and 324 shown in FIG. 3) is obtained by calculation. That is, the heat transfer rate is not directly measured but is calculated from the measured sensor values. Note that this is just an example, and any suitable physics-based feature can be used.

[0053] In block 606, the anomaly detection service determines parameters from the digital twin. In one aspect, the digital twin is a virtual representation of a physical asset (e.g., realized by data and simulators). By using the digital twin, real-time prediction, optimization, monitoring, control, and improvement of decision-making are possible (there are also many other applications). For example, the digital twin is a digital representation that appropriately synchronizes useful information (e.g., structure, function, and behavior) of a physical entity in a virtual space, enabling the fusion of physical and virtual states through information exchange. In one aspect, the digital twin is a digital replica of an operating physical asset and has one or more of the characteristics of individuality, adaptability, continuity, and scalability.

[0054] In one aspect, the anomaly detection service uses (or generates) a digital twin of a target subsystem (e.g., the pneumatic compression subsystem shown in FIG. 3). The anomaly detection service uses the digital twin to identify the parameters of the subsystem under various operating conditions and virtual scenarios. The anomaly detection service uses these parameters to identify the average variation in all redundant subsystems, as described above in connection with FIG. 4.

[0055] FIG. 7 is a flowchart 700 showing one aspect of anomaly detection and fault isolation of a subsystem in a particular aircraft tail. In one aspect, FIGS. 3-6 show anomaly detection and fault isolation of multiple redundant subsystems (e.g., more than two redundant subsystems as shown in FIG. 3). This corresponds to block 132 of FIG. 1.

[0056] FIG. 7 corresponds to block 142 and shows the process of performing anomaly detection of a subsystem in a particular aircraft tail using the historical data of the subsystem (e.g., without requiring multiple redundant subsystems). At block 702, the anomaly detection service (e.g., the anomaly detection service 212 shown in FIG. 2) identifies a chain of operations in a particular system (e.g., a particular aircraft tail). For example, the anomaly detection service may identify a series of flight legs (e.g., 40 flight legs) for a particular aircraft tail. The anomaly detection service may use the historical warnings for the aircraft to identify a series of flight legs. For example, the anomaly detection service can identify past warnings in a particular aircraft and then identify the flight legs separated from that warning (e.g., before or after the warning) as a series of flight legs.

[0057] In block 704, the anomaly detection service downloads sensor data regarding the series of operations. For example, in block 702, the anomaly detection service may identify the history of a series of flight legs (e.g., 40 flight legs) in an aircraft. The anomaly detection service may download sensor data regarding one or more specific subsystems in this series of flight legs.

[0058] In block 706, the anomaly detection service clusters the operating phases based on the operating conditions. For example, the anomaly detection service clusters the flight phases based on the operating conditions during flight. The operating conditions include, for example, altitude, speed (e.g., Mach number), throttle position, flight phase, and any other suitable operating conditions.

[0059] In block 708, the anomaly detection service calculates the average value, maximum value, and minimum value of the entire operating phase cluster for the selected parameter. For example, the anomaly detection service can calculate the average value, maximum value, and minimum value (or any combination thereof) of the entire operating phase cluster for one or more parameters of the target subsystem.

[0060] In block 710, the anomaly detection service identifies and removes outliers (if any) from the data. For example, the anomaly detection service may identify abnormal parameter values using the average value, maximum value, and minimum value calculated in block 708. This includes parameter values that deviate significantly from the average value based on statistical analysis.

[0061] In block 712, the anomaly detection service determines whether there is a local nominal value. In one aspect, the local nominal value is a user-specified setting parameter. If such a value exists, the process proceeds to block 716. If such a value does not exist, the process proceeds to block 714. In block 714, the anomaly detection service identifies anomalies considering all series of sensor data in the system. In block 716, the anomaly detection service considers the most recent series of sensor data (e.g., not all series of data). In block 718, the anomaly detection service recomputes the average value, maximum value, and minimum value (or any combination thereof) of the entire operation phase cluster for the parameter, considering only the selected series of sensor data.

[0062] In one aspect, the nominal value of the target subsystem is identified using the technique shown in FIG. 7 (e.g., based on the operation history of a specific system, rather than based on a plurality of redundant subsystems as shown in FIGS. 3-6). Once the local nominal value is identified, thereafter, anomaly detection and fault isolation can be performed using the same techniques as described above in relation to blocks 408-414. For example, the anomaly detection service can calculate a health index of the target subsystem using the nominal value, detect anomalies, identify the subsystem containing the anomalies, execute training of an inference algorithm for fault isolation, and use this inference algorithm to identify the component causing the fault. All of these details have been described above in relation to blocks 408, 410, 412, and 414 of FIG. 4.

[0063] FIG. 8 further shows one aspect of the detection of anomalies and isolation of faults in a particular aircraft tail assembly. In one aspect, FIG. 8 shows some characteristic (e.g., a parameter, or a combination of parameters) in the subsystem over a plurality of flight legs. The y-axis represents the value of that characteristic in the flight leg, and the x-axis represents the number of flight legs. The line indicated by reference numeral 814 shows the nominal value of the system (e.g., the value determined using the above-described technique related to FIG. 7). By comparing the variations in the graph with the nominal value 814, anomalies in the operation of the subsystem can be identified.

[0064] For example, at 810, a degradation or fault in the subsystem is corrected. For example, a maintenance message is triggered and a component replacement or other appropriate correction is made. After 810, the characteristic shown by the graph (e.g., a parameter of the subsystem, or a combination of parameters) has increased, suggesting an improvement in operation. At 812, a degradation alert is triggered (e.g., associated with a decrease in the characteristic shown by the graph). In one aspect, the characteristic shown by the graph falls within an average value (e.g., standard deviation plus or minus 3) based on a plurality of flight legs (e.g., 15 flight legs) at 816.

[0065] FIG. 9 is a flowchart 900 showing one aspect of the detection of anomalies and isolation of faults in a certain subsystem in all aircraft of a fleet. In one aspect, FIGS. 3 - 6 show the detection of anomalies and separation of faults in a plurality of redundant subsystems (e.g., more than two redundant subsystems as shown in FIG. 3). This corresponds to block 132 of FIG. 1.

[0066] FIG. 9 corresponds to block 144 and shows a process of detecting an abnormality in a certain subsystem in all aircraft of a fleet using the historical data of the fleet (for example, not requiring a plurality of redundant subsystems). In block 902, an abnormality detection service (for example, the abnormality detection service 212 shown in FIG. 2) identifies a series of operations in a group of systems (for example, a group of aircraft (fleet)). For example, the abnormality detection service identifies a series of flight legs for an aircraft fleet. The abnormality detection service can utilize the history of past warnings in the fleet for identifying a series of flight legs. For example, the abnormality detection service can identify past warnings for aircraft in the fleet and then identify a series of flight legs separated from that warning (for example, before and after the warning).

[0067] In block 904, the abnormality detection service downloads sensor data regarding the series of operations. For example, in block 902, the abnormality detection service identifies a series of flight leg histories for an aircraft fleet. The abnormality detection service downloads sensor data regarding one or more specific subsystems in this series of flight legs.

[0068] In block 906, the abnormality detection service clusters operation phases based on operation conditions. For example, the abnormality detection service clusters flight phases based on in - flight operation conditions. Operation conditions include, for example, altitude, speed (for example, Mach number), throttle position, flight phase, and any other suitable operation conditions.

[0069] In block 908, the abnormality detection service calculates the average value, maximum value, and minimum value of the entire operation - phase cluster for a selected parameter. For example, the abnormality detection service can calculate the average value, maximum value, and minimum value (or any combination thereof) of the entire various operation - phase clusters for one or more parameters of a target subsystem.

[0070] In block 910, the anomaly detection service identifies (if any) outliers and removes them from the data. For example, the anomaly detection service may identify abnormal parameter values using the mean, maximum, and minimum values calculated in block 908. This includes parameter values that deviate significantly from the mean based on statistical analysis.

[0071] In block 912, the anomaly detection service recalculates the mean, maximum, and minimum values (or any combination thereof) of the entire operation cluster for the said parameter. For example, the anomaly detection service can calculate the mean, maximum, and minimum values after excluding outliers from the data in block 910 (e.g., without including outlier data).

[0072] In one aspect, the nominal value of the target subsystem is identified using the technique shown in FIG. 9 (e.g., based on the operation history of a group of subsystems rather than based on a plurality of redundant subsystems as shown in FIGS. 3 - 6). Once the fleet-level nominal value is calculated, then, using the same techniques as described above in relation to blocks 408 - 414, anomaly detection and fault isolation can be performed. For example, the anomaly detection service can calculate the health index of the target subsystem using the nominal value, detect anomalies, identify the subsystem containing the anomaly, execute the training of the inference algorithm for fault isolation, and use this inference algorithm to identify the component causing the fault. All of these details have been described above in relation to blocks 408, 410, 412, and 414 of FIG. 4.

[0073] FIG. 10 is a diagram showing one aspect of anomaly detection and fault isolation of a certain subsystem in all aircraft of a fleet. Graph 1010 shows the statistics (e.g., average value, maximum value, minimum value) of parameters in each normal series of flight legs among the flight leg histories of the fleet's aircraft. In one aspect, point 1012 indicates the nominal value (e.g., calculated using the technique described with reference to FIG. 9), while data point 1014 indicates a value different from the nominal value and can be used for anomaly detection. Table 1020 shows a plurality of chains of flight legs for a certain aircraft and represents the legs that are most likely to be normal flight legs, as described above in relation to block 902 of FIG. 9.

[0074] In the present disclosure, various aspects have been referred to. However, the present disclosure is not limited to the specific aspects described. Rather, in implementing and practicing the teachings of the present disclosure, it is assumed that these features and elements can be arbitrarily combined regardless of whether they are related to separate aspects. In addition, when an element of the present disclosure is described as "at least one of A and B", aspects including only element A, aspects including only element B, and aspects including both element A and element B are each assumed. In addition, even if some aspects may have effects not present in other solutions or prior art, whether a certain aspect has a specific effect is not a limiting matter of the present disclosure. Therefore, the aspects, features, aspects, and effects described in the present disclosure are merely examples and are not considered to be components or limitations of the appended claims unless explicitly recited in the claims. Similarly, reference to "the present invention" should not be construed as a generalization of the inventive subject matter of the present disclosure unless explicitly recited in the claims, nor should it be construed as a component or limitation of the appended claims.

[0075] As will be understood by those skilled in the art, the aspects described herein can be implemented as a system, method, or computer program product. Accordingly, the forms of implementing each aspect include not only the form of implementing all in hardware, but also the form of implementing all in software (including firmware, resident software, microcode, etc.), or the form of implementing in combination with software and hardware. In this specification, these are generally referred to as "circuits", "modules", or "systems". Furthermore, the aspects described herein can also be implemented in the form of a computer program product that incorporates computer-readable program code of a computer program into one or more computer-readable storage media.

[0076] The program code incorporated in the computer-readable medium can be transmitted using any suitable medium, and such media include, but are not limited to, for example, wireless, wired, fiber optic cable, radio wave, etc., and also include any suitable combination thereof.

[0077] The computer program code for executing the operations of the aspects of the present disclosure can be described using any combination of one or more programming languages. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, etc., conventional procedural programming languages such as the "C" language, and other similar languages. The program code may all be executed on the user's computer, or part of it may be executed on the user's computer as a stand-alone software package. Alternatively, part of it may be executed on the user's computer and part of it may be executed on a remote computer or server. In this case, the remote computer can be connected to the user's computer via any type of network such as a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, via the Internet using an Internet service provider).

[0078] Aspects of the present disclosure are described as methods, apparatus (systems), and computer program products according to aspects of the present disclosure with reference to flowcharts and block diagrams. It will be understood that each block in the flowcharts and block diagrams, and combinations of blocks, can be implemented by computer program instructions. By providing such computer program instructions to a processor of a general purpose computer, a special purpose processor, or other programmable data processing apparatus, a machine is formed that constitutes means for performing the functions / processes specified in the blocks of the flowcharts and block diagrams by instructions executed by these computers or the processors of the programmable data processing apparatus.

[0079] The computer program instructions can be stored in a computer-readable medium that can cause a computer, a programmable data processing apparatus, or other devices to function in a particular manner, whereby the instructions stored in the computer-readable medium form an article that includes instructions for implementing the functions / processes specified in the blocks of the flowcharts and block diagrams.

[0080] The computer program instructions can be arranged in a computer, other programmable data processing apparatus, or other devices, and by a computer process implemented by executing a series of processing steps in these computers, other programmable data processing apparatus, or other devices, the instructions executed in the computer, other programmable data processing apparatus, or other devices can implement the functions / processes specified in the blocks of the flowcharts and block diagrams.

[0081] The flowcharts and block diagrams shown illustrate the structure, functions, and processing of a system implementation, method, and computer program product capable of realizing various aspects of the present disclosure. In this regard, each block in the shown flowcharts or block diagrams may represent a module, segment, or portion of code that comprises one or more executable instructions for implementing a logical function. Additionally, in some alternative implementations, the functions indicated in the blocks may be executed in an order different from that shown. For example, the instructions shown in two consecutive blocks may, depending on the related functions, actually be executed substantially simultaneously, or in reverse order or a different order. Also, each block of the block diagrams or flowcharts, and combinations of blocks of the block diagrams or flowcharts, can be executed by a special-purpose hardware system for performing a particular function, process, or combination thereof, or by a combination of a special-purpose hardware system and computer instructions.

[0082] As described above, aspects of the present disclosure have been described, but other aspects and additional aspects can also be conceived without departing from the essence of the scope of the present disclosure, and the scope of the present disclosure is determined by the claims described below.

Claims

1. Identifying three or more redundant subsystems in the system; forming a plurality of combinations of the plurality of redundant subsystems, each combination being a subset of the plurality of redundant subsystems; identifying a first combination of the redundant subsystems that has the smallest variation between the subsystems from among the plurality of combinations of the redundant subsystems; calculating one or more nominal values ​​of one or more parameters for a first subsystem of the plurality of subsystems using the first combination; detecting an anomaly in the first subsystem based on the calculated one or more nominal values.

2. The method of claim 1 , wherein the system is an aircraft and the three or more redundant subsystems are redundant subsystems in the aircraft.

3. 3. The method of claim 2, wherein identifying the first combination with the least variability is based on measured sensor values ​​for one or more subsystems and at least one of: (i) calculated physics-based parameters for the one or more subsystems, or (ii) parameters from a digital twin for the one or more subsystems.

4. 4. The method of claim 3, wherein identifying the first combination with the least variation is based on both physics-based parameters calculated for the one or more subsystems and parameters from the digital twin for the one or more subsystems.

5. Determining the one or more nominal values ​​of the one or more parameters for the first subsystem of the plurality of subsystems using the first combination includes: The method of claim 2 , comprising averaging each of the one or more parameters across all subsystems in the first combination.

6. 6. The method of claim 5, wherein identifying a first combination of the multiple combinations of redundant subsystems that has the least variation between subsystems further comprises identifying one or more outliers that are excluded from the first combination.

7. Detecting an anomaly in the first subsystem based on the calculated one or more nominal values ​​includes:

3. The method of claim 2, comprising determining a health index for the first subsystem by calculating at least one of a cosine similarity or a Euclidean distance for a plurality of parameters in the first subsystem compared to the calculated one or more nominal values.

8. 8. The method of claim 7, wherein determining the health index of the first subsystem is based on calculating both the cosine similarity and the Euclidean distance for the plurality of parameters in that subsystem compared to the calculated one or more nominal values.

9. The method of claim 2 , further comprising identifying a first component that is at least partially responsible for the anomaly in the first subsystem.

10. Identifying the first component as at least partially responsible for the anomaly in the first subsystem includes: The method of claim 9 , further comprising using an inference algorithm to identify the first component based on the anomaly.

11. The method of claim 10 , wherein the inference algorithm is a Bayesian network trained based on historical data regarding operation of the aircraft.

12. one or more processors; and one or more memories storing a program, the program being configured to, in any combination of the one or more processors: Identifying three or more redundant subsystems in the system; forming a plurality of combinations of the plurality of redundant subsystems, each combination being a subset of the plurality of redundant subsystems; identifying a first combination of the redundant subsystems that has the smallest variation between the subsystems from among the plurality of combinations of the redundant subsystems; calculating one or more nominal values ​​of one or more parameters for a first subsystem of the plurality of subsystems using the first combination; detecting an anomaly in the first subsystem based on the calculated one or more nominal values.

13. 13. The system of claim 12, wherein the system is an aircraft and the three or more redundant subsystems are redundant subsystems in the aircraft.

14. 14. The system of claim 13, wherein identifying the first combination with least variability is based on measured sensor values ​​for one or more subsystems and at least one of: (i) calculated physics-based parameters for the one or more subsystems, or (ii) parameters from a digital twin for the one or more subsystems.

15. Determining, for the first subsystem of the plurality of subsystems, the one or more nominal values ​​of the one or more parameters using the first combination. averaging each of the one or more parameters across all subsystems in the first combination; Detecting an anomaly in the first subsystem based on the calculated one or more nominal values ​​includes:

14. The system of claim 13, further comprising determining a health index for the first subsystem by calculating at least one of a cosine similarity or a Euclidean distance for a plurality of parameters in the first subsystem compared to the calculated one or more nominal values.

16. identifying a first component that is at least partially responsible for the anomaly in the first subsystem, The system of claim 13 , further comprising using an inference algorithm to identify the first component based on the anomaly.

17. 1. A computer program product comprising a computer readable non-transitory storage medium having computer readable program code embodied therein, the computer readable program code being executable by one or more computer processors to thereby: Identifying three or more redundant subsystems in the system; forming a plurality of combinations of the plurality of redundant subsystems, each combination being a subset of the plurality of redundant subsystems; identifying a first combination of the redundant subsystems that has the smallest variation between the subsystems from among the plurality of combinations of the redundant subsystems; calculating one or more nominal values ​​of one or more parameters for a first subsystem of the plurality of subsystems using the first combination; Detecting an anomaly in the first subsystem based on the calculated one or more nominal values.

18. 20. The computer program product of claim 17, wherein the system is an aircraft and the three or more redundant subsystems are redundant subsystems in the aircraft.

19. Determining, for the first subsystem of the plurality of subsystems, the one or more nominal values ​​of the one or more parameters using the first combination. averaging each of the one or more parameters over all subsystems in the first combination. Detecting an anomaly in the first subsystem based on the calculated one or more nominal values ​​includes:

20. The computer program product of claim 18, comprising determining a health index for the first subsystem by calculating at least one of a cosine similarity or a Euclidean distance for a plurality of parameters in the first subsystem compared to the calculated one or more nominal values.

20. identifying a first component that is at least partially responsible for the anomaly in the first subsystem, 20. The computer program product of claim 18, further comprising using an inference algorithm to identify the first component based on the anomaly.