Protection of industrial production against high attack
The integration of real-time error detection and correction using Kalman filters, autoencoders, and reinforcement learning in manufacturing systems addresses the limitations of SPC by actively managing cyberattacks, enhancing security and efficiency.
Patent Information
- Application Number
- JP2025094829
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-11-20
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-02
AI Technical Summary
Conventional statistical process control (SPC) methods in manufacturing systems are inadequate in detecting and correcting cyberattacks, which can cause widespread damage and increased downtime due to their passive and static nature, failing to coordinate operations across nodes and allowing malicious activity to go undetected until significant quality issues arise.
Implementing a monitoring platform and control module with error detection techniques such as Kalman filters, autoencoders, and deep reinforcement learning to dynamically monitor and correct cyberattacks in real-time by treating them as process variations, adjusting operating parameters to mitigate damage across downstream stations.
Enhances industrial security by actively detecting and correcting cyberattacks, reducing downtime and remediation costs by integrating machine learning algorithms to manage process control and security, ensuring continuous operation and compliance.
Smart Images

Figure 2025128264000001_ABST
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Application No. 62 / 938,158, filed October 20, 2019, which is incorporated herein by reference in its entirety.
[0002] FIELD OF THE DISCLOSURE The present disclosure generally relates to systems, methods, and media for manufacturing processes. [Background technology]
[0003] Cyberattacks over the past few decades have witnessed an astonishing degree of proliferation, adaptation, specificity, and sophistication. Industrial and military security is the study of physical and digital barriers that limit the malicious insertion or deletion of information. For high-security factories and military installations, this means creating systems that are disconnected from global computer networks and, in many cases, disconnected from internal networks. Summary of the Invention [Problem to be solved by the invention]
[0004] [Means for solving the problem]
[0005] In some embodiments, a manufacturing system is disclosed herein. The manufacturing system includes one or more stations, a monitoring platform, and a control module. Each station of the one or more stations is configured to perform at least one step in a multi-step manufacturing process of a component. The monitoring platform is configured to monitor the progress of the component throughout the multi-step manufacturing process. The control module is configured to detect a cyberattack on the manufacturing system, the control module being configured to perform an action. The action includes receiving a control value for a first station of the one or more stations. The control value includes an attribute of the first processing station. The action also includes using one or more machine learning algorithms to determine whether there is a cyberattack based on the control value of the first station. The action further includes generating an alert to stop processing of the component based on the determination.
[0006] In some embodiments, a computer-implemented method is disclosed herein. A computing system receives a control value for a first station of one or more stations in a manufacturing system configured to process a component. The control value includes an attribute of the first station. The computing system uses one or more machine learning algorithms to determine whether there is a cyber attack based on the control value of the first station. Based on the determination, the computing system generates an alert to stop processing of the component. The computing system generates a set of actions to correct an error caused by the cyber attack. The set of actions is associated with a downstream station in the manufacturing system.
[0007] In some embodiments, a manufacturing system is disclosed herein. The manufacturing system includes one or more stations, a monitoring platform, and a control module. Each station of the one or more stations is configured to perform at least one step in a multi-step manufacturing process of a component. The monitoring platform is configured to monitor the progress of the component throughout the multi-step manufacturing process. The control module is configured to detect a cyberattack on the manufacturing system, the control module being configured to perform an action. The action includes receiving a control value of a first station of the one or more stations. The control value includes an attribute of the first station. The action also includes using one or more machine learning algorithms to determine whether there is a cyberattack based on the control value of the first station. The action further includes generating an alert to stop processing of the component based on the determination. The action further includes using one or more second machine learning algorithms to generate a set of actions to correct the error caused by the cyberattack. The set of actions is associated with downstream stations of the manufacturing system.
[0008] So that the above-mentioned features of the present disclosure can be understood in detail, a more particular description of the present disclosure briefly summarized above can be had by reference to embodiments, some of which are illustrated in the accompanying drawings. It should be noted, however, that the accompanying drawings illustrate only typical embodiments of the present disclosure and therefore should not be considered as limiting its scope, since the present disclosure may admit of other equally effective embodiments. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a block diagram illustrating a manufacturing environment in accordance with an illustrative embodiment.
[0010] [Figure 2]FIG. 1 is a block diagram illustrating an architecture of a single-input, single-output system implementing a Kalman filter in accordance with an illustrative embodiment.
[0011] [Figure 3] FIG. 1 is a block diagram illustrating the architecture of a system implementing an autoencoder, according to an example embodiment.
[0012] [Figure 4] FIG. 1 is a block diagram illustrating an architecture of a system for implementing a reinforcement learning approach using a machine learning module, in accordance with an illustrative embodiment.
[0013] [Figure 5] 1 is a flow chart illustrating a method for managing a cyber-attack on a manufacturing process in accordance with an illustrative embodiment.
[0014] [Figure 6A] 1 illustrates a system bus computing system architecture according to an exemplary embodiment.
[0015] [Figure 6B] 1 illustrates a computer system having a chipset architecture according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0016] For ease of understanding, where possible, like reference numerals have been used to designate like elements common to the figures. It is contemplated that elements disclosed in one embodiment may be beneficially utilized on other embodiments without specific recitation.
[0017] A manufacturing process can be complex and can involve raw materials that are processed by different process stations (or "stations") until a final product is produced. In some embodiments, each process station can receive inputs for processing and output intermediate outputs that can be passed to the next (downstream) process station for additional processing. In some embodiments, a final process station can receive inputs for processing and output a final product, or more generally, a final output.
[0018] In some embodiments, each station may include one or more tools / equipment capable of performing a series of process steps. Exemplary process stations may include, but are not limited to, conveyor belts, injection molding presses, cutting machines, die stamping machines, extruders, computer numerically controlled (CNC) mills, grinders, assembly stations, 3D printers, quality control stations, verification stations, etc.
[0019] In some embodiments, the operation of each process station may be controlled by one or more process controllers. In some embodiments, each process station may include one or more process controllers that may be programmed to control the operation of the process station. In some embodiments, an operator or a control algorithm may provide station controller setpoints, which may represent a desired value or range of values, to the station controller for each control value. In some embodiments, values used for feedback or feedforward in a manufacturing process may be referred to as control values. Exemplary control values may include, but are not limited to, speed, temperature, pressure, vacuum, rotations, current, voltage, power, viscosity, materials / resources used at the station, throughput rate, downtime, hazardous gases, pH, light absorption, particle density, and geometric configuration.
[0020] Statistical process control (SPC) is a quality management method that uses statistical methods to monitor and control processes. Generally, SPC requires that process standards be established for each step in the manufacturing process and monitored throughout the production lifecycle. The goal of SPC is to continuously improve the process throughout its lifecycle.
[0021] For the purposes of SPC, it is assumed that as long as each node operates within its specifications, the end product will also be within specifications. Specifications can be set based on subject matter expertise and past performance. The reliability and impact of one node on the next or subsequent nodes are not directly coordinated in SPC. Instead, each subprocess can be examined as an independent entity. This approach allows for a wide margin of operation for each node, preventing the system from operating at its absolute highest efficiency or even its highest stability. From a security perspective, this margin can be a target for advanced process cyberattacks. If one or more nodes in a system begin operating at the upper (or lower) limits of their specifications, individual alarms will not be triggered, but the quality of the entire process will be affected. This is especially true for man-in-the-middle cyberattacks, for example, where reported sensor signals are forged by malicious code. The lifecycle of the node is also affected, requiring increased downtime for repairs. Several layers of downstream nodes are also affected, and over time, the system's continued drift tends to lead to non-compliance. By that point, the remediation required to restore the system is extensive and prohibitively expensive.
[0022] One or more techniques provided herein are directed toward a new approach to industrial security by treating suspected malicious activity as a process variation and correcting it by actively adjusting the system's operating parameters. As threats to industrial systems increase in number and sophistication, traditional security methods must be layered with advances in process control to harden the entire system.
[0023] FIG. 1 is a block diagram illustrating a manufacturing environment 100, according to an exemplary embodiment. The manufacturing environment 100 may include a manufacturing system 102, a monitoring platform 104, and a control module 106. The manufacturing system 102 may broadly represent a multi-process manufacturing system. In some embodiments, the manufacturing system 102 may represent an assembly line system, with each processing station representing a human worker. In some embodiments, the manufacturing system 102 may represent a manufacturing system for use with additive manufacturing (e.g., a 3D printing system). In some embodiments, the manufacturing system 102 may represent a manufacturing system for use with subtractive manufacturing (e.g., CNC machining). In some embodiments, the manufacturing system 102 may represent a manufacturing system for use with a combination of additive manufacturing and subtractive manufacturing. More generally, in some embodiments, the manufacturing system 102 may represent a manufacturing system for use in a general manufacturing process.
[0024] The manufacturing system 102 includes one or more stations 1081-1088. n (generally, "stations 108"). Each station 108 may represent a step and / or station in a multi-step manufacturing process. For example, each station 108 may represent a layer deposition operation in a 3D printing process (e.g., station 1081 may correspond to layer 1, station 1082 may correspond to layer 2, etc.). In another example, each station 108 may correspond to a particular processing station. In another example, each station 108 may correspond to a particular human operator performing a particular task in an assembly line manufacturing process.
[0025] Each station 108 may include a process controller 114 and control logic 116. Each process controller 1411-114 nEach of the control logic 116 may be programmed to control the operation of a respective station 108. In some embodiments, the control module 106 may provide each process controller 114 with station controller setpoints, which may represent a desired value or range of values for each control value. The control logic 116 may reference attributes / parameters associated with the process operation of the station 108. During operation, the control logic 116 of each station 108 may be dynamically updated throughout the manufacturing process by the control module 106 depending on the current trajectory of the final quality criteria.
[0026] The monitoring platform 104 may be configured to monitor each station 108 of the manufacturing system 102. In some embodiments, the monitoring platform 104 may be a component of the manufacturing system 102. For example, the monitoring platform 104 may be a component of a 3D printing system. In some embodiments, the monitoring platform 104 may be independent of the manufacturing system 102. For example, the monitoring platform 104 may be retrofitted to an existing manufacturing system 102. In some embodiments, the monitoring platform 104 may represent an imaging device configured to capture images of the product or tooling (e.g., workers or process tools) at each step of a multi-step process. For example, the monitoring platform 104 may be configured to capture images of the components at each station 108 and / or images of the components (e.g., tools, humans, etc.) developing the product at each station 108. In general, the monitoring platform 104 may be configured to capture information related to the production of the product (e.g., images, voltage readings, speed readings, etc.) and / or tooling (e.g., hand position, tooling position, etc.) and provide that information as input to the control module 106 for evaluation.
[0027] The control module 106 can communicate with the manufacturing system 102 and the monitoring platform 104 via one or more communication channels. In some embodiments, the one or more communication channels can represent individual connections over the Internet, such as a cellular network or a Wi-Fi network. In some embodiments, the one or more communication channels can connect terminals, services, and mobile devices using a direct connection, such as radio frequency identification (RFID), near field communication (NFC), Bluetooth™, Bluetooth Low Energy (BLE), Wi-Fi™, ZigBee™, backscatter communication (ABC) protocol, USB, WAN, or LAN.
[0028] The control module 106 may be configured to control each process controller in the manufacturing system 102. For example, based on information obtained by the monitoring platform 104, the control module 106 may be configured to adjust the process controls associated with a particular station 108. In some embodiments, the control module 106 may be configured to adjust the process controls of a particular station 108 based on predicted final quality criteria.
[0029] As mentioned above, traditional approaches to process detection undermine various SPC techniques. SPC is a static, non-intrusive approach to process control, where well-defined statistical characteristics are passively observed to pass or fail at each node. It is only after processing of the last node that these traditional systems decide whether to keep or discard the manufactured product.
[0030] To improve upon conventional processes, the control module 106 includes an error detection module 130. The error detection module 130 may be configured to detect errors at a given station 108 or node of the manufacturing system 102. For example, in an error detection module 130 used as part of a dynamic intervention approach to process control, each node following the detected damage-causing node is factored into an optimization problem (e.g., a damage recovery problem) and actively controlled to instantiate its solution. In some embodiments, this process can occur in real time or near real time, as each cycle progresses, rather than at the end of a given cycle.
[0031] To understand one or more techniques implemented by the error detection module 130, it is important to understand how the control module 106 defines a manufacturing system (e.g., manufacturing system 102). A manufacturing system can be defined using a variety of topology schemes, such as feedback or feedforward configurations. In some embodiments, a manufacturing system F can be defined as a linear sequence of n process nodes (or stations 108), labeled 1,...,N, connected in a feedforward-linked chain. For example: F:→1→2→···→i→····→n
[0032] Similarly, in some embodiments, a manufacturing system F may be defined as a nonlinear sequence of n process nodes (or stations 108), labeled 1,...,N. In some embodiments, the processing performed by each node i may have two attributed distributions: the predicted distribution Q i , the observed distribution P i Q i teeth,
number
number
number
number
number
number
[0033] In some embodiments, the damage caused by node i is Q i P about i can be defined as the Kullback-Leibler divergence of
number
[0034] In some embodiments, the damage may be cumulative or additive across F. For example:
number
[0035] Referring back to the error detection module 130, the error detection module 130 may be configured to detect damage or errors at a given node k of the manufacturing system 102. For example, if the error detection module 130 detects that node k has caused damage (i.e., has produced a damaged or skewed distribution), the error detection module 130 may k The distribution of all subsequent outcomes that flow from it, P k+1,...,P N A control strategy can be adopted to generate the remaining cumulative damage d k+1 ,...,d k Therefore, the damage recovery problem of the error detection module 130 can be formulated as follows:
number
[0036] In some embodiments, the error detection module 130 may implement one or more techniques for identifying or correcting damage detected at a given node. In some embodiments, the error detection module 130 may use a Kalman filter 132 to detect damage or errors at a given processing node. In some embodiments, the error detection module 130 may include an autoencoder 134 to detect damage or errors at a given processing node. In some embodiments, the error detection module 130 may use deep reinforcement learning techniques in a machine learning module 136 to detect damage or errors at a given processing node and correct detected variations caused by damage or errors at downstream nodes or stations 108. In some embodiments, the error detection module 130 may use one or more of the Kalman filter 132, the autoencoder 134, or the machine learning module 136 to detect damage or errors at a given processing node and / or correct detected variations caused by damage or errors at downstream nodes or stations 108.
[0037] In some embodiments, the error detection module 130 may implement a Kalman filter 132 to detect errors in the processing nodes. i To generalize, a single-input, single-output system can be established in state-space form as follows:
number
number
number
[0038] In general, the Kalman filter 132 may rely on zero-mean noise. However, in the case of malicious cyber attacks, offsets in the input instructions may appear as non-zero mean additive noise. Therefore, the Kalman filter 132 may be interpreted for an estimated time-invariant system as follows:
number
[0039] In some embodiments, the Kalman filter 132 uses measurements of the output, y V,i (t), and the regular, untouched input instruction u i (t) can be constructed using (t). If the process is properly calibrated, the input / output sensor measurements of the station 108 or node should have zero mean noise. However, in the case of malicious cyber attacks, non-zero bias occurs.
[0040] In some embodiments, the Kalman filter 132 may be interpreted as follows:
number
number
number
number
number
number
[0041] FIG. 2 is a block diagram illustrating the architecture of a single-input, single-output system (hereinafter "system 200") implementing Kalman filter 132, according to an example embodiment.
[0042] As shown, system 200 may include a controller 202 (e.g., C(s)), a plant 204 (e.g., G(s)), a measurement unit 206 (e.g., H(s)), an attack 208 (e.g., A(s)), and a Kalman filter 132 (e.g., KF). In some embodiments, system 200 may include a second controller 202. In some embodiments, controller 202, plant 204, and measurement unit 206 may represent the basic configuration of nodal control, while Kalman filter 132 generates an innovation error.
[0043] In some embodiments, such as that shown in FIG. 2, the twin controller may be used as an unbiased reference for the Kalman filter 132.
[0044] 1, in some embodiments, the error detection module 130 may use an autoencoder 134 to detect anomalies corresponding to cyber-attacks.
number
number
[0045] In some embodiments, the error of the autoencoder 134 may be defined as follows:
number
number
number
number
number
[0046] Similar to the Kalman filter132, the anomaly score a i >γ i If , the error detection module 130 can use the autoencoder 134 to detect the anomaly.
[0047] 3 is a block diagram illustrating the architecture of a system 300 implementing an autoencoder 134, according to some embodiments. As shown, the system 300 may include a controller 302 (e.g., C(s)), a plant 304 (e.g., G(s)), a measurer 306 (e.g., H(s)), an attack 308 (e.g., A(s)), an autoencoder 134 (e.g., AE), and an alarm 312 (e.g., A). The controller 302, plant 304, and measurer 306 may represent the basic components of node control, while the autoencoder 344 may detect errors. In some embodiments, the error detection module 130 may trigger the alarm 312 based on a sufficient anomaly score.
[0048] 1, in some embodiments, the error detection module 130 may use one or more deep reinforcement learning techniques to identify errors or anomalies in the processing that correspond to a cyber-attack. i Given the definition of
number
number
number
number
[0049] In some embodiments, the error detection module 130 may be configured to:
number
number
number
number
[0050] In some embodiments, the update law associated with the reinforcement learning technique may be:
number
[0051] In some embodiments, the update law can reduce or minimize the Q value, thereby minimizing the damage, and can manifest itself in actions aimed at returning the distribution to its normal shape. In some embodiments, one formulation of the actions can be:
[0052] In some embodiments, the formulation of the action may be:
number
number
number
[0053] By utilizing a reinforcement learning approach, the error detection module 130 may offer a new way to address system security by bundling process-based malicious cyber-attacks with nominal process variations and providing direct control and correction of those variations. The approach is not merely a detection or passive prevention method. Rather, cyber-attacks may be assumed to manifest as routine (e.g., likely) system changes, such as machinery going out of standard or raw material inventory going out of strict specification.
[0054] 4 is a block diagram illustrating the architecture of a system 400 that implements a reinforcement learning approach using machine learning module 136, according to some embodiments. As shown, system 400 can represent a multi-node system, i=0,...,N. For each node i, controllers 4020, 4021, and 402 N (e.g., C0(s), C i (s),...C N (s)), Plant 4040, 404 i , and 404 N (e.g., G0(s), G i (s), G N (s)), and measuring units 4060, 406 i , and 406 N (e.g., H0(s), H i(s), H N Together, the nodes have a set of nodes sampled from the data store 408 (e.g., Y) at time k, S k The policy learning feedback loop is governed by the state of the system 400 at k ) The attack 412 can be represented by a block A(s) for a single node i.
[0055] In some embodiments, the state S at time sample k is used to identify a set of actions to take to correct the error caused by the cyber attack. k may be input to a nonlinear filter, whose weights may be selected to minimize the subsequent corruption of time sample k+n given the observed artifact or component. In some embodiments, the output of the filter may be a scalar or vector that modifies a predetermined process setpoint or control value. The transformation from state to action may be called a policy.
[0056] 5 is a flow diagram illustrating a method 500 for managing a cyber-attack on a manufacturing process, according to an example embodiment. Method 500 may begin as step 502.
[0057] In step 502, the control module 106 may receive control values from stations 108 of the manufacturing system 102. In some embodiments, the control module 106 may receive control values from a process controller associated with a given station 108. The process controller may generally be programmed to control the operation of the station 108. Exemplary control values may include, but are not limited to, speed, temperature, pressure, vacuum, rotations, current, voltage, power, viscosity, materials / resources used at the station, throughput rate, downtime, hazardous gases, etc. More generally, the control values may refer to attributes of the station 108 rather than attributes of the component being processed by the station 108.
[0058] In step 504, the control module 106 may determine that a cyber-attack exists based on the control value received from the station 108. For example, in some embodiments, the error detection module 130 may use a Kalman filter 132 to generate an anomaly score for the station 108 given the control value. For example, if the anomaly score is greater than a predetermined threshold, the control module 106 may determine whether a cyber-attack is currently underway. In another example, the error detection module 130 may use an autoencoder 134 to generate an anomaly score for the station 108 given the control value. For example, if the anomaly score is greater than a predetermined threshold, the control module 106 may determine whether a cyber-attack is currently underway. In another example, the error detection module 130 may use a machine learning module 136 to predict a Q value corresponding to the station 108. For example, if the Q value is outside of a range of acceptable values, the control module 106 may determine whether a cyber-attack is currently underway.
[0059] In some embodiments, method 500 may include step 506. At step 506, in response to determining that a cyber-attack is occurring, control module 106 may trigger an alert or alarm. In some embodiments, the alert or alarm may be a notification to a user overseeing manufacturing system 102. In some embodiments, the alert or alarm may be a notification to each station 1081-1082 of manufacturing system 102. n It can be a signal to stop or halt the processing of
[0060] In some embodiments, method 500 may include steps 508-510. In step 508, in response to determining that a cyber-attack is occurring, control module 106 may generate one or more actions to correct the damage caused by the cyber-attack. For example, error detection module 130 may generate one or more actions to correct the damage caused by the cyber-attack.
number
number
number
number
[0061] In some embodiments, the update law associated with the reinforcement learning technique may be:
number
[0062] In some embodiments, the update law may manifest itself in actions aimed at reducing or minimizing the Q value, thereby minimizing damage and returning the distribution to its normal shape. In some embodiments, one formulation of the actions may be:
[0063] In some embodiments, the formulation of the action may be:
number
number
number
[0064] In step 510, the control module 106 may provide the updated actions generated by the machine learning module 136 to the downstream stations 108. In some embodiments, the control module 106 may send the updated instructions to a process controller of each downstream station 108.
[0065] FIG. 6A illustrates a system bus computing system architecture 600 according to an exemplary embodiment. One or more components of the system 600 may be in electronic communication with each other using a bus 605. The system 600 may include a processor (e.g., one or more CPUs, GPUs, or other types of processors) 610 and a system bus 605 coupling various system components to the processor 610, including system memory 615 such as read-only memory (ROM) 620 and random access memory (RAM) 625. The system 600 may include a cache of high-speed memory directly connected to, adjacent to, or integrated as part of the processor 610. The system 600 may copy data from the memory 615 and / or storage device 630 to the cache 612 for quick access by the processor 610. In this manner, the cache 612 can provide performance improvements that avoid delays to the processor 610 while waiting for data. These and other modules may control or be configured to control the processor 610 to perform various actions. Other system memories 615 may be available as well. Memory 615 may include multiple different types of memory with different performance characteristics. Processor 610 can represent a single processor or multiple processors. Processor 610 may include one or more of a general-purpose processor or hardware or software modules, such as service 1 632, service 2 634, and service 3 636 stored in storage device 630, configured to control processor 610 and dedicated processors whose software instructions are incorporated into the actual processor design. Processor 610 may essentially be a completely self-contained computing system, including multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.
[0066] To enable user interaction with the computing device 600, the input device 645 can be any number of input mechanisms, such as a microphone for audio, a touch-sensitive screen for gesture or graphic input, a keyboard, a mouse, motion input, voice, etc. The output device 635 can also be one or more of several output mechanisms known to those skilled in the art. In some cases, a multimodal system can allow a user to provide multiple types of input to communicate with the computing device 600. The communications interface 640 can generally manage and control user input and system output. There are no limitations to operation with a specific hardware configuration. Therefore, the basic functions herein can be easily replaced with improved hardware or firmware configurations as development progresses.
[0067] The storage device 630 may be a non-volatile memory or may be a hard disk or other type of computer-readable medium capable of storing data accessible by a computer, such as a magnetic cassette, a flash memory card, a solid-state memory device, a digital versatile disk, a cartridge, random access memory (RAM) 625, read-only memory (ROM) 620, and hybrids thereof.
[0068] The storage device 630 may include services 632, 634, and 636 for controlling the processor 610. Other hardware or software modules are contemplated. The storage device 630 may be connected to the system bus 605. In one aspect, hardware modules that perform specific functions may include software components stored on computer-readable media in association with the hardware components (such as the processor 610, the bus 605, the display 635, etc.) necessary to perform the functions.
[0069] FIG. 6B illustrates a computer system 650 having a chipset architecture according to an exemplary embodiment. The computer system 650 may be an example of computer hardware, software, and firmware that can be used to implement the disclosed techniques. The system 650 may include one or more processors 655, representing any number of physically and / or logically distinct resources capable of executing software, firmware, and hardware configured to perform the identified computations. The one or more processors 655 may communicate with a chipset 660, which may control input to and output from the one or more processors 655. In this example, the chipset 660 may output information to an output 665, such as a display, and may read and write information to a storage device 670, which may include, for example, magnetic and solid-state media. The chipset 660 may also read and write data to a RAM 675. To interface with the chipset 660, a bridge 680 may be provided for interfacing with various user interface components 685. Such user interface components 685 may include a keyboard, a microphone, touch detection and processing circuitry, a pointing device such as a mouse, and the like. In general, input to the system 650 can come from any of a variety of sources, machine-generated and / or human-generated.
[0070] The chipset 660 may also interface with one or more communication interfaces 690, which may have different physical interfaces. Such communication interfaces may include interfaces for wired and wireless local area networks, broadband wireless networks, and personal area networks. Some applications of the methods for generating, displaying, and using GUIs disclosed herein may involve receiving an ordered data set via a physical interface, or may be generated by the machine itself by one or more processors 655 analyzing data stored in storage 670 or 675. Additionally, the machine may receive inputs from a user via a user interface component 685 and perform appropriate functions, such as browsing functions, by interpreting these inputs using one or more processors 655.
[0071] It will be appreciated that the exemplary systems 600 and 650 may have multiple processors 610 or may be part of a group or cluster of computing devices networked together to provide greater processing power.
[0072] While the foregoing is directed to the embodiments described herein, other and further embodiments may be devised without departing from the basic scope thereof. For example, aspects of the present disclosure may be implemented in hardware or software, or a combination of hardware and software. An embodiment described herein may be implemented as a program product for use with a computer system. The program of the program product defines the functions of the embodiments (including the methods described herein) and may be contained on various computer-readable storage media. Exemplary computer-readable storage media include, but are not limited to: (i) non-writable storage media on which information is permanently stored (e.g., a read-only memory (ROM) device in a computer, such as a CD-ROM disk readable by a CD-ROM drive, flash memory, a ROM chip, or any type of solid-state nonvolatile memory); and (ii) writable storage media on which changeable information is stored (e.g., a floppy disk in a diskette drive or hard disk drive, or any type of solid-state random access memory). Such computer-readable storage media, when carrying computer-readable instructions that direct the functions of the disclosed embodiments, are embodiments of the present disclosure.
[0073] Those skilled in the art will understand that the foregoing embodiments are illustrative and not limiting. All permutations, extensions, equivalents, and improvements thereon will be apparent to those skilled in the art upon reading the specification and studying the drawings, and are intended to be within the true spirit and scope of the present disclosure. It is therefore intended that the following appended claims cover all such modifications, permutations, and equivalents that fall within the true spirit and scope of these teachings.
Claims
1. 1. A manufacturing system comprising: a plurality of stations, each configured to perform at least one step in a multi-step manufacturing process for producing a component; a control module configured to detect anomalies in the manufacturing system, receiving a control value including an attribute of a first station of the plurality of stations; determining that there is an anomaly in the manufacturing system based on the control value of the first station; predicting cumulative damage to the component due to the anomaly; and identifying, via one or more deep reinforcement learning techniques, a combination of one or more actions that is most likely to correct the cumulative damage; and causing one or more downstream stations to perform a combination of the one or more actions to minimize the cumulative damage to the component; and a control module configured to perform operations including:
2. The operation is The manufacturing system of claim 1 , further comprising generating an anomaly score for the first station based on the control value.
3. generating the anomaly score for the first station based on the control value; The manufacturing system of claim 2 , further comprising using one or more machine learning algorithms including a Kalman filter to generate the anomaly score for the first station based on the control value.
4. generating the anomaly score for the first station based on the control value; 3. The manufacturing system of claim 2, further comprising using one or more machine learning algorithms including an autoencoder to generate the anomaly score for the first station based on the control value.
5. determining that there is an anomaly based on the control value of the first station; The manufacturing system of claim 2 , further comprising determining that the anomaly score exceeds a threshold indicative of an anomaly.
6. determining that there is an anomaly based on the control value of the first station; generating a predicted quality metric for the component based on the control value; determining that the predicted quality metric is outside a range of acceptable values; The manufacturing system of claim 1 , comprising:
7. The operation is The manufacturing system of claim 1 , further comprising generating an alert comprising a notification of the anomaly.
8. 1. A computer-implemented method for detecting anomalies in a manufacturing system, comprising: receiving control values including attributes of a first station of a plurality of stations, each configured to perform at least one step in a multi-step manufacturing process for producing a component in a manufacturing system; determining that there is an anomaly in the manufacturing system based on the control value of the first station; predicting cumulative damage to the component due to the anomaly; and identifying, via one or more deep reinforcement learning techniques, a combination of one or more actions that is most likely to correct the cumulative damage; and causing one or more downstream stations to perform a combination of the one or more actions to minimize the cumulative damage to the component; 11. A computer-implemented method comprising:
9. The computer-implemented method of claim 8 , further comprising generating an anomaly score for the first station based on the control value.
10. generating the anomaly score for the first station based on the control value; 10. The computer-implemented method of claim 9, comprising using one or more machine learning algorithms including a Kalman filter to generate the anomaly score for the first station based on the control value.
11. generating the anomaly score for the first station based on the control value; 10. The computer-implemented method of claim 9, comprising using one or more machine learning algorithms including an autoencoder to generate the anomaly score for the first station based on the control value.
12. determining that there is an anomaly based on the control value of the first station; The computer-implemented method of claim 9 , comprising determining that the anomaly score exceeds a threshold that indicates an anomaly.
13. determining that there is an anomaly based on the control value of the first station; generating a predicted quality metric for the component based on the control value; determining that the predicted quality metric is outside a range of acceptable values; The computer-implemented method of claim 8 , comprising:
14. The computer-implemented method of claim 8 , further comprising generating an alert comprising a notification of the anomaly.
15. A computer-readable medium having stored thereon instructions that, when executed by one or more processors, perform operations, the operations including: receiving a control value for a first station of a plurality of stations, each configured to perform at least one step in a multi-step manufacturing process for producing a component in a manufacturing system; Detecting an abnormality in the manufacturing system based on the control value of the first station; predicting cumulative damage to the component due to the anomaly; and identifying, via one or more deep reinforcement learning techniques, a combination of one or more actions that is most likely to correct the cumulative damage; and causing one or more downstream stations to perform a combination of the one or more actions to minimize the cumulative damage to the component; 1. A computer-readable medium comprising:
16. The operation is The computer-readable medium of claim 15 , further comprising generating an anomaly score for the first station based on the control value.
17. generating the anomaly score for the first station based on the control value; 17. The computer-readable medium of claim 16, comprising using one or more machine learning algorithms including a Kalman filter to generate the anomaly score for the first station based on the control value.
18. generating the anomaly score for the first station based on the control value; 17. The computer-readable medium of claim 16, comprising using the one or more machine learning algorithms including an autoencoder to generate the anomaly score for the first station based on the control value.
19. determining that there is an anomaly based on the control value of the first station; The computer-readable medium of claim 16 , further comprising determining that the anomaly score exceeds a threshold indicative of an anomaly.
20. determining that there is an anomaly based on the control value of the first station; generating a predicted quality metric for the component based on the control value; determining that the predicted quality metric is outside a range of acceptable values; 16. The computer-readable medium of claim 15, comprising: