Abnormality detection system in connected service system
The anomaly detection system in connected service systems quickly identifies the source of abnormalities by calculating and comparing area-specific and entire-area index values, addressing the challenge of multiple simultaneous abnormalities across vehicles, server centers, and networks.
Patent Information
- Application Number
- JP2024071982
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-25
- Publication Date
- 2025-11-07
AI Technical Summary
In connected service systems, identifying the cause of multiple simultaneous abnormalities across vehicles, server centers, and communication networks is challenging due to the lack of proper evaluation of the extent to which each abnormality affects the system, leading to difficulties in detecting the true source of the issue.
An anomaly detection system that calculates area-specific and entire-area abnormality index values to identify the region with the highest degree of abnormality, using normalized anomaly score values and machine learning algorithms to determine the abnormality occurrence period and source.
Enables rapid identification of the area causing the abnormality by comparing the degree of abnormality in each area with the entire system, facilitating quick response and resolution.
Smart Images

Figure 2025167415000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a connected service system, and more specifically to a system for detecting abnormalities that occur in devices such as user vehicles that are involved in the connected service system, server centers that provide users with various information and services using communications, user terminals that receive the various information and services, and the communications networks between them. [Background technology]
[0002] Connected services are provided through the cooperation of multiple systems, including a vehicle or other device used by a user (hereinafter referred to as "vehicle, etc."), a communication network between the vehicle and a server center, the server center, a communication network between the server center and the user's terminal, and the user's terminal. More specifically, a communication device is installed in the vehicle, etc., and various data acquired by sensors in the vehicle, etc. is transmitted to the manufacturer's server center. The server center analyzes and processes the received data, for example, to predict vehicle failures and acquire information for driver assistance. Based on these results, various information and services are provided via communication to the user's terminal. In addition, the data collected by the server center is stored in a storage device and may be used to analyze the cause of vehicle failures or malfunctions. Connected services have become important services for users of vehicles, etc. Therefore, if an abnormal condition occurs that makes a connected service unavailable, it is desirable to be able to detect and address it early. Note that such abnormalities can occur not only in the communication devices of the vehicle, the server center, and the user's terminal, but also in the communication network connecting them.
[0003] Various technologies have been proposed for detecting abnormalities in the devices, facilities, and communication networks used in the above-mentioned connected services. For example, Patent Document 1 proposes a method for detecting equipment failures in autonomous vehicles by monitoring the vehicle's main equipment in real time using monitoring equipment, and when an abnormality is confirmed, issuing a warning via a fault alarm device to reduce the incidence of safety accidents caused by equipment failures in the system. Patent Document 2 proposes enabling a central device to check the appropriateness of the combination of configuration information for each electronic control device installed in the vehicle and detecting conditions that may interfere with the vehicle's operation as abnormalities. Patent Document 3 proposes a method for detecting abnormalities in base stations in a communication network by using an anomaly detection model for each base station when communication at the base station is normal to distinguish input data when an abnormality occurs in communication, and appropriately detecting abnormalities that do not appear in alarms issued by the base station. Patent Document 4 discloses a method for detecting abnormalities in processing at a server center, in which an anomaly detection device of an anomaly determination system analyzes log messages acquired from a data processing device, a conversion unit in the information processing device that provides information based on the analysis results to the data processing device converts the number of occurrences of log messages collected from the monitored system into the number of days since the log messages occurred, and a detection unit detects log messages related to abnormalities in the monitored system based on the number of days since the log messages occurred converted by the conversion unit. Patent Documents 5 to 9 also describe technologies related to detecting abnormalities in equipment, facilities, and communication networks. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent Publication No. 2022-106834 [Patent Document 2] Patent Publication No. 2020-27670 [Patent Document 3] Patent Publication No. 2021-78076 [Patent Document 4] Patent Publication No. 2022-61678 [Patent Document 5] Patent Publication No. 2021-128423 [Patent Document 6] Patent Publication No. 2022-56746 [Patent Document 7] Patent Publication No. 2022-32631 [Patent Document 8] Patent Publication No. 2023-69705 [Patent Document 9] Patent Publication No. 2023-55064 Summary of the Invention [Problem to be solved by the invention]
[0005] As described above, in a system providing connected services, multiple areas, such as vehicles, server centers, user terminals, and the communication networks between them, work in coordination. Therefore, if an abnormality occurs in one of these areas—for example, an abnormal increase or decrease in communication speed or traffic, an abnormal failure or operation of an unexpected function, an abnormal increase or decrease in resource usage, or an abnormal occurrence or absence of an error message or log message—the behavior of other areas within the system may be affected, resulting in the detection of multiple abnormalities. In such cases, it is necessary to identify the cause of the abnormality for each area where an abnormality is detected, even if it is caused by an abnormality in another area. Alternatively, setting a high threshold to separate out multiple abnormality factors can result in the overlooking of the cause of the abnormality (i.e., making it difficult to detect abnormalities in order to reduce the frequency of abnormality detection can lead to the overlooking of abnormalities). This is because the extent to which each abnormality affects each area within the connected service system is not properly evaluated and determined. Thus, in a connected service system, when abnormalities are detected in multiple areas, it would be advantageous to have a configuration that makes it possible to detect which area is the cause of the abnormality or which area is the true abnormality.
[0006] In view of the above circumstances, a main object of the present invention is to provide a configuration that, when an abnormality is detected in a connected service system, can detect in which area the cause of the abnormality lies. [Means for solving the problem]
[0007] According to the present invention, the above problem can be solved by providing an anomaly detection system for a connected service system including a machine or appliance of a user, a user terminal of the user, a server center that provides a service for the user including providing service data to the user terminal and the machine or appliance based on input data received from the machine or appliance and the user terminal, and a communication network between the machine or appliance, the server center, and the user terminal, an area-specific abnormality index value acquiring means for acquiring area-specific abnormality index values representing the degree of abnormality in each area, the area being provided in each of the machine / tool, the server center, the user terminal, the communication network between the machine / tool and the server center, and the communication network between the user terminal and the server center; an entire-area abnormality index value acquisition means for acquiring an entire-area abnormality index value representing the degree of abnormality of the entire area of the connected service system based on the degree of abnormality of each area; an abnormality region determination unit that determines a region among the regions having the region-specific abnormality index value that is greater than the region-wide abnormality index value; This is achieved by a system having:
[0008] In the above configuration, the "machine or equipment" is typically, but is not limited to, a vehicle such as an automobile. The "user terminal" may be any terminal capable of communication via a network, such as a dedicated terminal equipped in a vehicle, a smartphone, a tablet, or a mobile phone. The "connected service system" itself may be a typical connected service system. Specifically, as already mentioned, abnormalities in each area of the connected service system include symptoms such as an abnormal decrease or increase in communication speed or communication volume, an unexpected malfunction or malfunction, an abnormal increase or decrease in resource usage, or an abnormal occurrence or absence of an error message or log message. The method of detecting the degree of abnormality and its expression may be determined for each area, and the "area-specific abnormality index value" is a value obtained by converting the degree of abnormality for each area into a mutually comparable value. Furthermore, the "area-wide abnormality index value" is a value comparable to the area-specific abnormality index value.
[0009] In the system of the present invention, the degree of abnormality in each area of the machines and devices, user terminals, server center, and communication network connecting them included in the connected service system is expressed as a mutually comparable area-specific abnormality index value, and the degree of abnormality in the entire connected service system (entire area) obtained by integrating the degrees of abnormality in each area is expressed as a region-wide abnormality index value comparable to the region-specific abnormality index value. When a symptom that is determined to be an abnormality is detected in the connected service system, the degree of abnormality in the area that caused the abnormality is considered to be greater than the degree of abnormality in the other areas, and to stand out among the entire area, and the region-wide abnormality index value for that area is considered to be greater than the region-wide abnormality index value. Thus, in the system of the present invention, when an abnormal symptom is detected in the connected service system, an attempt is made to determine the area that caused the abnormality by referring to the region-wide abnormality index value and the region-wide abnormality index value. With this configuration, when an abnormal symptom is detected in a connected service system, the area that is thought to be the cause or the area where the abnormality actually occurs is identified, which is expected to enable the cause of the abnormality to be quickly identified and addressed.
[0010] In the system of the present invention, the region-wide abnormality index value represents the degree of abnormality in the entire connected service system, and specifically, may be a value (representative value) determined to represent the region-specific abnormality index values for each region. Specifically, the region-wide abnormality index value may be determined by any method so as to correspond to the average or median of the region-specific abnormality index values.
[0011] In an embodiment, each of the area-specific abnormality index value acquisition means provided in each area comprises: means for detecting a parameter value related to the degree of abnormality in each of said regions as an abnormality score value; means for converting the anomaly score value into a normalized corrected anomaly score value; a means for setting a region-specific reference value based on the corrected abnormality score value over a predetermined learning period, calculating the magnitude of the difference between the corrected abnormality score value after the learning period has elapsed and the region-specific reference value as an abnormality degree, specifying a period in which the abnormality degree exceeds a predetermined threshold as an abnormality occurrence period, and determining the abnormality degree in the abnormality occurrence period as the region-specific abnormality index value; Including, The whole region abnormality index value acquisition means means for calculating an abnormality degree of the entire region from the abnormality degree for each region; means for determining the degree of abnormality of the entire region during the abnormality occurrence period as the entire region abnormality index value; It may be configured to include:
[0012] In the above embodiment, when calculating the region-specific anomaly index value for each region, a parameter value related to the degree of anomaly in each region is first detected as an anomaly score value. The parameter value may be, for example, but is not limited to, communication speed, communication volume, frequency of activation / deactivation of unplanned functions, resource usage, frequency of log messages, etc. As a specific method for determining the parameter value corresponding to the anomaly score value, any method may be adopted for each region.
[0013] The anomaly score value is converted into an "anomaly level" that can be integrated and compared with other areas, with the anomaly score value increasing as the degree of abnormality increases. Specifically, in converting the anomaly score value into an anomaly level, for example, the anomaly score value is first normalized to calculate a corrected anomaly score value so that the anomaly levels calculated from the anomaly score values for each area are comparable and integrable. Prior to the normalization, missing data portions may be interpolated and outliers may be removed. The corrected anomaly score value obtained here is a measure for determining an abnormal symptom when its value is larger or smaller than normal. Therefore, as described above, the area-specific reference value, which is a normal value of the corrected anomaly score value, may be determined by referring to the corrected anomaly score value over a learning period of a predetermined length (e.g., 10 minutes) that may be set appropriately. Here, a machine learning algorithm such as LSTM (Long Short Term Memory) or Transformer may be used to determine the area-specific reference value. In this case, the magnitude of the difference between the corrected anomaly score value and the region-specific reference value increases as the degree of abnormality increases, and is therefore used as the "degree of abnormality." Note that the magnitude of the corrected anomaly score value is adjusted by the normalization, allowing the degree of abnormality to be compared and integrated with the degree of abnormality of other regions. Furthermore, since it can be assumed that the frequency distribution of the difference between the corrected anomaly score value and the region-specific reference value generally follows a normal distribution, it is possible to determine that an abnormality has occurred when the absolute value of the difference, that is, the degree of abnormality, falls within an appropriately set percentage range from the top of the frequency distribution. Therefore, an appropriately set percentage value from the top of the frequency distribution of the degree of abnormality may be set as a predetermined threshold, and a period during which the degree of abnormality exceeds the predetermined threshold may be determined as an abnormality occurrence period. The degree of abnormality during such an abnormality occurrence period may be determined as a region-specific abnormality index value. Note that the learning process for determining the region-specific reference value may be sequentially executed during operation of each region of the connected service system, and the determination of whether the degree of abnormality exceeds the threshold may also be sequentially executed.
[0014] The abnormality level for the entire region may be calculated appropriately from the abnormality levels for each region. Specifically, for example, the abnormality level for the entire region may be the average, median, or mode of the abnormality levels for each region, but is not limited to these. In this embodiment, the abnormality level for the entire region during a period identified as an abnormality occurrence period in any region is determined as the abnormality index value for the entire region.
[0015] In the above configuration, during a maintenance period of the connected service system, the above series of processes are not executed, and values during the maintenance period are excluded from learning for setting the region-specific reference widths. [Effects of the Invention]
[0016] Thus, according to the system of the present invention, rather than each area in the connected service system separately detecting and reporting abnormal symptoms, the degree of abnormality in each area is compared with the degree of abnormality for the entire area, thereby identifying areas with a relatively high degree of abnormality. As a result, when an abnormality occurs in any area in the connected service system, it is possible to quickly identify which area is the cause or which area is actually experiencing the abnormality. With this configuration, it is possible to check for abnormalities in areas starting with the areas with the highest degree of abnormality, enabling rapid response to the occurrence of an abnormality.
[0017] Other objects and advantages of the present invention will become apparent from the following description of preferred embodiments of the invention. [Brief explanation of the drawings]
[0018] [Figure 1] FIG. 1 is a schematic diagram of a connected service system to which the system of this embodiment is applied. [Figure 2] FIG. 2 is a block diagram showing the configuration of the system according to this embodiment. [Figure 3]Fig. 3(A) is a schematic diagram showing time changes in the corrected abnormality score values for each region in this embodiment. Fig. 3(B) is a diagram explaining a method for determining an abnormality occurrence period. Fig. 3(C) is a diagram explaining the relationship between the learning period for determining a reference value from the corrected abnormality score values for each region in this embodiment and the timing for determining an abnormality occurrence period. [Explanation of symbols]
[0019] 10... Vehicle (machine / equipment), 10a... Vehicle communication device, 20... Server center, 30... User terminal, 40... Communication network between vehicle and server center, 50... Communication network between user terminal and server center, 11, 21, 31, 41, 51... Area-specific abnormality score value acquisition unit, 12, 22, 32, 42, 52... Area-specific abnormality score value normalization calculation unit, 13, 23, 33, 43, 53... Area-specific abnormality index value determination unit, 14, 24, 34, 44, 54... Area-specific abnormality judgment unit, 15, 25, 35, 45, 55... Area-specific abnormality judgment display unit, 63... Area-wide abnormality index value determination unit BEST MODE FOR CARRYING OUT THE INVENTION
[0020] The present invention will now be described in detail with reference to some preferred embodiments thereof with reference to the accompanying drawings, in which like reference numerals indicate like parts.
[0021] Overview of the connected service system The connected service system to which the anomaly detection system of this embodiment is applied may be a conventional system. Generally speaking, in the connected service system, as illustrated in Fig. 1, a communicator 10a mounted on a machine or appliance (vehicle or the like), which may be a user's vehicle 10, a user terminal 30 of the user, and a server center 20 are communicably connected via wireless communication networks 40 and 50. Here, when various data, such as data representing the operating status of the vehicle or the like 10 and various requests from the user, are transmitted from the vehicle or the like 10 or the user terminal 30 to the server center 20 via the communication networks 40 and 50, the server center 20 provides services for the user, including providing service data to the user terminal 30 and the vehicle or the like 10 and remotely operating the machine or appliance, based on the received data.
[0022] Anomaly detection system for connected service systems (a) Overview In the connected service system described above, if an abnormal symptom occurs, it is preferable to be able to quickly identify the cause and resolve the symptom. Specifically, as already mentioned in the summary of the invention, in the connected service system, abnormal symptoms include an abnormal increase or decrease in communication speed or communication volume in each area, such as the vehicle 10, the server center 20, the user terminal 30, and the communication networks 40 and 50 between them, an unplanned function not operating or operating, an abnormal increase or decrease in resource usage, and an abnormal occurrence or absence of an error message or log message. In this regard, because each area in the connected service system operates in coordination with each other, if an abnormality occurs in one area, abnormalities may occur in other areas in a chain reaction. In such cases, it may appear as if abnormalities have occurred in multiple areas simultaneously, making it difficult to quickly identify which area is causing the abnormality. Therefore, the anomaly detection system of this embodiment does not detect the occurrence of an anomaly in each area individually, but monitors the degree of anomaly in each area and calculates the degree of anomaly in the entire connected service system (entire area) that integrates them. When the degree of anomaly in any area becomes large and it is determined that an abnormal state has occurred, the degree of anomaly in each area is compared with the degree of anomaly in the entire area. Here, the degree of anomaly in the area where an anomaly that is the cause of the abnormal state that has occurred in the connected service system is considered to be relatively larger than the degree of anomaly in the entire area, so it is possible to quickly identify an area where the degree of anomaly in each area is larger than the degree of anomaly in the entire area as the source of the anomaly or the area where a true anomaly has occurred.
[0023] In addition, with regard to the degree of abnormality in each area of a connected service system, parameter values related to the degree of abnormality (specifically, for example, communication speed or communication volume, frequency of unexpected function inactivity or activation, resource usage, frequency of error occurrence messages or log messages, etc.) generally differ for each area. Therefore, since the way of expressing the degree of abnormality differs, it may not be possible to comprehensively evaluate the degree of abnormality in each area as it is. Therefore, in one embodiment of the system of this embodiment, parameter values related to the degree of abnormality in each area are obtained as abnormality score values, and these abnormality score values are converted into abnormality degrees expressed in a state that makes them comparable or integrable. The abnormality degree may be adjusted so that the greater the degree of abnormality, the larger the value. Thereafter, to represent the degree of abnormality in the entire area, the average or median of the abnormality degrees for each area may be calculated as the abnormality degree for the entire area. More specifically, as will be described in detail later, the abnormality level for each region may be calculated as the magnitude of the difference between a corrected anomaly score value, which is obtained by normalizing the anomaly score value for each region, and the normal value. A period during which the abnormality level exceeds a normal range is identified as an abnormality occurrence period. Here, as described above, when an abnormal state occurs in one region, other regions may also become abnormal, and abnormality occurrence periods may be identified for multiple regions simultaneously. Therefore, simply identifying an abnormality occurrence period makes it difficult to determine which region caused the abnormality or whether a true abnormality has occurred. Therefore, once an abnormality occurrence period is identified in one region, the magnitude relationship between the abnormality level for each region and the abnormality level for the entire region is determined, and a region exhibiting an abnormality level greater than the abnormality level for the entire region is identified as the source of the abnormality. In this aspect, the abnormality level for each region during an abnormality occurrence period identified in one region is the “anomaly index value for each region,” and the abnormality level for the entire region during such an abnormality occurrence period is the “anomaly index value for the entire region.”
[0024] The anomaly detection system of this embodiment is realized by the operation of a computer device in accordance with a program provided for each area. The state of the communication network may be monitored at a server center.
[0025] (b) System configuration and operation In one configuration of the anomaly detection system of this embodiment, as shown in Figure 2, for each of the vehicle etc. 10, the server center 20, the user terminal 30 and the communication networks 40, 50 therebetween, there are provided area-specific abnormality score value acquisition units 11, 21, 31, 41, 51, area-specific abnormality score value normalization units 12, 22, 32, 42, 52, area-specific abnormality index value determination units 13, 23, 33, 43, 53, area-specific abnormality judgment units 14, 24, 34, 44, 54 and area-specific abnormality judgment display units 15, 25, 35, 45, 55, and an area-wide abnormality index value determination unit 63.
[0026] More specifically, the region-specific anomaly score value acquisition units 11, 21, 31, 41, and 51 first sequentially acquire parameter values related to the degree of anomaly in the corresponding region as anomaly score values. The method for acquiring the anomaly score values may be appropriately selected for each region. The region-specific anomaly score value normalization units 12, 22, 32, 42, and 52 normalize the anomaly score values for each region so that the anomaly degrees calculated later are comparable and integrable between regions. Specifically, the region-specific anomaly score value normalization units may normalize the anomaly score values after interpolating missing data and excluding outliers. Note that normalization may be performed, for example, by dividing the anomaly score values by a predetermined reference value, which may be appropriately set through experiments or the like. Note that values for periods during which maintenance is performed in each region may be labeled so that they are excluded in subsequent processing.
[0027] In brief, the region-specific anomaly index value determiners 13, 23, 33, 43, and 53 determine, for each region, a region-specific reference value, which is a value that normally occurs, based on the sequential behavior of the corrected anomaly score value, which is a normalized anomaly score value, and calculate the magnitude of the difference between the corrected anomaly score value and the reference value as the anomaly degree. A period in which the anomaly degree deviates from the normal range may be identified as an anomaly occurrence period, and the anomaly degree for that period may be used as the region-specific anomaly index value. More specifically, the region-specific reference value may be determined by learning from the sequentially obtained corrected anomaly score value. For example, as shown in FIG. 3A , for the sequentially obtained corrected anomaly score value X, a value BL that the corrected anomaly score value X normally takes may be determined as the region-specific reference value from values over a learning period L of a predetermined length (e.g., 10 minutes) that may be set appropriately. A machine learning algorithm, such as LSTM (Long Short Term Memory) or Transformer, may be used for this learning. Thus, the abnormality degree Z is given as the magnitude of the difference between the corrected abnormality score value X and the region-specific reference value BL. Then, as shown in FIG. 3B, the upper limit value of the range Δr in which the abnormality degree Z can normally be assumed is set as a threshold. When the abnormality degree Z is below this upper limit value, it is determined to be normal (OK). When the abnormality degree Z exceeds this upper limit value, it is determined to be abnormal (NG). As already mentioned, assuming that the frequency distribution of the difference between the corrected abnormality score value X and the region-specific reference value BL follows a normal distribution, an abnormality can be determined when the abnormality degree Z, which is its absolute value, is within a suitably set percentage (N% from the tail of the distribution) from the upper side of the frequency distribution. Therefore, the upper limit value of the range Δr in which the abnormality degree Z can normally be assumed may be set to a value at a suitably set percentage position from the upper side of the frequency distribution of the abnormality degree Z. Furthermore, learning and determination may be performed sequentially. 3(C), learning and judgment may be performed so that the learning period L and judgment time J transition sequentially for the corrected anomaly score value X that is sequentially acquired and calculated. Then, as described above, the period in which an anomaly is determined to occur is identified as the anomaly occurrence period, and the degree of anomaly in that period is the region-specific anomaly index value.
[0028] The region-wide abnormality index value determiner 63 first calculates a region-wide abnormality degree that represents the degree of abnormality for the entire region by integrating the region-specific abnormality degrees in an arbitrary manner. Typically, the region-wide abnormality degree may be the average value, median, or mode of the region-specific abnormality degrees, but is not limited to these (for example, a value obtained by adding or subtracting the standard deviation or a multiple thereof to the average value is also possible). Then, the region-wide abnormality degree corresponding to the period identified as the abnormality occurrence period by any of the region-wide abnormality index value determiners 13, 23, 33, 43, and 53 is used as the region-wide abnormality index value, as described above. Note that the region-wide abnormality index value determiner 63 may also set a threshold value for the region-wide abnormality degree, and identify a period in which the abnormality degree deviates from the threshold value as the abnormality occurrence period, as in the region-wide abnormality index value determiner.
[0029] The by-region abnormality determination units 14, 24, 34, 44, 54 compare, for each region, the by-region abnormality index value determined by the by-region abnormality index value determiner 13, 23, 33, 43, 53 with the overall-region abnormality index value determined by the overall-region abnormality index value determiner 63, and if the former is larger, identify that region as the source of the abnormality or as a region in which an abnormality has truly occurred. The by-region abnormality determination display units 15, 25, 35, 45, 55 may display the determination result of the occurrence of an abnormality in any manner.
[0030] In the operation of the present embodiment, the region-specific anomaly score value acquisition unit, region-specific anomaly score value normalization unit, region-specific anomaly index value determination unit, region-specific anomaly determination unit, region-specific anomaly determination display unit, and region-wide anomaly index value determination unit may each be operated sequentially as described above. Once an abnormality occurrence period is identified in any region and the presence or absence of an abnormality in each region is determined, measures to resolve the abnormality may be implemented. In this case, since the region where the abnormality originated or the region where the abnormality truly occurred can be quickly identified as described above, it is expected that measures to resolve the abnormality can also be quickly initiated.
[0031] Thus, according to the configuration of the present embodiment, in the connected service system, the degree of abnormality in each area is compared with the degree of abnormality in the entire area, thereby identifying areas with a relatively high degree of abnormality. This makes it easy to identify the area in which the abnormality truly occurs when an abnormality occurs in any area in the connected service system. This is expected to enable prompt action to be taken in response to the occurrence of the abnormality.
[0032] The above description has been made in relation to the embodiments of the present invention, but it will be apparent that many modifications and changes will be readily apparent to those skilled in the art, and the present invention is not limited to the above-described exemplary embodiments, but can be applied to various devices without departing from the concept of the present invention.
Claims
1. An anomaly detection system for a connected service system including a machine or appliance of a user, a user terminal of the user, a server center that provides a service for the user including providing service data to the user terminal and the machine or appliance based on input data received from the machine or appliance and the user terminal, and a communication network between the machine or appliance, the server center, and the user terminal, an area-specific abnormality index value acquiring means for acquiring area-specific abnormality index values representing the degree of abnormality in each area, the area being provided in each of the machine / tool, the server center, the user terminal, the communication network between the machine / tool and the server center, and the communication network between the user terminal and the server center; an entire-area abnormality index value acquisition means for acquiring an entire-area abnormality index value representing the degree of abnormality of the entire area of the connected service system based on the degree of abnormality of each area; an abnormality region determination unit that determines a region among the regions having the region-specific abnormality index value that is greater than the region-wide abnormality index value; A system having:
2. The system of claim 1 , wherein the region-wide abnormality index value is a representative value of the region-specific abnormality index values for each of the regions.
3. 10. The system of claim 1, Each of the area-specific abnormality index value acquisition means provided in each area means for detecting a parameter value related to the degree of abnormality in each of said regions as an abnormality score value; means for converting the anomaly score value into a normalized corrected anomaly score value; a means for setting a region-specific reference value based on the corrected abnormality score value over a predetermined learning period, calculating the magnitude of the difference between the corrected abnormality score value after the learning period has elapsed and the region-specific reference value as an abnormality degree, specifying a period in which the abnormality degree exceeds a predetermined threshold as an abnormality occurrence period, and determining the abnormality degree in the abnormality occurrence period as the region-specific abnormality index value; Including, The whole region abnormality index value acquisition means means for calculating an abnormality degree of the entire region from the abnormality degree for each region; means for determining the degree of abnormality of the entire region during the abnormality occurrence period as the entire region abnormality index value; A system including:
4. 4. The system of claim 3, wherein the degree of anomaly is a value obtained by normalizing the anomaly score value after interpolating missing data portions in the anomaly score value and excluding outliers.
5. The system according to claim 3 , wherein the degree of abnormality of the entire region is the average value, median value, or mode value of the degree of abnormality for each region.
Citation Information
Patent Citations
Vehicle information communication system, vehicle information communication method, vehicle information communication program, and center device
JP2020027670A
Abnormality detection model learning device, abnormality detection model, and abnormality detection device
JP2021078076A
Anomaly detection device and anomaly detection program
JP2021128423A
Control system incorporating abnormality detection function and abnormality detection method thereof
JP2022032631A
Abnormality detection model evaluating system and evaluating method
JP2022056746A