Abnormality predictor detection system, abnormality predictor detection method, and abnormality predictor detection program
The abnormality sign detection system addresses nonlinear sensor relationships in predictive maintenance by using covariant relationship models to detect abnormalities, enhancing the effectiveness of predictive maintenance in manufacturing sites.
Patent Information
- Application Number
- JP2024114322
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-17
- Publication Date
- 2026-01-29
AI Technical Summary
Existing predictive maintenance technologies struggle to detect signs of abnormalities in manufacturing sites using invariant analysis when the relationship between sensors is nonlinear.
An abnormality sign detection system that includes an observation data acquisition unit, a pair selection unit, a model generation unit, and a detection unit to identify breakdowns in covariant relationships between sensors, using covariant relationship models trained on normal states to detect abnormalities, even when sensor relationships are nonlinear.
Enables effective detection of abnormalities in manufacturing sites by analyzing time-series data from multiple sensors, regardless of linear or nonlinear relationships, supporting predictive maintenance.
Smart Images

Figure 2026013759000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an abnormality sign detection system, an abnormality sign detection method, and an abnormality sign detection program, and in particular to an abnormality sign detection system, an abnormality sign detection method, and an abnormality sign detection program that are characterized by detecting signs of abnormality occurrence using invariant analysis. [Background technology]
[0002] Traditionally, in the maintenance and management of manufacturing sites such as factories or systems, predictive maintenance has been performed by analyzing observation data, which is time-series data acquired from multiple sensors installed at these sites. Predictive maintenance refers to the detection of signs of abnormalities in machines, equipment, etc. at manufacturing sites or systems, and then performing maintenance accordingly.
[0003] In predictive maintenance, it has been proposed to use invariant analysis to detect signs of abnormalities (see, for example, Patent Document 1). Invariant analysis in predictive maintenance refers to modeling and analyzing the invariant relationships that exist between multiple installed sensors under normal circumstances when no abnormalities have occurred.
[0004] The technology disclosed in Patent Document 1 employs a method of observing the correlation between sensors and determining that a deviation from the correlation under normal conditions when no abnormality occurs is a sign of an abnormality. However, when observing the correlation between sensors, the relationship between the sensors is assumed to be linear, so when the relationship between the sensors is nonlinear, the technology disclosed in Patent Document 1 may not be applied effectively. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2019 / 026193 Summary of the Invention [Problem to be solved by the invention]
[0006] Therefore, the present invention aims to provide an abnormality sign detection system, an abnormality sign detection method, and an abnormality sign detection program that can detect signs of abnormalities using invariant analysis in predictive maintenance performed by analyzing observation data, which is time-series data obtained from multiple sensors, not only when the relationship between sensors is linear but also when it is nonlinear. [Means for solving the problem]
[0007] That is, the abnormality sign detection system according to the first aspect is characterized by comprising an observation data acquisition unit that acquires observation data from each of a plurality of sensors; a pair selection unit that selects, for each of the plurality of sensors, from among pairs of sensors each formed by combining the plurality of sensors with another sensor, a pair having the strongest causal relationship based on the respective observation data; a model generation unit that generates, for each of the pairs selected for each of the plurality of sensors, a covariant relationship model that indicates the relationship between the pair of sensors that constitute the pair and evaluates any breakdown of the relationship from a normal state; and a detection unit that detects a breakdown of the normal relationship between the pair of sensors that constitute the pair based on the covariant relationship model.
[0008] In a second aspect, the abnormality precursor detection system according to the first aspect may further include an alarm unit that notifies a user of an abnormality when the number of times the detection unit detects a breakdown in the normal relationship exceeds a threshold value.
[0009] In a third aspect, in the anomaly sign detection system according to the first aspect, the covariant relationship model may be trained using observation data in a normal state of a pair of sensors that constitute a pair as training data.
[0010] In a fourth aspect, in the anomaly sign detection system according to the first aspect, the covariant relationship model may output a predicted value that evaluates the relationship between a pair of sensors that form a pair, and the predicted value may become a large value when the relationship reaches a state that was not experienced during learning.
[0011] In a fifth aspect, in the anomaly sign detection system according to the first aspect, the covariant relationship model may be selected from four regression models: a linear regression model in a first causal direction, a linear regression model in a second causal direction that is opposite to the first causal direction, a nonlinear regression model in the first causal direction, and a nonlinear regression model in the second causal direction, so that the covariant relationship model that minimizes the mean absolute percentage error between the observed values constituting the sensor observation data and the predicted values of the regression model related to the observed values is selected.
[0012] As a sixth aspect, in the anomaly sign detection system according to the first aspect, a causal relationship may be estimated by using a causal search.
[0013] The abnormality sign detection method according to the seventh aspect is characterized in that a computer executes the following steps: an observation data acquisition step of acquiring observation data from each of a plurality of sensors; a pair selection step of selecting, for each of the plurality of sensors, from among pairs of sensors each formed by combining the plurality of sensors with another sensor, a pair having the strongest causal relationship based on the respective observation data; a model generation step of generating, for each of the pairs selected for each of the plurality of sensors, a covariant relationship model that indicates the relationship between the pair of sensors that constitute the pair and evaluates a breakdown of the relationship from a normal state; and a detection step of detecting a breakdown of the normal relationship between the pair of sensors that constitute the pair based on the covariant relationship model.
[0014] The abnormality sign detection program according to the eighth aspect is characterized in that it implements in a computer an observation data acquisition function that acquires observation data from each of a plurality of sensors, a pair selection function that selects, for each of the plurality of sensors, from among pairs formed by combining each of the plurality of sensors with other sensors, a pair that has the strongest causal relationship based on the respective observation data, a model generation function that generates, for each of the pairs selected for each of the plurality of sensors, a covariant relationship model that indicates the relationship between the pair of sensors that constitute the pair and evaluates any breakdown of the relationship from a normal state, and a detection function that detects a breakdown of the normal relationship between the pair of sensors that constitute the pair based on the covariant relationship model. [Effects of the Invention]
[0015] The anomaly sign detection system of the present invention includes an observation data acquisition unit that acquires observation data from each of a plurality of sensors; a pair selection unit that selects, for each of the plurality of sensors, from among pairs formed by combining each of the plurality of sensors with another sensor, a pair that has the strongest causal relationship based on the respective observation data; a model generation unit that generates, for each of the pairs selected for each of the plurality of sensors, a covariant relationship model that indicates the relationship between the pair of sensors that constitutes the pair and evaluates any disruption of the relationship from a normal state; and a detection unit that detects disruption of the normal relationship between the pair of sensors that constitutes the pair based on the covariant relationship model.Therefore, in predictive maintenance that is performed by analyzing observation data, which is time-series data acquired from the plurality of sensors, signs of an abnormality can be detected by invariant analysis not only when the relationship between the sensors is linear, but also when it is nonlinear.
[0016] Furthermore, similar to the anomaly sign detection system of the present invention, the anomaly sign detection method and anomaly sign detection program of the present invention can detect signs of anomalies through invariant analysis in predictive maintenance that is performed by analyzing observation data, which is time-series data obtained from multiple sensors, not only when the relationship between sensors is linear, but also when it is nonlinear. [Brief explanation of the drawings]
[0017] [Figure 1] 1A and 1B are diagrams for explaining a general example and problem of conventional abnormality sign detection. [Figure 2] 1A and 1B are diagrams for explaining a general example and problem of conventional abnormality sign detection. [Figure 3] FIG. 2 is a diagram for explaining an image of a mechanism for detecting an abnormality sign according to the present embodiment. [Figure 4] FIG. 2 is a diagram for explaining an image of a mechanism for detecting an abnormality sign according to the present embodiment. [Figure 5] FIG. 2 is a diagram for explaining an image of a mechanism for detecting an abnormality sign according to the present embodiment. [Figure 6] 10 is a flowchart showing the procedure for determining the strength of the causal relationship between x and y in this embodiment. [Figure 7] 10 is a flowchart of an operational algorithm using a covariant relationship model of the anomaly sign detection system according to the present embodiment. [Figure 8] 1 is a block diagram showing an example of a hardware configuration of an abnormality sign detection system according to an embodiment of the present invention. [Figure 9] 1 is a block diagram showing an example of the functional configuration of an abnormality sign detection system according to an embodiment of the present invention; [Figure 10] 3 is a flowchart of an abnormality sign detection program according to the present embodiment. [Figure 11] 10 is a flowchart of an abnormality sign detection program according to another embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0018] (Outline of the proposed method of this disclosure) Large-scale facilities, factories, systems, etc. operate using a combination of various devices, machinery, equipment, etc., so there are an enormous number of points to be monitored, and when attempting to perform predictive maintenance using observation data acquired from sensors installed in these facilities, etc., the number of sensors required to acquire the observation data is quite large. In this embodiment, the observation data is assumed to be time-series data. Predictive maintenance is a maintenance method for facilities, equipment, and machinery, and involves predicting abnormalities in the facilities, equipment, and machinery to prevent breakdowns and other anomalies before they occur. Its main feature is that it uses monitoring devices such as sensors to constantly monitor facilities, equipment, and machinery in factories and other locations, and detects and addresses abnormalities before they occur. Predictive maintenance can be rephrased as predictive maintenance. Preventive maintenance is a maintenance method that prevents accidents and breakdowns by periodically performing maintenance and replacing parts on facilities, equipment, machines, etc. The difference between predictive maintenance and preventive maintenance is that predictive maintenance detects signs of abnormalities in facilities, equipment, machines, etc. and performs maintenance by detecting them, while preventive maintenance performs maintenance and part replacement at regular intervals regardless of whether there are signs of abnormalities.
[0019] Even if an abnormality can be detected for a large facility as a whole from the data obtained from all sensors (hereinafter referred to as observation data), a separate analysis is required to determine which parts should be inspected. For example, even if an abnormality is detected in the observation data obtained from sensors installed in facility A, a separate analysis is required to determine which parts of facility A should be inspected. Furthermore, the problem can be solved if each sensor detects an abnormality, but the observed data is diverse, including temperature, vibration, and voltage, and it is necessary to detect abnormalities using algorithms tailored to the individual physical characteristics of each sensor, which is time-consuming and costly. Therefore, this disclosure proposes a new method to detect abnormalities in the relationships (breakdown of statistical causal relationships) (detect phenomena that differ from normal times) by focusing on the statistical causal relationships between observational data rather than on individual observational data, thereby finding signs of abnormalities such as breakdowns and supporting predictive maintenance.
[0020] (Common examples and challenges of traditional anomaly detection) A general example and problem of conventional anomaly detection will be described with reference to Figures 1 and 2. Figures 1 and 2 are diagrams for explaining a general example and problem of conventional anomaly detection. There are cases where abnormalities cannot be detected from the observation data of each sensor in the manufacturing process, etc. Conversely, there are cases where a phenomenon that is not abnormal is recognized as an abnormality. In reality, manufacturing processes and the like involve a series of flows that often have some kind of causal relationship. It can also be said that these flow according to a certain rhythm that humans cannot understand. Anomalies can be detected by analyzing the statistical causal relationships between data and focusing on those relationships. Why causal relationships? Correlation often makes unrelated relationships appear to be related. Correlation is a relationship between things that has no meaning apart from one another, and in the world of mathematics, correlation is the relationship between two quantities where when one increases, the other tends to increase or decrease. In other words, correlation means that there is some kind of relationship between things A and B. On the other hand, causality refers to the relationship between a cause and the result that results from it. In other words, causality means that A causes B to fluctuate. The relationship between correlation and causation is that a causal relationship is one that represents cause and effect within a correlation, and things that have a causal relationship are correlated, but things that have a correlation do not necessarily have a causal relationship.
[0021] FIG. 1(a) shows a waveform 15 when sensor A is normal, FIG. 1(b) shows a waveform 16 when sensor B detects an abnormality, and FIG. 1(c) shows a waveform 17 when sensor A is abnormal. In the waveform 16 of FIG. 1(b), occurrence of anomalies 16a and 16b was detected. Figure 1(c) shows waveform 17 when sensor A is abnormal. Sensors A and B are in a causal relationship, and waveform 17 of sensor A is assumed to be affected by sensor B, where abnormalities 16a and 16b have occurred. At first glance, waveform 17 of sensor A shown in Figure 1(c) appears to have no abnormalities, but in fact there is an abnormality. Waveform (observation data) 17 of sensor A shown in Figure 1(c) is an example where an abnormality cannot be detected from waveform (observation data) 17 alone.
[0022] FIG. 2(a) shows a waveform 18 of sensor A, and FIGS. 2(b) and 2(c) are diagrams for comparing the waveform 18 of sensor A with the waveform 19 of sensor B. FIG. 2(b) shows an example in which a waveform 18 from sensor A is compared with a waveform 19 from sensor B, and it can be seen that no abnormality has occurred. FIG. 2(c) shows an example in which the occurrence of an abnormality can be detected by comparing the waveform 18 of sensor A with the waveform 19 of sensor B. 2(d) and 2(e) are diagrams for explaining the detection of the abnormality shown in FIG. 2(c). As shown in FIG. 2(a), the waveform 18 of sensor A may appear to be abnormal, but actually includes a normal portion 18a, and an abnormality may be detected by observing the waveform 18 alone. Therefore, as shown in Figure 2(b), when waveform 19 of sensor B, which has a causal relationship with sensor A, is viewed alongside waveform 18 of sensor A, it can be seen that waveform 18 of sensor A and waveform 19 of sensor B are synchronized, and that there is no abnormality in sensor A. Period 19a appears to be abnormal when looking at waveform 18 of sensor A alone, but it is a period in which synchronization with waveform 19 of sensor B can be confirmed. The case shown in Figure 2(b) is a common occurrence, and can be seen, for example, when the power is turned off during a break or for maintenance. Furthermore, as shown in Figure 2(c), when waveform 19 of sensor B, which is in a causal relationship with sensor A, is viewed alongside waveform 18 of sensor A, it is clear that there is a portion (period 19a) where waveform 18 of sensor A and waveform 19 of sensor B are synchronized, as well as periods 19b and 19c where the rhythm between waveform 18 of sensor A and waveform 19 of sensor B is broken, and it can be said that some kind of abnormality has clearly been detected from Figure 2(c). Figure 2(d) shows step waveform 20 of sensor A and step waveform 21 of sensor B, which make it easier to see the cycles of waveform 18 of sensor A and waveform 19 of sensor B shown in Figure 2(c). When step waveform 20 of sensor A and step waveform 21 of sensor B are superimposed (see Figure 2(e)), it is clear that there is a timing discrepancy between the two step waveforms 20, 21, and it is detected that some kind of abnormality has occurred.
[0023] (About the proposed method of this disclosure) In this disclosure, a nonlinear prediction model is constructed based on the causal relationships between sensors and their independence. While the causal relationships may not change due to the signs of an anomaly, the degree of impact may change. Furthermore, when there is a relationship between the cause and effect of an anomaly, the observed data changes, so the relationship is not disturbed. However, when there is a difference between normal and abnormal conditions, even if the relationship is covariant, a disturbance appears in the calculation (as a prediction error in the model).
[0024] The general logic used in the abnormality sign detection system 10 according to the present disclosure is as follows (1) to (3). (1) Usually, the causal relationships between sensors are complex and are not one-to-one but one-to-many. From these relationships, we select a one-to-one relationship (corresponding to the pair relationship described below) after excluding those with weak causal relationships. Normally, this relationship is a covariant relationship. A covariant relationship is a relationship that changes together. If the relationship is weak, we test its independence to see if it is truly unrelated. (2) When an event that is out of the ordinary occurs, this relationship is disrupted. (3) The breakdown of this covariant relationship is seen as a sign of the occurrence of an abnormality. It uses causality and independence as its criteria rather than simple correlation or regression. The greatest advantage of this method is that it does not require any data showing abnormal conditions in order to detect anomalies; it only requires data from normal (normal) times.
[0025] (Image of the mechanism for detecting abnormal signs disclosed in this disclosure) An image of the mechanism of abnormal sign detection used by the abnormal sign detection system 10 of the present disclosure will be described with reference to Figures 3, 4, and 5. Figures 3, 4, and 5 are diagrams for explaining an image of the mechanism of abnormal sign detection of the present disclosure. As shown in Figure 3, looking at the waveform 35 of sensor A and the waveform 36 of sensor B, it can be determined that they are synchronized and there is no abnormality. Also, as shown in Figure 3, when looking at the waveform 36 of sensor B and the waveform 37 of sensor C, it can be determined that they are synchronized and there is no abnormality. If there is a causal relationship between sensors A and B, between sensors B and C, and between sensors A and C, then even if an abnormality occurs in sensor C, it would seem that sensors A and B would not be able to detect the abnormality because they would be covariantly synchronized with sensor C. This is where the covariant relationship model (covariant_relationship_model(x,y)) plays an important role. This covariant relationship model is based on the normal relationship, and if this normal relationship collapses, the value calculated by the covariant relationship model will become larger. If the frequency of abnormalities is high and there are not many normal states, it is better to carry out regular maintenance by detecting signs of abnormalities in the first place.At the very least, the assumption that there must be many normal "usual" states in order to detect "unusual" states that make it meaningful to detect signs of abnormalities should not be a strong constraint on building a covariant relationship model.
[0026] The function of the covariant relationship model (covariant_relationship_model(x,y)) will be explained with reference to FIG. FIG. 4(a) shows a comparison between a waveform 35 of sensor A when it is normal and a waveform 35a of sensor A affected by an abnormality that occurred in sensor C after the learning period of sensor A. FIG. 4(b) shows a comparison between a waveform 36 of sensor B when it is normal and a waveform 36a of sensor B affected by an abnormality that occurred in sensor C after the learning period of sensor B. FIG. 4(c) shows the waveform of sensor C when an anomaly 37a occurs after the learning period of sensor C.
[0027] First, it is assumed that there is a causal relationship between sensors A and B shown in FIG. 4, and there is a causal relationship between sensors B and C. The covariant relationship model that models the covariant relationship between the observation data of sensor A and the observation data of sensor B is expressed by the following equation (A). The covariant relationship model that models the covariant relationship between the observation data of sensor B and the observation data of sensor C is expressed by the following equation (B). The value e on the left side of equations (A) and (B) is the predicted value of the covariant relationship model, and is also an evaluation value for assessing the covariant relationship. e basically takes a large value when the state of the relationship between sensor A and sensor B becomes a state not experienced in the observation data (learning data) that indicates the normal state learned during the learning period. When e exceeds the threshold and the relationship between sensor A and sensor B is determined to be a rare event (event), it is determined that an abnormality has occurred in the covariant relationship. The covariant relationship model (covariant_relationship_model(A,B)) in equation (A) is trained using observation data (training data) that indicate the normal states of sensors A and B during the training period. The covariant relationship model (covariant_relationship_model(B,C)) in equation (B) is trained using observation data (training data) that indicate the normal states of sensors B and C during the training period.
[0028]
number
[0029] In the covariant relationship model (covariant_relationship_model(A,B)) of formula (A), the predicted value e basically becomes large when a state not experienced during the learning period is reached. If this value exceeds the threshold, it is determined that an event that rarely occurs has occurred, and an abnormality has occurred in the covariant relationship between sensor A and sensor B. Similarly, in the covariant relationship model (covariant_relationship_model(B,C)) of formula (B), when a state that has not been experienced during the learning period is encountered, the predicted value e is generally large, and when this value exceeds a threshold, it is determined that an event that rarely occurs has occurred. The covariant relationship model of equations (A) and (B) can detect a state that is "different from usual" and at the same time determine that one of sensors A, B, and C has entered a state that is different from normal (an abnormal state), which rarely occurs.
[0030] Next, it is assumed that there is a causal relationship between sensors A and B shown in Fig. 4, but there is no causal relationship between sensors C and A, and between sensors B and C. In other words, the pairs described below are not created between sensors C and A, and between sensors B and C. In this case, equation (A) holds, but equation (B) does not hold. The causal relationship between two sensors refers to the relationship between the numerical orders of the quantities of physical phenomena measured by the sensors, excluding the units of the quantities.
[0031] In the covariant relationship model (covariant_relationship_model(A,B)) of formula (A), the predicted value e is generally large when a state not experienced during learning (learning period) is reached. If this exceeds the threshold, it is determined that an event (which rarely occurs) has occurred, and an abnormality has occurred in the covariant relationship between sensor A and sensor B. This detects a state that is "different from usual," and at the same time, it can be determined that a state different from normal (an abnormal state) that rarely occurs in sensor A or sensor B has occurred. From the perspective of sensor A and sensor B, the cause is unknown, but a breakdown in the covariant relationship between sensor A and sensor B has been detected. Because sensor C is independent of sensors A and B, it has no causal relationship with sensors A and B. In other words, an example of a phenomenon that did not exist during learning would be when sensor C suddenly interferes with sensor A or sensor B. This would be equivalent to an accident in which sensor C breaks and the debris damages sensor B. On the other hand, because the correlation between sensors A and B is likely to be maintained, it can be said that an abnormality in sensor C is difficult to detect due to a breakdown in the correlation. However, in such a case, it should be easy to detect using conventional anomaly detection methods.
[0032] Figure 5 shows a comparison between the waveforms of sensors a1 and a2. Figure 5(a) shows the waveform 40 of the environmental data of sensor a1, and Figure 5(b) shows the waveform 41 of the environmental data of sensor a2. Figure 5(c) shows the waveform 42 of the time series data of the anomaly degree of the covariant relationship between sensors a1 and a2. The learning period 43 is a period during which learning data (learning data) used for machine learning of the covariant relationship model between the sensor a1 and the sensor a2 is acquired. Environmental data indicating the normal state of the sensor a1 and the sensor a2 during the learning period 43 is acquired and becomes the learning data (learning data) of the covariant relationship model between the sensor a1 and the sensor a2. The period 44 is a period during which the breakdown of the covariant relationship between the sensor a1 and the sensor a2 is detected before the occurrence of an anomaly. The period 44 is a period during which the waveform 42 of the time-series data of the anomaly degree exceeds the notification threshold 47. Anomaly occurrence detection 46 indicates the time when an actual occurrence of an abnormality is detected.
[0033] (Regarding the causal relationship of proposed method (1)) To estimate causal relationships, we use LiNGAM (Linear Non-Gaussian Acyclic Model), a causal search algorithm. LiNGAM is a linear model that assumes a non-Gaussian (non-normal) distribution. Because LiNGAM estimates a linear model of causal relationships, if LiNGAM is used as is, it may construct an incorrect causal relationship if the actual causal relationship is a nonlinear relationship, a relationship between continuous values and discrete values, or a relationship between discrete values and discrete values. However, experiments by the inventors have shown that although the direction and strength of causality may be incorrect, it is rare for a causal relationship to be inferred as unrelated. In other words, in LiNGAM estimations, estimates regarding the direction of causality cannot be trusted as they are, but estimates that there is a relationship can be considered useful. Those with a weak causal relationship are checked to see if they are unrelated (independent), and those who are determined to be independent are excluded from the following processing as they are not related. In determining this independence (unrelatedness), correlation can only be determined in the case of a linear relationship, but in order to accurately determine the independence (unrelatedness) of causal relationships, including linear and non-linear relationships, the Hilbert-Schmidt independence criterion (HSIC) is used.
[0034] (Modeling covariant relationships) Therefore, we model the covariant relationship in the following way. When causal exploration predicts that x is related to y, the four regression models shown in the following formulas (1) to (4) are generated. These four regression models are a linear regression model and a nonlinear regression model in the causal direction (x → y), and a linear regression model and a nonlinear regression model in the causal direction (y → x). Note that x and y here refer to independent variables expressed on a certain coordinate plane. Then, the error rate (prediction accuracy) is confirmed for each of the four regression models using the error rate calculation formula expressed in formula (5) (formulas (6) to (9)).
[0035]
number
[0036]
number
[0037] The regression model of equation (1) is a linear regression model expressed as a linear function with y as the dependent variable and x as the explanatory variable, and the causal direction is x (cause) → y (result). The regression model of equation (2) is a linear regression model expressed as a linear function with x as the dependent variable and y as the explanatory variable, and the causal direction is y (cause) → x (result). The regression model of equation (3) is a nonlinear regression model expressed by a nonlinear function with y as the objective variable and x as the explanatory variable, and the causal direction is x (cause) → y (result). The regression model of equation (4) is a nonlinear regression model expressed by a nonlinear function with x as the objective variable and y as the explanatory variable, and the causal direction is y (cause) → x (result).
[0038] The mean absolute percentage error (MAPE: referred to as the error rate in this embodiment) shown in formula (5) is a function that calculates the absolute value of the "difference between the predicted value (pred) and the correct value (observed value) (obs) divided by the correct value (observed value) (=percentage error)" for each data, and outputs the value (=average value) obtained by dividing the sum of these values by the number of data. The predicted value here is the numerical value predicted by the regression model, and the correct value (observed value) is the actual numerical value observed, which refers to the individual numerical values that make up the sensor's observation data. Equation (6) represents the error rate between the predicted value y and the observed value y of the regression model of equation (1). Equation (7) represents the error rate between the predicted value x and the observed value x of the regression model of equation (2). Equation (8) represents the error rate between the predicted value y and the observed value y in the regression model of equation (3). Equation (9) represents the error rate between the predicted value x and the observed value x of the regression model of equation (4).
[0039] Of the four regression models, the one with the smallest error rate represented by equations (6) to (9), i.e., the one with the highest accuracy, is determined to model the covariant relationship. For example, if the error rate of equation (7) is the smallest among the error rates represented by equations (6) to (9), the regression model of equation (2) (a linear regression model with a causal direction of y → x) is determined to model the covariant relationship. As a result, a regression model determined to model a covariant relationship is a model that maintains a correct causal relationship in the sense of Granger causality, even if the relationship between x and y is nonlinear or has discrete values. Granger causality means that, for example, in time series data x and y, when predicting future y values, the accuracy of the prediction is improved by adding the value of x rather than by using the current and past values of y, and therefore there is a causal relationship from x to y in the sense of Granger causality. If the minimum error rate is greater than the allowable value (e.g., the error rate MAPE is 20%), the subsequent processing will not be performed. On the other hand, independent information has no causal relationship with any other party, so even if an abnormality occurs, there is no correlation, so monitoring using normal anomaly detection is sufficient.
[0040] Hereinafter, the procedure for determining the strength of the causal relationship between x and y will be described with reference to FIG. FIG. 6 is a flowchart showing the procedure for determining the strength of the causal relationship between x and y in this embodiment.
[0041] Step S100 The strength of the causal relationship between x and y is determined by the weight value of the adjacency matrix calculated by LiNGAM. This involves leaving the top N weights when all weights related to x are sorted in descending order. LiNGAM uses all observed data (training data) {x i All the observation data is data under normal circumstances and is used as learning data when generating the model described in this embodiment.
[0042] Step S110 The remaining items are those with a weak causal relationship between x and y, so their independence is tested using the Hilbert-Schmidt Independence Criterion (HSIC), and if they are deemed to be independent, they are excluded from the causal relationship.
[0043] Step S120 x the remaining i It will be paired with. A pair is a set of all observed data (training data) {x i}, other observed data (training data) that show the strongest causal relationship for each j} (where i≠j). The quantities (physical quantities) of the physical phenomena handled by the two observation data constituting the combination here may be the same type of physical quantity or different types of physical quantities. In other words, the combination refers to a combination of the order of magnitudes excluding the units of the quantities of the physical phenomena handled by the observation data. In addition, independent information that has no paired partner has no causal relationship with another party, so even if an abnormality occurs, there is no linkage and so monitoring is performed using normal abnormality detection.
[0044] (Definition of the covariant relationship model) The model that evaluates the residuals (error rate) of the regression model selected as described above is defined as a covariant relationship model (see equation (10)).
[0045]
number
[0046] As described above, which of the right-hand sides of equation (10) is selected is determined to be the one that models the covariant relationship among the four regression models, with the smallest error rate expressed by equations (6) to (9), i.e., the one with the highest accuracy. The model for the pair pair(x,y) that shows the strongest causal relationship between x and y is the covariant relationship model (covariant_relationship_model(x,y)). Because the covariant relationship model models the relationship between the two, it will have a small value as long as the covariant relationship is maintained, and will have a value of 0 if the relationship is completely covariant. Therefore, if the model evaluation value (the calculated value of covariant_relationship_model(x,y) and equivalent to e on the left-hand side of equations (A) and (B)) is large, it can be considered that the covariant relationship has collapsed. This gives us a covariant relationship model for each sensor pair.
[0047] (Operational algorithm using covariant relationship model) Next, an operational algorithm using the covariant relationship model of the abnormal sign detection system 10 will be described with reference to Fig. 7. Fig. 7 is a flowchart of the operational algorithm using the covariant relationship model of the abnormal sign detection system 10.
[0048] Step S200 Obtain observation data. The observed data is a={a i} and refers to the observation data since the anomaly sign detection system 10 started operation.
[0049] Step S210 Each observation data pair (a i ,#) and the associated covariant relationship model are evaluated. pair(a i ,#) is a i represents the whole set of pairs, and # means all observed data (training data). The evaluation value for evaluating the covariant relationship model is expressed by Equation (11).
[0050]
number
[0051] Step S220 Each pair of observation data (a i ,#) and evaluate the breakdown of the covariant relationship. The evaluation value for evaluating the breakdown of the covariant relationship is expressed by equation (12). mean means the average, and std means the standard deviation. i is the covariant relationship model expressed by equation (13), where x={x i}, ♯ means all observed data (training data).
[0052]
number
[0053]
number
[0054] Step S230 If Z exceeds a threshold, it is determined that the covariant relationship has been broken. Z>Chi-squared (percentile) If the percentile is 99.9%, then chi-square (0.001) = 10.82 That is, the probability that the threshold appears to be exceeded by chance is 0.1%, and x i and x j ∈pair(x i ,#)It can be determined that the covariant relationship has been broken. A percentile is a data value that, when observed data are sorted in ascending order, represents a specified percentage of values smaller than that value. For example, the 99th percentile is the data value that represents 99 percent of data smaller than that value.
[0055] Basically, the above method is used to create pairs of observation data (a i ,a j ) is detected, but it may be detected by chance due to an incomplete model or noise. Therefore, the following method is used to calculate the pair (a) of each observed data. i ,a j ) to reduce false alerts as much as possible. It is assumed that an alert will not be issued for a certain period of time after the anomaly sign detection system 10 starts operation. (1) Pairs of observation data within a certain period of time i ,a j ) and counts the number of detected breakdowns in the covariant relationship, and issues an alert if the number exceeds a threshold. (2) Each pair of observation data (a i ,a j ) and issue an alert if the number exceeds a threshold. (3) Each pair of observation data (a i ,a j ) weighted count exceeds the threshold, an alert is issued unconditionally. When the percentile is 99.999%, the chi-square (0.0001) = 15.14 The weighted count is expressed by equation (14).
[0056]
number
[0057] Equation (14) is the pair of observation data (a i ,a j ) is counted as 1, and the sum of the pair of observation data from the start of operation of the anomaly sign detection system 10 to the present is calculated. i ,a j However, immediately after the start of operation of the abnormal sign detection system 10, f(t)=0, and immediately after the start of operation of the abnormal sign detection system 10, the number of times that the covariant relationship between the pair of observation data pair(a i ,a j ) does not count the breakdown of the covariant relationship.
[0058] (Hardware configuration of the abnormality sign detection system 10) The hardware configuration of the abnormality sign detection system 10 according to this embodiment will be described with reference to Fig. 8. Fig. 8 is a block diagram showing an example of the hardware configuration of the abnormality sign detection system 10. The abnormality sign detection system 10 is a so-called computer, which may also be referred to as an information processing device. The abnormality sign detection system 10 includes a communication unit 10a, a ROM 10b, a RAM 10c, a storage unit 10d, a calculation unit 10e, and an input / output interface 10f. Furthermore, the abnormality sign detection system 10 includes external devices such as an input device 10g and an output device 10h that input and output data via an input / output interface 10f.
[0059] The communication unit 10a has a function of performing two-way communication with other information processing devices. When the communication unit 10a performs two-way communication with other information processing devices, the communication unit 10a may perform the two-way communication via the information communication network 25, or may perform the two-way communication by directly connecting to the other information processing device. The communication unit 10a may use wired communication or wireless communication for communication with other information processing devices.
[0060] The ROM 10b can be used as a recording device, and stores a BIOS (Basic Input Output System) required for controlling the operation of each functional unit of the abnormality sign detection system 10, various data used by the BIOS, and the like. BIOS is a program that manages the basic input / output functions of the abnormality sign detection system 10. It is the first program to run when the abnormality sign detection system 10 is turned on, controlling hardware such as the communication unit 10a, ROM 10b, RAM 10c, memory unit 10d, calculation unit 10e, and input / output interface 10f, and preparing to start up the OS (Operating System).
[0061] The RAM 10c is used to configure the main memory accessed by the calculation unit 10e, and is also used to temporarily store various data acquired or generated by the abnormality sign detection system 10 before storing it in the memory unit 10d.
[0062] The storage unit 10d is realized by an HDD (Hard Disk Drive), an SSD (Solid State Drive), online storage, etc., and stores the OS, the abnormality sign detection program described below, other application software, various data used by these programs, etc. The storage unit 10d also stores various data acquired or generated by the abnormality sign detection system 10.
[0063] The calculation unit 10e includes a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a GPU (Graphic Processing Unit), etc., and is realized by a logic circuit or a dedicated circuit formed by an integrated circuit (IC (Integrated circuit) chip, LSI (Large-Scale Integration)), etc. The calculation unit 10e may be a processing unit that performs the function of a machine-learned learning model, or a processing unit that performs the function of artificial intelligence (AI) such as generation AI. The input / output interface 10f is an interface for transmitting and receiving data to and from external devices such as the input device 10g and the output device 10h. The input / output interface 10f may use different standards depending on the data to be handled, and may support multiple standards, such as HDMI (registered trademark), USB 2.0, USB 3.0, and IEEE 1394.
[0064] The input device 10g includes a keyboard, a mouse, and the like, and receives inputs for operating the abnormal sign detection system 10 by a user. The output device 10h includes a monitor, a printer, and the like, and displays data generated by the abnormality sign detection system 10 to a user or the like.
[0065] (Functional configuration of the abnormality sign detection system 10) Next, an example of the functional configuration of the abnormality sign detection system 10 will be described with reference to Fig. 9. Fig. 9 is a block diagram for explaining an example of the functional configuration of the abnormality sign detection system 10. The abnormality sign detection system 10 loads an abnormality sign detection program, which will be described later and is stored in the storage unit 10d, into a main memory configured with a RAM 10c, etc. The calculation unit 10e accesses the main memory into which the abnormality sign detection program has been loaded, and executes the abnormality sign detection program. By executing the abnormality sign detection program, the abnormality sign detection system 10 provides the calculation unit 10e with functional units such as an observation data acquisition unit 30, a pair selection unit 31, a model generation unit 32, a detection unit 33, and a notification unit .
[0066] The observation data acquisition unit 30 acquires observation data from each of a plurality of sensors. The sensor may be a sensor that detects the state of various physical quantities such as devices, machinery, and equipment installed in a monitored facility, factory, system, etc. For example, the sensor may be a sensor that detects a wide variety of physical quantities such as temperature, vibration, voltage, current, air pressure, and humidity. Step S200 in the flowchart shown in FIG.
[0067] The pair selection unit 31 selects, for each of the plurality of sensors, a pair having the strongest causal relationship based on the respective observation data from among pairs of each of the plurality of sensors and other sensors. The strength of the causal relationship is determined by the weight value of the adjacency matrix calculated using LiNGAM (Linear Non-Gaussian Acyclic Model). LiNGAM is a method for causal discovery, and refers to a linear model that assumes a non-Gaussian (non-normal) distribution.
[0068] For each pair selected for each of the multiple sensors, the model generation unit 32 generates a covariant relationship model for each pair that indicates the relationship between the pair of sensors that make up the pair and evaluates any deviation from the normal state of the relationship. The covariant relationship model is trained using the normal state observation data of a pair of sensors as training data. The covariant relationship model outputs a predicted value that evaluates the relationship between a pair of sensors that make up a pair, and the predicted value becomes large when the relationship reaches a state that was not experienced during learning. The covariant relationship model is selected from four regression models: a linear regression model in a first causal direction, a linear regression model in a second causal direction that is opposite to the first causal direction, a nonlinear regression model in the first causal direction, and a nonlinear regression model in the second causal direction, so that the covariant relationship model that minimizes the mean absolute percentage error between the observed values constituting the sensor observation data and the predicted values of the regression model related to the observed values is selected. Causal discovery is used to infer causal relationships.
[0069] A covariant relationship is one in which the data vary together. For example, a relationship in which the data from sensor B changes in response to changes in the data from sensor A is called a covariant relationship. The covariant relationship model is defined by equation (10) above. As described above, which of the right-hand sides of equation (10) is selected is determined to be the one that models the covariant relationship among the four regression models, with the smallest error rate expressed by equations (6) to (9), i.e., the one with the highest accuracy.
[0070] The detection unit 33 detects a breakdown of the normal relationship between a pair of sensors based on the covariant relationship model. The detection unit 33 detects a breakdown in the covariant relationship between the sensors when an evaluation value for evaluating the covariant relationship model exceeds a threshold. The detection unit 33 may take charge of steps S220 and S230 in the flowchart shown in FIG.
[0071] The notification unit 34 notifies the user of an abnormality when the number of times that the detection unit 33 detects the breakdown of the normal relationship exceeds a threshold value. The term "user" refers to a user of the abnormal sign detection system 10, as well as a user of the abnormal sign detection method and abnormal sign detection program described below. The notification unit 34 may notify the user by using an email, a push notification, or the like, or may notify the user by using an alarm sound.
[0072] (Method and program for detecting abnormal signs) Next, an abnormality sign detection method and an abnormality sign detection program according to this embodiment will be described with reference to Fig. 10. Fig. 10 is a flowchart of the abnormality sign detection program according to this embodiment. The abnormality sign detection method is executed by the calculation unit 10e of the abnormality sign detection system 10 based on an abnormality sign detection program. The abnormality sign detection program includes an observation data acquisition step S30, a pair selection step S31, a model generation step S32, and a detection step S33. The abnormal sign detection program causes the calculation unit 10e of the abnormal sign detection system 10 to realize an observation data acquisition function, a pair selection function, a model generation function, a detection function, and the like. These functions are executed in the order shown in the flowchart of Fig. 10, but the order can also be changed as appropriate. Note that each function overlaps with the description of the various functional units of the abnormal sign detection system 10 described above, and therefore detailed description thereof will be omitted.
[0073] The observation data acquisition function acquires observation data from each of a plurality of sensors (step S30: observation data acquisition step).
[0074] The pair selection function selects, for each of the plurality of sensors, a pair having the strongest causal relationship based on the respective observation data from among pairs of each of the plurality of sensors and other sensors (step S31: pair selection step).
[0075] The model generation function generates a covariant relationship model for each pair selected for each of the multiple sensors, which shows the relationship between the pair of sensors that make up the pair and evaluates any deviation from the normal state of the relationship (step S32: model generation step).
[0076] The detection function detects a breakdown of the normal relationship between a pair of sensors based on the covariant relationship model (step S33: detection step).
[0077] (Regarding abnormality sign detection method and abnormality sign detection program according to other embodiments) Next, an abnormality sign detection program according to another embodiment will be described together with an abnormality sign detection method according to another embodiment with reference to Fig. 11. Fig. 11 is an example of a flowchart of the abnormality sign detection method according to another embodiment. The flowchart of the abnormality sign detection program according to another embodiment shown in FIG. 11 differs from the flowchart of the abnormality sign detection program shown in FIG. 10 in that a notification step S34 is added. The abnormality sign detection method according to the other embodiment is executed by the calculation unit 10e of the abnormality sign detection system 10 based on the abnormality sign detection program according to the other embodiment shown in FIG. The abnormality sign detection program according to another embodiment shown in FIG. 11 includes an observation data acquisition step S30, a pair selection step S31, a model generation step S32, a detection step S33, and a notification step S34.
[0078] 11 causes the calculation unit 10e of the abnormal sign detection system 10 to realize an observation data acquisition function, a pair selection function, a model generation function, a detection function, and a notification function. These functions are executed in the order shown in the flowchart of FIG. 11, but the order can also be changed as appropriate. The abnormality sign detection method and abnormality sign detection program according to another embodiment shown in FIG. 11 will be described below, focusing only on the differences from the abnormality sign detection method and abnormality sign detection program shown in FIG. Furthermore, since each function overlaps with the description of the various functional units of the abnormality sign detection system 10 described above, detailed description thereof will be omitted.
[0079] The notification function notifies the user of an abnormality when the number of times that the detection function detects a breakdown of the normal relationship exceeds a threshold value (step S34: notification step).
[0080] According to the abnormality sign detection system 10 of the above-described embodiment, it is possible to detect signs of abnormalities in equipment, machinery, facilities, etc. in facilities, factories, systems, etc., thereby making it possible to suppress the occurrence of abnormalities in equipment, machinery, facilities, etc.
[0081] Furthermore, according to the abnormality sign detection system 10 of the above-described embodiment, learning the covariant relationship model does not require environmental data indicating an abnormal state obtained from a sensor, and therefore it is possible to reduce the effort required to obtain learning data used to learn the covariant relationship model.
[0082] Furthermore, according to the abnormality sign detection system 10 of the embodiment described above, it is only necessary to detect the collapse of the normal covariant relationship between the pair of sensors that make up the above-mentioned pair, and there is no need to individually check for abnormalities in all sensors installed in facilities, factories, systems, etc., which makes it possible to reduce the amount of work required.
[0083] The present invention is not limited to the abnormality sign detection system 10, the abnormality sign detection method, and the abnormality sign detection program according to the above-described embodiments, and can be embodied in various other modified examples or application examples without departing from the spirit of the present invention as set forth in the claims. Also, although the term "information" is used in the above-described embodiments, the term "information" can be replaced with "data," and the term "data" can be replaced with "information." [Explanation of symbols]
[0084] 10. Anomaly detection system 10a Communications Department 10b ROM (Read Only Memory) 10c RAM (Random Access Memory) 10d storage section 10e Calculation unit 10f Input / Output Interface 10g input device 10h output device 15 Normal waveform of sensor A 16 Waveform when sensor A is abnormal 16a Abnormal 16b Abnormal 17 Waveforms where abnormalities cannot be detected 18 Waveform of sensor A 18a It appears that something is wrong, but it is actually a normal part. 19 Waveform of sensor B 19a Period 19b Period 19c Period 20 Step waveform of sensor A 21 Step waveform of sensor B 25 Information and Communications Networks 30 Observation data acquisition section 31 Pair Selection Section 32 Model Generation Unit 33 Detection unit 34 Information Department 35 Normal waveform of sensor A 35a Waveform of sensor A affected by an abnormality 36 Waveform of sensor B 36a Waveform of sensor A affected by an abnormality 37 Waveform of sensor C 37a Abnormality 40 Waveform of environmental data from sensor a1 41 Waveform of sensor a2 42 Waveform of time series data of abnormality 43 Study Period 44 period 45 Abnormality detection 46 Abnormality detection 47 Notification Threshold
Claims
1. an observation data acquisition unit that acquires observation data from each of a plurality of sensors; a pair selection unit that selects, for each of the plurality of sensors, a pair having the strongest causal relationship based on the respective observation data from among pairs of each of the plurality of sensors and another of the plurality of sensors; a model generation unit that generates, for each of the pairs selected for each of the plurality of sensors, a covariant relationship model that indicates a relationship between the pair of sensors that constitutes the pair and evaluates a deviation of the relationship from a normal state; a detection unit that detects a breakdown of a normal relationship between the pair of sensors based on the covariant relationship model; An abnormality sign detection system comprising:
2. The abnormality sign detection system according to claim 1, further comprising an alarm unit that notifies a user of an abnormality when the number of times the detection unit detects a breakdown of the normal relationship exceeds a threshold value.
3. 2. The abnormality sign detection system according to claim 1, wherein the covariant relationship model is trained using observation data of a pair of the sensors in a normal state as training data.
4. the covariant relationship model outputs a predicted value that evaluates the relationship between the pair of sensors that constitute the pair; The abnormality sign detection system according to claim 1 , wherein the predicted value becomes large when the relationship becomes a state that has not been experienced during learning.
5. 2. The anomaly sign detection system according to claim 1, wherein the covariant relationship model is selected from four regression models: a linear regression model in a first causal direction, a linear regression model in a second causal direction that is opposite to the first causal direction, a nonlinear regression model in the first causal direction, and a nonlinear regression model in the second causal direction, so that the covariant relationship model has the smallest mean absolute percentage error between the observed values constituting the observation data of the sensor and the predicted values of the regression model related to the observed values.
6. 2. The abnormality sign detection system according to claim 1, wherein a causal relationship is estimated by causal search.
7. The computer an observation data acquisition step of acquiring observation data from each of a plurality of sensors; a pair selection step of selecting, for each of the plurality of sensors, a pair having the strongest causal relationship based on the respective observation data from among pairs of each of the plurality of sensors and another of the plurality of sensors; a model generation step of generating, for each of the pairs selected for each of the plurality of sensors, a covariant relationship model that indicates a relationship between the pair of sensors constituting the pair and evaluates a deviation of the relationship from a normal state; a detection step of detecting a breakdown of a normal relationship between the pair of sensors based on the covariant relationship model; An abnormality sign detection method, characterized by executing the above.
8. On the computer, an observation data acquisition function for acquiring observation data from each of a plurality of sensors; a pair selection function for selecting, for each of the plurality of sensors, a pair having the strongest causal relationship based on the respective observation data from among pairs of the plurality of sensors and other sensors; a model generation function that generates, for each of the pairs selected for each of the plurality of sensors, a covariant relationship model that indicates a relationship between the pair of sensors that constitutes the pair and evaluates a deviation of the relationship from a normal state; a detection function that detects a breakdown of a normal relationship between the pair of sensors based on the covariant relationship model; An abnormality sign detection program characterized by realizing the above.
Citation Information
Patent Citations
Information processing device, information processing system, information processing method, and recording medium
WO2019026193A1