Anomaly detection device, anomaly detection method, and anomaly detection program

The anomaly detection device uses machine learning to estimate physical quantities from event keys, enhancing the ability to detect abnormalities in monitored devices and prevent failures by identifying issues early.

JP2026052382APending Publication Date: 2026-03-24MITSUBISHI ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-11
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Existing technologies struggle to detect abnormalities in measurement values such as current, voltage, and temperature before a monitored device becomes inoperable, making it difficult to prevent failures by timely replacement of parts.

Method used

An anomaly detection device that includes an evaluation target log acquisition unit, an event key assignment unit, an inference unit, and a state determination unit, which utilize machine learning to estimate physical quantities based on event keys and actual measurements to detect operational anomalies in monitored devices.

Benefits of technology

Enables accurate detection of abnormalities in measured values, allowing for proactive maintenance and preventing device failures by identifying issues before they become critical.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026052382000001_ABST
    Figure 2026052382000001_ABST
Patent Text Reader

Abstract

To obtain an anomaly detection device capable of detecting abnormalities in measured values ​​measured by a monitored device. [Solution] The abnormality detection device 1 includes an evaluation target log acquisition unit 13 that acquires an evaluation target log in which information of events that occurred in the monitored device is recorded; an event key assignment unit 41 that assigns an event key to the events included in the evaluation target log; an evaluation target data acquisition unit 14 that acquires an evaluation target physical quantity measured in the monitored device; an inference unit 42 that estimates a physical quantity to be acquired from the monitored device based on a trained model 32 generated by learning the event keys of events that occurred in the monitored device during normal operation and the physical quantities measured in the monitored device during normal operation, the event keys of the events included in the evaluation target log, and the evaluation target physical quantity; and a state determination unit 50 that determines whether or not there is an operational abnormality in the monitored device based on the estimated physical quantity and the physical quantity actually acquired from the monitored device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an abnormality detection device, an abnormality detection method, and an abnormality detection program that analyze log data output from a device to be monitored (hereinafter referred to as the monitored device) to detect abnormalities in the device.

Background Art

[0002] Log data recording the content, results, etc. of processes executed within a device is used for investigating the cause when the device malfunctions or an abnormality occurs, and for detecting abnormalities in the device.

[0003] For example, in Patent Document 1, performance data of a monitored device is predicted based on log data representing the operation of the monitored device and measurement values measured by a measuring device installed in the monitored device, and an abnormality in the monitored device is detected based on the predicted performance data and the performance data acquired from the monitored device. A technique is disclosed.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] [[ID=3८]] The above conventional technology can detect abnormalities in the monitored device, but it is difficult to detect abnormalities in measurement values, for example, abnormalities in measurement values such as current, voltage, and temperature. When the monitored device fails, there are cases where the measurement value becomes an abnormal value at a stage before the monitored device becomes inoperable due to the occurrence of the failure. By detecting an abnormality in the measurement value, it becomes possible to prevent the failure of the monitored device by replacing parts, etc. in advance. Therefore, the realization of a technology for detecting abnormalities in measurement values is desired.

[0006] This disclosure is made in view of the above, and aims to provide an anomaly detection device capable of detecting abnormalities in measured values ​​measured by a monitored device. [Means for solving the problem]

[0007] To solve the above-mentioned problems and achieve the objective, the anomaly detection device according to this disclosure is characterized by comprising: an evaluation target log acquisition unit that acquires an evaluation target log, which is log data recording information of events that occurred in a monitored device in operation; an event key assignment unit that assigns an event key, which is a value that uniquely identifies an event, to each event included in the evaluation target log; an evaluation target data acquisition unit that acquires an evaluation target physical quantity, which is a physical quantity measured in a monitored device in operation; an inference unit that estimates a physical quantity that the evaluation target data acquisition unit is scheduled to acquire from the monitored device based on a trained model generated by learning the event keys of events that occurred in a monitored device in normal operation, the physical quantities measured in a monitored device in normal operation, the event keys of events included in the evaluation target log, and the evaluation target physical quantity; and a state determination unit that determines whether or not there is an operational anomaly in the monitored device based on the physical quantity estimated by the inference unit and the physical quantity actually acquired by the evaluation target data acquisition unit from the monitored device. [Effects of the Invention]

[0008] According to this disclosure, it is possible to realize an anomaly detection device that can detect abnormalities in the measured values ​​measured by the monitored device. [Brief explanation of the drawing]

[0009] [Figure 1] This figure shows an example of the configuration of the anomaly detection device according to Embodiment 1. [Figure 2] A flowchart illustrating the operation of the anomaly detection device according to Embodiment 1 in which it creates an event key correspondence table and a trained model. [Figure 3] This figure shows an example of events and event keys included in the log data acquired from the monitored device by the anomaly detection device according to Embodiment 1. [Figure 4] This figure shows an example of the event key and physical quantity waveforms learned by the learning unit of the anomaly detection device according to Embodiment 1. [Figure 5] This figure shows an example of the learning operation by the learning unit of the anomaly detection device according to Embodiment 1. [Figure 6] A flowchart illustrating the operation by which the abnormality detection device according to Embodiment 1 determines the status of the monitored device. [Figure 7] This figure shows the relationship between the estimated physical quantity and the actual physical quantity, without using an event key. [Figure 8] This figure shows the relationship between the results of estimating physical quantities using event keys and the actual physical quantities. [Figure 9] This figure shows an example of the learning operation by the learning unit of the anomaly detection device according to Embodiment 2. [Figure 10] This figure shows an example of the estimation results of physical quantities when each of Embodiment 1 and Embodiment 2 is applied. [Figure 11] This figure shows an example of the learning operation by the learning unit of the anomaly detection device according to Embodiment 3. [Figure 12] This figure shows an example of the hardware configuration of an anomaly detection device according to Embodiments 1 to 3. [Modes for carrying out the invention]

[0010] The anomaly detection device, anomaly detection method, and anomaly detection program according to embodiments of this disclosure will be described in detail below with reference to the drawings.

[0011] Embodiment 1. Figure 1 is a diagram showing an example configuration of an anomaly detection device 1 according to Embodiment 1. As shown in Figure 1, the anomaly detection device 1 comprises a data acquisition unit 10 consisting of a normal data acquisition unit 11, a normal log acquisition unit 12, an evaluation target log acquisition unit 13, and an evaluation target data acquisition unit 14; a model creation unit 20 consisting of an event extraction unit 21 and a learning unit 22; a storage unit 30 that stores an event key correspondence table 31 and a trained model 32; an estimation unit 40 consisting of an event key assignment unit 41 and an inference unit 42; and a state determination unit 50.

[0012] The normal data acquisition unit 11 and the evaluation target data acquisition unit 14 of the data acquisition unit 10 acquire physical quantities measured by measuring devices such as sensors installed on the monitored device (not shown in the figure). Examples of physical quantities include current, voltage, temperature, etc. In addition, the normal log acquisition unit 12 and the evaluation target log acquisition unit 13 of the data acquisition unit 10 acquire log data generated by the monitored device. The log data records information about events that occurred in the monitored device.

[0013] The normal data acquisition unit 11 acquires physical quantities measured when the monitored device is operating normally (which may be referred to as normal physical quantities in the following explanation).

[0014] The normal log acquisition unit 12 acquires normal log data (which may be referred to as normal logs in the following explanation) generated when the monitored device is operating normally. A normal log here refers to log data generated when the monitored device executes processes in a predetermined and correct order. Even if the operation of the monitored device appears normal, log data generated when processes are not performed in the correct order will not be considered a normal log. For example, if the process of reading data from a specific area of ​​memory is repeated twice, that is, the same data is read twice consecutively from the same address in memory, and then processing is performed using the read data, the apparent operation of the monitored device will be normal. However, since the data reading process that only needs to be performed once is performed twice, one of the two read operations is unnecessary and will be considered abnormal as log data.

[0015] The evaluation target log acquisition unit 13 acquires log data of the evaluation target, specifically, log data in which information on events that occurred in a monitoring target device whose normal operation status is unknown is recorded (hereinafter, may be referred to as evaluation target log in the following description).

[0016] The evaluation target data acquisition unit 14 acquires physical quantities of the evaluation target, specifically, physical quantities measured by a monitoring target device whose normal operation status is unknown (hereinafter, may be referred to as evaluation target physical quantity in the following description).

[0017] The event extraction unit 21 of the model creation unit 20 analyzes the normal logs acquired by the normal log acquisition unit 12, extracts various events included in the normal logs, assigns an event key to each of the extracted events, and creates an event key correspondence table 31 showing the correspondence between the events and the event keys. The event key is a numerical value that uniquely indicates one of the events that occurred in the monitoring target device. The events that occurred in the monitoring target device are processes executed in the monitoring target device, operations of the monitoring target device, operations performed on the monitoring target device, and the like. The event key correspondence table 31 is used when the event key assignment unit 41 described later assigns event keys to each event in the evaluation target log.

[0018] The learning unit 22 of the model creation unit 20 performs machine learning using the event keys assigned by the event extraction unit 21 to each event in the normal logs and the normal-time physical quantities acquired by the normal data acquisition unit 11, and generates a learned model 32 that estimates future physical quantities from the event keys and the normal-time physical quantities. The future physical quantity is the physical quantity that the evaluation target data acquisition unit 14 is scheduled to acquire.

[0019] The event key assignment unit 41 of the estimation unit 40 extracts various events included in the evaluation target log acquired by the evaluation target log acquisition unit 13 from the evaluation log, and assigns an event key to each of the extracted events according to the event key correspondence table 31.

[0020] The inference unit 42 of the estimation unit 40 estimates future physical quantities, i.e., physical quantities that the evaluation data acquisition unit 14 is scheduled to acquire, based on the event keys assigned by the event key assignment unit 41 to each event in the evaluation log, the evaluation target physical quantities acquired by the evaluation target data acquisition unit 14, and the trained model 32.

[0021] The state determination unit 50 determines whether the monitored device is in a normal state or not based on the physical quantity estimated by the inference unit 42 and the physical quantity to be evaluated acquired by the evaluation target data acquisition unit 14.

[0022] Next, the operation of the anomaly detection device 1 will be described. In this embodiment, the explanation will be divided into two parts: preparatory operations for determining the state of the monitored device, specifically, preparatory operations for creating the event key correspondence table 31 and the trained model 32, and operational operations for actually determining the state of the monitored device. In the following explanation, log data may be referred to as logs. Also, events included in the log data may be referred to as log events.

[0023] (Preparation steps) Figure 2 is a flowchart showing the operation in which the anomaly detection device 1 according to Embodiment 1 creates the event key correspondence table 31 and the trained model 32.

[0024] First, the normal data acquisition unit 11 acquires physical quantities (normal physical quantities) measured while the monitored device is operating normally (step S11). The normal data acquisition unit 11 acquires a large number of normal physical quantities.

[0025] Next, the normal log acquisition unit 12 acquires logs (normal logs) created while the monitored device is operating normally (step S12). The normal log acquisition unit 12 acquires a large number of normal logs.

[0026] Furthermore, the physical quantities acquired by the normal data acquisition unit 11 and the logs acquired by the normal log acquisition unit 12 include time data, making it possible to understand the correspondence between events and physical quantities included in the logs, that is, to understand which physical quantities were measured when which events occurred.

[0027] Next, the event extraction unit 21 extracts events included in the logs acquired by the normal log acquisition unit 12 (step S13), and further assigns event keys to the extracted events to create an event key correspondence table 31 (step S14). An example of the operation of the event extraction unit 21 in steps S13 and S14 will be explained using Figure 3. Figure 3 is a diagram showing an example of events and event keys included in the log data acquired by the abnormality detection device 1 according to Embodiment 1 from the monitored device. In Figure 3, the left column is log data 101, the middle column is log events 102, and the right column is event keys 103.

[0028] The event extraction unit 21 receives log data 101, which is a normal log, from the normal log acquisition unit 12, and in step S12 extracts log events 102 from the log data 101. The event extraction unit 21 also assigns a unique event key 103 to each of the extracted log events 102 and creates an event key correspondence table 31. The event extraction unit 21 extracts log events 102 and assigns event keys 103 to all normal logs (log data 101) acquired by the normal log acquisition unit 12 and creates the event key correspondence table 31. The event extraction unit 21 outputs the series of event keys 103 assigned to each event extracted from the normal log to the learning unit 22. If the log data 101 shown in Figure 3 is input from the normal log acquisition unit 12, and the log events 102 shown in Figure 3 are extracted and event keys 103 are assigned, the event extraction unit 21 outputs '5', '6', '7', and '8' to the learning unit 22.

[0029] Next, the learning unit 22 learns the relationship between the time change (waveform) of the event key, the time change (waveform) of the physical quantity, and the physical quantity at a predetermined point in time (step S15). An example of the event key and physical quantity waveforms learned by the learning unit 22 is shown in Figure 4. Figure 4 is a diagram showing an example of the event key and physical quantity waveforms learned by the learning unit 22 of the anomaly detection device 1 according to Embodiment 1. In Figure 4, current is used as the physical quantity. The upper part of Figure 4 shows an example of waveform data for the event key column of the log, and the lower part shows an example of waveform data for current. Also, in Figure 4, the horizontal axis represents time. When an event occurs in the monitored device, the value of the event key in the upper part of Figure 4 changes. In addition, when an event occurs and the value of the event key changes, a change in current also occurs accordingly.

[0030] A specific example of the learning operation by the learning unit 22 will be explained. Figure 5 is a diagram showing an example of the learning operation by the learning unit 22 of the anomaly detection device 1 according to Embodiment 1.

[0031] The learning unit 22 first learns the relationship between the time variation of event keys and current in the learning target region 450 shown in Figure 5 and the instantaneous value of current 450c. Specifically, the learning unit 22 learns the relationship between the waveform 450a of the event key sequence in the first interval T1, the waveform 450b of the current in the second interval T2, and the instantaneous value of current 450c. The relationship T1 = T2 + Δt1 holds between the first interval T1 and the second interval T2. That is, the second interval T2 is Δt1 shorter than the first interval T1. The start times of the first interval T1 and the second interval T2 are assumed to be the same, and the instantaneous value of current 450c is the current value at the point Δt1 elapsed from the end time of the second interval T2. When performing learning, the instantaneous value of current 450c is used as the correct data.

[0032] Here, if the value of Δt1 is smaller than an appropriate value, the value at the end of the input current waveform 450b and the ground truth data 450c will be too close, making it impossible to construct a learning model that takes into account the event key waveform. Conversely, if the value of Δt1 is larger than an appropriate value, it will be impossible to construct a learning model that can predict the ground truth data 450c from the current waveform and the event key waveform. For this reason, the value of Δt1 must be appropriately selected. In this embodiment, the start times of the first interval T1 and the second interval T2 are the same, but the start times may not be the same, however, the end time of the second interval may be earlier than the end time of the first interval.

[0033] Subsequently, the learning unit 22 repeats the same learning process while changing the learning target area and the acquisition position (time) of the instantaneous current value, generating a trained model 32 for estimating the instantaneous current value from the waveform of the event key sequence and the waveform of the current. For example, each time the learning process is performed, the learning unit 22 slides the learning target area and the acquisition position of the instantaneous current value by a predetermined unit time. One unit time can be, for example, the period in which the current sensor measures the current, or an integer multiple of this period. In the learning target area 500, the learning unit 22 learns the relationship between the waveform 500a of the event key sequence, the waveform 500b of the current, and the instantaneous current value 500c.

[0034] The example of learning electric current as a physical quantity has been explained, but the preparatory steps for learning other physical quantities are similar. Furthermore, you may learn the relationship between two or more physical quantities and event keys. The preparatory steps for learning two or more physical quantities are also the same as for learning electric current.

[0035] (operational behavior) Figure 6 is a flowchart showing the operation in which the abnormality detection device 1 according to Embodiment 1 determines the status of the monitored device.

[0036] First, the evaluation target log acquisition unit 13 acquires the log (evaluation target log) created by the monitored device in operation (step S21).

[0037] Next, the event key assignment unit 41 extracts events included in the logs acquired by the evaluation target log acquisition unit 13 (step S22), and assigns event keys to the extracted events according to the event key correspondence table 31 (step S23). The operation by the event key assignment unit 41 to extract events from the evaluation target logs is the same as the operation by the event extraction unit 21 to extract events from normal logs.

[0038] Next, the evaluation target data acquisition unit 14 acquires the physical quantities measured by the monitored device in operation (step S24).

[0039] Next, the inference unit 42 estimates future physical quantities based on the event key and physical quantity (step S25). That is, the inference unit 42 estimates future physical quantities using the event key assigned to the event by the event key assignment unit 41 in step S23, the physical quantity acquired by the evaluation target data acquisition unit 14 in step S24, and the trained model 32 stored in the memory unit 30. Specifically, the inference unit 42 inputs waveform data showing the time change of the event key and waveform data showing the time change of the physical quantity into the trained model 32, thereby obtaining the inference result of the physical quantity that the evaluation target data acquisition unit 14 is scheduled to acquire in the future from the trained model 32. In the above inference unit 42, the waveform data showing the time change of the event key, the waveform data showing the time change of the physical quantity, and the inference of the scheduled physical quantity are time relationships represented by intervals T1, T2, and ΔT1, which are time relationships during training.

[0040] Next, the state determination unit 50 determines whether or not there is an operational abnormality in the monitored device based on the estimated value of the physical quantity and the actual physical quantity (step S26). Specifically, the state determination unit 50 compares the estimated value of the physical quantity at time t estimated by the inference unit 42 with the actual physical quantity at time t acquired by the evaluation target data acquisition unit 14 to determine whether or not the monitored device is operating normally. For example, if the difference between the estimated value of the physical quantity and the actual physical quantity is greater than a predetermined threshold, the state determination unit 50 determines that there is an operational abnormality.

[0041] As described above, the anomaly detection device 1 according to Embodiment 1 extracts events from the evaluation target log output by the monitored device and assigns an event key. It learns the relationship between first waveform data showing the time change of the event key assigned to the event in the evaluation target log in a first interval, second waveform data showing the time change of the physical quantity measured by the monitored device in a second interval, and the instantaneous value of the physical quantity at times not included in the first and second intervals, and generates a trained model 32 for estimating the instantaneous value of the physical quantity from the event key and the waveform data of the physical quantity. Furthermore, in operation after the generation of the trained model 32 is completed, the anomaly detection device 1 estimates the instantaneous value of the physical quantity using the waveform data of the event key and the waveform data of the physical quantity and the trained model 32, and compares the estimated instantaneous value with the actual instantaneous value of the physical quantity at the time corresponding to the estimated value to determine whether the operation of the monitored device is normal or not.

[0042] In this embodiment, as described above, the learning unit 22 learns the relationship between the time changes of a series of event keys representing each event included in the normal log acquired from the monitored device, the time changes of physical quantities, and the instantaneous values ​​of physical quantities, and generates a trained model 32. By including the time changes of event keys in the training data and performing training, the accuracy of estimating physical quantities can be improved.

[0043] If training is performed without including the time evolution of event keys in the training data, that is, if a trained model is used that is generated by learning only the relationship between the time evolution of a physical quantity and its instantaneous value, the relationship between the estimated physical quantity and the actual physical quantity will be as shown in Figure 7. Figure 7 shows the relationship between the estimated physical quantity (current) and the actual physical quantity when using event keys. Figure 7 shows an example where the physical quantity is current. The dotted line shows the time evolution (time series waveform) of the estimated current, and the solid line shows the time evolution (time series waveform) of the actual current. Also, an anomaly occurs at 400a. When event keys are not used in the estimation of physical quantities, as shown in Figure 7, the difference between the actual physical quantity and the estimated physical quantity can become large at times other than when an anomaly actually occurs. For this reason, it is difficult to achieve highly accurate anomaly detection, and there is a risk of misidentifying a normal situation as an anomaly or missing anomaly detection.

[0044] On the other hand, when using event keys, that is, when using a trained model 32 generated by learning the relationship between the time change of a physical quantity and the time change of the event key and its instantaneous value, the relationship between the estimated physical quantity and the actual physical quantity is as shown in Figure 8. Figure 8 is a diagram showing the relationship between the results of estimating a physical quantity using event keys and the actual physical quantity. Similar to Figure 7, Figure 8 shows an example where the physical quantity is electric current. The dotted line shows the time change of the estimated value of the current, and the solid line shows the time change of the actual current. Also, an anomaly occurs at 400a. When event keys are used in estimating physical quantities, the difference between the actual physical quantity that occurs at times other than when an anomaly actually occurs and the estimated physical quantity is smaller compared to when event keys are not used (see Figure 7). Therefore, highly accurate anomaly detection can be achieved.

[0045] Embodiment 2. Next, we will describe the anomaly detection device according to Embodiment 2. The configuration of the anomaly detection device according to Embodiment 2 is the same as that of Embodiment 1 (see Figure 1). In this embodiment, we will describe the parts that differ from Embodiment 1.

[0046] The anomaly detection device 1 according to Embodiment 2 differs from the anomaly detection device 1 according to Embodiment 1 in the operation of the learning unit 22, that is, the operation of generating the trained model 32. Specifically, the learning data used in the learning process of the learning unit 22 of the anomaly detection device 1 according to Embodiment 2 is different from that of Embodiment 1. The learning operation of the learning unit 22 according to Embodiment 2 will be described below.

[0047] Figure 9 shows an example of the learning operation by the learning unit 22 of the anomaly detection device 1 according to Embodiment 2. In Figure 9, electric current is used as the physical quantity.

[0048] The learning unit 22 in Embodiment 2 uses the waveform data of the event key sequence, the waveform data of the current, and the instantaneous value of the current (450c, 500c, etc.) shown in the middle and lower parts of Figure 9 as learning data, similar to the learning unit 22 in Embodiment 1. Furthermore, the learning unit 22 in Embodiment 2 also uses the waveform data shown in the upper part of Figure 9, specifically, the waveform data obtained by accelerating and duplicating the waveform data of the event key sequence in the middle part by time Δt2, as learning data. That is, the learning unit 22 in Embodiment 2 learns the relationship between the first waveform data showing the time change of the event key sequence, the second waveform data showing the time change of a physical quantity (current), the third waveform data obtained by advancing the first waveform data by a predetermined time Δt2, and the instantaneous value of the current, and generates a trained model 32 that infers the instantaneous value of the current from the first waveform data, the second waveform data, and the third waveform data. This makes it possible to generate a trained model 32 with higher accuracy in estimating instantaneous current values ​​than in Embodiment 1, enabling more accurate detection of abnormalities in the monitored device (see Figure 10).

[0049] Figure 10 shows examples of the estimation results of physical quantities when Embodiment 1 and Embodiment 2 are applied, respectively. The upper panel shows the estimation results when Embodiment 1 is applied, and the lower panel shows the estimation results (estimated values) when Embodiment 2 is applied. The solid line shows the actual physical quantity (measured value), and the dotted line shows the estimated value of the physical quantity. As shown in Figure 10, when Embodiment 2 is applied, the error between the estimated value and the measured value is smaller compared to when Embodiment 1 is applied. In particular, the error is reduced around the timing when the physical quantity changes significantly.

[0050] In this embodiment, when estimating a physical quantity, the inference unit 42 generates waveform data by advancing the waveform data representing the event key sequence input from the event key assignment unit 41 by time Δt2. The generated waveform data, the original waveform data before advancing by time Δt2, and the waveform data of the physical quantity acquired by the evaluation target data acquisition unit 14 are input to the trained model 32 to obtain an estimated value of the future physical quantity.

[0051] As described above, the anomaly detection device 1 according to Embodiment 2 uses the same data as the training data used by the anomaly detection device 1 according to Embodiment 1, and waveform data obtained by advancing the event key sequence waveform data by time Δt2, as training data to generate a trained model 32. As a result, the accuracy of estimating physical quantities can be further improved compared to Embodiment 1, and the anomaly detection accuracy of the monitored device is also improved.

[0052] Embodiment 3. Next, an anomaly detection device according to Embodiment 3 will be described. The configuration of the anomaly detection device according to Embodiment 3 is the same as that of Embodiment 1 (see Figure 1). In this embodiment, the differences from Embodiment 1 will be described.

[0053] The anomaly detection device 1 according to Embodiment 3 differs from the anomaly detection device 1 according to Embodiment 1 in the operation of the learning unit 22, that is, the operation of generating the trained model 32. Specifically, the learning data used in the learning process of the learning unit 22 of the anomaly detection device 1 according to Embodiment 3 is different from that of Embodiment 1. The learning operation of the learning unit 22 according to Embodiment 3 will be described below.

[0054] Figure 11 shows an example of the learning operation by the learning unit 22 of the anomaly detection device 1 according to Embodiment 3. In Figure 11, electric current is used as the physical quantity.

[0055] The learning unit 22 in Embodiment 3, like the learning unit 22 in Embodiment 1, uses the waveform data of the event key sequence shown in the upper part of Figure 11, the current waveform data shown in the lower part, and the instantaneous current values ​​(450c, 500c, etc.) as learning data. However, the learning range of the event key sequence waveform data differs from that of Embodiment 1. Specifically, the learning unit 22 in Embodiment 3 expands the first interval T1 by time Δt3 and learns the waveform data of the event key sequence in a third interval T1a that includes the measurement timing of the instantaneous current values ​​to be learned.

[0056] As described above, the anomaly detection device 1 according to Embodiment 3 uses the same data as the learning data used by the anomaly detection device 1 according to Embodiment 1, and also expands the learning range of the waveform data of the event key sequence to learn a range that includes the timing of measuring the instantaneous value of the physical quantity to be learned. As a result, similar to Embodiment 2, the accuracy of estimating the physical quantity can be further improved compared to Embodiment 1, and the anomaly detection accuracy of the monitored device can also be improved.

[0057] Next, the hardware configuration of the anomaly detection device 1 according to each of the embodiments described above will be explained.

[0058] Figure 12 shows an example of the hardware configuration of the anomaly detection device 1 according to Embodiments 1 to 3. The anomaly detection device 1 is composed of, for example, the processor 91 and memory 92 shown in Figure 12.

[0059] The processor 91 includes a CPU (Central Processing Unit, also known as a microprocessor, microcomputer, or DSP (Digital Signal Processor)), a system LSI (Large Scale Integration), etc. The memory 92 includes non-volatile or volatile semiconductor memory such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, magnetic disks, etc.

[0060] When the anomaly detection device 1 consists of a processor 91 and a memory 92, the data acquisition unit 10, model creation unit 20, estimation unit 40, and state determination unit 50 of the anomaly detection device 1 are realized by the processor 91 executing programs for each of these units to operate. The programs for the data acquisition unit 10, model creation unit 20, estimation unit 40, and state determination unit 50 to operate are pre-stored in the memory 92. The processor 91 reads the above programs from the memory 92 and executes them to operate as the data acquisition unit 10, model creation unit 20, estimation unit 40, and state determination unit 50.

[0061] The programs stored in memory 92 for operating as the data acquisition unit 10, model creation unit 20, estimation unit 40, and state determination unit 50 may be provided to the user, for example, by being written to a storage medium such as a CD (Compact Disc)-ROM or DVD (Digital Versatile Disc)-ROM, or by being provided to the user, for example, via a network.

[0062] Furthermore, the storage unit 30 of the anomaly detection device 1 is implemented by the memory 92.

[0063] Furthermore, the data acquisition unit 10, model creation unit 20, estimation unit 40, and state determination unit 50 of the anomaly detection device 1 may be implemented using dedicated hardware, such as a single circuit, a composite circuit, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a circuit combining these.

[0064] The configurations shown in the above embodiments are examples, and it is possible to combine them with other known technologies, combine different embodiments, and omit or modify parts of the configuration without departing from the gist of the invention. For example, in each embodiment, a trained model 32 for inferring the instantaneous value of a physical quantity is generated by learning the relationship between the waveform data of an event key and the waveform data of a physical quantity and the instantaneous value of the physical quantity. However, instead of instantaneous values, the waveform data of a physical quantity within a certain period including the time when the instantaneous value was measured may be learned, and a trained model 32 for inferring the waveform data of a physical quantity may be generated. Furthermore, the state determination unit 50 may determine an operation abnormality if it detects a predetermined number of consecutive times that the difference between the estimated value of a physical quantity and the actual physical quantity is greater than a threshold. Also, in each embodiment, waveform data of a single event key based on a single log is used, but it is obvious that a configuration in which waveform data of multiple event keys is created based on multiple logs can be handled similarly. [Explanation of Symbols]

[0065] 1 Anomaly detection device, 10 Data acquisition unit, 11 Normal data acquisition unit, 12 Normal log acquisition unit, 13 Evaluation target log acquisition unit, 14 Evaluation target data acquisition unit, 20 Model creation unit, 21 Event extraction unit, 22 Learning unit, 30 Storage unit, 31 Event key correspondence table, 32 Trained model, 40 Estimation unit, 41 Event key assignment unit, 42 Inference unit, 50 State determination unit.

Claims

1. An evaluation target log acquisition unit acquires evaluation target logs, which are log data recording information about events that occurred in the monitored device while it was in operation. An event key assignment unit assigns an event key, which is a value that uniquely identifies an event, to each event included in the log to be evaluated. An evaluation target data acquisition unit acquires an evaluation target physical quantity, which is a physical quantity measured by the monitoring target device while it is in operation, An inference unit that estimates the physical quantities that the evaluation target data acquisition unit plans to acquire from the monitoring target device based on a trained model generated by learning the event keys of events that occurred in the monitoring target device during normal operation, the physical quantities measured in the monitoring target device during normal operation, the event keys of events included in the evaluation target log, and the evaluation target physical quantities, A state determination unit determines whether or not there is an operational abnormality in the monitored device based on the physical quantity estimated by the inference unit and the physical quantity actually acquired from the monitored device by the evaluation target data acquisition unit. An anomaly detection device characterized by being equipped with the following features.

2. A normal log acquisition unit acquires normal logs, which are log data recording information about events that occurred in the monitored device while it was operating normally. A normal data acquisition unit acquires normal physical quantities, which are physical quantities measured by the monitored device during normal operation. An event extraction unit that extracts events included in the normal log and assigns the event key, A first waveform data showing the time change of the event key assigned to a series of events extracted from the normal log in a first interval, a second waveform data showing the time change of the normal physical quantity in a second interval different from the first interval, and a learning unit that learns the relationship with the normal physical quantity acquired by the normal data acquisition unit at a time not included in the second interval and generates the trained model, An anomaly detection device according to claim 1, characterized by comprising:

3. The end time of the second section is before the end time of the first section. The anomaly detection device according to feature 2.

4. The end time of the second section is before the end time of the first section. The learning unit performs the learning using the normal physical quantities acquired by the normal data acquisition unit between the end of the second section and the end of the first section. The anomaly detection device according to feature 3.

5. A normal log acquisition unit acquires normal logs, which are log data recording information about events that occurred in the monitored device while it was operating normally. A normal data acquisition unit acquires normal physical quantities, which are physical quantities measured by the monitored device during normal operation. An event extraction unit that extracts events included in the normal log and assigns the event key, A first waveform data showing the time change of the event key assigned to a series of events extracted from the normal log in a first interval; a second waveform data showing the time change of the normal physical quantity in a second interval different from the first interval; a third waveform data obtained by advancing the first waveform data by a predetermined time; and a learning unit that learns the relationship with the normal physical quantity acquired by the normal data acquisition unit at a time not included in the second interval and generates the trained model. An anomaly detection device according to claim 1, characterized by comprising:

6. The first step is to acquire the evaluation log, which is log data containing information about events that occurred on the monitored device while it was in operation. The second step involves assigning an event key, which is a value that uniquely identifies an event, to each event included in the log to be evaluated. A third step involves acquiring an evaluation target physical quantity, which is a physical quantity measured by the monitored device while it is in operation. A fourth step of estimating the physical quantities to be acquired from the monitored device based on a trained model generated by learning the event keys of events that occurred in the monitored device during normal operation, the physical quantities measured in the monitored device during normal operation, the event keys of events included in the log to be evaluated, and the physical quantities to be evaluated. A fifth step involves determining whether or not there is an operational abnormality in the monitored device based on the physical quantity estimated in the fourth step and the physical quantity actually obtained from the monitored device. An anomaly detection method characterized by including

7. The first step is to acquire the evaluation log, which is log data containing information about events that occurred on the monitored device while it was in operation. The second step involves assigning an event key, which is a value that uniquely identifies an event, to each event included in the log to be evaluated. A third step involves acquiring an evaluation target physical quantity, which is a physical quantity measured by the monitored device while it is in operation. A fourth step of estimating the physical quantities to be acquired from the monitored device based on a trained model generated by learning the event keys of events that occurred in the monitored device during normal operation, the physical quantities measured in the monitored device during normal operation, the event keys of events included in the log to be evaluated, and the physical quantities to be evaluated. A fifth step involves determining whether or not there is an operational abnormality in the monitored device based on the physical quantity estimated in the fourth step and the physical quantity actually obtained from the monitored device. An anomaly detection program characterized by causing a computer to execute a command.

Citation Information

Patent Citations

  • Time-series data processing method

    WO2023148843A1