Protection of industrial production from sophisticated attacks
The manufacturing system uses machine learning algorithms to detect and correct cyberattacks as process variations, addressing the vulnerability of traditional SPC methods by dynamically adjusting parameters, thereby maintaining process stability and quality.
Patent Information
- Application Number
- JP2023192140
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-11-20
- Filing Date
- 2023-11-10
- Publication Date
- 2025-06-25
- Estimated Expiration
- 2040-11-20
AI Technical Summary
Conventional manufacturing process control systems are vulnerable to sophisticated cyberattacks, which can cause subtle deviations that go undetected by traditional Statistical Process Control (SPC) methods, leading to quality issues and extensive downtime, as they treat each node independently and do not account for interconnected process variations.
A manufacturing system equipped with a monitoring platform and control module that uses machine learning algorithms, including Kalman filters, autoencoders, and reinforcement learning, to dynamically detect and correct cyberattacks by treating them as process variations, adjusting operating parameters in real-time to minimize damage across interconnected nodes.
Enhances industrial security by actively identifying and mitigating cyber threats, reducing downtime and costs by treating cyberattacks as process anomalies, ensuring continuous process stability and quality control.
Smart Images

Figure 0007698333000047 
Figure 0007698333000048 
Figure 0007698333000049
Abstract
Description
Technical Field
[0001] Cross - Reference to Related Applications This application claims priority to U.S. Provisional Application No. 62 / 938,158, filed October 20, 2019, which is hereby incorporated by reference in its entirety.
[0002] The present disclosure generally relates to systems, methods, and media for manufacturing processes.
Background Art
[0003] Cyberattacks over the past few decades have witnessed a surprising degree of spread, adaptation, specificity, and sophistication. Industrial and military security is the study of physical and digital walls that limit the malicious insertion or deletion of information. In the case of highly secure factories and military facilities, this means creating systems that are disconnected from global computer networks and often from internal networks.
Summary of the Invention
Problems to be Solved by the Invention
[0004]
Means for Solving the Problems
[0005] In some embodiments, a manufacturing system is disclosed herein. The manufacturing system includes one or more stations, a monitoring platform, and a control module. Each of the one or more stations is configured to perform at least one step in a multi-step manufacturing process of a component. The monitoring platform is configured to monitor the progress of the component throughout the multi-step manufacturing process. The control module is configured to detect a cyber-attack on the manufacturing system, and the control module is configured to execute an operation. The operation includes receiving a control value of a first station of the one or more stations. The control value includes an attribute of the first processing station. The operation also includes using one or more machine learning algorithms to determine whether there is a cyber-attack based on the control value of the first station. The operation further includes generating an alert to stop the processing of the component based on the determination.
[0006] In some embodiments, a computer-implemented method is disclosed herein. A computing system receives a control value of a first station of one or more stations of a manufacturing system configured to process a component. The control value includes an attribute of the first station. The computing system uses one or more machine learning algorithms to determine whether there is a cyber-attack based on the control value of the first station. The computing system generates an alert to stop the processing of the component based on the determination. The computing system generates a set of actions for correcting an error caused by the cyber-attack. The set of actions is associated with downstream stations of the manufacturing system.
[0007] In some embodiments, a manufacturing system is disclosed herein. The manufacturing system includes one or more stations, a monitoring platform, and a control module. Each of the one or more stations is configured to perform at least one step in a multi-step manufacturing process of components. The monitoring platform is configured to monitor the progress of the components throughout the multi-step manufacturing process. The control module is configured to detect a cyber-attack on the manufacturing system, and the control module is configured to execute an operation. The operation includes receiving a control value of a first station of the one or more stations. The control value includes an attribute of the first station. The operation also includes using one or more machine learning algorithms to determine whether there is a cyber-attack based on the control value of the first station. The operation further includes generating an alert to stop the processing of the components based on the determination. The operation further includes using one or more second machine learning algorithms to generate a set of actions for correcting an error caused by the cyber-attack. The set of actions is associated with a downstream station of the manufacturing system.
[0008] To better understand the above features of the present disclosure, a more specific description of the present disclosure briefly summarized above can be obtained by referring to the embodiments, some of which are shown in the accompanying drawings. However, it should be noted that the accompanying drawings show only typical embodiments of the present disclosure, and thus should not be considered as limiting its scope, as the present disclosure can admit other equally effective embodiments.
Brief Description of the Drawings
[0009]
Figure 1
[0010]
Figure 2
[0011]
Figure 3
[0012]
Figure 4
[0013]
Figure 5
[0014]
Figure 6A
[0015]
Figure 6B
Best Mode for Carrying Out the Invention
[0016] For ease of understanding, the same reference numbers have been used to denote the same elements common to the figures, where possible. It is contemplated that elements disclosed in one embodiment may be beneficially utilized in other embodiments without specific recitation.
[0017] The manufacturing process can be complex and can include raw materials that are processed by different process stations (or "stations") until the final product is manufactured. In some embodiments, each process station can receive an input for processing and output an intermediate output that can be passed to the next (downstream) process station for additional processing. In some embodiments, the final process station can receive an input for processing and output the final product, or more generally, the final output.
[0018] In some embodiments, each station can include one or more tools / devices that can perform a series of process steps. Exemplary process stations can include, but are not limited to, conveyor belts, injection molding presses, cutting machines, die stamping machines, extruders, computer numerical control (CNC) mills, grinders, assembly stations, 3D printers, quality control stations, verification stations, and the like.
[0019] In some embodiments, the operation of each process station can be controlled by one or more process controllers. In some embodiments, each process station can include one or more process controllers that can be programmed to control the operation of the process station. In some embodiments, an operator or control algorithm can provide the station controller with setpoint values that can represent desired values or ranges of values for each control value. In some embodiments, the values used for feedback or feedforward in the manufacturing process may sometimes be referred to as control values. Exemplary control values can include, but are not limited to, speed, temperature, pressure, vacuum, rotation, current, voltage, power, viscosity, materials / resources used at the station, throughput rate, downtime, harmful gases, pH, light absorption, particle density, and geometric structure.
[0020] Statistical Process Control (SPC) is a quality management method that uses statistical methods to monitor and control processes. Generally, SPC requires establishing process standards for each step of the manufacturing process and monitoring them throughout the production life cycle. The goal of SPC is to continuously improve the process throughout the life cycle.
[0021] For the purpose of SPC, as long as each node is operating within the specification range, it is assumed that the final product is also within the specification range. Specifications can be set based on the expertise in the target field and past performance. The reliability and influence of one node on the next or subsequent nodes are not directly adjusted in SPC. Instead, each sub-process can be examined as an independent entity. This approach widens the margin of operating conditions for each node and may even prevent the system from operating with absolute maximum efficiency or stability. From a security perspective, this margin can be a target for sophisticated process cyberattacks. If one or more nodes within the system start operating at the upper (or lower) limit of their specifications, individual alarms are not triggered, but it affects the quality of the overall process. This is especially true for man-in-the-middle cyberattacks where, for example, the reported sensor signals are forged by malicious code. Since the node's life cycle is also affected, it is necessary to increase the downtime for repair. Some layers of downstream nodes are also affected, and over time, the continuous drift of the system tends to result in non-compliance. By that point, the corrections required to recover the system are extensive and incur exorbitant costs.
[0022] One or more of the technologies provided in this specification are directed towards a new approach to industrial security by treating suspected malicious activities as process variations and correcting them by actively adjusting the operating parameters of the system. As threats to industrial systems increase and become more sophisticated, it is necessary to overlay traditional security methods with advancements in process control to strengthen the overall system.
[0023] FIG. 1 is a block diagram showing a manufacturing environment 100 according to an exemplary embodiment. The manufacturing environment 100 may include a manufacturing system 102, a monitoring platform 104, and a control module 106. The manufacturing system 102 can broadly represent a multi-step manufacturing system. In some embodiments, the manufacturing system 102 can represent an assembly line system, and each processing station can represent a human worker. In some embodiments, the manufacturing system 102 can represent a manufacturing system for use in additive manufacturing (e.g., a 3D printing system). In some embodiments, the manufacturing system 102 can represent a manufacturing system for use in subtractive manufacturing (e.g., CNC machining). In some embodiments, the manufacturing system 102 can represent a manufacturing system for use in a combination of additive manufacturing and subtractive manufacturing. More generally, in some embodiments, the manufacturing system 102 can represent a manufacturing system for use in a general manufacturing process.
[0024] The manufacturing system 102 may include one or more stations 1081-108 n (generally, "station 108"). Each station 108 can represent a process and / or a station in a multi-step manufacturing process. For example, each station 108 can represent a layer deposition operation in a 3D printing process (e.g., station 1081 can correspond to layer 1, station 1082 can correspond to layer 2, etc.). In another example, each station 108 can correspond to a specific processing station. In another example, each station 108 can correspond to a specific human operator performing a specific task in an assembly line manufacturing process.
[0025] Each station 108 may include a process controller 114 and control logic 116. Each process controller 1411-114 ncan be programmed to control the operation of each respective station 108. In some embodiments, the control module 106 can provide each process controller 114 with a station controller setpoint that can represent a desired value or range of values for each control value. The control logic 116 can reference attributes / parameters associated with the process steps of the station 108. During operation, the control logic 116 of each station 108 can be dynamically updated throughout the manufacturing process by the control module 106 according to the current trajectory of the final quality criteria.
[0026] The monitoring platform 104 can be configured to monitor each station 108 of the manufacturing system 102. In some embodiments, the monitoring platform 104 can be a component of the manufacturing system 102. For example, the monitoring platform 104 can be a component of a 3D printing system. In some embodiments, the monitoring platform 104 may be independent of the manufacturing system 102. For example, the monitoring platform 104 can be retrofitted to an existing manufacturing system 102. In some embodiments, the monitoring platform 104 can represent an imaging device configured to capture images of products or tooling (e.g., workers or process tools) at each step of a multi-step process. For example, the monitoring platform 104 can be configured to capture images of components at each station 108 and / or images of components (e.g., tools, humans, etc.) developing products at each station 108. Generally, the monitoring platform 104 can be configured to capture information related to the production of products (e.g., images, voltage readings, speed readings, etc.) and / or tools (e.g., hand positions, tooling positions, etc.) and provide that information as input to the control module 106 for evaluation.
[0027] The control module 106 can communicate with the manufacturing system 102 and the monitoring platform 104 via one or more communication channels. In some embodiments, the one or more communication channels can represent individual connections over the Internet, such as a cellular network or a Wi-Fi network. In some embodiments, the one or more communication channels can use direct connections to connect terminals, services, and mobile devices, such as, for example, radio frequency identification (RFID), near field communication (NFC), Bluetooth™, low energy Bluetooth™ (BLE), Wi-Fi™, ZigBee™, backscatter communication (ABC) protocol, USB, WAN, or LAN, etc.
[0028] The control module 106 can be configured to control each process controller of the manufacturing system 102. For example, based on the information obtained by the monitoring platform 104, the control module 106 can be configured to adjust the process control related to a particular station 108. In some embodiments, the control module 106 can be configured to adjust the process control of a particular station 108 based on predicted final quality criteria.
[0029] As described above, conventional approaches for detecting processes attack various SPC techniques. SPC is a static and non-intrusive approach to process control, where well-defined statistical characteristics are passively observed to be either qualified or unqualified at each node. These conventional systems only determine whether to hold or discard the manufactured product after the processing of the last node.
[0030] To improve the conventional process, the control module 106 includes an error detection module 130. The error detection module 130 can be configured to detect errors at a given station 108 or a node of the manufacturing system 102. For example, in the error detection module 130 used as part of a dynamic intervention approach to process control, each node following the node causing the detected damage is incorporated into an optimization problem (e.g., a damage recovery problem) and actively controlled to instantiate its solution. In some embodiments, this process can be performed in real time or near real time while each cycle is in progress, rather than at the end of a given cycle.
[0031] To understand one or more techniques implemented by the error detection module 130, it is important to understand how the control module 106 defines a manufacturing system (e.g., the manufacturing system 102). A manufacturing system can be defined using various topological schemes such as feedback and feedforward configurations. In some embodiments, the manufacturing system F can be defined as a linear sequence of n process nodes (or stations 108) labeled 1,..., N, connected by a feedforward-linked chain. For example: F:→1→2→···→i→···→n
[0032] Similarly, in some embodiments, the manufacturing system F can be defined as a non-linear sequence of n process nodes (or stations 108) labeled 1,..., N. In some embodiments, the processing performed by each node i can have two attributed distributions. The predicted distribution Q i , the observed distribution P i . Q i is
Number
Number
Number
Number
Number
Number
[0033] In some embodiments, the damage caused by node i can be defined as the Kullback-Leibler divergence of P with respect to Q i with respect to P i can be defined as the Kullback-Leibler divergence.
Number
[0034] In some embodiments, the damage can be cumulative or additive across F. For example:
Number
[0035] Referring back to the error detection module 130, the error detection module 130 can be configured to detect damage or errors at a given node k of the manufacturing system 102. For example, if the error detection module 130 detects that node k has caused damage (i.e., has generated a damaged or distorted distribution), the error detection module 130 samples from P k and the distribution of all subsequent results flowing therefrom, P k+1,...,P N Since a control strategy can be adopted to generate N , the remaining cumulative damage d k+1 ,...,d k can be reduced or minimized. Therefore, the damage recovery problem of the error detection module 130 can be formulated as follows.
Number
[0036] In some embodiments, the error detection module 130 can implement one or more techniques for identifying or correcting damage detected at a given node. In some embodiments, the error detection module 130 can use a Kalman filter 132 to detect damage or errors at a given processing node. In some embodiments, the error detection module 130 can include an autoencoder 134 for detecting damage or errors at a given processing node. In some embodiments, the error detection module 130 can use the deep reinforcement learning techniques of the machine learning module 136 to detect damage or errors at a given processing node and correct the detected variations caused by damage or errors at downstream nodes or stations 108. In some embodiments, the error detection module 130 can use one or more of the Kalman filter 132, the autoencoder 134, or the machine learning module 136 to detect damage or errors at a given processing node and / or correct the detected variations caused by damage or errors at downstream nodes or stations 108.
[0037] In some embodiments, the error detection module 130 can implement a Kalman filter 132 to detect errors at the processing node. To generalize the distribution description from above, i.e., d i a single-input, single-output system can be established in state-space form as follows.
Number
[0038] Generally, the Kalman filter 132 may rely on zero-mean noise. However, in the case of a malicious cyber attack, the offset of the input command may appear as non-zero mean additive noise. Therefore, the Kalman filter 132 can be interpreted for the following estimated time-invariant system. [Number]
[0039] In some embodiments, the Kalman filter 132 can be constructed using the measured value of the output, y V,i (t), of the node or process, and the normal, unmanipulated input command u i (t). If the process is properly calibrated, the input / output sensor measurements of station 108 or the node should have zero-mean noise. However, in the case of a malicious cyber-attack, a non-zero bias occurs.
[0040] In some embodiments, the Kalman filter 132 can be interpreted as follows. [Number] For the k-th sample i of the process node, [Number] can be the measurement update notation, Σ i,k is the covariance of the state prediction, R i is the covariance of the input noise ε t , K i,k can be the Kalman gain. When the sample is large enough, the innovation distribution [Number] is [Number] required to be. However, in a malicious cyber-attack, [Number] is, but this can occur naturally within a minimal sample. When the sample threshold k > k min is reached, [Number] An alarm is established for. Here, γ i is adjusted for the process node. If the innovation error is non-zero and exceeds the threshold γ i , the error detection module 130 may determine whether a malicious cyber attack may have occurred.
[0041] FIG. 2 is a block diagram showing the architecture of a single-input, single-output system (hereinafter, "system 200") implementing a Kalman filter 132 according to an exemplary embodiment.
[0042] As shown, the system 200 may include a controller 202 (e.g., C(s)), a plant 204 (e.g., G(s)), a measurement unit 206 (e.g., H(s)), an attack 208 (e.g., A(s)), and a Kalman filter 132 (e.g., KF). In some embodiments, the system 200 may include a second controller 202. In some embodiments, the controller 202, the plant 204, and the measurement unit 206 may represent the basic configuration of node control, while the Kalman filter 132 generated an innovation error.
[0043] In some embodiments as shown in FIG. 2, the twin controller may be used as an unbiased reference for the Kalman filter 132.
[0044] Referring back to FIG. 1, in some embodiments, the error detection module 130 may use an autoencoder 134 to detect anomalies corresponding to cyber attacks. The measured output
Number
Number
[0045] In some embodiments, the error of the autoencoder 134 can be defined as follows.
Number
Number
Number
Number
Number
[0046] Similar to the Kalman filter 132, when the anomaly score a i > γ i the error detection module 130 can detect anomalies using the autoencoder 134.
[0047] FIG. 3 is a block diagram showing the architecture of a system 300 implementing an autoencoder 134 according to some embodiments. As shown, system 300 may include a controller 302 (e.g., C(s)), a plant 304 (e.g., G(s)), a measurement unit 306 (e.g., H(s)), an attack 308 (e.g., A(s)), an autoencoder 134 (e.g., AE), and an alarm 312 (e.g., A). The controller 302, the plant 304, and the measurement unit 306 can represent the basic configuration of node control, while the autoencoder 344 can detect errors. In some embodiments, the error detection module 130 can trigger the alarm 312 based on a sufficient anomaly score.
[0048] Referring back to FIG. 1, in some embodiments, the error detection module 130 can use one or more deep reinforcement learning techniques to identify errors or anomalies in the process of dealing with cyberattacks. As described above, when the definition of the damage d i is given, [Number] the damage recovery problem of [Number] can be solved through a series of distributions P [Number] (where i = k + 1,..., n, over a set of iterations j = 1,..., m) to formulate a delayed reward function for a reinforcement learning agent attempting to construct: k+1 ,..., P n : [Number] where [Number]
[0049] In some embodiments, the error detection module 130 may be in a state for the k-th sample of the i-th node of the process
Number
Number
Number
Number
[0050] In some embodiments, the update law related to reinforcement learning techniques can be as follows.
Number
[0051] In some embodiments, the update law can reduce or minimize the Q-value, thereby minimizing the damage and can appear in actions aimed at returning the distribution to its normal form. In some embodiments, one formulation of the action can be as follows.
[0052] In some embodiments, the formulation of the action can be as follows.
Number
[0053] By using a reinforcement learning approach, the error detection module 130 can provide a new way to address system security by bundling process-based malicious cyberattacks into nominal process variations and provide direct control and correction of those variations. The approach is not just a method of detection or passive prevention. Rather, cyberattacks can be assumed to appear as everyday (e.g., likely) system changes such as a machine deviating from a standard or a raw material inventory deviating from strict specifications.
[0054] Figure 4 is a block diagram showing the architecture of a system 400 that implements a reinforcement learning approach using a machine learning module 136 according to some embodiments. As shown, system 400 can represent a multi-node system, i = 0,..., N. For each node i, controllers 4020, 4021, and 402 N (e.g., C0(s), C i (s),...C N (s)), plants 4040, 404 i , and 404 N (e.g., G0(s), G i (s), G N (s)), and measurement units 4060, 406 i , and 406 N (e.g., H0(s), H i(s), H N (s)) may exist. Together, the node is sampled from the data store 408 (e.g., Y) at time k, S k in a policy learning feedback loop governed by the state of the system 400 at time k, and the current state 410 is input π(S k ) and can be embedded in the policy. The attack 412 can be represented by the block A(s) for a single node i.
[0055] In some embodiments, to identify the set of actions to take to correct errors caused by a cyber attack, the state S at time sample k k can be input into a non-linear filter, and its weights can be selected to minimize subsequent damage at time sample k + n given the observed artifacts or components. In some embodiments, the output of the filter can be a scalar or vector that changes a predetermined process setpoint or control value. The conversion from state to action may sometimes be referred to as a policy.
[0056] FIG. 5 is a flowchart showing a method 500 for managing a cyber attack on a manufacturing process according to an exemplary embodiment. The method 500 can start as step 502.
[0057] In operation 502, the control module 106 can receive control values from the station 108 of the manufacturing system 102. In some embodiments, the control module 106 can receive control values from a process controller associated with a given station 108. The process controller can generally be programmed to control the operation of the station 108. Exemplary control values can include, but are not limited to, speed, temperature, pressure, vacuum, rotation, current, voltage, power, viscosity, materials / resources used at the station, throughput rate, downtime, harmful gases, etc. More generally, the control values can refer to the attributes of the station 108 rather than the attributes of the components being processed by the station 108.
[0058] In operation 504, the control module 106 can determine that a cyber-attack exists based on the control values received from the station 108. For example, in some embodiments, the error detection module 130 can use a Kalman filter 132 to generate an anomaly score for the station 108 when a control value is provided. For example, if the anomaly score is greater than a predetermined threshold, the control module 106 can determine whether a cyber-attack is currently in progress. In another example, the error detection module 130 can use an autoencoder 134 to generate an anomaly score for the station 108 when a control value is provided. For example, if the anomaly score is greater than a predetermined threshold, the control module 106 can determine whether a cyber-attack is currently in progress. In another example, the error detection module 130 can use a machine learning module 136 to predict a Q-value corresponding to the station 108. For example, if the Q-value is outside the acceptable range, the control module 106 can determine whether a cyber-attack is currently in progress.
[0059] In some embodiments, method 500 may include step 506. In step 506, in response to a determination that a cyber-attack is occurring, control module 106 may trigger an alert or alarm. In some embodiments, the alert or alarm may be a notification to a user monitoring manufacturing system 102. In some embodiments, the alert or alarm may be a signal to stop or halt the processing of each of stations 1081-108 n of manufacturing system 102.
[0060] In some embodiments, method 500 may include steps 508-510. In step 508, in response to a determination that a cyber-attack is occurring, control module 106 may generate one or more actions to correct damage caused by the cyber-attack. For example, error detection module 130 may determine the state of the k-th sample of the i-th node of a process
Number
Number
Number
Number
[0061] In some embodiments, the update law associated with reinforcement learning techniques may be as follows.
Number
[0062] In some embodiments, the update law may appear in actions aimed at reducing or minimizing the Q - value, thereby minimizing damage and returning the distribution to its normal form. In some embodiments, one formulation of the action may be as follows.
[0063] In some embodiments, the formulation of the action may be as follows.
Number
Number
Number
[0064] In step 510, the control module 106 can provide the updated action generated by the machine learning module 136 to the downstream station 108. In some embodiments, the control module 106 can send the updated instruction to the process controller of each downstream station 108.
[0065] FIG. 6A shows a system bus computing system architecture 600 according to an exemplary embodiment. One or more components of system 600 may communicate electrically with each other using bus 605. System 600 may include a system bus 605 that couples various system components, including a processor (e.g., one or more CPUs, GPUs, or other types of processors) 610, to system memory 615 such as read only memory (ROM) 620 and random access memory (RAM) 625. System 600 may include a cache of high-speed memory that is directly connected to, in proximity to, or integrated as part of processor 610. System 600 can copy data from memory 615 and / or storage device 630 to cache 612 for quick access by processor 610. In this way, cache 612 can provide a performance improvement that avoids latency of processor 610 while data is waiting. These and other modules can be configured to control processor 610 or be controlled to perform various actions. Other system memory 615 may similarly be available. Memory 615 may include multiple different types of memory with different performance characteristics. Processor 610 may represent a single processor or multiple processors. Processor 610 may include one or more of a general-purpose processor, a hardware module, or a software module, such as service 1 632, service 2 634, and service 3 636 stored in storage device 630, configured to control a dedicated processor in which processor 610 and software instructions are incorporated into an actual processor design. Processor 610 may essentially be a fully self-contained computing system that includes multiple cores or processors, buses, memory controllers, caches, etc. A multi-core processor may be symmetric or asymmetric.
[0066] To enable user interaction with the computing device 600, the input device 645 can be any number of input mechanisms such as a microphone for voice, a touch-sensitive screen for gesture or graphic input, a keyboard, a mouse, motion input, voice, etc. The output device 635 can also be one or more of several output mechanisms known to those skilled in the art. In some cases, the multimodal system can be capable of enabling the user to provide multiple types of input to communicate with the computing device 600. The communication interface 640 can generally operate and manage user input and system output. There are no restrictions on operation with a specific hardware configuration. Thus, the basic functions here can be easily replaced with an improved hardware or firmware configuration during development.
[0067] The storage device 630 can be non-volatile memory, or a hard disk, or other types of computer-readable media such as magnetic cassettes, flash memory cards, solid-state memory devices, digital versatile disks, cartridges, random access memory (RAM) 625, read-only memory (ROM) 620, and their hybrids, which can store data accessible by a computer.
[0068] The storage device 630 can include services 632, 634, and 636 for controlling the processor 610. Other hardware or software modules are contemplated. The storage device 630 can be connected to the system bus 605. In one aspect, a hardware module that performs a specific function can include software components stored in a computer-readable medium in relation to the hardware components (such as the processor 610, bus 605, display 635, etc.) necessary to perform the function.
[0069] FIG. 6B shows a computer system 650 having a chipset architecture according to an exemplary embodiment. Computer system 650 can be an example of computer hardware, software, and firmware that can be used to implement the disclosed techniques. System 650 can include one or more processors 655 representing any number of physically and / or logically distinct resources capable of executing software, firmware, and hardware configured to perform the identified computations. The one or more processors 655 can communicate with a chipset 660 that can control inputs to and outputs from the one or more processors 655. In this example, chipset 660 can output information to an output 665 such as a display and can read and write information to a storage device 670 that can include, for example, magnetic and solid state media. Chipset 660 can also read and write data to and from RAM 675. To interface with chipset 660, a bridge 680 can be provided to interface with various user interface components 685. Such user interface components 685 can include, for example, a keyboard, a microphone, touch detection and processing circuitry, a pointing device such as a mouse, and the like. In general, inputs to system 650 can come from any of a variety of sources, machine-generated and / or human-generated.
[0070] The chipset 660 can also interface with one or more communication interfaces 690 that can have different physical interfaces. Such communication interfaces can include interfaces for wired and wireless local area networks, broadband wireless networks, and personal area networks. Some of the uses of the methods for generating, displaying, and using the GUI disclosed herein can include receiving an ordered dataset via a physical interface or can be generated by the machine itself by one or more processors 655 analyzing data stored in storage 670 or 675. Further, the machine can receive input from a user via user interface components 685 and perform appropriate functions such as a browsing function by using one or more processors 655 to interpret these inputs.
[0071] It can be appreciated that the exemplary systems 600 and 650 can have multiple processors 610 or can be part of a group or cluster of networked computing devices to provide greater processing power.
[0072] Although the foregoing is directed to embodiments described in this specification, additional embodiments can be devised without departing from the basic scope thereof. For example, aspects of the present disclosure can be implemented in hardware or software, or a combination of hardware and software. One embodiment described herein can be implemented as a program product for use in a computer system. The program of the program product defines the functions of the embodiment (including the methods described herein) and can be included in various computer-readable storage media. Exemplary computer-readable storage media include, but are not limited to, the following. (i) Non-writable storage media in which information is permanently stored (e.g., read-only memory (ROM) devices in a computer such as CD-ROM disks readable by a CD-ROM drive, flash memory, ROM chips, or any type of solid-state non-volatile memory), (ii) Writable storage media in which modifiable information is stored (e.g., floppy disks in a diskette drive or hard disk drive, or any type of solid-state random access memory). Such computer-readable storage media are embodiments of the present disclosure when carrying computer-readable instructions that direct the functions of the disclosed embodiments.
[0073] It will be understood by those skilled in the art that the foregoing examples are illustrative and not limiting. After reading the specification and studying the drawings, all permutations, extensions, equivalents, and improvements thereto will be apparent to those skilled in the art and are intended to be included within the true spirit and scope of the present disclosure. Accordingly, the following appended claims are intended to include all such modifications, permutations, and equivalents that are within the true spirit and scope of these teachings.
Claims
**Claim 1** A manufacturing system for detecting anomalies in a multi - process manufacturing process, comprising: a plurality of stations configured to perform at least one process in a multi - process manufacturing process for manufacturing components respectively; a monitoring platform configured to monitor the progress of the components throughout the multi - process manufacturing process; a control module configured to detect anomalies in the manufacturing system, receiving a control value including an attribute of a first station among the plurality of stations; determining that there is an anomaly based on the control value of the first station; generating a set of actions for correcting an error caused by the anomaly by determining a set of control values changed to minimize damage caused by the anomaly based on the determination, generating a plurality of actions that can be taken to minimize the damage caused by a cyber - attack; identifying a set of actions with the highest likelihood of minimizing the damage caused by the cyber - attack from the plurality of actions that can be taken; generating a set of actions, including; providing the set of actions to at least one process controller associated with at least one downstream station in the manufacturing system; a control module configured to perform operations including. A manufacturing system. **Claim 2** The operation further includes: generating an anomaly score of the first station based on the control value. The manufacturing system according to claim 1. **Claim 3** Generating the anomaly score of the first station based on the control value includes: using one or more machine - learning algorithms including a Kalman filter to generate the anomaly score of the first station based on the control value. The manufacturing system according to claim 2. **Claim 4** Generating the anomaly score of the first station based on the control value includes: using one or more machine - learning algorithms including an auto - encoder to generate the anomaly score of the first station based on the control value. The manufacturing system according to claim 2. **Claim 5** Determining that there is an abnormality based on the control value of the first station includes the manufacturing system according to claim 2, wherein determining that the abnormality score exceeds a threshold indicating an abnormality.
6. Determining that there is an abnormality based on the control value of the first station includes generating a predicted quality standard of the component based on the control value, determining that the predicted quality standard is outside the allowable value range, the manufacturing system according to claim 1, comprising:
7. The operation the manufacturing system according to claim 1, further comprising generating an alert including the notification of the abnormality.
8. A computer-implemented method for detecting an abnormality in a multi-step manufacturing process, comprising: receiving, by a computing system, a control value including an attribute of a first station among a plurality of stations in a manufacturing system; determining, by the computing system, that there is an abnormality based on the control value of the first station; generating, based on the determination, a set of actions for correcting an error caused by the abnormality by determining a set of control values changed to minimize damage caused by the abnormality, generating a plurality of actions that can be taken to minimize the damage caused by a cyber attack; identifying, from the plurality of actions that can be taken, a set of actions with the highest likelihood of minimizing the damage caused by the cyber attack; generating a set of actions, including: causing, by the computing system, at least one process controller associated with at least one downstream station in the manufacturing system to adjust a set of attributes of the at least one downstream station based on the set of changed control values, thereby causing the at least one downstream station to execute the set of actions; A computer-implemented method, comprising:
9. The computer-implemented method according to claim 8, further comprising generating, by the computing system, an abnormality score of the first station based on the control value.
10. The computing system generates the anomaly score of the first station based on the control value, The computer-implemented method according to claim 9, comprising generating the anomaly score of the first station based on the control value using one or more machine learning algorithms including a Kalman filter.
11. The computing system generates the anomaly score of the first station based on the control value, The computer-implemented method according to claim 9, comprising generating the anomaly score of the first station based on the control value using one or more machine learning algorithms including an autoencoder.
12. The computing system determines that there is an anomaly based on the control value of the first station, The computer-implemented method according to claim 9, comprising determining that the anomaly score exceeds a threshold indicating an anomaly.
13. The computing system determines that there is an anomaly based on the control value of the first station, generating predicted quality criteria for components during manufacturing based on the control value, determining that the predicted quality criteria are outside the allowable range, The computer-implemented method according to claim 9, comprising.
14. The computer-implemented method according to claim 8, further comprising the computing system generating an alert including the notification of the anomaly.
15. A manufacturing system that determines anomalies and generates alerts, a plurality of stations each configured to perform at least one step in a multi-step manufacturing process for manufacturing components, a control module configured to detect anomalies in the manufacturing system, receiving a control value including an attribute of a first station among the plurality of stations, determining that there is an anomaly based on the control value of the first station, generating a set of actions for correcting an error caused by the anomaly by determining a set of control values changed to minimize damage caused by the anomaly based on the determination. Generating a plurality of actions that can be taken to minimize the damage caused by the cyber attack; Identifying a set of actions from the plurality of actions that can be taken that have the highest likelihood of minimizing the damage caused by the cyber attack; Generating a set of actions, including; Providing the set of actions to at least one process controller associated with at least one downstream station in the manufacturing system A control module configured to perform operations including, a manufacturing system.
16. The operation is The manufacturing system according to claim 15, further comprising generating an anomaly score for the first station based on the control value.
17. Generating the anomaly score for the first station based on the control value is The manufacturing system according to claim 16, comprising generating the anomaly score for the first station based on the control value using one or more machine learning algorithms including a Kalman filter.
18. Generating the anomaly score for the first station based on the control value is The manufacturing system according to claim 16, comprising generating the anomaly score for the first station based on the control value using one or more machine learning algorithms including an autoencoder.
19. Determining that there is an anomaly based on the control value of the first station is The manufacturing system according to claim 16, comprising determining that the anomaly score exceeds a threshold indicating an anomaly.
20. Determining that there is an anomaly based on the control value of the first station is Generating a predicted quality criterion for the component based on the control value; Determining that the predicted quality criterion is outside an acceptable value range; The manufacturing system according to claim 15, including.
Citation Information
Patent Citations
Automatic change system of process condition and determination condition of manufacturing device
JP2012123521A
Self-aware and corrective heterogeneous platform incorporating an integrated semiconductor processing module and method of use thereof
JP2021518674A
Abnormality detection program, abnormality detection method and abnormality detection device
WO2018061842A1