Adaptive resource-aware anomaly detection (ARADD) for edge environments

The ARADD system addresses resource constraints in edge environments by dynamically selecting features and models, ensuring efficient and accurate anomaly detection, even with limited resources, through adaptive resource management and edge-cloud collaboration.

WO2026049738A1PCT designated stage Publication Date: 2026-03-05SIEMENS AG +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/US2024/044613
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing anomaly detection systems struggle in resource-constrained edge environments due to limited computational resources, storage capacity, and network bandwidth, making it impractical to deploy traditional security analytics like the ELK stack, leading to suboptimal resource utilization and delayed threat identification.

Method used

Adaptive Resource-Aware Anomaly Detection (ARADD) system that optimizes computational resources by dynamically selecting features and models based on available resources, using modules like dynamic feature selection, incremental learning, model compression, and edge-cloud collaboration to maintain real-time anomaly detection accuracy.

Benefits of technology

Ensures efficient and accurate anomaly detection in resource-constrained edge environments by balancing resource utilization with detection accuracy, allowing for real-time threat identification and adaptive model updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024044613_05032026_PF_FP_ABST
    Figure US2024044613_05032026_PF_FP_ABST
Patent Text Reader

Abstract

An edge device can monitor and analyze security-related data from legacy devices in various edge computing and resource-constrained environments, so as to detect and address potential threats or anomalies.
Need to check novelty before this filing date? Find Prior Art

Description

202411124ADAPTIVE RESOURCE-AWARE ANOMALY DETECTION (ARADD) FOR EDGE ENVIRONMENTSBACKGROUND

[0001] An anomaly or faulty behavior can generally be defined as an event or occurrence that does not follow expected or normal behavior. An efficient anomaly detector should be capable of differentiating between anomalous and normal instances with high precision and accuracy, so as to detect as many as possible of the anomalous instances while avoiding false alarms. Various security analytics operations involve anomaly detection. In many edge computing environments, for instance edge computing environments involving legacy devices, there are limitations in terms of conducting security analytics (e.g., anomaly detection). Example limitations or constraints in edge environments include limited computational resources, limited storage capacity, limited network bandwidth, and the like. In some cases, such constraints can make it impractical or burdensome to deploy and maintain traditional security analytics, such as a full-fledge ELK (Elasticsearch, Logstash, Kibana) stack for security analytics, which can result in various security vulnerabilities.BRIEF SUMMARY

[0002] Embodiments of the invention address and overcome one or more of the described- herein shortcomings or technical problems by providing methods, systems, and apparatuses for performing security analytics, for instance security analytics that involve anomaly detection, in resource-constrained environments. In particular, for example, embodiments define a system that can monitor and analyze security-related data from legacy devices in various edge computing environments, so as to detect and address potential threats or anomalies.

[0003] In an example aspect, an edge device is configured to operate on premise of an industrial system or building. The edge device includes a memory storing instructions that, when executed by the processor, cause the processor to perform various operations. For example, the edge device can receive a data stream from within the industrial system or the building, wherein the data stream defines a plurality of data features. The edge device can determine a computational resource size available to the edge device. Based on the computational resource size, the edge device can select a first data feature from the plurality of data features, so as to define a first selected data feature. The edge device can input a first portion of the data stream to an anomaly detection model. The first portion of the data stream202411124 can correspond to the first selected data feature. Based on the first portion of the data stream corresponding to the first selected data feature, the edge device can detect an anomaly within the industrial system or the building. Responsive to detecting the anomaly, the edge device can trigger an alert or shut down a device associated with anomaly.

[0004] In another example aspect, the edge device can determine whether the anomaly detection model improves over time, based on the first selected data feature. When it is determined that the anomaly detection model is not improving, the edge device can select a second data feature, so as to define a second selected data feature. The edge device can input a second portion of the data stream to the anomaly detection model, wherein the second portion of the data stream corresponds to the selected data feature. Based on the second portion of the data stream corresponding to the second selected data feature, the edge device can detect the anomaly within the industrial system or the building. Additionally, or alternatively, based on the computation resource size available to the edge device, the edge device can select the anomaly detection model from a plurality of anomaly detection models on the edge device, so as to define a selected anomaly model. Furthermore, the industrial system or building can define a plurality of network segments. Based on the selected anomaly model, the edge device can drop at least one network segment of the plurality of network segments, so as to define a dropped network segment. The edge device can input portions of the data stream into the selected anomaly detection model that are not associated with the dropped network segment.BRIEF DESCRIPTION OF THE DRAWINGS

[0005] The foregoing and other aspects of the present invention are best understood from the following detailed description when read in connection with the accompanying drawings. For the purpose of illustrating the invention, there is shown in the drawings embodiments that are presently preferred, it being understood, however, that the invention is not limited to the specific instrumentalities disclosed. Included in the drawings are the following Figures:

[0006] FIG. 1 is a block diagram of an example industrial system or building that includes a plurality of edge devices or nodes, in accordance with an example embodiment.

[0007] FIG. 2 is a block diagram of an example edge device, in accordance with an example embodiment.

[0008] FIG. 3 is a flow diagram that shows example operations performed by the edge device, in accordance with an example embodiment.202411124

[0009] FIG. 4 shows an example of a computing environment within which embodiments of the disclosure may be implemented.DETAILED DESCRIPTION

[0010] As an initial matter, it is recognized herein that traditional security analytics, such as security analytics that are reliant on an ELK (Elasticsearch, Logstash, Kibana) stack, are often not feasible in resource-constrained environments. In particular, for example, implementation of a traditional ELK stack can require significant computing resources that are often deployed in the cloud. But smaller scale deployments (e.g., small hospitals, production facilities, etc.) often have significant and important data security and information protection needs despite being resource-constrained in terms of, for example, not having their own data center for cyber security analytics and the like. Resource-constrained environments can include many edge computing environments, for instance edge computing environments that include legacy devices, in which there are limitations in terms of computational resources, storage capacity, network bandwidth, etc. It is further recognized herein that such resource-constrained environments often have significant data security and anomaly detection needs, but anomaly detection in edge environments presents unique computational challenges due to the limited resources available on edge devices. Traditional anomaly detection mechanisms may struggle to operate efficiently in real-time or near-real-time settings, leading to suboptimal resource utilization and delayed threat identification.

[0011] In accordance with various example embodiments, a computing system performs adaptive resource-aware anomaly detection (ARAAD) to perform efficient and real-time anomaly detection in resource-constrained edge environments. In particular, the system can perform ARAAD to optimize the utilization of computational resources while maintaining the responsiveness and accuracy of anomaly detection in edge computing scenarios.

[0012] Referring initially to FIG. 1 , an example industrial or building system 100 can include one or more plants or production networks 104 that contain control logic, host web servers, and the like. For example, the industrial system 100 can include an enterprise or IT network 102 and multiple operational plant or production networks 104 communicatively coupled to the IT network 102. The production network 104 or enterprise network 102 can include a plurality of edge devices or nodes 106 connected within the production network 104. The edge devices 106 can include virtual programmable logic controllers (PLCs), industrial computers, management computing devices, or the like. The edge devices 106 that are configured as worker nodes (further described herein) can include embedded or plugged GPUs, such as an202411124 industrial PC with GPU added. In an example, the edge device 106 defines an edge connectivity device (e.g., Connect X300) configured gather data for a given building on premise. The arrangement of edge devices 106 can vary as desired, and all such arrangements are contemplated as being within the scope of this disclosure.

[0013] Still referring to FIG. 1 , the production network 104 can include various production machines configured to work together to perform one or more manufacturing operations. Example production machines of the production network 104 can include, without limitation, robots 108 and other field devices that can be controlled by a respective PLC 114, such as sensors 110, actuators 112, or other machines, such as automatic guided vehicles (AGVs). The PLC 114 can send instructions to respective field devices. In some cases, a given PLC 114 can be coupled to a human machine interfaces (HMIs) 116. It will be understood that the industrial control network 100 is simplified for purposes of example. That is, the industrial system 100 may include additional or alternative nodes or systems, for instance other network devices, that define alternative configurations, and all such configurations are contemplated as being within the scope of this disclosure.

[0014] The system 100, in particular each production network 104, can define a field portion or level 118 and plant level or portion 120. For example, and without limitation, the plant level 120 can define one or more industrial plants or systems that can be geographically and functionally separate from or independent of each other. For example, the plant level 120 can include Brownfield plants and Greenfield plants that are each connected to respective field devices within the field level 118. The field level 118 can include various field devices such as the robots 108, PLC 114, sensors 110, actuators 112, HMIs 116, and AGVs. The field portion 118 can define one or more production lines or control zones associated with a given plant in the plant level 120. The PLC 114, sensors 110, actuators 112, and HMI 116 within a given production line can communicate with each other via a respective field bus 122. Each control zone can be defined by a respective PLC 114, such that the PLC 114, and thus the corresponding control zone, can connect to the respective plant portion 120 via an Ethernet connection 124. In some cases, the robots 108 and AGVs can be configured to communicate with other devices within the fieldbus portion 118 via a Wi-Fi connection 126. Similarly, the robots 108 and AGVs can communicate with the Ethernet portion 120, in particular a Supervisory Control and Data Acquisition (SCADA) server 128, via the Wi-Fi connection 126. In various examples, a respective edge device 106 is communicatively coupled between the PLC 114 and the respective plant in the plant level 120, for instance via the Ethernet connection 124 or the Wi-Fi connection 126.202411124

[0015] The plant level 120 of a given production network 104 can include various computing devices or subsystems communicatively coupled together via the Ethernet connection 124. Example computing devices or subsystems in the plant portion 120 include, without limitation, a mobile data collector 130, HMIs 132, the SCADA server 128, the edge devices 106, a wireless router 134, a manufacturing execution system (MES) 136, an engineering system (ES) 138, and a log server 140. The ES 138 can include one or more engineering works stations. In an example, the MES 136, HMIs 132, ES 138, and log server 140 are connected to the production network 104 directly. The wireless router 134 can also connect to the production network 104 directly. Thus, in some cases, mobile users, for instance the mobile data collector 130 and robots 108 (e.g., AGVs), can connect to the production network 104 via the wireless router 134.

[0016] As described above, the industrial system 100 can define a heterogenous IT / OT network, for instance an IT / OT network that includes the IT network 102 and the production network 104. For example, the IT network 102 and the production network 104 can include or implement various devices, protocols, users, network administrators, and the like so as to define a heterogenous IT / OT network. In various examples, the industrial system 100, and thus the heterogeneous IT / OT network, defines multiple production networks 104 or plants across multiple sites, each with their own operational histories.

[0017] Referring now to FIG. 2, the example edge device 106 can include one or more processing units and memory having stored thereon applications, agents, and computer program modules including, for example, a dynamic feature module 202, an incremental learning module 204, an edge-optimized model compression module 206, an adaptive threshold module 208, a context-aware processing module 210, and an edge-cloud synchronization module 212. It will be appreciated that the program modules, applications, computer-executable instructions, code, or the like depicted in FIG. 2 are merely illustrative and not exhaustive, and that processing described as being supported by any particular module may alternatively be distributed across multiple modules or performed by a different module. In addition, various program module(s), script(s), plug-in(s), Application Programming Interface(s) (API(s)), or any other suitable computer-executable code may be provided to support functionality provided by the program modules, applications, or computer-executable code depicted in FIG. 2 and / or additional or alternate functionality. Further, functionality may be modularized differently such that processing described as being supported collectively by the collection of program modules depicted in FIG. 2 may be performed by a fewer or greater number of modules, or functionality described as being supported by any particular module may be supported, at least in part, by another module. In addition, program modules that support the functionality described herein may form part of one or more applications202411124 executable across any number of systems or devices in accordance with any suitable computing model such as, for example, a client-server model, a peer-to-peer model, and so forth. In addition, any of the functionality described as being supported by any of the program modules depicted in FIG. 2 may be implemented, at least partially, in hardware and / or firmware across any number of devices.

[0018] Referring also to FIG. 3, example ARAAD operations 300 can be performed by the edge device 106. At 302, the edge device 106 can receive or otherwise obtain data. The data can be associated with a building within which the edge device is located. For example, the edge device 106 might receive data related to the production system 104 from the sensors 110. In various examples, the obtained data can include system logs and event data, which record actions such as login attempts, file accesses, network connections, and the like, so as to define a foundational data set for anomaly detection. Each log entry can include various features such as, for example and without limitation, timestamps, event types, user IDs, IP addresses, and the status of the event. This data can be collected directly from the system's logging mechanisms, which may include syslog on Unix-like systems or Windows Event Logs on Windows-based systems. In some cases, the granularity and detail provided by these logs are essential for tracking user and system behavior over time.

[0019] Network traffic data can further enrich the anomaly detection process by providing insights into the flow of data packets across the device's network interfaces. Key features extracted from this data can include, for example and without limitation, packet size, source and destination IP addresses, protocol types, and packet timestamps. This information can be captured using network monitoring tools such as packet sniffers (e.g., tcpdump) or flow collectors (e.g., NetFlow), which allow for deep inspection and analysis of the device's network activity. In various examples, the real-time nature of this data is particularly valuable for detecting anomalies related to network-based threats.

[0020] Resource usage metrics offer a direct measure of the device's operational status, including CPU and memory usage, disk I / O, and network bandwidth consumption. These metrics can be collected via system monitoring tools or APIs, and features can be extracted to create a profile of the device's resource consumption patterns. Monitoring these metrics over time enables the edge device 106 performing ARAAD to detect deviations from normal operational behavior, which may indicate the presence of an anomaly.

[0021] Application-specific data can provide another layer of context, focusing on the performance and behavior of the applications running on the edge device 106. This data might include metrics such as API call frequency, error rates, and latency, all of which can be critical for understanding how applications interact with the system and where potential issues may202411124 arise. Such data can be collected through application logs or performance monitoring systems embedded within the application itself.

[0022] In some example scenarios where edge devices are equipped with (or communicatively coupled to) sensors, sensor data such as temperature, humidity, and pressure readings can also be collected. Each sensor reading can be associated with a timestamp and, where applicable, the location or ID of the sensor. This data can be particularly relevant in loT environments, where physical conditions monitored by sensors can be as important as digital metrics for detecting anomalies.

[0023] The collected or obtained data can be in a structured manner to facilitate processing by the ARAAD operations. Time-series formatting can be used for data types that are timedependent, such as resource usage metrics and sensor readings. This format can allow the edge device 106, via the ARAAD operations, to track changes over time and identify trends or sudden shifts that may indicate an anomaly. For machine learning models, data can be transformed into feature vectors, where each feature represents a specific attribute or metric from the data. Categorical data, such as event types or protocol types, can be encoded numerically using various techniques such as, for example, one-hot encoding or label encoding to ensure compatibility with the algorithm's processing requirements.

[0024] Normalization and scaling can be applied to features with different ranges to ensure that no single feature disproportionately influences the model's output. This can be crucial when dealing with diverse data types, such as CPU usage percentages and network packet sizes, which operate on different scales. By standardizing these features, the edge device 106 can perform the ARAAD operations 300 to more effectively analyze the data and detect anomalies.

[0025] In an example, the data can define an input data matrix that is processed by the dynamic feature module 202. For example, ( ) in Equation (1) below can represent the input data matrix, wherein each row can correspond to a data sample and each column can correspond to a feature:Thus, the dynamic feature selection module 202 can receive the input data matrix, and based on the input data, select features (at 304) for anomaly detection based on available computational resources, for instance based on available computational resources of the edge device 106. In various examples, the dynamic feature selection module 202 reduces the dimensionality of sampled input data to focus on the most informative features, so as to optimize resource utilization without compromising detection accuracy. In some examples, the dynamic feature selection module 202 can assess the importance of each feature through a202411124 combination of statistical methods and model-based importance scores. This evaluation can result in a determination as to how much each feature contributes to the detection of anomalies. Statistical techniques such as, for example and without limitation, variance analysis, mutual information, and correlation with the target variable can be employed to gauge the relevance of each feature. In parallel, model-based approaches, like those used in decision trees for example, can assess feature importance by measuring the information gain each feature provides when used in data splitting. Such a dual evaluation process can ensure that only the most critical features are considered for further analysis.

[0026] Once the importance of each feature is established, the adaptive threshold module 208 can perform adaptive thresholding to decide which features to retain. Unlike static methods, this thresholding process is dynamic and adjusts based on the current availability of computational resources and the operational conditions of the edge device 106. For instance, in scenarios where CPU or memory resources are under heavy load, the threshold for feature selection may be raised, allowing only the most essential features to be processed. This adaptive approach ensures that the ARAAD can continue to function effectively even as resource availability fluctuates.

[0027] The module 202 can perform incremental feature selection, so as to continuously update the selection of features in response to new data, allowing it to adapt to evolving data patterns in real time. This can be achieved through a sliding window analysis, where feature importance is periodically re-evaluated based on the most recent data. Additionally, the module 202 is capable of detecting "feature drift," where the importance of certain features changes over time. By recognizing and adapting to these shifts, the ARAAD operations can maintain their effectiveness in identifying anomalies as conditions evolve.

[0028] The module 202 can further enhance the adaptability of the ARAAD operations by considering the specific operational context of the edge device 106. In an example, features are not only evaluated for their general importance but also for their relevance to the current environment. For example, in a network-heavy scenario, the module may prioritize features related to network traffic. Additionally, certain events, such as a sudden spike in CPU usage, may trigger a re-evaluation of feature importance, leading to a temporary shift in focus to features that are more pertinent to the immediate context.

[0029] The modules can also incorporate techniques for feature compression and aggregation, which help reduce the computational burden while retaining critical information. Dimensionality reduction methods, such as Principal Component Analysis (PCA), can be used to condense the feature set by focusing on the most informative aspects of the data.Additionally, feature aggregation can combine similar features into composite metrics, simplifying the data without losing essential details. For instance, multiple network traffic202411124 metrics might be merged into a single "network activity" feature, which captures the overall behavior more efficiently.

[0030] In practice, the dynamic feature selection module 202 can operate seamlessly within the ARAAD operations 300 to balance the need for detailed anomaly detection with the constraints of edge computing. By continuously adapting to the available resources and the changing nature of the data, the module 202 can ensure that the most relevant and informative features are always prioritized. Thus, ARAAD operations 300 can maintain high detection accuracy while minimizing resource consumption, making it particularly well-suited for realtime security analytics in resource-constrained edge environments.

[0031] By way of example, if given input data defines network traffic that includes packets with multiple fields, for instance greater than 100 or greater than 1000 fields, dynamic feature selection module 202 can be configured to only monitor a subset of the multiple fields, for instance one field or more, thereby reducing the resources required to monitor the network field. The subset of fields that the dynamic feature selection module can depend on the resources of the edge device 106 that are available. By way of example, and without limitation, the dynamic feature selection module 202 might select a single field to monitor, for instance the source IP address, when a first memory amount is available (e.g., 2 GB) on the edge device 106, and the dynamic feature selection module 202 might select multiple fields to monitor, for instance the source IP address and destination IP address, when a second memory amount is available (e.g., 8 GB) on the edge device 106 that is greater than the first memory amount.

[0032] At 306, the incremental learning module 204 can update an anomaly detection model using the received data or incoming data streams. In scenarios where pre-trained models are deployed on the edge device 106, the dynamic feature selection module 202 can leverage the feature importance scores or relevance metrics that were established during the initial training phase. In some cases, these models can be trained in resource-rich environments, such as cloud-based servers or centralized data centers, using extensive datasets. Once deployed to the edge, the module 204 can dynamically adjust these pre-established feature importance scores in response to the current operational context and available computational resources. This enables the ARAAD operations 300 to result in, and maintain, high detection accuracy while adapting to the limited resources of the edge device 106.

[0033] In situations where a model is trained directly on the edge device 106, the dynamic feature selection module 204 can play an integral role throughout the training process. As the model is exposed to new data, the module 204 can continuously evaluate and select features that are most relevant to the anomaly detection task at hand. This ongoing adjustment can202411124 ensure that the model remains responsive to the specific conditions and data patterns unique to the edge environment. This approach can be particularly valuable in dynamic or highly context-specific settings, where the data is subject to rapid changes that necessitate real-time adaptation.

[0034] By incrementally updating the model, the edge device 106 reduces or eliminates the need for extensive retraining, thereby conserving computational resources while ensuring adaptability to evolving threat landscapes. The update of an anomaly detection model (V / ) can be represented by Equation (2):[lVt+1= lVt+ a - VL(lVt,Xt, Yt)] (2) where (V / t) is the model at time (t), (cr) is the learning rate, (VL(V / t, Xt, Kt)) is the gradient of the loss function (L)with respect to the model parameters, and ((t, Kt)) represents the new data sample and its label at time (t).

[0035] By way of example, the incremental learning module 204 might select a packet field or feature, for instance the IP source or destination address, to input into the anomaly detection model, which might define an off-the-shelf autoencoder or the like that is trained for anomaly detection on the edge device 106. For example, the anomaly detection model can define an off-the-shelf autoencoder that does not have weights. In some cases, the autoencoder can be trained with data in a lab, and then can be deployed at the edge device 106 so that it can be further trained with various features by the incremental learning module 204. In some cases, the selected field corresponds to the one or more fields (features) that are selected by the dynamic feature selection module 202. The incremental learning module 204 can monitor the anomaly detection model to determine how its predictions improve over time. For example, if the model does not improve, the incremental learning module 204 might select a new feature to monitor and input into the anomaly detection model. In particular, for example, if the model is using the source IP address to determine whether the corresponding packets are anomalous, but the model is erroneously labeling non-malicious packets as malicious packets, incremental learning module 204 can select a different feature (e.g., IP destination address) to monitor and further train the anomaly detection model. In various examples, the incremental learning module 204 can evaluate various key performance indicators (KPIs) to determine whether the model is improving over time.

[0036] An example KPI is detection accuracy, which can encompass metrics such as, for example and without limitation, precision, recall, and the F1-score. These metrics can be instrumental in assessing how well the selected features enable the ARAAD operations to identify true anomalies while minimizing false positives and false negatives. Precision can202411124 measure the proportion of true anomalies among all detected anomalies, indicating the effectiveness of the features in correctly identifying threats. Recall, on the other hand, can evaluate the ARAAD operations’ ability to detect the relevant anomalies in the data. The F1- score, which balances precision and recall, can provide a comprehensive measure of the ARAAD operations’ accuracy, highlighting whether the selected features are indeed the most informative for anomaly detection.

[0037] Computational efficiency is another example KPI, which can be particularly important in resource-constrained edge environments. This KPI cam include various metrics such as, for example and without limitation, CPU usage, memory consumption, and processing time. By monitoring these metrics, the dynamic feature selection module 202 can ensure that the selected features do not overburden the edge device 106. For instance, low CPU usage and memory consumption are indicators that the feature set is optimized for the limited resources available, while fast processing times suggest that the ARAAD operations 300 can operate in real-time or near-real-time, which is essential for effective anomaly detection, in some cases.

[0038] Model robustness is another example KPI that can be used, particularly when evaluating whether the selected features enable the ARAAD operations to generalize well to new, unseen data. The modules can assesses generalization error — the difference in performance between the training data and a validation or test set — to ensure that the model is not overfitting to the training data. Overfitting can occur when features are too closely tailored to the specific training data, leading to poor performance on new data. By monitoring this KPI, the module 202 can adjust its feature selection to improve the model's robustness, ensuring that it remains effective in diverse and evolving conditions.

[0039] Contextual relevance is another example KPI that evaluates how well the selected features align with the specific operational context of the edge device 106. This KPI can be particularly important in environments where the nature of the data or the operational demands may change. For example, in a network-heavy environment, features related to network traffic can be prioritized if they are more relevant to the current operational scenario. By assessing the contextual relevance score, the modules ensures that the feature selection process is not just generally informative but also specifically tailored to the environment in which the device operates.

[0040] The dynamic feature selection module 202 can consider the trade-offs associated with resource utilization, particularly when adjusting the feature selection threshold in response to changing resource availability. This KPI evaluates how well the device 106 (via the ARAAD operations 300) maintains detection accuracy and processing efficiency when computational resources are constrained. By monitoring the impact of these adjustments, the modules ensure that the ARAAD operations continue to function effectively, even when resources are202411124 limited. This balance between resource usage and detection performance can be crucial for maintaining the overall efficiency and reliability of the anomaly detection process.

[0041] With continuing reference to FIGs. 2 and 3, at 308, the edge-optimized model compression module 206 can compress the anomaly detection model, so as to reduce the memory footprint and computational complexity of the anomaly detection model, thereby enabling efficient operation and real-time anomaly detection within the constrained-resources of the edge device 106. In particular, the edge device 106 can perform feature selection and dimensionality reduction. For example, by carefully evaluating the relevance of each feature, the edge device 106 can discard those that contribute minimally to the anomaly detection task. This reduction in the number of features might not only decrease the amount of data that needs to be processed but also can reduce the overall computational load. Techniques such as Principal Component Analysis (PCA) can further condense high-dimensional data into a lower-dimensional space, thereby preserving essential patterns while streamlining the processing requirements.

[0042] Model compression can also be performed, for instance by the model compression module 206, to decrease the memory and processing demands anomaly detection. Approaches such as quantization, pruning, and knowledge distillation can be applied to reduce the size and complexity of the machine learning models used within the ARAAD framework. Quantization can reduce the precision of the model’s weights, significantly lowering the memory required to store the model and speeding up computations. Pruning can eliminate less important weights or neurons, decreasing the number of operations needed during inference. Meanwhile, knowledge distillation can allow a smaller, more efficient model to replicate the performance of a larger one, retaining much of the accuracy while substantially reducing the computational burden.

[0043] Adaptive thresholding, for instance performed by the adaptive threshold module 208, is another technique that can be performed so as to dynamically adjust the complexity of the detection process based on the available computational resources. When resources are limited, the module 208 can raise thresholds to focus on the most critical data, thereby reducing the sensitivity of anomaly detection and optimizing resource usage. This adaptive approach ensures that the anomaly detection continues to function effectively without overloading the edge device 106.

[0044] Incremental learning, for instance performed by the incremental learning module 204, can further enhance the efficiency of the anomaly detection by updating the model gradually with new data, thereby avoiding the need for complete retraining. Incremental learning can conserve computational resources and memory, making continuous learning feasible on edge202411124 devices. For example, instead of processing large-scale updates, the edge device 106 might handle small batches of data, thereby ensuring that updates are manageable and do not strain the device's capabilities.

[0045] The edge device 106, can also employ efficient data storage and retrieval methods to minimize memory usage. By storing only the most relevant historical data in compressed formats or using sparse representations, the edge device 106 can reduce the memory required while still retaining essential information for anomaly detection. Additionally, data caching strategies can enhance retrieval speed, ensuring that frequently accessed data is readily available without the need for repeated, resource-intensive operations.

[0046] Edge-cloud collaboration, for instance performed by the edge-cloud synchronization module 212, can also reduce computational complexity. The ARAAD operations can define complex tasks that can be offloaded to the cloud, allowing the edge device 106 to handle initial, lightweight processing. In some examples, by sending only the most critical data or tasks to the cloud, the edge device 106 can operate within its resource limitations while benefiting from the cloud's computational power when necessary. This division of labor ensures that the anomaly detection operations remain responsive and efficient, even under constrained conditions.

[0047] Furthermore, the edge device 106 can use batch processing and data aggregation to further reduce computational load. By processing data in groups or summarizing multiple data points into aggregated metrics, the frequency and intensity of computations can be decreased. In some cases, this approach not only speeds up processing times but also conserves memory, making it easier to manage the anomaly detection operations’ demands on limited resources.

[0048] The edge-optimized model compression can include quantization and pruning, and can be represented by Equation (3):where (IV') represents the compressed model, and (©compression) represents compression parameters.

[0049] At 310, the adaptive threshold module 208 can dynamically adjust anomaly detection thresholds based on available computational resources and operational constraints at the edge device 106. By adaptively setting detection thresholds, the adaptive threshold module 208 can optimize the trade-off between detection sensitivity and resource utilization, ensuring efficient anomaly detection under varying resource conditions. Adaptive thresholding performed by the adaptive threshold module 208 can be represented by Equation (4):[Thresholdt + 1 = / threshold-update(Thresholdt, ^threshold)] (4)202411124 where (Thresholdt)represents the threshold at time (t), and (^threshold) represents an update value based on available computational resources. In various examples, the accuracy of a given prediction of the anomaly detection model can depend on the quality of the anomaly detection model itself, and the quality of inputs to the anomaly detection model. In an example environment with unlimited computational resources, the model might receive every header that a given IP packet might have. Parameters can vary in size, so if a simple (less resources required) model is used with a small number of parameters, the relative accuracy of the model might be low. Thus, the adaptive threshold module 208 can be configured to adjust which anomaly detection model is used based on the various parameters (resources) associated with the edge device 106, for instance based on memory and processing power.

[0050] Threshold determination can be performed by module 208 so as to define a process that is not static. Rather, thresholds can be dynamically adjusted based on real-time operational conditions and the available resources on the edge device 106. For example, when the edge device 106 experiences high CPU or memory usage, the module 208 may raise the detection threshold, thereby allowing only the most critical anomalies or features to be processed. This can help to manage the computational load effectively. Conversely, during periods of lower resource usage, the threshold can be lowered, enabling the edge device 106 to perform more sensitive and comprehensive anomaly detection. This adaptive mechanism can ensure that the ARAAD operations remain responsive to changing conditions, balancing the need for accurate detection with the practical limitations of the edge device 106.

[0051] The process of threshold adjustment can be guided by a feedback loop that continuously evaluates the outcomes of the anomaly detection. For example, if the ARAAD operations detects too many false positives or fails to catch significant anomalies, the threshold can be fine-tuned to optimize performance. This fine-tuning might be driven by predefined rules, machine learning models, or a combination thereof, ensuring that the threshold settings are aligned with the current operational demands and resource availability.

[0052] In terms of model management, in some examples, the edge device 106 may host multiple models, each tailored for different types of data or specific anomaly detection tasks, such as network traffic analysis or system log monitoring. The selection of which model to deploy at any given moment can be determined by the nature of the incoming data or the specific operational context. In environments with severe resource constraints, a single, generalized model might be used to handle multiple tasks, ensuring a balance between efficiency and detection capability.

[0053] The models deployed on the edge device 106 can be optimized for size and computational efficiency. Techniques like model quantization, pruning, and knowledge202411124 distillation can be employed to reduce the size and complexity of these models, making them suitable for the limited resources available on edge devices. Despite these optimizations, in various examples, the models remain effective in detecting anomalies, ensuring that the device 106 can maintain high levels of security and operational integrity.

[0054] Furthermore, the modules (e.g., for instance the incremental learning module 204) can support the periodic update or retraining of models, either locally using incremental learning methods or through updates received from a central server. This capability can be crucial in environments where threats or operational conditions evolve rapidly, as it can ensure that the models remain up-to-date and capable of addressing the latest security challenges. When multiple models are available, the modules (for instance the context-aware processing module 210) can use context-aware decision-making to select the most appropriate model for the task at hand, further optimizing the balance between detection performance and resource usage.

[0055] At 312, the context-aware processing module 210 can select or prioritize the analysis of data segments that exhibit potential anomalous behavior. For example, the context-aware processing module 210 can allocate computational resources to the most relevant areas of the data stream, thereby enhancing the efficiency of anomaly detection within edge environments. The context-aware processing can be represented by Equation (5):where (sanOmaiy) represents the prioritized segment s for anomaly analysis, and 0contextrepresents the context-aware processing parameters.

[0056] For example, a given building or physical environment (e.g., industrial system 100) can include multiple segregated networks, for instance an air flow network, an energy network, etc. The context-aware processing module 210 can prioritize or drop certain network segments, for instance based on historical data or computational resources. Prioritization of network segments can be guided by the contextual relevance of the traffic being analyzed. The edge device 106 can assess the importance of different types of network traffic based on the specific operational context of the edge device 106. For instance, in an industrial control system, traffic related to critical control commands or sensor data might be prioritized due to its direct impact on operational safety and integrity. The edge device 106 can classify network segments by type, such as, for example and without limitation, control traffic, sensor data, or routine IT communications, and assign higher priority to those that are most relevant to the device's core functions. This classification can be informed by predefined rules or patterns202411124 learned from historical data, ensuring that the most crucial segments receive the attention they deserve.

[0057] In addition to contextual relevance, the ARAAD operations can also prioritize network segments based on a risk assessment of the traffic. Segments that exhibit unusual or suspicious patterns — such as repeated failed login attempts or large, unexpected data transfers — can be flagged for closer scrutiny. The edge device 106 can employ anomaly detection techniques to score these segments based on their deviation from normal behavior. Segments with higher anomaly scores can be prioritized, allowing the edge device 106 to focus its resources on analyzing potential security threats while deprioritizing segments that pose less risk.

[0058] Historical data and trends can further inform the prioritization process. Network segments that have previously been associated with security incidents or anomalies can be given higher priority. By analyzing historical logs and previous detection results, the ARAAD operations can identify patterns that suggest which segments are more likely to contain future anomalies. This adaptive prioritization can ensure that resources are allocated to the segments most likely to present security challenges, based on past behavior.

[0059] Conversely, the ARAAD operations may result in a determination to drop certain network segments, particularly in situations where the edge device 106 is under significant resource strain. When CPU, memory, or bandwidth resources are limited, the modules can dynamically adjust thresholds to determine which segments are processed and which are dropped. In some cases, segments considered less critical or lower risk are more likely to be excluded from analysis, allowing the modules to conserve resources for more essential tasks. This real-time adjustment can ensure that the system continues to operate effectively, even under constrained conditions.

[0060] Segments deemed low relevance or redundant can also define candidates for being dropped. For example, repetitive traffic that consistently matches known safe patterns might not require continuous monitoring. The modules can use pattern recognition to identify such segments, processing them less frequently or excluding them altogether when resources are tight. This can allow the modules to focus on more variable or suspicious traffic, thereby optimizing the use of available resources.

[0061] In some cases, the decision to drop a network segment is temporary, based on the current operational load or specific situational factors. During peak traffic periods, the modules might temporarily suspend monitoring of non-essential segments to prioritize critical traffic. As resource availability improves, these dropped segments can be reintroduced into the202411124 monitoring process, ensuring that the edge device 106 maintains a balance between resource conservation and comprehensive network analysis.

[0062] By way of example, in an industrial control system, the ARAAD operations might prioritize network segments carrying control commands or sensor data critical to operations, particularly those linked to safety systems. These segments might be monitored closely due to their potential impact on operational integrity. Routine administrative traffic, however, might be deprioritized or dropped if the system is experiencing high resource demand. Once the load decreases, the modules can resume monitoring the previously dropped segments, thereby ensuring that all relevant traffic is eventually analyzed.

[0063] The context can refer to various network segments. By way of an example, a particular network segment might include a first number of connected devices, but the context- aware processing module 210 might select a second number of connected device for using in the anomaly detection model, wherein the second number is less than the first number. Thus, the module 210 can reduce the traffic size that is monitored, based on computational resources, and based on historical data that might indicate which devices are most likely to transmit malicious data.

[0064] In some examples, the edge device 106, in particular the edge-cloud synchronization module 212, can be coupled to a cloud-based server or cloud resources. At 314, the edgecloud synchronization module 212 can allocate, for instance based on resource constraints of the edge device 106, one or more task to the cloud-based server, so as to offload computationally intensive tasks, thereby balancing a computational load between the edge device 106 and cloud resources. The edge device 106 can thus perform efficient anomaly detection in varying resource conditions. At 316, based on the anomaly detection operations that are performed, the edge device 106 can trigger an action. For example, the edge device 106 might render an alert to an inform an operator of a threat associated with a detected anomaly, or the edge device 106 might shut down a device or network segment associated with a detected anomaly that is indicative of a security threat.

[0065] Thus, as described herein, an edge device can be configured to operate on premise of an industrial system or building. The edge device includes a memory storing instructions that, when executed by the processor, cause the processor to perform various operations. For example, the edge device can receive a data stream from within the industrial system or the building, wherein the data stream defines a plurality of data features. The edge device can determine a computational resource size available to the edge device. Based on the computational resource size, the edge device can select a first data feature from the plurality of data features, so as to define a first selected data feature. The edge device can input a first202411124 portion of the data stream to an anomaly detection model. The first portion of the data stream can correspond to the first selected data feature. Based on the first portion of the data stream corresponding to the first selected data feature, the edge device can detect an anomaly within the industrial system or the building. Responsive to detecting the anomaly, the edge device can trigger an alert or shut down a device associated with anomaly.

[0066] In another example aspect, the edge device can determine whether the anomaly detection model improves over time, based on the first selected data feature. When it is determined that the anomaly detection model is not improving, the edge device can select a second data feature, so as to define a second selected data feature. The edge device can input a second portion of the data stream to the anomaly detection model, wherein the second portion of the data stream corresponds to the selected data feature. Based on the second portion of the data stream corresponding to the second selected data feature, the edge device can detect the anomaly within the industrial system or the building. Additionally, or alternatively, based on the computation resource size available to the edge device, the edge device can select the anomaly detection model from a plurality of anomaly detection models on the edge device, so as to define a selected anomaly model. Furthermore, the industrial system or building can define a plurality of network segments. Based on the selected anomaly model, the edge device can drop at least one network segment of the plurality of network segments, so as to define a dropped network segment. The edge device can input portions of the data stream into the selected anomaly detection model that are not associated with the dropped network segment.

[0067] FIG. 4 illustrates an example of a computing environment within which embodiments of the present disclosure may be implemented. A computing environment 400 includes a computer system 410 that may include a communication mechanism such as a system bus 421 or other communication mechanism for communicating information within the computer system 410. The computer system 410 further includes one or more processors 420 coupled with the system bus 421 for processing the information. The industrial system 100, for instance the edge device 106, may include, or be coupled to, the one or more processors 420.

[0068] The processors 420 may include one or more central processing units (CPUs), graphical processing units (GPUs), or any other processor known in the art. More generally, a processor as described herein is a device for executing machine-readable instructions stored on a computer readable medium, for performing tasks and may comprise any one or combination of, hardware and firmware. A processor may also comprise memory storing machine-readable instructions executable for performing tasks. A processor acts upon information by manipulating, analyzing, modifying, converting or transmitting information for use by an executable procedure or an information device, and / or by routing the information to202411124 an output device. A processor may use or comprise the capabilities of a computer, controller or microprocessor, for example, and be conditioned using executable instructions to perform special purpose functions not performed by a general purpose computer. A processor may include any type of suitable processing unit including, but not limited to, a central processing unit, a microprocessor, a Reduced Instruction Set Computer (RISC) microprocessor, a Complex Instruction Set Computer (CISC) microprocessor, a microcontroller, an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), a System-on-a- Chip (SoC), a digital signal processor (DSP), and so forth. Further, the processor(s) 320 may have any suitable microarchitecture design that includes any number of constituent components such as, for example, registers, multiplexers, arithmetic logic units, cache controllers for controlling read / write operations to cache memory, branch predictors, or the like. The microarchitecture design of the processor may be capable of supporting any of a variety of instruction sets. A processor may be coupled (electrically and / or as comprising executable components) with any other processor enabling interaction and / or communication there-between. A user interface processor or generator is a known element comprising electronic circuitry or software or a combination of both for generating display images or portions thereof. A user interface comprises one or more display images enabling user interaction with a processor or other device.

[0069] The system bus 421 may include at least one of a system bus, a memory bus, an address bus, or a message bus, and may permit exchange of information (e.g., data (including computer-executable code), signaling, etc.) between various components of the computer system 410. The system bus 421 may include, without limitation, a memory bus or a memory controller, a peripheral bus, an accelerated graphics port, and so forth. The system bus 421 may be associated with any suitable bus architecture including, without limitation, an Industry Standard Architecture (ISA), a Micro Channel Architecture (MCA), an Enhanced ISA (EISA), a Video Electronics Standards Association (VESA) architecture, an Accelerated Graphics Port (AGP) architecture, a Peripheral Component Interconnects (PCI) architecture, a PCI-Express architecture, a Personal Computer Memory Card International Association (PCMCIA) architecture, a Universal Serial Bus (USB) architecture, and so forth.

[0070] Continuing with reference to FIG. 4, the computer system 410 may also include a system memory 430 coupled to the system bus 421 for storing information and instructions to be executed by processors 420. The system memory 430 may include computer readable storage media in the form of volatile and / or nonvolatile memory, such as read only memory (ROM) 431 and / or random access memory (RAM) 432. The RAM 432 may include other dynamic storage device(s) (e.g., dynamic RAM, static RAM, and synchronous DRAM). The ROM 431 may include other static storage device(s) (e.g., programmable ROM, erasable202411124PROM, and electrically erasable PROM). In addition, the system memory 430 may be used for storing temporary variables or other intermediate information during the execution of instructions by the processors 420. A basic input / output system 433 (BIOS) containing the basic routines that help to transfer information between elements within computer system 410, such as during start-up, may be stored in the ROM 431. RAM 432 may contain data and / or program modules that are immediately accessible to and / or presently being operated on by the processors 420. System memory 430 may additionally include, for example, operating system 434, application programs 435, and other program modules 436. Application programs 435 may also include a user portal for development of the application program, allowing input parameters to be entered and modified as necessary.

[0071] The operating system 434 may be loaded into the memory 430 and may provide an interface between other application software executing on the computer system 410 and hardware resources of the computer system 410. More specifically, the operating system 434 may include a set of computer-executable instructions for managing hardware resources of the computer system 410 and for providing common services to other application programs (e.g., managing memory allocation among various application programs). In certain example embodiments, the operating system 434 may control execution of one or more of the program modules depicted as being stored in the data storage 440. The operating system 434 may include any operating system now known or which may be developed in the future including, but not limited to, any server operating system, any mainframe operating system, or any other proprietary or non-proprietary operating system.

[0072] The computer system 410 may also include a disk / media controller 443 coupled to the system bus 421 to control one or more storage devices for storing information and instructions, such as a magnetic hard disk 441 and / or a removable media drive 442 (e.g., floppy disk drive, compact disc drive, tape drive, flash drive, and / or solid state drive). Storage devices 440 may be added to the computer system 410 using an appropriate device interface (e.g., a small computer system interface (SCSI), integrated device electronics (IDE), Universal Serial Bus (USB), or FireWire). Storage devices 441 , 442 may be external to the computer system 410.

[0073] The computer system 410 may also include a field device interface 465 coupled to the system bus 421 to control a field device 466, such as a device used in a production line. The computer system 410 may include a user input interface or GUI 461 , which may comprise one or more input devices, such as a keyboard, touchscreen, tablet and / or a pointing device, for interacting with a computer user and providing information to the processors 420.

[0074] The computer system 410 may perform a portion or all of the processing steps of embodiments of the invention in response to the processors 420 executing one or more202411124 sequences of one or more instructions contained in a memory, such as the system memory 430. Such instructions may be read into the system memory 430 from another computer readable medium of storage 440, such as the magnetic hard disk 441 or the removable media drive 442. The magnetic hard disk 441 and / or removable media drive 442 may contain one or more data stores and data files used by embodiments of the present disclosure. The data store 440 may include, but are not limited to, databases (e.g., relational, object-oriented, etc.), file systems, flat files, distributed data stores in which data is stored on more than one node of a computer network, peer-to-peer network data stores, or the like. The data stores may store various types of data such as, for example, skill data, sensor data, or any other data generated in accordance with the embodiments of the disclosure. Data store contents and data files may be encrypted to improve security. The processors 420 may also be employed in a multi-processing arrangement to execute the one or more sequences of instructions contained in system memory 430. In alternative embodiments, hard-wired circuitry may be used in place of or in combination with software instructions. Thus, embodiments are not limited to any specific combination of hardware circuitry and software.

[0075] As stated above, the computer system 410 may include at least one computer readable medium or memory for holding instructions programmed according to embodiments of the invention and for containing data structures, tables, records, or other data described herein. The term “computer readable medium” as used herein refers to any medium that participates in providing instructions to the processors 420 for execution. A computer readable medium may take many forms including, but not limited to, non-transitory, nonvolatile media, volatile media, and transmission media. Non-limiting examples of non-volatile media include optical disks, solid state drives, magnetic disks, and magneto-optical disks, such as magnetic hard disk 441 or removable media drive 442. Non-limiting examples of volatile media include dynamic memory, such as system memory 430. Non-limiting examples of transmission media include coaxial cables, copper wire, and fiber optics, including the wires that make up the system bus 421 . Transmission media may also take the form of acoustic or light waves, such as those generated during radio wave and infrared data communications.

[0076] Computer readable medium instructions for carrying out operations of the present disclosure may be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, statesetting data, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The computer readable program instructions may execute entirely on the user's computer, partly on the user's202411124 computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) may execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.

[0077] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, may be implemented by computer readable medium instructions.

[0078] The computing environment 400 may further include the computer system 410 operating in a networked environment using logical connections to one or more remote computers, such as remote computing device 480. The network interface 470 may enable communication, for example, with other remote devices 480 or systems and / or the storage devices 441 , 442 via the network 471 . Remote computing device 480 may be a personal computer (laptop or desktop), a mobile device, a server, a router, a network PC, a peer device or other common network node, and typically includes many or all of the elements described above relative to computer system 410. When used in a networking environment, computer system 410 may include modem 472 for establishing communications over a network 471 , such as the Internet. Modem 472 may be connected to system bus 421 via user network interface 470, or via another appropriate mechanism.

[0079] Network 471 may be any network or system generally known in the art, including the Internet, an intranet, a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a direct connection or series of connections, a cellular telephone network, or any other network or medium capable of facilitating communication between computer system 410 and other computers (e.g., remote computing device 480). The network 471 may be wired, wireless or a combination thereof. Wired connections may be implemented using Ethernet, Universal Serial Bus (USB), RJ-6, or any other wired connection generally known in the art. Wireless connections may be implemented using Wi-Fi, WiMAX, and Bluetooth, infrared, cellular networks, satellite or any other wireless connection methodology202411124 generally known in the art. Additionally, several networks may work alone or in communication with each other to facilitate communication in the network 471.

[0080] It should be appreciated that the program modules, applications, computerexecutable instructions, code, or the like depicted in FIG. 4 as being stored in the system memory 430 are merely illustrative and not exhaustive and that processing described as being supported by any particular module may alternatively be distributed across multiple modules or performed by a different module. In addition, various program module(s), script(s), plug-in(s), Application Programming Interface(s) (API(s)), or any other suitable computer-executable code hosted locally on the computer system 410, the remote device 480, and / or hosted on other computing device(s) accessible via one or more of the network(s) 471 , may be provided to support functionality provided by the program modules, applications, or computer-executable code depicted in the figures and / or additional or alternate functionality. Further, functionality may be modularized differently such that processing described as being supported collectively by the collection of program modules depicted in the figures may be performed by a fewer or greater number of modules, or functionality described as being supported by any particular module may be supported, at least in part, by another module. In addition, program modules that support the functionality described herein may form part of one or more applications executable across any number of systems or devices in accordance with any suitable computing model such as, for example, a client-server model, a peer-to-peer model, and so forth. In addition, any of the functionality described as being supported by any of the program modules depicted in the figures may be implemented, at least partially, in hardware and / or firmware across any number of devices.

[0081] It should further be appreciated that the computer system 410 may include alternate and / or additional hardware, software, or firmware components beyond those described or depicted without departing from the scope of the disclosure. More particularly, it should be appreciated that software, firmware, or hardware components depicted as forming part of the computer system 410 are merely illustrative and that some components may not be present or additional components may be provided in various embodiments. While various illustrative program modules have been depicted and described as software modules stored in system memory 430, it should be appreciated that functionality described as being supported by the program modules may be enabled by any combination of hardware, software, and / or firmware. It should further be appreciated that each of the above-mentioned modules may, in various embodiments, represent a logical partitioning of supported functionality. This logical partitioning is depicted for ease of explanation of the functionality and may not be representative of the structure of software, hardware, and / or firmware for implementing the functionality. Accordingly, it should be appreciated that functionality described as being202411124 provided by a particular module may, in various embodiments, be provided at least in part by one or more other modules. Further, one or more depicted modules may not be present in certain embodiments, while in other embodiments, additional modules not depicted may be present and may support at least a portion of the described functionality and / or additional functionality. Moreover, while certain modules may be depicted and described as sub-modules of another module, in certain embodiments, such modules may be provided as independent modules or as sub-modules of other modules.

[0082] Although specific embodiments of the disclosure have been described, one of ordinary skill in the art will recognize that numerous other modifications and alternative embodiments are within the scope of the disclosure. For example, any of the functionality and / or processing capabilities described with respect to a particular device or component may be performed by any other device or component. Further, while various illustrative implementations and architectures have been described in accordance with embodiments of the disclosure, one of ordinary skill in the art will appreciate that numerous other modifications to the illustrative implementations and architectures described herein are also within the scope of this disclosure. In addition, it should be appreciated that any operation, element, component, data, or the like described herein as being based on another operation, element, component, data, or the like can be additionally based on one or more other operations, elements, components, data, or the like. Accordingly, the phrase “based on,” or variants thereof, should be interpreted as “based at least in part on.”

[0083] Although embodiments have been described in language specific to structural features and / or methodological acts, it is to be understood that the disclosure is not necessarily limited to the specific features or acts described. Rather, the specific features and acts are disclosed as illustrative forms of implementing the embodiments. Conditional language, such as, among others, “can,” “could,” “might,” or “may,” unless specifically stated otherwise, or otherwise understood within the context as used, is generally intended to convey that certain embodiments could include, while other embodiments do not include, certain features, elements, and / or steps. Thus, such conditional language is not generally intended to imply that features, elements, and / or steps are in any way required for one or more embodiments or that one or more embodiments necessarily include logic for deciding, with or without user input or prompting, whether these features, elements, and / or steps are included or are to be performed in any particular embodiment.

[0084] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of202411124 instructions, which comprises one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the block may occur out of the order noted in the Figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.

Claims

202411124CLAIMSWhat is claimed is:1 . A method performed by an edge device on premise of an industrial system or building, the method comprising: receiving a data stream from within the industrial system or the building, the data stream defining a plurality of data features; determining a computational resource size available to the edge device; based on the computational resource size, selecting a first data feature from the plurality of data features, so as to define a first selected data feature; inputting a first portion of the data stream to an anomaly detection model, the first portion of the data stream corresponding to the first selected data feature; and based on the first portion of the data stream corresponding to the first selected data feature, detecting an anomaly within the industrial system or the building.

2. The method as recited claim 1 , the method further comprising: responsive to detecting the anomaly, triggering an alert or shut down a device associated with anomaly.

3. The method as recited in claim 1 , the method further comprising: determining whether the anomaly detection model improves over time, based on the first selected data feature; when it is determined that the anomaly detection model is not improving, selecting a second data feature, so as to define a second selected data feature; and inputting a second portion of the data stream to the anomaly detection model, the second portion of the data stream corresponding to the selected data feature.

4. The method as recited in claim 3, the method further comprising: based on the second portion of the data stream corresponding to the second selected data feature, detecting the anomaly within the industrial system or the building.

5. The method as recited in claim 1 , the method further comprising:202411124 based on the computation resource size available to the edge device, selecting the anomaly detection model from a plurality of anomaly detection models on the edge device, so as to define a selected anomaly model.

6. The method as recited in claim 5, wherein the industrial system or building defines a plurality of network segments, the method further comprising: based on the selected anomaly model, dropping at least one network segment of the plurality of network segments, so as to define a dropped network segment; and inputting portions of the data stream into the selected anomaly detection model that are not associated with the dropped network segment.

7. An edge device configured to operate on premise of an industrial system or building, the edge device comprising: a memory storing instructions that, when executed by the processor, cause the processor to: receive a data stream from within the industrial system or the building, the data stream defining a plurality of data features; determine a computational resource size available to the edge device; based on the computational resource size, select a first data feature from the plurality of data features, so as to define a first selected data feature; input a first portion of the data stream to an anomaly detection model, the first portion of the data stream corresponding to the first selected data feature; and based on the first portion of the data stream corresponding to the first selected data feature, detect an anomaly within the industrial system or the building.

8. The edge device as recited in claim 7, the memory further storing instructions that, when executed by the processor, cause the processor to: responsive to detecting the anomaly, trigger an alert or shutting down a device associated with anomaly.

9. The edge device as recited in claim 7, the memory further storing instructions that, when executed by the processor, cause the processor to: determine whether the anomaly detection model improves over time, based on the first selected data feature; when it is determined that the anomaly detection model is not improving, select a second data feature, so as to define a second selected data feature; and202411124 input a second portion of the data stream to the anomaly detection model, the second portion of the data stream corresponding to the selected data feature.

10. The edge device as recited in claim 9, the memory further storing instructions that, when executed by the processor, cause the processor to: based on the second portion of the data stream corresponding to the second selected data feature, detect the anomaly within the industrial system or the building.11 . The edge device as recited in claim 7, the memory further storing instructions that, when executed by the processor, cause the processor to: based on the computation resource size available to the edge device, select the anomaly detection model from a plurality of anomaly detection models on the edge device, so as to define a selected anomaly model.

12. The edge device as recited in claim 11 , wherein the industrial system or building defines a plurality of network segments, and the memory further stores instructions that, when executed by the processor, cause the processor to: based on the selected anomaly model, drop at least one network segment of the plurality of network segments, so as to define a dropped network segment; and input portions of the data stream into the selected anomaly detection model that are not associated with the dropped network segment.

13. A non-transitory computer-readable medium encoded with executable instructions that, when executed, cause on or more computer systems to perform a process as in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Industrial control system intrusion detection method and device, computer equipment and storage medium

    CN114124460A

  • Industrial control anomaly detection method, system and device based on correlation analysis and three-dimensional convolution and storage medium

    CN114595448A

  • Conceptual drift-oriented adaptive interpretable industrial control system anomaly detection method

    CN116991137A

  • Telemetry Analysis System for Physical Process Anomaly Detection

    US20170230410A1