Cyber-Physical System Anomaly Detection via Forecasting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for monitoring cyber-physical systems lack the capability for early anomaly detection, often resulting in delayed response times due to reliance on manual intervention and local self-diagnostic systems that are prone to false alarms and high costs.

Innovation Solution

A graphic user interface (GUI) system that generates data for monitoring cyber-physical systems by forecasting feature values using a model, determining total forecast errors, and identifying anomalies, allowing for automated control and real-time anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If traditional emergency shutdown (ESD) systems are used for monitoring cyber-physical systems, then the system provides basic anomaly detection capability, but the response time is delayed and manual intervention is required

Engineering Contradiction:
Improveresponse timeVSAvoidmanual intervention requirement
Core Design Contradiction:
Loss of timeVSExtent of automation

Solution Approach 1:

The system performs preliminary actions by continuously forecasting future values of CPS features using trained machine learning models. This allows the system to detect anomalies before they manifest as actual problems, enabling early warning and preventive action rather than reactive response. The forecasting mechanism predicts parameter values ahead of time, so deviations can be identified in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service through automated anomaly detection and alert generation. The machine learning models automatically monitor CPS features, compare predicted values with actual measurements, and generate alerts without requiring manual intervention. This automation eliminates the need for human operators to continuously monitor system parameters, reducing response time and enabling 24/7 monitoring.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If local self-diagnostic systems are installed on individual equipment, then the system allows specific monitoring of particular subassemblies, but the systems are local and detached from monitoring of processes in their full totality

Engineering Contradiction:
Improvespecific monitoring capabilityVSAvoidsystem integration
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system merges multiple local self-diagnostic systems into a unified centralized monitoring platform. Instead of having separate isolated monitoring systems for different equipment, the invention integrates them all under one system that uses a single machine learning model to forecast and detect anomalies across the entire cyber-physical system. This unified approach maintains the specific monitoring capability of individual components while providing holistic system-wide visibility and correlation.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If additional control systems external to equipment are installed for nondestructive control, then the system provides redundancy of diagnostic instrumentation and unlimited capabilities for processing diagnostic information, but the cost and complexity of deploying them in actual production is high

Engineering Contradiction:
Improvediagnostic redundancyVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system achieves universality by using a single multi-functional machine learning-based monitoring platform that can detect anomalies across diverse equipment and processes. Instead of deploying separate specialized diagnostic systems for different types of equipment, the invention uses one universal system that adapts to monitor various CPS features through trained models. This eliminates the need for multiple specialized systems while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses virtual copying of physical monitoring infrastructure through software-based machine learning models. Rather than installing redundant physical sensors and diagnostic equipment, the invention creates virtual copies of monitoring capabilities using trained models that simulate and predict system behavior. This software-based approach provides the benefits of redundant diagnostic capability without the physical complexity and cost of duplicating hardware infrastructure.

Inventive Principle:
Principle #26Copying

4Ease of operation

If traditional monitoring systems wait for sensor readings to exceed specified technological ranges before warning users, then the system provides simple anomaly detection, but the anomaly could be corrected ahead of time if detected earlier

Engineering Contradiction:
Improvedetection simplicityVSAvoidanomaly detection time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary anomaly detection by forecasting future parameter values and comparing them with expected ranges before actual deviations occur. Instead of waiting for sensor readings to exceed thresholds, the machine learning models predict what values should be and alert operators when actual or predicted values deviate from expected behavior. This preliminary detection enables corrective action before anomalies develop into problems.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11175976B2System and method of generating data for monitoring of a cyber-physical system for early determination of anomalies
Publication Date: 2021.11.16 AO KASPERSKY LAB
  • US11175976B2 patent drawing
  • US11175976B2 patent drawing
  • US11175976B2 patent drawing

AI summary

The present disclosure provides systems and methods of early determination of anomalies using a graphical user interface. In one aspect such a method comprises: receiving information about one or more features of a cyber-physical system, receiving information about a period of time for monitoring the one or more features, generating a forecast of values of the one or more features of the cyber-physical system over the period of time based on a forecasting model for graphing in a graphical user interface, determining a total error of the forecast for all of the one or more features and determining an error for each of the one or more features over the period of time, determining that the error for one feature of the one or more features is greater than a predetermined threshold and identifying the one feature as a source of an anomaly in the cyber-physical system.