IoT Mesh Network Anomalous Behavior Corroboration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT networks struggle to effectively corroborate and notify users of anomalous behavior detected by IoT devices, which can indicate potential harm to persons and property from events like natural disasters or social unrest.

Innovation Solution

A computer-implemented method and system that trains IoT devices in a mesh network to independently identify anomalous behavior, receives event data from these devices, corroborates the behavior to determine if it meets a reporting threshold, and generates notifications for anomalous events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple IoT devices independently detect anomalous behavior, then detection coverage and reliability improve, but false positive rates increase due to lack of corroboration

Engineering Contradiction:
Improveanomalous behavior detection reliabilityVSAvoidfalse positive information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system merges detection results from multiple IoT devices by collecting anomaly reports from different devices and evaluating whether they corroborate the same anomalous behavior. This combination approach maintains high detection reliability while reducing false positives through cross-validation of multiple independent detections.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback mechanisms where detection results from multiple devices are continuously evaluated and compared. The corroboration process provides feedback to filter out inconsistent or isolated anomaly reports, thereby reducing false positives while maintaining reliable detection of genuine anomalies.

Inventive Principle:
Principle #23Feedback

2Loss of information

If all detected anomalous behavior is reported, then user awareness of potential threats improves, but notification volume increases causing alert fatigue

Engineering Contradiction:
Improvethreat information completenessVSAvoidnotification system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system applies different quality thresholds to different types of anomalous behavior. Corroboration requirements and reporting thresholds are adjusted based on the severity and nature of the anomaly, ensuring that critical threats are reported while less significant anomalies require stronger corroboration before triggering notifications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes reporting parameters based on the corroboration level of detected anomalies. When multiple devices corroborate the same anomalous behavior, the reporting threshold is met and notifications are generated. This parameter adjustment ensures comprehensive threat information is communicated while avoiding notification overload from uncorroborated false positives.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If corroboration threshold is set high, then false positive notifications are reduced, but response time to genuine threats increases

Engineering Contradiction:
Improvenotification accuracyVSAvoidthreat response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The corroboration threshold is made dynamic rather than static. The system adjusts the number and type of corroboration required based on the severity and characteristics of the detected anomaly. Critical threats may trigger notifications with lower corroboration requirements to ensure rapid response, while less critical anomalies require higher thresholds to maintain accuracy.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary corroboration checks using available device data before generating notifications. By pre-evaluating anomaly reports from multiple devices and maintaining a buffer of corroborated but unnotified anomalies, the system can quickly issue notifications when thresholds are met without waiting for complete corroboration in real-time, thus reducing response time while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12266254B2Corroborating device-detected anomalous behavior
Publication Date: 2025.04.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12266254B2 patent drawing
  • US12266254B2 patent drawing
  • US12266254B2 patent drawing

AI summary

Described are techniques for corroborating anomalous behavior. The techniques include training devices included in an Internet of Things (IoT) mesh network to independently identify occurrences of anomalous behavior in a proximate physical environment. The techniques further include receiving event data from at least a portion of the devices in the IoT mesh network corresponding to a time window, where the event data reports occurrences of at least one type of anomalous behavior. The techniques further include corroborating the at least one type of anomalous behavior to determine that the occurrences of the at least one type of anomalous behavior indicate an anomalous event that meets a reporting threshold for providing notice of the anomalous event. The techniques further include generating a notification regarding the anomalous event.