IoT Mesh Network Anomalous Behavior Corroboration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT networks struggle to effectively corroborate and notify users of anomalous behavior detected by IoT devices, which can indicate potential harm to persons and property from events like natural disasters or social unrest.
Innovation Solution
A computer-implemented method and system that trains IoT devices in a mesh network to independently identify anomalous behavior, receives event data from these devices, corroborates the behavior to determine if it meets a reporting threshold, and generates notifications for anomalous events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple IoT devices independently detect anomalous behavior, then detection coverage and reliability improve, but false positive rates increase due to lack of corroboration
Solution Approach 1:
The system merges detection results from multiple IoT devices by collecting anomaly reports from different devices and evaluating whether they corroborate the same anomalous behavior. This combination approach maintains high detection reliability while reducing false positives through cross-validation of multiple independent detections.
Solution Approach 2:
The system implements feedback mechanisms where detection results from multiple devices are continuously evaluated and compared. The corroboration process provides feedback to filter out inconsistent or isolated anomaly reports, thereby reducing false positives while maintaining reliable detection of genuine anomalies.
2Loss of information
If all detected anomalous behavior is reported, then user awareness of potential threats improves, but notification volume increases causing alert fatigue
Solution Approach 1:
The system applies different quality thresholds to different types of anomalous behavior. Corroboration requirements and reporting thresholds are adjusted based on the severity and nature of the anomaly, ensuring that critical threats are reported while less significant anomalies require stronger corroboration before triggering notifications.
Solution Approach 2:
The system dynamically changes reporting parameters based on the corroboration level of detected anomalies. When multiple devices corroborate the same anomalous behavior, the reporting threshold is met and notifications are generated. This parameter adjustment ensures comprehensive threat information is communicated while avoiding notification overload from uncorroborated false positives.
3Reliability
If corroboration threshold is set high, then false positive notifications are reduced, but response time to genuine threats increases
Solution Approach 1:
The corroboration threshold is made dynamic rather than static. The system adjusts the number and type of corroboration required based on the severity and characteristics of the detected anomaly. Critical threats may trigger notifications with lower corroboration requirements to ensure rapid response, while less critical anomalies require higher thresholds to maintain accuracy.
Solution Approach 2:
The system performs preliminary corroboration checks using available device data before generating notifications. By pre-evaluating anomaly reports from multiple devices and maintaining a buffer of corroborated but unnotified anomalies, the system can quickly issue notifications when thresholds are met without waiting for complete corroboration in real-time, thus reducing response time while maintaining accuracy.
Data Source
AI summary
Described are techniques for corroborating anomalous behavior. The techniques include training devices included in an Internet of Things (IoT) mesh network to independently identify occurrences of anomalous behavior in a proximate physical environment. The techniques further include receiving event data from at least a portion of the devices in the IoT mesh network corresponding to a time window, where the event data reports occurrences of at least one type of anomalous behavior. The techniques further include corroborating the at least one type of anomalous behavior to determine that the occurrences of the at least one type of anomalous behavior indicate an anomalous event that meets a reporting threshold for providing notice of the anomalous event. The techniques further include generating a notification regarding the anomalous event.


