IP Library Granted Patent US 12705530
Granted Patent B2
US 12705530 · App. 17/382,593 · Granted Aug 11, 2026

Off-duty-cycle-robust machine learning for anomaly detection in assets with random down times

Inventors: William A. Wimsatt (Kennebunk, ME); Matthew T. Gerdes (Oakland, CA); Kenny C. Gross (Escondido, CA); Guang C. Wang (San Diego, CA)
Assignee: Oracle International Corporation
G06N20/00G06N5/04G06F2218/06G06F2218/10G06F2218/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705530
App. No.
17/382,593
Granted
Aug 11, 2026
Kind
B2
Abstract

Systems, methods, and other embodiments associated with off-duty-cycle-robust machine learning for anomaly detection in assets with random downtimes are described. In one embodiment, a method includes inferring ranges of asset downtime from spikes in a numerical derivative of a time series signal for an asset; extracting an asset downtime signal from the time series signal based on the inferred ranges of asset downtime; determining that the asset downtime signal carries telemetry based on the variance of the asset downtime signal; training a first machine learning model for the asset downtime signal; detecting a first spike in the numerical derivative of the time signal that indicates a transition to asset downtime; and in response to detection of the first spike, monitoring the time series signal for anomalous activity with the trained first machine learning model.

Claims (82)

1 . A computer-implemented method comprising:

receiving a transmission of an electronic time series signal of readings by one or more sensors configured to sense one or more physical phenomena occurring in or around an asset;

inferring ranges of asset downtime from the time series signal for the asset;

extracting an asset downtime signal from the time series signal based on the inferred ranges of asset downtime;

determining that the asset downtime signal carries telemetry based on noise in the asset downtime signal;

training a first machine learning model for the asset downtime signal using segments of the extracted asset downtime signal that were determined to carry telemetry, wherein the trained first machine learning model is configured to detect anomalous activity during asset downtime and configured to automatically replace, during periods of asset downtime surveillance of the time series signal performed by a second machine learning model;

detecting, in real time, an indication in the time series signal of a transition to asset downtime; and

in response to detecting the indication, automatically switching from surveillance of the time series signal using the second machine learning model to surveillance of the time series signal for anomalous activity using the trained first machine learning model.

2 . The computer-implemented method of claim 1 , further comprising:

inferring ranges of asset uptime from the time series signal for the asset;

extracting an asset uptime signal from the time series signal based on the inferred ranges of asset uptime;

training the second machine learning model for the asset uptime signal;

detecting, in the time series signal, a second indication of a transition to asset uptime; and

in response to detection of the second indication, automatically switching back to monitoring the time series signal for anomalous activity with the trained second machine learning model.

3 . The computer-implemented method of claim 1 , further comprising:

in response to determining that the asset downtime signal carries telemetry, determining that the asset downtime signal is stationary stochastic background activity;

analyzing the asset downtime signal to detect anomalies using a sequential probability ratio test; and

in response to detection of anomalous dynamic background activity, monitoring the time series signal with the trained first machine learning model, wherein the trained first machine learning model is trained with normal dynamic background activity.

4 . The computer-implemented method of claim 1 , further comprising:

in response to determining that the asset downtime signal carries telemetry, determining that the asset downtime signal is dynamic background activity; and

monitoring the time series signal with the trained first machine learning model, wherein the trained first machine learning model is trained with normal dynamic background activity.

5 . The computer-implemented method of claim 1 , further comprising:

in response to determining that the asset downtime signal carries telemetry, determining that the asset downtime signal is dynamic background activity that transitions to stationary stochastic background activity;

monitoring the time series signal with the trained first machine learning model until the time series signal transitions from dynamic background activity to stationary stochastic background activity, wherein the trained first machine learning model is trained with normal dynamic background activity;

in response to the transition to the stationary stochastic background activity, monitoring the time series signal using a sequential probability ratio test to detect anomalies; and

in response to detection of an anomalous dynamic background activity in the stationary stochastic background activity, resume monitoring the time series signal with the trained first machine learning model.

6 . The computer-implemented method of claim 1 , wherein onset of asset downtime is inferred based on negative spikes and initiation of asset uptime is inferred based on positive spikes.

7 . The computer-implemented method of claim 1 , wherein onset of asset downtime is inferred based on positive spikes and initiation of asset uptime is inferred based on negative spikes.

8 . The computer-implemented method of claim 1 , wherein the first machine learning model is a Multivariate State Estimation Technique model.

9 . A non-transitory computer-readable medium that includes stored thereon computer-executable instructions that when executed by at least a processor of a computer cause the computer to:

receive a transmission of an electronic time series signal of readings by one or more sensors configured to sense one or more physical phenomena occurring in or around an asset;

infer ranges of asset downtime from the time series signal for the asset;

extract an asset downtime signal from the time series signal based on the inferred ranges of asset downtime;

determine that the asset downtime signal carries telemetry based on a variance of the asset downtime signal;

train a first machine learning model for the asset downtime signal using segments of the extracted asset downtime signal that were determined to carry telemetry, wherein the trained first machine learning model is configured to detect anomalous activity during asset downtime and configured to automatically replace surveillance of the time series signal performed by a second machine learning model during periods of asset downtime;

detect an indication in the time series signal of a transition to asset downtime; and

in response to the indication being detected, automatically switch from surveillance of the time series signal using the second machine learning model to surveillance of the time series signal for anomalous activity using the trained first machine learning model.

10 . The non-transitory computer-readable medium of claim 9 , wherein the computer-executable instructions when executed further cause the computer to:

infer ranges of asset uptime from the time series signal for the asset;

extract an asset uptime signal from the time series signal based on the inferred ranges of asset uptime;

train the second machine learning model for the asset uptime signal;

detect, in the time series signal, a second indication of a transition to asset uptime; and

in response to detection of the second indication, automatically switch back to monitoring the time series signal for anomalous activity with the trained second machine learning model.

11 . The non-transitory computer-readable medium of claim 9 , wherein the computer-executable instructions when executed further cause the computer to:

in response to determining that the asset downtime signal carries telemetry, determine that the asset downtime signal is stationary stochastic background activity;

analyze the asset downtime signal to detect anomalies using a sequential probability ratio test; and

in response to detection of anomalous dynamic background activity, monitor the time series signal with the trained first machine learning model, wherein the trained first machine learning model is trained with normal dynamic background activity.

12 . The non-transitory computer-readable medium of claim 9 , wherein the computer-executable instructions when executed further cause the computer to:

in response to determining that the asset downtime signal carries telemetry, determine that the asset downtime signal is dynamic background activity; and

monitor the time series signal with the trained first machine learning model, wherein the trained first machine learning model is trained with the dynamic background activity.

13 . The non-transitory computer-readable medium of claim 9 , wherein the computer-executable instructions when executed further cause the computer to:

in response to determining that the asset downtime signal carries telemetry, determine that the asset downtime signal is dynamic background activity that transitions to stationary stochastic background activity;

monitor the time series signal with the trained first machine learning model until the time series signal transitions from dynamic background activity to stationary stochastic background activity, wherein the trained first machine learning model is trained with normal dynamic background activity;

in response to the transition to the stationary stochastic background activity, monitor the time series signal using a sequential probability ratio test to detect anomalies; and

in response to detection of an anomalous dynamic background activity in the stationary stochastic background activity, resume monitoring the time series signal with the trained first machine learning model.

14 . The non-transitory computer-readable medium of claim 9 , wherein onset of asset downtime is inferred based on spikes of a first direction and initiation of asset operational time is inferred based on spikes of a second direction opposite the first direction.

15 . The non-transitory computer-readable medium of claim 9 , wherein the first machine learning model is a Multivariate State Estimation Technique model.

16 . A computing system comprising:

a processor;

a memory operably connected to the processor;

one or more sensors operably connected to the processor and memory and configured to sense one or more physical phenomena occurring in or around an asset;

a non-transitory computer-readable medium operably connected to the processor and memory and storing computer-executable instructions that when executed by at least the processor of the computing system cause the computing system to:

receive a transmission of an electronic time series signal of readings by the one or more sensors;

infer ranges of asset downtime from the time series signal for the asset;

extract an asset downtime signal from the time series signal based on the inferred ranges of asset downtime;

determine that the asset downtime signal carries telemetry based on a variance of the asset downtime signal;

train a first machine learning model for the asset downtime signal using segments of the extracted asset downtime signal that were determined to carry telemetry, wherein the trained first machine learning model is configured to detect anomalous activity during asset downtime and configured to automatically replace, during periods of asset downtime surveillance of the time series signal performed by a second machine learning model;

detect an indication in the time series signal of a transition to asset downtime; and

in response to the indication being detected, automatically switch from surveillance of the time series signal using the second machine learning model to surveillance of the time series signal for anomalous activity using the trained first machine learning model.

17 . The computing system of claim 16 , wherein the instructions further cause the computing system to:

infer ranges of asset uptime from the time series signal for the asset;

extract an asset uptime signal from the time series signal based on the inferred ranges of asset uptime;

train the second machine learning model for the asset uptime signal;

detect, in the time series signal, a second indication of a transition to asset uptime; and

in response to detection of the second indication, automatically switch back to monitoring the time series signal for anomalous activity with the trained second machine learning model.

18 . The computing system of claim 16 , wherein the instructions further cause the computing system to:

in response to determining that the asset downtime signal carries telemetry, determine that the asset downtime signal is dynamic background activity that transitions to stationary stochastic background activity;

monitor the time series signal with the trained first machine learning model until the time series signal transitions from dynamic background activity to stationary stochastic background activity, wherein the trained first machine learning model is trained with normal dynamic background activity;

in response to the transition to the stationary stochastic background activity, monitor the time series signal using a sequential probability ratio test to detect anomalies; and

in response to detection of an anomalous dynamic background activity in the stationary stochastic background activity, resume monitoring the time series signal with the trained first machine learning model.

19 . The computing system of claim 16 , wherein the instructions further cause the computing system to, in response to detecting anomalous activity in the asset downtime signal, automatically adjust operation of the asset.

20 . The computing system of claim 16 , wherein the instructions further cause the computing system to automatically select the time series signal for the asset from among other time series signals for the asset.