IP Library › Granted Patent US 12,266,254
Granted Patent B2
US 12,266,254 · App. 17/932,494 · Granted Apr 1, 2025

Corroborating device-detected anomalous behavior

Inventors: Kevin W. Brew (Niskayuna, NY); Michael S. Gordon (Chappaqua, NY); Mattias Fitzpatrick (Mount Kisco, NY); Brian Paul Gaucher (Brookfield, NY)
Assignee: International Business Machines Corporation
G08B21/10G16Y20/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,266,254
App. No.
17/932,494
Granted
Apr 1, 2025
Kind
B2
Abstract

Described are techniques for corroborating anomalous behavior. The techniques include training devices included in an Internet of Things (IoT) mesh network to independently identify occurrences of anomalous behavior in a proximate physical environment. The techniques further include receiving event data from at least a portion of the devices in the IoT mesh network corresponding to a time window, where the event data reports occurrences of at least one type of anomalous behavior. The techniques further include corroborating the at least one type of anomalous behavior to determine that the occurrences of the at least one type of anomalous behavior indicate an anomalous event that meets a reporting threshold for providing notice of the anomalous event. The techniques further include generating a notification regarding the anomalous event.

Claims (51)

1. A computer-implemented method comprising:

training a first behavior classifier hosted on a first device included in an Internet of Things (IOT) mesh network to independently identify occurrences of anomalous behavior in a first human environment proximate to the first device, the anomalous behavior resulting from one or more non-computer network events occurring within the first human environment;

training a second behavior classifier hosted on a second device included in the IoT mesh network to independently identify occurrences of anomalous behavior in a second human environment proximate to the second device, the anomalous behavior resulting from one or more non-computer network events occurring within the second human environment;

receiving event data from the first and second devices corresponding to a time window, wherein the event data reports occurrences of at least one type of anomalous behavior in the first and second human environments;

corroborating the at least one type of anomalous behavior to determine that the occurrences of the at least one type of anomalous behavior indicate an anomalous event that meets a reporting threshold for providing notice of the anomalous event; and

generating a notification regarding the anomalous event.

2. The computer-implemented method of claim 1 , wherein corroborating the at least one type of anomalous behavior further comprises:

correlating a first type of anomalous behavior and a second type of anomalous behavior reported in the event data to the anomalous event.

3. The computer-implemented method of claim 1 , wherein corroborating the at least one type of anomalous behavior further comprises:

determining that an intensity and frequency of the at least one type of anomalous behavior meets the reporting threshold for providing the notification of the anomalous event.

4. The computer-implemented method of claim 1 , further comprising:

analyzing external event data to determine whether an external event provoked the occurrences of the at least one type of anomalous behavior; and

determining an absence of an external event that could have provoked the at least one type of anomalous behavior.

5. The computer-implemented method of claim 1 , further comprising:

sending the notification to one or more user-devices associated with users of the IoT mesh network.

6. The computer-implemented method of claim 1 , further comprising sending the notification to one or more user-devices subscribed to receive notifications regarding the anomalous event, wherein the one or more user-devices are not associated with users of the IoT mesh network.

7. The computer-implemented method of claim 1 , wherein training the first and second devices further comprises training the first and second devices using reinforcement learning.

8. A system comprising:

one or more computer readable storage media storing program instructions and one or more processors which, in response to executing the program instructions, are configured to:

receive event data from at least a portion of devices in an Internet of Things (IOT) mesh network corresponding to a time window,

wherein the devices include a behavior classifier, and the devices are independently trained to identify occurrences of anomalous behavior in a human environment where the devices are situated, where the anomalous behavior results from one or more non-computer network events occurring within the human environment where the devices are situated, and

wherein the event data reports occurrences of at least one type of anomalous behavior identified by the devices;

corroborate the at least one type of anomalous behavior to determine that the occurrences of the at least one type of anomalous behavior indicate an anomalous event;

determine that a number of the devices in the IoT mesh network reporting the at least one type of anomalous behavior during the time window meets a reporting threshold for providing notice of the anomalous event; and

generate a notification regarding the anomalous event.

9. The system of claim 8 , wherein the program instructions configured to cause the one or more processors to corroborate the at least one type of anomalous behavior are further configured to cause the one or more processors to:

correlate a first type of anomalous behavior and a second type of anomalous behavior reported in the event data to the anomalous event.

10. The system of claim 8 , wherein the program instructions configured to cause the one or more processors to determine that the number of the devices reporting the at least one type of anomalous behavior during the time window meets the reporting threshold are further configured to cause the one or more processors to:

determine that an intensity of the at least one type of anomalous behavior meets the reporting threshold for providing the notification of the anomalous event.

11. The system of claim 8 , wherein the program instructions are further configured to cause the one or more processors to:

analyze external event data to determine whether an external event provoked the occurrences of the at least one type of anomalous behavior; and

determine an absence of an external event that could have provoked the at least one type of anomalous behavior.

12. The system of claim 8 , wherein the program instructions are further configured to cause the one or more processors to send the notification to one or more user-devices associated with users of the IoT mesh network.

13. The system of claim 8 , wherein the program instructions are further configured to cause the one or more processors to send the notification to one or more user-devices subscribed to receive notifications regarding the anomalous event, wherein the one or more user-devices are not associated with users of the IoT mesh network.

14. The system of claim 8 , wherein the devices are trained to identify the at least one type of anomalous behavior using reinforcement learning, and the training of the devices is performed within the human environment where the devices are situated.

15. A computer program product comprising:

one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions configured to cause one or more processors to:

receive event data from at least a portion of devices in an Internet of Things (IOT) mesh network corresponding to a time window,

wherein the devices include a behavior classifier, and the devices are independently trained to identify occurrences of anomalous behavior in a human environment where the devices are situated, where the anomalous behavior results from one or more non-computer network events occurring within the human environment where the devices are situated, and

wherein the event data reports occurrences of at least one type of anomalous behavior identified by the devices;

corroborate the at least one type of anomalous behavior to determine that the occurrences of the at least one type of anomalous behavior indicate an anomalous event that meets a reporting threshold for providing notice of the anomalous event; and

generate a notification regarding the anomalous event.

16. The computer program product of claim 15 , wherein the program instructions configured to cause the one or more processors to corroborate the at least one type of anomalous behavior are further configured to cause the one or more processors to:

correlate a first type of anomalous behavior and a second type of anomalous behavior reported in the event data to the anomalous event.

17. The computer program product of claim 15 , wherein the program instructions configured to cause the one or more processors to corroborate the at least one type of anomalous behavior are further configured to cause the one or more processors to:

determine that an intensity and frequency of the at least one type of anomalous behavior meets the reporting threshold for providing the notification of the anomalous event.

18. The computer program product of claim 15 , wherein the program instructions are further configured to cause the one or more processors to:

analyze external event data to determine whether an external event provoked the occurrences of the at least one type of anomalous behavior; and

determine an absence of an external event that could have provoked the at least one type of anomalous behavior.

19. The computer program product of claim 15 , wherein the program instructions are further configured to cause the one or more processors to send the notification to one or more user-devices subscribed to receive notifications regarding the anomalous event.

20. The computer program product of claim 15 , wherein the devices are trained to identify the at least one type of anomalous behavior using reinforcement learning, and the training of the devices is performed within the human environment where the devices are situated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2022
From: BREW, KEVIN W.; GORDON, MICHAEL S.; FITZPATRICK, MATTIAS; GAUCHER, BRIAN PAUL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 061109/0082 →
Continuity (1)
Related Publication 20240096191A1 · Mar 21, 2024
References Cited (54)
US 8350694B1 · Trundle · 2013 [cited by examiner]
US 9196148B1 · Hutz · 2015 [cited by examiner]
US 10104098B2 · Baxley · 2018 [cited by examiner]
US 10182066B2 · Flacher · 2019 [cited by applicant]
US 10258295B2 · Fountaine · 2019 [cited by examiner]
US 11032302B2 · Garcia · 2021 [cited by applicant]
US 11102236B2 · Shurtleff · 2021 [cited by examiner]
US 11200799B2 · Vrabete · 2021 [cited by examiner]
US 11258874B2 · Walsh · 2022 [cited by applicant]
US 11374819B2 · Lou · 2022 [cited by examiner]
US 11556740B2 · DeLuca · 2023 [cited by examiner]
US 11683328B2 · Ektare · 2023 [cited by examiner]
US 11694149B2 · Bartlett · 2023 [cited by examiner]
US 11855865B2 · Sharma · 2023 [cited by examiner]
US 20030080867A1 · Rusinol Simon · 2003 [cited by examiner]
US 20050099271A1 · Sasaki · 2005 [cited by examiner]
US 20090066488A1 · Qiahe · 2009 [cited by examiner]
US 20150333992A1 · Vasseur · 2015 [cited by examiner]
US 20180325470A1 · Fountaine · 2018 [cited by examiner]
US 20190182278A1 · Das · 2019 [cited by examiner]
US 20200082340A1 · Wing · 2020 [cited by examiner]
US 20200111350A1 · Julian · 2020 [cited by examiner]
US 20200162503A1 · Shurtleff · 2020 [cited by examiner]
US 20200211364A1 · Kasiviswanathan · 2020 [cited by examiner]
US 20200242471A1 · Busch · 2020 [cited by examiner]
US 20200320845A1 · Livny · 2020 [cited by examiner]
US 20200358810A1 · Fellows · 2020 [cited by examiner]
US 20210077036A1 · Fountaine · 2021 [cited by examiner]
US 20210174140A1 · DeLuca · 2021 [cited by examiner]
US 20210209144A1 · Trim · 2021 [cited by examiner]
US 20210243084A1 · Lou · 2021 [cited by examiner]
US 20220103591A1 · Maturana · 2022 [cited by examiner]
US 20220191113A1 · Oh · 2022 [cited by examiner]
US 20220303291A1 · Baldini Das Neves · 2022 [cited by examiner]
US 20220407769A1 · Thornton · 2022 [cited by examiner]
US 20230055677A1 · Dhelaria · 2023 [cited by examiner]
US 20230290121A1 · Park · 2023 [cited by examiner]
US 20230326325A1 · Bedford · 2023 [cited by examiner]
US 20230333958A1 · Zhang · 2023 [cited by examiner]
US 20230419083A1 · Niu · 2023 [cited by examiner]
WO 2019178149A1 · 2019 [cited by applicant]
“Furbo”, Downloaded from the Internet on Jun. 21, 2022, 9 pgs., <https://shopus.furbo.com/?gclid=Cj0KCQiAjJOQBhCkARIsAEKMtO34cd2On6t-MDTRNK1GiN3a1y0v3XPEmRfKz5loOXLc81GjHFVjPxMaAso2EALw_wcB>. [cited by applicant]
Chen, et al., “Intrusion Detection in Wireless Mesh Networks”, Security in Wireless Mesh Networks, 2009, 32 pgs. [cited by applicant]
Choi, et al., “Human Behavioral Pattern Analysis-Based Anomaly Detection System in Residential Space”, The Journal of Supercomputing, Feb. 4, 2021, 18 pgs., <https://doi.org/10.1007/s11227-021-03641-7>. [cited by applicant]
Disclosed Anonymously, “A Method to Filter Low-Value Data in IoT Systems Using AI”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000262771D, Jun. 29, 2020, 4 pgs. [cited by applicant]
Disclosed Anonymously, “Anomalies and Threats Detect in IoT (Internet of Things) System Based on User Behavior”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000263688D, Sep. 27, 2020, 3 pgs. [cited by applicant]
Gibeault, S., “Can Dogs Predict Earthquakes?”, American Kennel Club, Feb. 21, 2018, 6 pgs., <https://www.akc.org/expert-advice/lifestyle/can-dogs-predict-earthquakes/>. [cited by applicant]
Hasan, et al., “Anomaly detection using streaming analytics & AI”, Data Analytics, Blog, Google Cloud, Aug. 10, 2020, 9 pgs., <https://cloud.google.com/blog/products/data-analytics/anomaly-detection-using-streaming-anal… [cited by applicant]
Khan, M., “Anomaly Detection with Isolation Forest and Kernel Density Estimation”, Machine Learning Algorithms, Jan. 1, 2020, 21 pgs., <https://machinelearningmastery.com/anomaly-detection-with-isolation-forest-and-kern… [cited by applicant]
Kukoba, A., “Connecting IoT Devices with Mesh Networking: Pros, Cons, and Existing Solutions”, Dev Blog, Apriorit, Apr. 23, 2020, 25 pgs., <https://www.apriorit.com/dev-blog/673-mobile-mesh-networking-for-iot>. [cited by applicant]
Latif, et al., “Intrusion Detection Framework for the Internet of Things using a Dense Random Neural Network”, IEEE Transactions on Industrial Informatics, Heriot Watt University, Digital Object Identifier (DOI): 10.110… [cited by applicant]
Lawal, et al., “Security Analysis of Network Anomalies Mitigation Schemes in IoT Networks”, IEEE Access, Feb. 2020, 20 pgs., Digital Object Identifier 10.1109/ACCESS.2020.2976624. [cited by applicant]
Robinson, M., “2011 Dog reacts to Earthquake in the Washington DC Metro Area”, YouTube, Aug. 23, 2011, 3pgs., <https://www.youtube.com/watch?v=hVoLUuUy-nY>. [cited by applicant]
Tan, et al., “Privacy Preserving Anomaly Detection for Internet of Things Data”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000252511D, Jan. 19, 2018, Copyright 2018 Cisco Systems, Inc., 6 pgs. [cited by applicant]