IP Library Granted Patent US 12,487,879
Granted Patent B2
US 12,487,879 · App. 18/152,546 · Granted Dec 2, 2025

Anomaly detection on dynamic sensor data

Inventors: LuAn Tang (Pennington, NJ); Haifeng Chen (West Windsor, NJ); Yuncong Chen (Plainsboro, NJ); Wei Cheng (Princeton Junction, NJ); Zhengzhang Chen (Princeton Junction, NJ); Yuji Kobayashi (Tokyo, JP)
Assignee: NEC Corporation
G06F11/0793G06F11/0721G06N3/0455
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,487,879
App. No.
18/152,546
Granted
Dec 2, 2025
Kind
B2
Abstract

Methods and systems for anomaly detection include determining whether a system is in a stable state or a dynamic state based on input data from one or more sensors in the system, using reconstruction errors from a respective stable model and dynamic model. It is determined that the input data represents anomalous operation of the system, responsive to a determination that the system is in a stable state, using the reconstruction errors. A corrective operation is performed on the system responsive to a determination that the input data represents anomalous operation of the system.

Claims (24)

1 . A method for anomaly detection, comprising:

determining whether a system is in a stable state or a dynamic state based on input data from one or more sensors in the system, using reconstruction errors from a respective stable autoencoder model and dynamic autoencoder model;

determining that the input data represents anomalous operation of the system with a hardware processor, responsive to a determination that the system is in a stable state; and

operating the system by performing a corrective action responsive to a determination that the input data represents anomalous operation of the system, wherein the corrective action is selected from the group consisting of halting and/or restarting an application, halting and/or rebooting a hardware component, and changing a network interface's status or settings.

2 . The method of claim 1 , wherein the stable model and the dynamic model are both trained on data that represents normal operation of the system.

3 . The method of claim 1 , wherein determining whether the system is in a stable state or a dynamic state further includes calculating a mode score based on the reconstruction scores from the stable model and the dynamic model.

4 . The method of claim 3 , further comprising determining a stable anomaly score and a dynamic anomaly score using the respective reconstructive errors from the stable model and the dynamic model.

5 . The method of claim 4 , wherein determining that the input data represents anomalous operation of the system includes determining a mode score as a ratio of the stable anomaly score to the dynamic anomaly score.

6 . The method of claim 1 , wherein determining that the input data represents anomalous operation of the system includes calculating an anomaly score from the reconstruction score of the stable model and comparing the anomaly score to a predetermined threshold value.

7 . The method of claim 1 , wherein determining the mode score includes comparing the reconstruction errors from the respective stable model and dynamic model to respective training reconstruction errors for the stable model and the dynamic model.

8 . The method of claim 1 , wherein the trained stable model and the trained dynamic model are each implemented as respective long-short term (LSTM) autoencoder neural network models.

9 . A system for anomaly detection, comprising:

a hardware processor; and

a memory that stores a computer program which, when executed by the hardware processor, causes the hardware processor to:

determine whether a system is in a stable state or a dynamic state based on input data from one or more sensors in the system, using reconstruction errors from a respective stable autoencoder model and dynamic autoencoder model;

determine that the input data represents anomalous operation of the system, responsive to a determination that the system is in a stable state; and

operate the system by performing a corrective action responsive to a determination that the input data represents anomalous operation of the system, wherein the corrective action is selected from the group consisting of halting and/or restarting an application, halting and/or rebooting a hardware component, and changing a network interface's status or settings.

10 . The system of claim 9 , wherein the stable model and the dynamic model are both trained on data that represents normal operation of the system.

11 . The system of claim 9 , wherein the computer program further causes the hardware processor to calculate a mode score based on the reconstruction scores from the stable model and the dynamic model.

12 . The system of claim 11 , wherein the computer program further causes the hardware processor to determine a stable anomaly score and a dynamic anomaly score using the respective reconstructive errors from the stable model and the dynamic model.

13 . The system of claim 12 , wherein the computer program further causes the hardware processor to determine a mode score as a ratio of the stable anomaly score to the dynamic anomaly score.

14 . The system of claim 12 , wherein the computer program further causes the hardware processor to calculate an anomaly score from the reconstruction score of the stable model and to compare the anomaly score to a predetermined threshold value.

15 . The system of claim 9 , wherein the computer program further causes the hardware processor to compare the reconstruction errors from the respective stable model and dynamic model to respective training reconstruction errors for the stable model and the dynamic model.

16 . The system of claim 9 , wherein the trained stable model and the trained dynamic model are each implemented as respective long-short term (LSTM) autoencoder neural network models.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2025
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 072592/0768 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2023
From: TANG, LUAN; CHEN, HAIFENG; CHEN, YUNCONG; CHENG, WEI; CHEN, ZHENGZHANG
To: NEC LABORATORIES AMERICA ,INC.
Reel/Frame 062331/0181 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2023
From: KOBAYASHI, YUJI
To: NEC CORPORATION
Reel/Frame 062331/0220 →
Continuity (3)
Provisional Application 63302250 · Jan 24, 2022
Provisional Application 63302249 · Jan 24, 2022
Related Publication 20230236927A1 · Jul 27, 2023
References Cited (13)
US 20060229743A1 · Boe · 2006 [cited by examiner]
US 20100084287A1 · Teramoto · 2010 [cited by examiner]
US 20190095266A1 · Chen · 2019 [cited by examiner]
US 20200364579A1 · Misu · 2020 [cited by examiner]
US 20210012190A1 · Murali · 2021 [cited by examiner]
US 20210098078A1 · Lozac'hmeur · 2021 [cited by examiner]
US 20210120031A1 · Dokucu · 2021 [cited by examiner]
US 20210164334A1 · Chen · 2021 [cited by examiner]
US 20230315048A1 · Kumar · 2023 [cited by examiner]
WO WO2017216647A1 · 2017 [cited by examiner]
WO WO2021171303A1 · 2021 [cited by examiner]
Cheng et al., “Meta multi-task learning for sequence modeling”, Proceedings of the AAAI Conference on Artificial Intelligence. vol. 32, No. 1. Apr. 27, 2018, pp. 5070-5077. [cited by applicant]
Kirsch et al., “Modular networks: Learning to decompose neural computation”, 32nd Conference on Neural Information Processing System. vol. 31. Dec. 2018, pp. 2408-2418. [cited by applicant]