IP Library Granted Patent US 12,449,799
Granted Patent B2
US 12,449,799 · App. 18/503,981 · Granted Oct 21, 2025

Anomaly detection for embedded systems

Inventors: Irtsam Ghazi (Pittsburgh, PA); Emily Ruppel (Pittsburgh, PA); Shruti Lall (Pittsburgh, PA)
Assignee: Robert Bosch GmbH
G05B23/0272G05B23/0286G06F8/61G06F11/3013
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,449,799
App. No.
18/503,981
Granted
Oct 21, 2025
Kind
B2
Abstract

Systems and methods for anomaly detection in embedded systems. One example provides an anomaly detection system including a device configured to be connected to a server. The device includes an electronic processor and a memory. The memory stores a first application. The electronic processor is configured to transmit a request for an anomaly detection application. The anomaly detection application includes a set of instructions for detecting anomalies of the device. The electronic processor is configured to receive, from the server, the anomaly detection application, and replace the first application with the anomaly detection application within the memory.

Claims (44)

1. An anomaly detection system comprising:

a computer including an electronic processor and a memory, the memory storing a first application, wherein the first application includes a first set of instructions that facilitate standard operations for the computer, wherein the electronic processor is configured to:

transmit a request to a server requesting an anomaly detection application, wherein the anomaly detection application includes a second set of instructions for detecting anomalies of the device,

receive, from the server, the anomaly detection application,

replace the first application with the anomaly detection application within the memory,

detect, while implementing the anomaly detection application, an operating error, and

transmit, in response to the operating error, an indication of the operating error to the server.

2. The anomaly detection system of claim 1 , wherein the electronic processor is further configured to:

shut down, in response to the operating error, operation of the computer.

3. The anomaly detection system of claim 1 , wherein the electronic processor is further configured to:

control an output mechanism of the computer to provide the indication of the operating error.

4. The anomaly detection system of claim 1 , wherein the electronic processor is configured to transmit the request for the anomaly detection application in response to a trigger event.

5. The anomaly detection system of claim 4 , wherein the trigger event is based on utilization of the computer.

6. The anomaly detection system of claim 4 , wherein the computer further includes a sensor, and wherein the electronic processor is configured to detect the trigger event is based on abnormal data from the sensor.

7. The anomaly detection system of claim 6 , wherein the sensor is a microphone configured to detect sounds associated with a motor, and wherein the electronic processor is configured to detect the trigger event based on the sounds detected by the microphone.

8. The anomaly detection system of claim 1 , wherein the electronic processor is further configured to:

receive, from the server and a predetermined amount of time after receiving the anomaly detection application, the first application, and

replace the anomaly detection application with the first application within the memory.

9. The anomaly detection system of claim 1 , wherein the electronic processor is further configured to:

transmit, after performing an anomaly detection operation using the anomaly detection application, a request for the first application to the server,

receive, from the server, the first application, and

replace the anomaly detection application with the first application within the memory.

10. The anomaly detection system of claim 1 , wherein the first application and the anomaly detection application are bytecode instruction modules, and wherein the electronic processor implements a bytecode instruction format runtime to implement the first application and the anomaly detection application.

11. A method for anomaly detection in embedded systems, the method comprising:

transmitting, via an electronic processor of a computer, a request requesting an anomaly detection application to an orchestrator stored in a server, wherein the anomaly detection application includes a first set of instructions for detecting anomalies of the computer,

receiving, via the electronic processor and from the server, the anomaly detection application,

replacing, via the electronic processor, a first application stored in a memory with the anomaly detection application, wherein the first application includes a second set of instructions that facilitate standard operations for the computer,

performing, via the electronic processor implementing the anomaly detection application, an anomaly detection operation,

detecting, via the electronic processor and while implementing the anomaly detection application, an operating error, and

transmitting, via the electronic processor and in response to the operating error, an indication of the operating error to the server.

12. The method of claim 11 , further comprising:

shutting down, via the electronic processor and in response to the operating error, operation of the computer.

13. The method of claim 11 , further comprising:

controlling, via the electronic processor, an output mechanism of the computer to provide the indication of the operating error.

14. The method of claim 11 , further comprising:

transmitting the request for the anomaly detection application in response to a trigger event.

15. The method of claim 14 , wherein the trigger event is based on utilization of the computer.

16. The method of claim 11 , further comprising:

receiving, via the electronic processor and a predetermined amount of time after receiving the anomaly detection application, the first application from the server, and

replacing the anomaly detection application with the first application within the memory.

17. The method of claim 11 , further comprising:

transmitting, via the electronic processor and after performing the anomaly detection operation using the anomaly detection application, a request for the first application to the server,

receiving, via the electronic processor, the first application from the server, and

replacing the anomaly detection application with the first application within the memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2023
From: GHAZI, IRTSAM; RUPPEL, EMILY; LALL, SHRUTI
To: ROBERT BOSCH GMBH
Reel/Frame 065506/0766 →
Continuity (2)
Provisional Application 63580864 · Sep 6, 2023
Related Publication 20250076867A1 · Mar 6, 2025
References Cited (14)
US 9668073B2 · Das et al. · 2017 [cited by applicant]
US 10410135B2 · Shumpert · 2019 [cited by applicant]
US 10715941B2 · Das · 2020 [cited by applicant]
US 20160062950A1 · Brodersen · 2016 [cited by examiner]
US 20170366935A1 · Ahmadzadeh · 2017 [cited by examiner]
US 20190294485A1 · Kukreja · 2019 [cited by examiner]
US 20200285997A1 · Bhattacharyya · 2020 [cited by examiner]
US 20200366702A1 · Mahaffey · 2020 [cited by examiner]
US 20220066435A1 · Thimmanaik et al. · 2022 [cited by applicant]
US 20220114044A1 · Singh · 2022 [cited by applicant]
US 20220171995A1 · Balasubramanian et al. · 2022 [cited by applicant]
US 20230025238A1 · Rudolph et al. · 2023 [cited by applicant]
US 20230063601A1 · Upadhyay · 2023 [cited by applicant]
Robert Bosch GmbH, “SoundSee—Insight with Audio AI,” <https://www.bosch.com/research/know-how/success-stories/audio-ai/> web page visited Aug. 28, 2023 (10 pages). [cited by applicant]