IP Library Patent Application 18868830
Patent Application
App. No. 18/868,830

DISTRIBUTED ANOMALY DETECTION AND LOCALIZATION FOR CYBER-PHYSICAL SYSTEMS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/868,830
Abstract

A system to protect an industrial asset includes a plurality of monitoring nodes each generating a data stream of current monitoring node values in time-domain, and a virtual agent associated with each of the plurality of monitoring nodes. the virtual agent being configured to detect anomalous performance of the corresponding monitoring node and configured to communicate with one or more other virtual agents via a network.

Claims (28)

1 . A system to protect an industrial asset comprising:

a plurality of monitoring nodes each generating a data stream of current monitoring node values in time-domain; and

a virtual agent associated with each of the plurality of monitoring nodes, the virtual agent being configured to detect anomalous performance of the corresponding monitoring node and configured to communicate with one or more other virtual agents via a network.

2 . The system of claim 1 , wherein the virtual agent is configured to detect and/or localize anomalous behavior via a machine learning model.

3 . The system of claim 2 , wherein the virtual agent is configured to continuously learn and update the machine learning model using a federated learning algorithm.

4 . The system of claim 1 , wherein the virtual agent is implemented at the physical location of a corresponding monitoring node.

5 . The system of claim 4 , wherein the virtual agent is configured to implement a machine learning model locally, without transferring timeseries data associated with a corresponding monitoring node, to detect anomalous performance of the corresponding monitoring node.

6 . The system of claim 5 , wherein the virtual agent is further configured to determine, upon detection of an anomaly in performance of the corresponding monitoring node, anomaly signatures relating to the anomaly in performance, and securely transmit the anomaly signatures to a remote monitoring center and/or one or more virtual agents associated with other of the plurality of monitoring nodes.

7 . The system of claim 1 , wherein the virtual agent is configured to detect anomalous performance of a corresponding monitoring node based on an anomaly detection model, the anomaly detection model including at least one sub-model based on historical operation of the plurality of monitoring nodes.

8 . The system of claim 7 , wherein the anomaly detection model is configured to predict a fault node among the plurality of monitoring nodes using a one-class classifier model trained on a normal operation data obtained during normal operation of the system.

9 . The system of claim 8 , wherein the anomaly detection model is further configured to compute a confidence level of malfunction detected in the predicted fault node using the one-class classifier.

10 . The system of claim 8 , wherein the anomaly detection model is further configured to compute reconstruction residuals for an input dataset obtained from the plurality of nodes such that the residual is low if the input dataset resembles the normal operation data, and high if the input dataset does not resemble the historical field data or simulation data.

11 . The system of claim 10 , wherein the anomaly detection model is further configured to compare decision thresholds to the reconstruction residuals to determine if a datapoint in the input dataset is normal or abnormal.

12 . The system of claim 8 , wherein the anomaly detection model is further configured to designate boundary conditions or hardened sensors to compute location of the input dataset with respect to a training dataset used to train the one-class classifier, for computing the confidence level of malfunction detection using the one-class classifier.

13 . The system of claim 7 , wherein the anomaly detection model is configured to generate a decision boundary based on normal and anomalous values of datapoints obtained from the plurality monitoring nodes.

14 . The system of claim 13 , wherein the normal and anomalous values are obtained by running a design of experiments (DoE) method.

15 . The system of claim 13 , wherein the anomaly detection model is further configured to automatically calculate a decision boundary and output, by processing current feature vectors relative to anomalous feature vectors.

16 . The system of claim 1 , wherein the virtual agent is configured to transmit a threat alert signal upon detection of an anomaly in the performance of a corresponding monitoring node.

17 . The system of claim 1 , wherein the virtual agent is implemented at an access point via which the corresponding monitoring node is connected to the network.

18 . The system of claim 1 , wherein data generated by the virtual agents is communicated at a remote monitoring center implementing a program to monitor, detect, localize, neutralize and/or isolate an attack on one or more of the plurality of the monitoring nodes and/or the industrial asset.

19 . The system of any of the preceding claims , wherein the network is based on a 3GPP standard.

20 . The system of any of the preceding claims , wherein the industrial asset is associated with at least one of: (i) a turbine, (ii) a gas turbine, (iii) a wind turbine, (iv) an engine, (v) a jet engine, (vi) a locomotive engine, (vii) a refinery, (viii) a power grid, (ix) an autonomous vehicle, (x) a telecommunication network, and (xi) an internet of things (IoT).

21 . The system of any of the preceding claims , wherein the virtual agent is configured to implement an anomaly detection model trained using a set of simulated attacks on the system.

22 . The system of claim 21 , wherein a simulated attack on the system comprises, for each of the plurality of monitoring nodes:

creating a series of synthetic attack monitoring node values over time that represent a simulated attacked operation of the system,

generating a set of synthetic attack monitoring feature vectors may be generated based on processing the synthetic attack monitoring node values using the anomaly detection model, and

storing a set of synthetic attack monitoring node feature vectors.

23 . The system of claim 1 , wherein the industrial asset is a network node, and the network is a 5G network.

Assignments (5)
QUITCLAIM ASSIGNMENT Recorded Sep 18, 2025
From: EDISON INNOVATIONS LLC
To: BLUE RIDGE INNOVATIONS, LLC
Reel/Frame 072938/0793 →
CHANGE OF NAME Recorded Mar 7, 2025
From: GE INTELLECTUAL PROPERTY LICENSING, LLC
To: DOLBY INTELLECTUAL PROPERTY LICENSING, LLC
Reel/Frame 070447/0237 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2025
From: ABBASZADEH, MASOUD; NIELSEN, MATTHEW; BUSH, STEPHEN F.
To: GENERAL ELECTRIC COMPANY
Reel/Frame 070424/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2025
From: GENERAL ELECTRIC COMPANY
To: GE INTELLECTUAL PROPERTY LICENSING, LLC
Reel/Frame 070403/0440 →
CHANGE OF NAME Recorded Jan 28, 2025
From: GE INTELLECTUAL PROPERTY LICENSING, LLC
To: DOLBY INTELLECTUAL PROPERTY LICENSING, LLC
Reel/Frame 070032/0228 →