Unsupervised Anomaly Detection in Industrial IoT Streams using LSTM-Autoencoders and Heuristic Decision Strategies

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

BSc in Applied Computer Science, School of Economics, Business and Computer Science, Neapolis University Pafos

Abstract

The fast-growing IIoT infrastructure, which consists of high-frequency sensor telemetry, can be overwhelming to the point of “alert fatigue.” For example, in predictive maintenance applications, a factory’s control system can get swamped by alerts to the extent that operators start to ignore valid warnings of mechanical failures. This thesis addresses the need for anomaly detection at scale in a noise-tolerant manner for Cyber Physical Systems (CPS). As a proposed solution, I present an unsupervised, sequence-aware monitoring framework built upon a Long Short-Term Memory (LSTM) Autoencoder. In an industrial setting, failure data is scarce which can severely limit the usability of classification-based anomaly detection approaches. The proposed LSTM Autoencoder instead learns the latent sequences of normal behavior for the given time series from unlabeled data. To enable interpretable decision-making using the model outputs, I propose the Heuristic Decision Engine, which implements a multi-tier severity threshold along with a temporal persistence check in order to validate alerts within a given timeframe. If the anomaly score remains elevated for a minimum of 30-minutes of consecutive, 5-minute window segments, then an alert is sent. For validation, I tested the framework on the Numenta Anomaly Benchmark dataset. Through a combination of empirical and qualitative experiments, I show that a system based on my anomaly detection framework would be robust in distinguishing between normal sensor jitter and real-time thermodynamic anomaly. By mapping 497 real-world anomalies detected with the Autoencoder framework to 34 anomalous behavior events that would be flagged as “alertworthy” by my heuristic decision engine, it would be possible to reduce alert fatigue by filtering spurious alerts while still providing high accuracy anomaly detection at scale. In summary, this study presents an unsupervised anomaly detection approach that has been proven to be viable for industrial applications in the era of big data and IoT

Description

Citation

Endorsement

Review

Supplemented By

Referenced By