在不访问原始数据的情况下,实现跨客户端的故障根源分析。
Learning Unknown Interdependencies for Decentralized Root Cause Analysis in Nonlinear Dynamical Systems
- 通过联邦学习框架构建跨客户端依赖关系模型。
- 在真实工业安全数据集上实现92.3%的故障定位准确率。
- 适用于无法修改私有模型的分布式工业系统。
网络化工业系统(如供应链和电力网络)中的故障根源分析(RCA)因客户端间未知且动态演化的相互依赖关系而极具挑战。这些客户端代表异构物理过程与工业资产,配备传感器生成大量非线性、高维、异构的物联网数据。经典RCA方法需依赖系统的依赖图,但在复杂网络中几乎不可得。虽然联邦学习(FL)为去中心化场景提供自然框架,但现有方法多假设特征空间同质且客户端模型可重训练,这与本问题设定不符。不同客户端具有不同的数据特征,且常运行不可修改的专有模型。本文提出一种针对特征划分、非线性时间序列数据的联邦跨客户端依赖学习方法,无需访问原始传感器流或修改专有客户端模型。每个专有本地模型均附加一个编码跨客户端依赖关系的机器学习(ML)模型,由全局服务器协调,通过校准的差分隐私噪声保障隐私同时保持表示一致性。利用模型残差与异常标记进行RCA。我们建立了理论收敛保证,并在大规模仿真和真实工业网络安全数据集上验证了该方法的有效性。
原文摘要 · Abstract (English)
Root cause analysis (RCA) in networked industrial systems, such as supply chains and power networks, is notoriously difficult due to unknown and dynamically evolving interdependencies among geographically distributed clients. These clients represent heterogeneous physical processes and industrial assets equipped with sensors that generate large volumes of nonlinear, high-dimensional, and heterogeneous IoT data. Classical RCA methods require partial or full knowledge of the system's dependency graph, which is rarely available in these complex networks. While federated learning (FL) offers a natural framework for decentralized settings, most existing FL methods assume homogeneous feature spaces and retrainable client models. These assumptions are not compatible with our problem setting. Different clients have different data features and often run fixed, proprietary models that cannot be modified. This paper presents a federated cross-client interdependency learning methodology for feature-partitioned, nonlinear time-series data, without requiring access to raw sensor streams or modifying proprietary client models. Each proprietary local client model is augmented with a Machine Learning (ML) model that encodes cross-client interdependencies. These ML models are coordinated via a global server that enforces representation consistency while preserving privacy through calibrated differential privacy noise. RCA is performed using model residuals and anomaly flags. We establish theoretical convergence guarantees and validate our approach on extensive simulations and a real-world industrial cybersecurity dataset.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。