Intelligent operation and maintenance method for electric power automation monitoring system based on multi-modal data
By adopting intelligent operation and maintenance methods of multimodal data in the power automation monitoring system, combined with statistics and deep learning models, screening and abnormal detection of structured and unstructured data of the power automation monitoring system, the problems of system operation and maintenance accuracy and efficiency are solved, and efficient and accurate abnormal detection and automated operation and maintenance are achieved.
Patent Information
- Application Number
- CN202510091004.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-16
AI Technical Summary
Due to its distribution and complexity, power automation monitoring systems lead to low operation and maintenance accuracy and efficiency, and the existing technology has failed to effectively solve this problem.
Using intelligent operation and maintenance methods based on multimodal data, through statistics, deep learning models and knowledge graphs and other technologies, the structured and unstructured data of the power automation monitoring system are screened, abnormal detection, feature extraction and fault cause analysis.
It realizes more comprehensive and accurate status monitoring of the power automation monitoring system, improves the efficiency and accuracy of abnormal detection, reduces the false alarm and omission rate, supports early warning and automated operation and maintenance, and reduces operation and maintenance costs.
Smart Images

Figure CN120013517A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence, and more specifically, to an intelligent operation and maintenance method for an electric power automation monitoring system based on multimodal data. Background Art
[0002] The power automation monitoring system directly determines the quality of safe and stable operation of my country's power system. Once a fault occurs, it will cause a large-scale power outage in the region or even the entire network. The power automation monitoring system is usually distributed, that is, a system in which a hardware or software component is distributed on different networked computers and communicates and coordinates with each other only through message passing. It contains multiple machine nodes with inconsistent physical locations and high complexity. In addition, each machine node has thousands of data indicators that need to be regularly observed and maintained. Manual inspection is the main method at present. When the operation and maintenance personnel do not have sufficient knowledge of the basic knowledge required for operation and maintenance and have misunderstandings, the accuracy and efficiency of operation and maintenance are low.
[0003] Distributed systems have a large number of servers and devices, and there are intricate dependencies between modules, which creates more uncertainty. The failure rate of the entire system will increase exponentially with the increase of equipment. Single node problems may be infinitely magnified, and abnormalities will inevitably occur during daily operations. Distributed system nodes are distributed over a wider range, with more nodes and non-uniform physical locations, and are highly dependent on the network. In addition, there are many representative heterogeneous data in the power automation monitoring system, such as operating system logs, CPU status, memory status, process heartbeats, etc., which carry information about the system's operating status. As the scale and complexity of distributed systems continue to increase, the accuracy and efficiency of distributed system operation and maintenance have become critical, and manual inspections alone cannot meet the requirements.
[0004] Currently, no effective solution has been proposed for the problems in the related technologies. Summary of the invention
[0005] In view of this, the present invention provides an intelligent operation and maintenance method for an electric power automation monitoring system based on multimodal data to solve the above-mentioned problems.
[0006] In order to solve the above problems, the specific technical solutions adopted by the present invention are as follows:
[0007] An intelligent operation and maintenance method for an electric power automation monitoring system based on multimodal data, the method comprising the following steps:
[0008] S1. Using statistics to perform screening and classification processing on structured data and unstructured data of the operation and maintenance data of the power automation monitoring system acquired in advance;
[0009] S2. Perform preliminary anomaly detection on structured data using the 3sigma method and adaptive threshold update method. If no anomaly is detected, perform secondary anomaly verification using the pre-trained CNN-LSTM deep learning model to obtain anomaly verification results.
[0010] S3, extracting feature vectors from unstructured data based on unstructured data attributes, and performing abnormal classification processing on the extracted feature vectors using an improved Transformer network model to obtain abnormal classification results;
[0011] S4. Build a knowledge graph based on historical cases of the power automation monitoring system, and combine the anomaly verification results and anomaly classification results to obtain the cause of the fault and the treatment measures through comparative analysis.
[0012] Preferably, the method performs preliminary anomaly detection on structured data by using the 3sigma method and the adaptive threshold update method; wherein, if no anomaly is detected, a secondary anomaly check is performed using a pre-trained CNN-LSTM deep learning model, and obtaining the anomaly check result comprises the following steps:
[0013] S21. Distributively storing the obtained structured data using a time series database, and performing data preprocessing on the stored structured data, wherein the preprocessing includes data cleaning and data encoding;
[0014] S22, using the 3sigma method and the adaptive threshold update method to perform preliminary anomaly detection on the preprocessed structured data. If no anomaly is detected, step S23 is executed. If an anomaly is detected, the abnormal point of the structured data is determined to obtain a verification result.
[0015] S23. Collect the structured data of the historical power automation monitoring system, build and train the CNN-LSTM deep learning model, and perform a secondary anomaly check on the pre-processed structured data through the trained CNN-LSTM deep learning model to obtain the verification result.
[0016] Preferably, the method of performing preliminary anomaly detection on the preprocessed structured data using the 3sigma method and the adaptive threshold update method comprises the following steps:
[0017] S221, based on the current time point of the operation and maintenance data in the preprocessed structured data, and using a sliding window method, update the average value and standard deviation of the operation and maintenance data in the structured data;
[0018] S222. Calculate the 3sigma threshold interval using the 3sigma principle according to the average value and standard deviation of the operation and maintenance data in the updated structured data;
[0019] S223, using the 3sigma threshold interval to perform preliminary anomaly detection on the operation and maintenance data in the preprocessed structured data. If the operation and maintenance data in the preprocessed structured data is within the 3sigma threshold interval, it indicates that the operation and maintenance data is initially normal; otherwise, it indicates that the operation and maintenance data is abnormal data.
[0020] Preferably, the method of updating the mean value and standard deviation of the operation and maintenance data in the structured data based on the current time point of the operation and maintenance data in the preprocessed structured data and using a sliding window method comprises the following steps:
[0021] S2211. Configure the initial mean value and initial standard deviation of the operation and maintenance data in the structured data;
[0022] S2212, according to the current time point of the operation and maintenance data in the preprocessed structured data, using a preset sliding window to obtain the maximum value and the minimum value of the operation and maintenance data in the preprocessed structured data;
[0023] S2213. Calculate the difference between the maximum and minimum values in the operation and maintenance data in the preprocessed structured data. If the difference is greater than the preset deviation threshold, recalculate the average value and standard deviation based on the operation and maintenance data in the preprocessed structured data in the sliding window, and update them to the current average value and standard deviation. Otherwise, use the initial average value and initial standard deviation as the current average value and standard deviation.
[0024] Preferably, the collecting of structured data of the historical electric power automation monitoring system, constructing and training a CNN-LSTM deep learning model, performing a secondary abnormality check on the pre-processed structured data through the trained CNN-LSTM deep learning model, and obtaining the check result comprises the following steps:
[0025] S231, dividing the collected historical structured data of the electric power automation monitoring system into a training set and a validation set;
[0026] S232. Build and use the training set to train the CNN-LSTM deep learning model, and optimize the model parameters by combining the adaptive momentum and variance correction mechanism;
[0027] S233, using the validation set to validate the trained CNN-LSTM deep learning model;
[0028] S234. Input the preprocessed structured data into the trained and verified CNN-LSTM deep learning model for secondary anomaly verification, and output the verification result, which is the identification of normal data and abnormal data.
[0029] Preferably, the construction and use of the training set to train the CNN-LSTM deep learning model, and the optimization of the model parameters by combining the mechanism of adaptive momentum and variance correction include the following steps:
[0030] S2321, configuring and initializing model parameters, wherein the model parameters include a learning rate, a first-order momentum coefficient, a second-order momentum coefficient, and a numerical stability factor;
[0031] S2322. Build a CNN-LSTM deep learning model and load the training data set to iteratively train the CNN-LSTM deep learning model.
[0032] S2323. In each iteration, the gradient of the loss function is calculated, and the calculation formulas of the first-order momentum and the second-order momentum are used to update the momentum value in combination with the mechanism of adaptive momentum and variance correction;
[0033] S2324. Update the model parameters according to the updated momentum value and the adaptively adjusted learning rate, and repeat the iteration until the stopping condition is met.
[0034] Preferably, the extracting feature vectors from the unstructured data based on the unstructured data attributes and performing abnormal classification processing on the extracted feature vectors using the improved Transformer network model to obtain the abnormal classification results comprises the following steps:
[0035] S31, based on the data attributes of the unstructured data, extracting feature vectors from the unstructured data using a pre-set feature extraction method to obtain a feature vector set;
[0036] S32, input the extracted feature vector set into the improved Transformer network model, and analyze the spatiotemporal correlation between the input feature vectors through the self-attention mechanism;
[0037] S33. Use the multi-head attention mechanism to perform global feature analysis, and use the classification layer of the improved Transformer network model to perform anomaly classification on the global feature vector and output the anomaly classification results.
[0038] Preferably, the step of extracting feature vectors from unstructured data using a preset feature extraction method based on the data attributes of the unstructured data to obtain a feature vector set comprises the following steps:
[0039] S311, for log data in unstructured data, create a dictionary for the log based on a pre-built corpus, and perform convolution feature extraction on the dictionary through a convolution layer;
[0040] S312, for voiceprint data in unstructured data, extract voiceprint features using linear prediction coding;
[0041] S313: Integrate the extracted convolution features and voiceprint features to obtain a feature vector set.
[0042] Preferably, the construction of a knowledge graph based on historical cases of the electric power automation monitoring system, and combining the abnormality verification results and the abnormality classification results, and obtaining the fault cause and disposal measures through comparative analysis include the following steps:
[0043] S41, extracting information related to power operation and maintenance failures from historical cases of the power automation monitoring system, and performing entity annotation on the information related to power operation and maintenance failures to obtain a preliminary knowledge graph structure, wherein the preliminary knowledge graph structure includes entities and entity relationships;
[0044] S42. Based on the preliminary knowledge graph structure, the extracted entities and relationships are vectorized using the SProjE model, and a knowledge graph is constructed based on the vectorized representation results;
[0045] S43, using the distance translation model to detect and filter the noise in the knowledge graph, and repairing the knowledge graph by pre-defining constraints and inference rules to obtain the final knowledge graph;
[0046] S44. Combine the anomaly verification results and anomaly classification results of the operation and maintenance data in the power automation monitoring system, and compare and analyze them with the knowledge graph to infer the cause of the fault, and combine the historical cases of the knowledge graph to generate fault handling measures.
[0047] Preferably, the method of vectorizing the extracted entities and relationships based on the preliminary knowledge graph structure using the SProjE model, and constructing the knowledge graph based on the vectorized representation results comprises the following steps:
[0048] S421, initializing the SProjE model, including configuring the model architecture, configuring hyperparameters, and initializing model parameters;
[0049] S422, converting the preliminary knowledge graph structure to extract triple data, and constructing a positive sample set and a negative sample set based on the triple data, wherein the triple data includes a head entity, an entity relationship, and a tail entity;
[0050] S423, using the cross entropy-based column sorting error loss function as the optimization target, and using the positive sample set and the negative sample set to train the SProjE model;
[0051] S424. Using the trained SProjE model, transform the entities and entity relationships in the preliminary knowledge graph structure into low-dimensional vector representations and construct a knowledge graph.
[0052] Preferably, the expression of the column sorting error loss function of the cross entropy is:
[0053]
[0054] Where G(e,r,y) represents the column-wise sorting error loss function of the cross entropy, y represents the binary label vector, and y i Indicates that the i-th tail entity is correct, e represents the head entity, r represents the relationship, (e,r) i Represents the i-th entity relationship pair, b(e,r) i represents the score of the i-th candidate entity given the head entity e and relation r.
[0055] Preferably, the method of detecting and filtering the noise in the knowledge graph by using the distance translation model, and patching the knowledge graph by pre-defining constraint relationships and inference rules to obtain the final knowledge graph includes the following steps:
[0056] S431, extracting structure information, path information and triple information according to the knowledge graph;
[0057] S432, calculating the energy function of the triples using the distance translation model, and calculating the association strength between entities;
[0058] S433, extracting a long-tail path containing multiple hops from the knowledge graph, and calculating the semantic relationship strength on the long-tail path using a temporal network with a memory gating mechanism;
[0059] S434. Calculate the overall structural environment score of each entity in the knowledge graph through a fully connected network by combining the entity association strength and the path semantic relationship strength;
[0060] S435, identifying noise in the knowledge graph using a preset threshold according to the association strength between entities, the path semantic relationship strength, and the overall structural environment score, and deleting the noise from the knowledge graph;
[0061] S436, based on the knowledge configuration constraint relationship in the electric power field, the triples of the knowledge graph are checked and the triples that do not satisfy the constraint relationship are deleted;
[0062] S437. Use logical reasoning rules to infer the missing triples in the knowledge graph, and patch the knowledge graph based on the inference results to obtain the final knowledge graph.
[0063] Preferably, the calculation formula for calculating the overall structural environment score of each entity in the knowledge graph through the fully connected network is:
[0064]
[0065] In the formula, P(e) represents the overall structural environment score of entity e in the knowledge graph. Represents the adjacent entity e i The semantic strength of the long-tail path, Represents the adjacent entity e i Weight, H(e i ) indicates the entity association strength.
[0066] The beneficial effects of the present invention are:
[0067] The present invention adopts multimodal data to realize intelligent operation and maintenance. Aiming at the data form and characteristics of the electric power automation monitoring system, it uses multimodal data for the first time to detect anomalies thereof, thereby realizing intelligent operation and maintenance. By using the complementary information provided by the multimodal data, the operation status of the system can be more comprehensively grasped. In addition, by combining a variety of algorithms to make a comprehensive judgment on the CPU occupancy rate, memory occupancy rate, disk occupancy rate, and network transceiver rate, the efficiency and accuracy of indicator anomaly detection are further improved, and the false alarm rate and missed alarm rate of anomaly detection are reduced. Therefore, the present invention provides the electric power automation monitoring software with the ability of early warning and foresight, and can realize the intelligent operation and maintenance of the electric power automation monitoring software in actual engineering projects, so as to achieve less or even no-man operation, greatly reducing the operation and maintenance cost of the electric power automation monitoring software, improving the reliability, stability and intelligence level of the power system, and promoting the green transformation of the power industry. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0069] Figure 1 is a flow chart of a smart operation and maintenance method for an electric power automation monitoring system based on multimodal data according to an embodiment of the present invention;
[0070] Figure 2 It is a CNN-LSTM network structure diagram in the intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to an embodiment of the present invention;
[0071] Figure 3 It is a schematic diagram of processing unstructured data vectors by an improved transformer in an intelligent operation and maintenance method for an electric power automation monitoring system based on multimodal data according to an embodiment of the present invention. DETAILED DESCRIPTION
[0072] In order to enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.
[0073] According to an embodiment of the present invention, a smart operation and maintenance method for an electric power automation monitoring system based on multimodal data is provided.
[0074] The present invention is further described with reference to the accompanying drawings and specific embodiments. Figure 1 As shown, according to an intelligent operation and maintenance method of a power automation monitoring system based on multimodal data according to an embodiment of the present invention, the method comprises the following steps:
[0075] S1. Using statistics to perform screening and classification processing on structured data and unstructured data of the operation and maintenance data of the power automation monitoring system acquired in advance;
[0076] It should be noted that the software and hardware status indicator data of the monitoring system, namely, structured data such as CPU occupancy, memory occupancy, disk occupancy, network transceiver rate, and process status, are read from the database in the power automation monitoring software.
[0077] The unstructured data such as server noise voiceprints and operating system logs of the electric power automation monitoring system are extracted from the hard disk of the electric power automation monitoring system.
[0078] S2. Perform preliminary anomaly detection on structured data using the 3sigma method and adaptive threshold update method. If no anomaly is detected, perform secondary anomaly verification using the pre-trained CNN-LSTM deep learning model to obtain anomaly verification results.
[0079] As a preferred implementation, the structured data is initially detected for anomalies using the 3sigma method and the adaptive threshold update method; if no anomaly is detected, a pre-trained CNN-LSTM deep learning model is used for secondary anomaly verification, and obtaining the anomaly verification result includes the following steps:
[0080] S21. Distributively storing the obtained structured data using a time series database, and performing data preprocessing on the stored structured data, wherein the preprocessing includes data cleaning and data encoding;
[0081] It should be noted that the InfluxDB high-performance time series database is selected to realize the distributed storage of structured data, and to achieve interaction with the power automation monitoring system through high-speed reading and writing and real-time analysis.
[0082] Among them, data cleaning: mainly fills missing data and all-0 data, the purpose is to solve the outliers in the data set and ensure the accuracy and completeness of the data. For missing data, the median interpolation method is used.
[0083] Data encoding: One-hot encoding is performed on categorical data so that computers can understand and process it, as shown in Table 1.
[0084] Table 1 One-hot encoding table
[0085] Process Name Process Status coding Live Library normal 1 Warehousing service stop 0 History Library Service stop 0 Data synchronization service normal 1
[0086] S22, using the 3sigma method and the adaptive threshold update method to perform preliminary anomaly detection on the preprocessed structured data. If no anomaly is detected, step S23 is executed. If an anomaly is detected, the abnormal point of the structured data is determined to obtain a verification result.
[0087] Specifically, for structured data such as CPU occupancy, memory occupancy and process status, the 3sigma method and adaptive threshold update method are used to perform preliminary anomaly detection on the preprocessed structured data.
[0088] For the disk usage and network receiving and sending rates in structured data, trend types and thresholds are used for anomaly detection.
[0089] The following methods are used to detect anomalies based on disk usage trends and thresholds:
[0090] A. If the disk usage of a single aspect exceeds 80% and the saturation exceeds 100%, an alarm is issued;
[0091] B. If there is a sudden decrease in disk IOPS, throughput, or bandwidth, an alarm will be issued;
[0092] C. The access duration is prolonged continuously and reaches the threshold, and an alarm is issued;
[0093] The following are the anomaly detection methods for network transmission and reception rates using trend types and thresholds:
[0094] A. The network is disconnected and an alarm is issued;
[0095] B. Sudden changes in quantity: A sudden increase or decrease in the number of incoming or outgoing network packets may indicate an abnormal situation in the network, and a sudden change may trigger an alarm;
[0096] C. The network access duration is continuously prolonged and reaches the threshold, and an alarm is issued;
[0097] As a preferred implementation, the preliminary anomaly detection of the preprocessed structured data using the 3sigma method and the adaptive threshold update method includes the following steps:
[0098] S221, based on the current time point of the operation and maintenance data in the preprocessed structured data, and using a sliding window method, update the average value and standard deviation of the operation and maintenance data in the structured data;
[0099] As a preferred implementation, the method of updating the mean value and standard deviation of the operation and maintenance data in the structured data based on the current time point of the operation and maintenance data in the preprocessed structured data and using a sliding window method includes the following steps:
[0100] S2211. Configure the initial mean value and initial standard deviation of the operation and maintenance data in the structured data;
[0101] It should be noted that sample data within a certain period of time is selected from the pre-acquired structured data. The sample data is sufficient to represent the regular fluctuations of the operation and maintenance data. It is usually a record of the initial equipment operation or when the system status is stable. It is ensured that there are no obvious abnormalities in the sample data to ensure that the initial average and standard deviation can reflect the normal status of the system.
[0102] Calculate the initial average value for the operation and maintenance data (such as voltage, current, power, etc.) in the sample data. The calculation formula for the initial average value is:
[0103]
[0104] The initial standard deviation is used to measure the degree of dispersion of the data. Its calculation formula is:
[0105]
[0106] In the formula, μ represents the initial average value of the operation and maintenance data in the sample data, x j represents the jth sample data, N represents the total number of samples, and σ represents the initial standard deviation.
[0107] S2212, according to the current time point of the operation and maintenance data in the preprocessed structured data, using a preset sliding window to obtain the maximum value and the minimum value of the operation and maintenance data in the preprocessed structured data;
[0108] It should be noted that the sliding window refers to a fixed-length subset in the data stream. The size of the window is a key parameter, which is usually set by the actual needs of the system. For example, the length of the window can be set to 10 hours, 24 hours, or a fixed number of samples (such as 100 data points). From the current time point t forward, the operation and maintenance data in the sliding window is extracted to form a new data subset. This subset contains structured data within a period of time or a number of samples in the past. In the extracted sliding window data subset, the maximum and minimum values of the data are calculated.
[0109] S2213. Calculate the difference between the maximum and minimum values in the operation and maintenance data in the preprocessed structured data. If the difference is greater than the preset deviation threshold, recalculate the average value and standard deviation based on the operation and maintenance data in the preprocessed structured data in the sliding window, and update them to the current average value and standard deviation. Otherwise, use the initial average value and initial standard deviation as the current average value and standard deviation.
[0110] Specifically, the maximum and minimum values are obtained in the data subset within the sliding window, and their difference is calculated to determine whether the difference exceeds a preset deviation threshold (e.g., 10%). If the difference exceeds the threshold, the mean and standard deviation are recalculated; otherwise, the initial values are kept unchanged.
[0111] In addition, for the update of the average value and standard deviation, the standard deviation and the average value can also be updated at 0:00 am every day. If the difference between the maximum CPU usage and the minimum CPU usage of the previous day exceeds 10%, and the difference between the maximum memory usage and the minimum memory usage exceeds 10%, the threshold will be updated to achieve adaptive thresholds and avoid false positives and false negatives.
[0112] S222. Calculate the 3sigma threshold interval using the 3sigma principle according to the average value and standard deviation of the operation and maintenance data in the updated structured data;
[0113] It should be noted that in statistics, the probability of a value being distributed in (μ-σ, μ+σ) is 0.6827; the probability of being distributed in (μ-2σ, μ+2σ) is 0.9545; and the probability of being distributed in (μ-3σ, μ+3σ) is 0.9973. The default data values are almost all concentrated in the interval (μ-3σ, μ+3σ), and the probability of exceeding this range is less than 0.3%. Therefore, if there are data points that exceed 3 times the standard deviation, then these points are likely to be outliers or outliers. The upper and lower limits of the 3sigma threshold interval are calculated as follows:
[0114] Lower limit = μ-3σ;
[0115] Upper limit = μ + 3σ;
[0116] The upper and lower limit calculation results are defined as the 3sigma threshold interval: [μ-3σ,μ+3σ]; the size of this interval changes with the update of the mean and standard deviation, and can dynamically adapt to data fluctuations.
[0117] S223, using the 3sigma threshold interval to perform preliminary anomaly detection on the operation and maintenance data in the preprocessed structured data. If the operation and maintenance data in the preprocessed structured data is within the 3sigma threshold interval, it indicates that the operation and maintenance data is initially normal; otherwise, it indicates that the operation and maintenance data is abnormal data.
[0118] It should be noted that if the above method does not detect an abnormality, the current data is considered normal. If the above method detects an abnormality, the CNN-LSTM-based time series data prediction algorithm is used for secondary verification. The prediction method is to model and predict the curve, and judge whether it is abnormal based on the error between the predicted value and the actual value. If the error is large, it is judged as abnormal, otherwise it is normal.
[0119] S23. Collect the structured data of the historical power automation monitoring system, build and train the CNN-LSTM deep learning model, and perform a secondary anomaly check on the pre-processed structured data through the trained CNN-LSTM deep learning model to obtain the verification result.
[0120] As a preferred implementation, the collecting of structured data of the historical electric power automation monitoring system, building and training a CNN-LSTM deep learning model, performing a secondary abnormality check on the pre-processed structured data through the trained CNN-LSTM deep learning model, and obtaining the check result includes the following steps:
[0121] S231, dividing the collected historical structured data of the electric power automation monitoring system into a training set and a validation set;
[0122] S232. Build and use the training set to train the CNN-LSTM deep learning model, and optimize the model parameters by combining the adaptive momentum and variance correction mechanism;
[0123] It should be noted that the preprocessed structured data is divided into a training set and a validation set, and the training set is sent to the CNN-LSTM deep learning model for training, and the validation set is sent to the trained model. If the model prediction accuracy is above 85%, the prediction model is retained, otherwise the hyperparameters are adjusted and the step is repeated. The network structure diagram of CNN-LSTM is shown in
[0124] ”'
[0125] Figure 2 As shown, where x1,x2...xt is a set of data to be predicted, the number of data is t. t is the output of the convolutional layer. h1,h2...h t is the output of the hidden layer. s1,s2...s t is the hidden layer output score, and softmax is the normalized exponential function. The convolution layer, BiLSTM layer, and Attention layer of CNN-LSTM are expressed as follows:
[0126] Convolutional layer: o i =f(W1×x i:i+t-1 +b1);
[0127] Among them, i is the i-th data in the sample data, o i is the output of the convolutional layer, x i:i+t-1 Represents the i-th sample data to the i+1-1-th data in the sample, W1 is the convolution weight, b1 is the bias, and f is the nonlinear activation function.
[0128] BiLSTM is composed of two independent LSTMs, each responsible for processing the input sequence from two directions (forward and reverse). This allows the model to simultaneously obtain information before and after the current time step. The output h1 of BiLSTM is usually concatenated from the hidden states in two directions. It can be expressed as: h1 = h 11 +h 12 ;
[0129] where h 11 is the hidden layer output of the first LSTM layer, h 12 is the output of the hidden layer of the second LSTM layer.
[0130] Attention layer:
[0131] S i =tanh(Wh i +b i );
[0132] α i =softmax(S i );
[0133] Among them, S i For each hidden layer output score, α i is the weight coefficient, h i is the output of the hidden layer of the i-th LSTM layer, b i is the bias of the i-th LSTM layer, and the output of the attention layer is expressed as:
[0134] Among them, Ci represents the output of the attention layer, t is the number of sequence data, and finally, the prediction value is obtained through the fully connected layer.
[0135] As a preferred implementation, the construction and use of the training set to train the CNN-LSTM deep learning model, and the optimization of the model parameters by combining the mechanism of adaptive momentum and variance correction include the following steps:
[0136] S2321, configuring and initializing model parameters, wherein the model parameters include a learning rate, a first-order momentum coefficient, a second-order momentum coefficient, and a numerical stability factor;
[0137] It should be noted that the learning rate is used to control the step size of model parameter updates. The choice of learning rate affects the convergence speed and final effect of the model. An adaptive learning rate algorithm is often used.
[0138] First-order momentum coefficient: used to accelerate gradient descent, mainly by storing the weighted average of the gradient to smooth the gradient update, and the common value is 0.9.
[0139] Second-order momentum coefficient: used to correct the variance of the gradient and reduce fluctuations during updates. The common value is 0.999.
[0140] Numerical stability: used to prevent numerical instability caused by dividing by very small numbers when calculating momentum, usually set to 10 -8 .
[0141] S2322. Build a CNN-LSTM deep learning model and load the training data set to iteratively train the CNN-LSTM deep learning model.
[0142] S2323. In each iteration, the gradient of the loss function is calculated, and the calculation formulas of the first-order momentum and the second-order momentum are used to update the momentum value in combination with the mechanism of adaptive momentum and variance correction;
[0143] It should be noted that in each iteration, the model first calculates the predicted value through forward propagation, and calculates the error between the predicted value and the true value through the loss function. Then, the gradient of the loss function relative to the model parameters is calculated through the back-propagation algorithm.
[0144] The first-order momentum (often called the momentum term) is an estimate of the first-order moment of the gradient, which is used to accelerate the gradient descent process. The second-order momentum (often called the variance correction term) is an estimate of the second-order moment of the gradient, which is used to correct the variance of the gradient and reduce fluctuations during updates.
[0145] First-order momentum m t and the second-order momentum v t The calculation formula is as follows:
[0146] m t=β1·m t -1+(1-β1)·g t ;
[0147] v t =β2·v t -1+(1-β2)·g t 2 ;
[0148] Among them, g t is the gradient of the current iteration, β1 is the first-order momentum coefficient, g t 2 is the square of the current iteration gradient, and β2 is the second-order momentum coefficient.
[0149] Updating the momentum value and adjusting the model parameters are the core steps. This process ensures that the model can learn efficiently and stably.
[0150] Since the first-order momentum and second-order momentum at the initial moment are both zero vectors, this will cause the momentum values in the first few iterations to be underestimated. In order to eliminate this deviation, a deviation correction mechanism is introduced. The deviation correction needs to be used for correction:
[0151]
[0152] In the formula, m t and represents the corrected first-order and second-order momentum, β1 is the first-order momentum coefficient, β2 is the second-order momentum coefficient, t represents the number of iterations, and They respectively represent the effects of the cumulative product of β1 and β2 after t rounds of iterations.
[0153] S2324. Update the model parameters according to the updated momentum value and the adaptively adjusted learning rate, and repeat the iteration until the stopping condition is met.
[0154] It should be noted that the first-order momentum and second-order momentum after bias correction are used to update the model parameters θ t . Update formula:
[0155]
[0156] Among them, η is the learning rate and ε is a numerical stabilizer to prevent division by zero errors in calculations.
[0157] S233, using the validation set to validate the trained CNN-LSTM deep learning model;
[0158] It should be noted that after training, the validation set is used to evaluate the performance of the model. The purpose of this process is to check the generalization ability of the model on unseen data to avoid overfitting. The steps of the validation process are as follows:
[0159] Input validation data: Input the validation set into the trained CNN-LSTM model.
[0160] Predict the output of the validation set: The model generates corresponding predicted values based on the input validation data.
[0161] Calculate the loss of the validation set: Calculate the error between the model's predictions and the true labels through a loss function such as mean squared error or cross entropy loss.
[0162] Adjust model hyperparameters: If the validation set loss is high, you may need to adjust the model’s hyperparameters, such as the learning rate, the number of LSTM layers, or the number of CNN filters.
[0163] Early stopping strategy: If the loss of the validation set no longer decreases after several iterations, model training will stop early to prevent overfitting.
[0164] S234. Input the preprocessed structured data into the trained and verified CNN-LSTM deep learning model for secondary anomaly verification, and output the verification result, which is the identification of normal data and abnormal data.
[0165] It should be noted that the preprocessed structured data is input into the trained CNN-LSTM model for forward propagation to obtain the output of the model. The output of the model is usually the abnormal probability or classification label of each sample. According to the output of the model, the data is marked as normal data or abnormal data.
[0166] For example, if the model outputs anomaly probability, a threshold (such as 0.5) can be set, and samples with probability greater than the threshold are marked as abnormal data, otherwise they are marked as normal data.
[0167] S3, extracting feature vectors from unstructured data based on unstructured data attributes, and performing abnormal classification processing on the extracted feature vectors using an improved Transformer network model to obtain abnormal classification results;
[0168] As a preferred implementation, the method of extracting feature vectors from unstructured data based on unstructured data attributes, and performing abnormal classification processing on the extracted feature vectors using an improved Transformer network model to obtain abnormal classification results includes the following steps:
[0169] S31, based on the data attributes of the unstructured data, extracting feature vectors from the unstructured data using a pre-set feature extraction method to obtain a feature vector set;
[0170] As a preferred implementation, the method of extracting feature vectors from unstructured data using a pre-set feature extraction method based on the data attributes of the unstructured data to obtain a feature vector set includes the following steps:
[0171] S311, for log data in unstructured data, create a dictionary for the log based on a pre-built corpus, and perform convolution feature extraction on the dictionary through a convolution layer;
[0172] S312, for voiceprint data in unstructured data, extract voiceprint features using linear prediction coding;
[0173] S313: Integrate the extracted convolution features and voiceprint features to obtain a feature vector set.
[0174] It should be noted that the unstructured data such as the server noise voiceprint, operating system log, and process input log of the power automation monitoring system stored in the hard disk are feature extracted to convert the unstructured data into a vector representation that can be understood by the deep learning model. For operating system logs and process logs, the word embedding method is used to convert the text into a vector. The specific steps are as follows:
[0175] Create a corpus based on a large amount of historical operating system logs and process logs;
[0176] Create a dictionary for the log to be analyzed based on the corpus, and define the order of words in the corpus as the corresponding elements in the dictionary.
[0177] For example, if the operating system log is "node 1kernel:Killed process", the order of node in the corpus is 105, the order of kernel in the corpus is 33, the order of killed in the corpus is 2, and the order of process in the corpus is 5. Then the dictionary created based on the corpus is [105,0,33,0,2,5]. Since characters and numbers do not contain log information with analytical significance, both characters and numbers are set to 0;
[0178] Then the above dictionary is sent to the 1xN convolutional layer. The size of the dictionary is 6x1. According to the matrix multiplication, a 6xN vector representation is obtained.
[0179] For the voiceprint data of server noise, linear predictive coding (LPC) is used to extract features, that is, through the linear combination of several speech sampling values to infinitely approach, thereby obtaining a unique set of prediction coefficients, which are used as the features of the voiceprint data.
[0180] LPC fits the original speech signal by linearly combining several speech sampling values. In this way, the voiceprint data can be converted into a set of linear prediction coefficients. The prediction coefficients can describe the main characteristics of the voiceprint and can therefore be used as a feature representation of the voiceprint data. The LPC extraction process includes:
[0181] Sampling speech signal: First, preprocess the voiceprint data and extract several speech sampling values.
[0182] Prediction coefficient calculation: Through linear prediction coding technology, a unique set of prediction coefficients is found. This set of coefficients can be closest to the original voiceprint signal through the linear combination of several speech sampling values.
[0183] Generate feature vectors: Finally, the prediction coefficients obtained are used as feature vectors of the voiceprint data, which can effectively represent the essential characteristics of the voiceprint.
[0184] S32, input the extracted feature vector set into the improved Transformer network model, and analyze the spatiotemporal correlation between the input feature vectors through the self-attention mechanism;
[0185] It should be noted that if Figure 3 As shown, the improved Transformer network model is used to analyze and process the extracted feature vectors, including:
[0186] The extracted feature vector is used as the input of Transformer, where the attention mechanism of Transformer is expressed as follows:
[0187]
[0188] Among them, Q (Query), K (Key) and V (Value) represent query vector, key vector and value vector respectively. These vectors are obtained by weighting the input log feature and voiceprint feature vector with the parameter matrix. k Represents the vector dimensions of Q and K, used to scale the dot product results to avoid excessive values. Usually the dimension size of the feature vector.
[0189] In the present invention, since the source text embedding layer in the general Transformer model cannot analyze the voiceprint information, the source text embedding layer is removed as an improvement. After feature extraction, the data can directly enter the position encoder of the Transformer for processing.
[0190] Through the self-attention mechanism, each input feature vector can be correlated with other feature vectors to capture spatiotemporal relationships. The calculation process is as follows:
[0191] Calculate the similarity score: Calculate the similarity of Q and K through the dot product, reflecting the correlation between different feature vectors.
[0192] Scaling and normalization: Divide the similarity score by d k Finally, it is normalized by the softmax function to generate attention weights, which determine the influence of each feature vector on other feature vectors.
[0193] Weighted summation: According to the attention weight, V is weighted summed to generate the attention output. The output represents the performance of each feature vector under the current spatiotemporal association.
[0194] S33. Use the multi-head attention mechanism to perform global feature analysis, and use the classification layer of the improved Transformer network model to perform anomaly classification on the global feature vector and output the anomaly classification results.
[0195] It should be noted that the multi-head attention mechanism is a core component of the Transformer architecture. It splits the input feature vector into multiple heads (i.e., multiple subsets), and then applies the self-attention mechanism to each head independently. In this way, each head can focus on different aspects of the input data, thereby capturing richer and more diverse feature information.
[0196] Through the multi-head attention mechanism, the model can simultaneously focus on multiple different positions in the input feature vector, thereby capturing feature correlations on a global scale. This global feature analysis is crucial for understanding abnormal patterns in complex data.
[0197] At the top of the Transformer model, add a classification layer (usually a fully connected layer or a softmax layer) to map the global feature vector to predefined anomaly categories. This classification layer calculates a score for each anomaly category based on the information in the global feature vector and selects the category with the highest score as the final classification result. The output of the classification layer is a probability distribution, which indicates the possibility that the input data belongs to each anomaly category. Based on this probability distribution, the anomaly type of the input data can be determined, thereby achieving accurate anomaly classification.
[0198] Specifically, for different system status data, the forms of different indicators are ever-changing, and there is no single unchanging method that can cover all indicator situations. The present invention integrates different algorithms to perform anomaly detection on different system status data, improves the efficiency and accuracy of indicator anomaly detection, and reduces the false alarm rate and missed alarm rate of anomaly detection. As shown in Table 2:
[0199] Table 2 Anomaly detection algorithms for different system status data
[0200]
[0201] S4. Build a knowledge graph based on historical cases of the power automation monitoring system, and combine the anomaly verification results and anomaly classification results to obtain the cause of the fault and the treatment measures through comparative analysis.
[0202] As a preferred implementation, the knowledge graph is constructed based on the historical cases of the electric power automation monitoring system, and the abnormality verification results and abnormality classification results are combined to obtain the fault cause and disposal measures through comparative analysis, including the following steps:
[0203] S41, extracting information related to power operation and maintenance failures from historical cases of the power automation monitoring system, and performing entity annotation on the information related to power operation and maintenance failures to obtain a preliminary knowledge graph structure, wherein the preliminary knowledge graph structure includes entities and entity relationships;
[0204] It should be noted that key information related to power operation and maintenance failures is extracted from historical cases. This information usually includes:
[0205] Equipment information: For example, electrical equipment such as transformers, switches, and relays.
[0206] Fault information: Fault type, such as short circuit, overload, undervoltage, open circuit, etc.
[0207] Time information: the time point or time interval when the fault occurs.
[0208] Operation log: includes records of operation and maintenance operations, such as manual intervention and system automatic processing logs.
[0209] Monitoring data: data from sensors or other monitoring devices, such as current, voltage, temperature, etc.
[0210] The extracted information is annotated with entities. The purpose of entity annotation is to clearly identify the key elements in the text or record as "entities" and assign corresponding categories to each entity. The following are common entity types and annotation methods:
[0211] Equipment entity: represents the physical equipment in the power system. For example, "Transformer 123" is marked as an equipment entity.
[0212] Fault type entity: indicates the type of fault. For example, "short circuit fault" is marked as a fault type entity.
[0213] Time entity: identifies the time or time period when the fault occurs. For example, "October 15, 2022" is marked as a time entity.
[0214] Operation entity: represents the operation performed by the operation and maintenance personnel or the operation automatically processed by the system. For example, "restart switch" is marked as an operation entity.
[0215] In addition, after annotating the entities, it is necessary to construct relationships between the entities. These relationships usually represent the association between equipment and faults, faults and operations, equipment and time, etc.
[0216] After the entity annotation and relationship construction are completed, these entities and their relationships are formed into a preliminary knowledge graph. The basic structure of the knowledge graph consists of entity nodes and relationship edges, including:
[0217] Physical nodes: such as transformers, switches, fault types, time, etc.
[0218] Relationship edges: such as "occurs", "leads to", "operates", etc., connecting different entity nodes.
[0219] S42. Based on the preliminary knowledge graph structure, the extracted entities and relationships are vectorized using the SProjE model, and a knowledge graph is constructed based on the vectorized representation results;
[0220] As a preferred implementation, based on the preliminary knowledge graph structure, the extracted entities and relationships are vectorized using the SProjE model, and the knowledge graph is constructed based on the vectorized representation results, including the following steps:
[0221] S421, initializing the SProjE model, including configuring the model architecture, configuring hyperparameters, and initializing model parameters;
[0222] It should be noted that SProjE is a projection-based knowledge representation model that can map triples (head entity, relationship, tail entity) in the knowledge graph into low-dimensional vectors and optimize them through projection operations.
[0223] Input: triple data (e, r, z), where e is the head entity, r is the relation, and z is the tail entity.
[0224] Embedding layer: Each entity e, z and relation r is mapped to a corresponding vector embedding;
[0225] Entity: e, z∈R n ; R n is a collection of entities;
[0226] Relation: r∈R m ; R m is a set of relations;
[0227] Projection layer: The vector embedding of relation r is used to project the head entity vector e into a space aligned with the tail entity z.
[0228] Output: Low-dimensional vector distances are used to calculate energy functions and optimization objectives.
[0229] In order to train the SProjE model efficiently and model accurately, it is necessary to configure appropriate hyperparameters including: embedding dimension, learning rate, optimizer, initial learning rate, batch size, regularization coefficient, training rounds and number of negative sampling.
[0230] S422, converting the preliminary knowledge graph structure to extract triple data, and constructing a positive sample set and a negative sample set based on the triple data, wherein the triple data includes a head entity, an entity relationship, and a tail entity;
[0231] Specifically, in the input of the SProjE model, triple data is crucial, which includes head entity, entity relationship and tail entity. These triples are the basic units in the knowledge graph. In S422, it is necessary to extract triples from the preliminary knowledge graph and construct positive sample sets and negative sample sets.
[0232] The positive sample set consists of actual triplets extracted from the historical data of power operation and maintenance. These triplets reflect the actual fault events and operation processes that occurred in the system. These positive samples are used to train the model so that it can learn the association patterns between entities and relations in power operation and maintenance.
[0233] In order to train the model, it is also necessary to generate a negative sample set. The negative sample set consists of some fictitious and unreasonable triplets to help the model distinguish between correct and incorrect relations. The generation of negative samples can be achieved by randomly replacing the head entity, relation, or tail entity.
[0234] For example, given a positive sample (transformer 123, causing a short circuit fault), a negative sample can be:
[0235] (Operator A, causes,short circuit fault);
[0236] (Transformer 123, repair, short circuit fault);
[0237] By comparing positive and negative samples, the model can effectively learn the correct entity relationships.
[0238] S423, using the cross entropy-based column sorting error loss function as the optimization target, and using the positive sample set and the negative sample set to train the SProjE model;
[0239] As a preferred implementation, the expression of the cross entropy column sorting error loss function is:
[0240]
[0241] Where G(e,r,y) represents the column-wise sorting error loss function of the cross entropy, y represents the binary label vector, and y i Indicates that the i-th tail entity is correct, e represents the head entity, r represents the relationship, (e,r) i Represents the i-th entity relationship pair, b(e,r) i represents the score of the i-th candidate entity given the head entity e and relation r.
[0242] S424. Using the trained SProjE model, transform the entities and entity relationships in the preliminary knowledge graph structure into low-dimensional vector representations and construct a knowledge graph.
[0243] Specifically, the SProjE model is used to map entities and relationships in the knowledge graph into low-dimensional vectors, including:
[0244] Embedding layer mapping, using the embedding layer of the SProjE model, maps each entity and relationship into a vector representation:
[0245] Entity embedding: vector embeddings of the head entity and the tail entity;
[0246] Relation Embedding: Vector embedding of relations;
[0247] Among them, the vector embedding of relation r is used to project the head entity e into the vector space aligned with the tail entity z, and the calculation formula is:
[0248] Projected(e,r)=e+r;
[0249] This projection operation adjusts the representation of the head entity e to the vector space where the tail entity z is located, ensuring that the intrinsic relationship of the triples is preserved in the vector space.
[0250] In order to evaluate the similarity between the projected head entity and the tail entity, it is necessary to calculate the distance between the two in the vector space. The commonly used distance metric is the Euclidean distance. The smaller the distance value, the closer the relationship between the head entity e and the tail entity z under the influence of the relationship r. In order to obtain the similarity score of the triple, the above distance is mapped to a probability score. The sigmoid function is usually used to convert the distance into a similarity score;
[0251] By performing the above embedding and projection operations on all entities and relations in the knowledge graph, a complete vectorized knowledge graph can be constructed. This graph contains the following elements:
[0252] Entity vector representation: the representation of all entities in a low-dimensional vector space.
[0253] Relation vector representation: projection operation of all relations in vector space.
[0254] Similarity score of triples: The similarity of triples is calculated by the distance after projection.
[0255] S43, using the distance translation model to detect and filter the noise in the knowledge graph, and repairing the knowledge graph by pre-defining constraints and inference rules to obtain the final knowledge graph;
[0256] As a preferred implementation, the use of the distance translation model to detect and filter the noise in the knowledge graph, and to repair the knowledge graph by pre-defining constraints and inference rules to obtain the final knowledge graph includes the following steps:
[0257] S431, extracting structure information, path information and triple information according to the knowledge graph;
[0258] It should be noted that the basic units of the knowledge graph are entities and relationships, which constitute the topological structure of the graph. The structural information of the graph includes the connection relationship between entities (i.e., triples) and the association between different paths.
[0259] Path information includes all intermediate nodes and relationships from one entity to another, especially long-tail paths (i.e., paths containing multiple hops). These paths can reflect deeper connections in the knowledge graph.
[0260] Triples are the basic building blocks of knowledge graphs, such as (e, r, z), which describe the relationship between the head entity e, the relation r, and the tail entity z.
[0261] S432, calculating the energy function of the triples using the distance translation model, and calculating the association strength between entities;
[0262] It should be noted that the distance translation model measures the rationality of the triple (e, r, z) in the vector space by calculating the energy function of the triple (e, r, z). The commonly used energy function form is:
[0263] E(e,r,z)=||e+rz||2;
[0264] The strength of association is determined by calculating the distance between the representation of the head entity e after projection of the relation r and the tail entity z. The smaller the distance, the more reasonable the triple is, otherwise it means that the triple may be noise, where ||e+rz||2 represents the Euclidean distance (L2 norm), which is used to calculate the distance between vectors.
[0265] The value calculated by the energy function can be used to measure the strength of association between entities. The strength of association between entities reflects the closeness of the relationship between the head entity and the tail entity. In the knowledge graph, the strength of association between entities directly affects the model's rational judgment of the knowledge graph triple combination. The strength of association can be represented by a nonlinear transformation of the value of the energy function. The sigmoid function is usually used to convert the distance into an association strength value ranging from 0 to 1. The calculation formula is:
[0266] H(e,r,z)=1 / (1+expE(e,r,z));
[0267] H(e,r,z) is the strength of the association between the head entity e and the tail entity z;
[0268] S433, extracting a long-tail path containing multiple hops from the knowledge graph, and calculating the semantic relationship strength on the long-tail path using a temporal network with a memory gating mechanism;
[0269] Specifically, in the knowledge graph, there may be multiple hops from one entity to another. These paths usually contain multiple intermediate nodes and relationships. Long-tail paths can be extracted in the knowledge graph through depth-first search (DFS) or breadth-first search (BFS). Multi-hop paths capture more indirect relationships and are particularly suitable for complex reasoning tasks, but they are also prone to noise, so it is necessary to further analyze the semantic relationship strength of the path.
[0270] Since the long-tail path is a series of ordered relations and entities, it can be modeled as a time series, and a temporal network with a memory gating mechanism (such as LSTM or GRU) can be used to capture the semantic relations in the path.
[0271] After using LSTM or GRU to model the path, the hidden state vector of each node on the path can be obtained. These hidden state vectors contain the semantic information of the path. The specific steps are as follows:
[0272] 1. Input sequence
[0273] The embedding vectors of entities and relations are used as input to LSTM or GRU. It is assumed that each entity and relation has a fixed embedding vector representation.
[0274] For example, for the path (A,r1,B,r2,C,r3,D), the input sequence is the embedding vector of [A,r1,B,r2,C,r3,D].
[0275] 2. Timing Network Processing
[0276] Feed the input sequence into LSTM or GRU to obtain the hidden state vector of each node.
[0277] These hidden state vectors reflect the semantic information of each node in the path and their relationships.
[0278] 3. Calculation of semantic relationship strength
[0279] Path score: The overall semantic relationship strength of a path can be calculated in a variety of ways. For example:
[0280] Last hidden state: Use the hidden state vector of the last node as the representative vector of the path.
[0281] Average hidden state: Calculate the average of all hidden state vectors as the representative vector of the path.
[0282] Attention mechanism: The attention mechanism is introduced to perform weighted summation of the hidden states of different nodes to highlight important nodes.
[0283] Normalization: To ensure the comparability of path scores, the path scores can be normalized (for example, using Sigmoid or Softmax functions).
[0284] S434. Calculate the overall structural environment score of each entity in the knowledge graph through a fully connected network by combining the entity association strength and the path semantic relationship strength;
[0285] It should be noted that the adjacent entity weight represents the adjacent entity e i The importance of entity e. This weight can be defined in many ways, for example:
[0286] Degree-based: The higher the degree of the neighboring entity, the greater the weight.
[0287] Based on type: Certain types of entities, such as critical equipment, may have higher weights.
[0288] Based on domain knowledge: weights are set based on the knowledge of domain experts.
[0289] As a preferred implementation, the calculation formula for calculating the overall structural environment score of each entity in the knowledge graph through a fully connected network is:
[0290]
[0291] In the formula, P(e) represents the overall structural environment score of entity e in the knowledge graph. Represents the adjacent entity e i The semantic strength of the long-tail path, w ei Represents the adjacent entity e i Weight, H(e i ) indicates the entity association strength.
[0292] S435, identifying noise in the knowledge graph using a preset threshold according to the association strength between entities, the path semantic relationship strength, and the overall structural environment score, and deleting the noise from the knowledge graph;
[0293] It should be noted that in the process of optimizing and maintaining the knowledge graph, noise (i.e., erroneous or invalid triples, entities, or relationships) will affect the accuracy and reasoning ability of the graph. Therefore, based on the association strength between entities, the path semantic relationship strength, and the overall structural environment score, noise can be effectively identified and filtered.
[0294] In order to identify noise, it is necessary to set certain thresholds for the above three indicators;
[0295] Threshold of entity association strength: If the association strength between two entities is below a certain set value, their relationship may be noise.
[0296] Threshold of path semantic relationship strength: If the multi-hop path semantic association between two entities is weak, it indicates that the path may be unreasonable.
[0297] Threshold for overall structural context score: If the score of an entity is below a preset threshold, it may be unimportant or problematic in the knowledge graph.
[0298] Specifically, if the association strength or path semantic strength of a triple is lower than the preset threshold, or the overall score of an entity is too low, these will be marked as noise. The marked noise may represent invalid or erroneous entities and relationships. Once the noise is identified, these noise triples or entities are removed from the knowledge graph, which helps to improve the accuracy of the knowledge graph and avoid the impact of invalid information on reasoning and query.
[0299] S436, based on the knowledge configuration constraint relationship in the electric power field, the triples of the knowledge graph are checked and the triples that do not satisfy the constraint relationship are deleted;
[0300] It should be noted that the configuration constraints in the power sector are:
[0301] Configuration constraints are set according to specific rules and operating restrictions in the power system. For example, the working mode and connection relationship of power equipment such as transformers, generators, and transmission lines must follow strict technical specifications.
[0302] For example, there must be a suitable line connection between the generator and transformer in the substation; the conversion of voltage levels must comply with national or industry standards, etc. These rules can be reflected as constraint relationships between entities in the knowledge graph.
[0303] Specifically, the triplet verification steps include:
[0304] a. Extract triple information and extract triples from the knowledge graph in the power field;
[0305] b. For each triplet, check whether they comply with industry specifications based on the configuration constraints in the power sector. For example, check whether a transformer is correctly connected to a standard transmission line, or whether the voltage levels of the generator and transformer match;
[0306] c. Delete triples that do not meet the constraints. If a triple does not meet the configuration constraints in the power field, it is considered to be noise or invalid knowledge. Such triples will be marked and deleted from the knowledge graph.
[0307] S437. Use logical reasoning rules to infer the missing triples in the knowledge graph, and patch the knowledge graph based on the inference results to obtain the final knowledge graph.
[0308] Specifically, in the knowledge graph, some triples may be missing, affecting the completeness and correctness of the graph. By applying logical reasoning rules, these missing triples can be inferred and the knowledge graph can be patched based on the reasoning results.
[0309] Among them, the inference rules are defined according to the logical rules in the power field. For example:
[0310] If e1 is a power station and e1 is connected to e2 (substation) through a line, then it can be logically inferred that substation e2 should be connected to load e3 (such as residential electrical equipment or industrial electrical equipment) through another line. Similar rules can be determined by expert knowledge or industry specifications.
[0311] Based on known triples and logical reasoning rules, possible but undocumented relationships can be inferred, and the missing triples obtained through logical reasoning can be added to the knowledge graph to repair the original incomplete parts. This step ensures that the knowledge graph is more complete and meets the standards of the power industry, and ultimately an optimized knowledge graph is obtained.
[0312] S44. Combine the anomaly verification results and anomaly classification results of the operation and maintenance data in the power automation monitoring system, and compare and analyze them with the knowledge graph to infer the cause of the fault, and combine the historical cases of the knowledge graph to generate fault handling measures.
[0313] Specifically, the anomaly detection results and anomaly classification results are compared and analyzed with the information in the knowledge graph to infer the cause of the failure. Including:
[0314] 1. Comparison of abnormal verification results
[0315] Matching triples: Find entities and relationships related to the anomaly check results in the knowledge graph. For example, if a device reports an overload alarm, you can find the device and its related relationships in the knowledge graph.
[0316] Path analysis: Through long-tail path analysis, find out other related devices or factors that may affect the device. For example, if a transformer is overloaded, it may be caused by problems in the upstream line.
[0317] 2. Comparison of abnormal classification results
[0318] Category matching: Based on the abnormal classification results, find cases with the same or similar fault types in the knowledge graph. For example, if the classification result shows that it is an "overload" fault, you can find all historical cases marked as "overload" in the knowledge graph.
[0319] Correlation analysis: Analyze the common features in these historical cases to find out the possible causes of the current failure. For example, similar overload failures in history may be caused by specific operating modes, environmental conditions, or equipment aging.
[0320] In addition, through the above comparative analysis, the abnormal verification results and abnormal classification results are comprehensively considered to infer the possible causes of the failure. The specific steps are as follows:
[0321] Multi-dimensional analysis: Combine the association strength between entities, path semantic relationship strength and overall structural environment score to conduct a comprehensive analysis of information in multiple dimensions.
[0322] Weight assignment: Different weights are assigned according to the importance of each dimension. For example, the strength of direct association may be more important than the strength of semantic relationship of indirect path.
[0323] Reasoning rules: Use predefined logical reasoning rules to further infer the cause of the fault. For example, if a device is frequently overloaded and its upstream devices also have similar problems, it may be due to a problem with the power supply line.
[0324] In addition, combined with historical cases in the knowledge graph, specific handling measures for the current fault are generated. The specific steps are as follows:
[0325] Search the knowledge graph for historical cases similar to the current failure, especially those that have been successfully resolved.
[0326] Specific troubleshooting measures are extracted from these historical cases, including operating steps, required tools, precautions, etc.
[0327] Generate a standardized disposal process template based on the disposal measures in historical cases.
[0328] Make appropriate adjustments to the disposal measures based on the current specific situation (such as equipment model, operating environment, etc.).
[0329] The generated disposal measures are reviewed by domain experts to ensure their rationality and feasibility.
[0330] To sum up, with the help of the above-mentioned technical scheme of the present invention, the present invention adopts multimodal data to realize intelligent operation and maintenance. Aiming at the data form and characteristics of the distributed power automation monitoring system, multimodal data is used for the first time to detect anomalies thereof, thereby realizing intelligent operation and maintenance; by using the complementary information provided by multimodal data, the state of system operation can be more comprehensively grasped. In addition, by combining multiple algorithms to make a comprehensive judgment on the CPU occupancy rate, memory occupancy rate, disk occupancy rate, and network transceiver rate, the efficiency and accuracy of indicator anomaly detection are further improved, and the false alarm rate and missed alarm rate of anomaly detection are reduced. Therefore, the present invention provides the power automation monitoring software with the ability of early warning and foresight, and can realize the intelligent operation and maintenance of the power automation monitoring software in actual engineering projects, so as to achieve less or even unmanned operation, greatly reducing the operation and maintenance cost of the power automation monitoring software, improving the reliability, stability and intelligence level of the power system, and promoting the green transformation of the power industry.
[0331] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) containing computer-usable program code.
[0332] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. An intelligent operation and maintenance method for a power automation monitoring system based on multimodal data, characterized in that: The method comprises the following steps: S1. Using statistics to perform screening and classification processing on structured data and unstructured data of the operation and maintenance data of the power automation monitoring system acquired in advance; S2. Perform preliminary anomaly detection on structured data using the 3sigma method and adaptive threshold update method. If no anomaly is detected, perform secondary anomaly verification using the pre-trained CNN-LSTM deep learning model to obtain anomaly verification results. S3, extracting feature vectors from unstructured data based on unstructured data attributes, and performing abnormal classification processing on the extracted feature vectors using an improved Transformer network model to obtain abnormal classification results; S4. Build a knowledge graph based on historical cases of the power automation monitoring system, and combine the anomaly verification results and anomaly classification results to obtain the cause of the fault and the treatment measures through comparative analysis.
2. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 1 is characterized in that: The method uses the 3sigma method and the adaptive threshold update method to perform preliminary anomaly detection on the structured data; if no anomaly is detected, a pre-trained CNN-LSTM deep learning model is used to perform a secondary anomaly check, and obtaining the anomaly check result includes the following steps: S21. Distributively storing the obtained structured data using a time series database, and performing data preprocessing on the stored structured data, wherein the preprocessing includes data cleaning and data encoding; S22, using the 3sigma method and the adaptive threshold update method to perform preliminary anomaly detection on the preprocessed structured data. If no anomaly is detected, step S23 is executed. If an anomaly is detected, the abnormal point of the structured data is determined to obtain a verification result. S23. Collect the structured data of the historical power automation monitoring system, build and train the CNN-LSTM deep learning model, and perform a secondary anomaly check on the pre-processed structured data through the trained CNN-LSTM deep learning model to obtain the verification result.
3. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 2 is characterized in that: The method of performing preliminary anomaly detection on the preprocessed structured data using the 3sigma method and the adaptive threshold updating method comprises the following steps: S221, based on the current time point of the operation and maintenance data in the preprocessed structured data, and using a sliding window method, update the average value and standard deviation of the operation and maintenance data in the structured data; S222. Calculate the 3sigma threshold interval using the 3sigma principle according to the average value and standard deviation of the operation and maintenance data in the updated structured data; S223, using the 3sigma threshold interval to perform preliminary anomaly detection on the operation and maintenance data in the preprocessed structured data. If the operation and maintenance data in the preprocessed structured data is within the 3sigma threshold interval, it indicates that the operation and maintenance data is initially normal; otherwise, it indicates that the operation and maintenance data is abnormal data.
4. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 3 is characterized in that: The method of updating the mean value and standard deviation of the operation and maintenance data in the structured data based on the current time point of the operation and maintenance data in the preprocessed structured data and using the sliding window method includes the following steps: S2211. Configure the initial mean value and initial standard deviation of the operation and maintenance data in the structured data; S2212, according to the current time point of the operation and maintenance data in the preprocessed structured data, using a preset sliding window to obtain the maximum value and the minimum value of the operation and maintenance data in the preprocessed structured data; S2213. Calculate the difference between the maximum and minimum values in the operation and maintenance data in the preprocessed structured data. If the difference is greater than the preset deviation threshold, recalculate the average value and standard deviation based on the operation and maintenance data in the preprocessed structured data in the sliding window, and update them to the current average value and standard deviation. Otherwise, use the initial average value and initial standard deviation as the current average value and standard deviation.
5. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 4 is characterized in that: The method of collecting structured data of the historical power automation monitoring system, constructing and training a CNN-LSTM deep learning model, and performing a secondary abnormality check on the pre-processed structured data through the trained CNN-LSTM deep learning model to obtain the check result includes the following steps: S231, dividing the collected historical structured data of the electric power automation monitoring system into a training set and a validation set; S232. Build and use the training set to train the CNN-LSTM deep learning model, and optimize the model parameters by combining the adaptive momentum and variance correction mechanism; S233, using the validation set to validate the trained CNN-LSTM deep learning model; S234. Input the preprocessed structured data into the trained and verified CNN-LSTM deep learning model for secondary anomaly verification, and output the verification result, which is the identification of normal data and abnormal data.
6. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 5 is characterized in that: The construction and use of the training set to train the CNN-LSTM deep learning model, and the optimization of the model parameters by combining the adaptive momentum and variance correction mechanism include the following steps: S2321, configuring and initializing model parameters, wherein the model parameters include a learning rate, a first-order momentum coefficient, a second-order momentum coefficient, and a numerical stability factor; S2322. Build a CNN-LSTM deep learning model and load the training data set to iteratively train the CNN-LSTM deep learning model. S2323. In each iteration, the gradient of the loss function is calculated, and the calculation formulas of the first-order momentum and the second-order momentum are used to update the momentum value in combination with the mechanism of adaptive momentum and variance correction; S2324. Update the model parameters according to the updated momentum value and the adaptively adjusted learning rate, and repeat the iteration until the stopping condition is met.
7. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 1 is characterized in that: The method of extracting feature vectors from unstructured data based on unstructured data attributes, and performing abnormal classification processing on the extracted feature vectors using an improved Transformer network model to obtain abnormal classification results includes the following steps: S31, based on the data attributes of the unstructured data, extracting feature vectors from the unstructured data using a pre-set feature extraction method to obtain a feature vector set; S32, input the extracted feature vector set into the improved Transformer network model, and analyze the spatiotemporal correlation between the input feature vectors through the self-attention mechanism; S33. Use the multi-head attention mechanism to perform global feature analysis, and use the classification layer of the improved Transformer network model to perform anomaly classification on the global feature vector and output the anomaly classification results.
8. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 7 is characterized in that: The method of extracting feature vectors from unstructured data using a preset feature extraction method based on the data attributes of the unstructured data to obtain a feature vector set includes the following steps: S311, for log data in unstructured data, create a dictionary for the log based on a pre-built corpus, and perform convolution feature extraction on the dictionary through a convolution layer; S312, for voiceprint data in unstructured data, extract voiceprint features using linear prediction coding; S313: Integrate the extracted convolution features and voiceprint features to obtain a feature vector set.
9. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 1 is characterized in that: The knowledge graph is constructed based on the historical cases of the electric power automation monitoring system, and the abnormality verification results and abnormality classification results are combined to obtain the fault cause and disposal measures through comparative analysis, including the following steps: S41, extracting information related to power operation and maintenance failures from historical cases of the power automation monitoring system, and performing entity annotation on the information related to power operation and maintenance failures to obtain a preliminary knowledge graph structure, wherein the preliminary knowledge graph structure includes entities and entity relationships; S42. Based on the preliminary knowledge graph structure, the extracted entities and relationships are vectorized using the SProjE model, and a knowledge graph is constructed based on the vectorized representation results; S43, using the distance translation model to detect and filter the noise in the knowledge graph, and repairing the knowledge graph by pre-defining constraints and inference rules to obtain the final knowledge graph; S44. Combine the anomaly verification results and anomaly classification results of the operation and maintenance data in the power automation monitoring system, and compare and analyze them with the knowledge graph to infer the cause of the fault, and combine the historical cases of the knowledge graph to generate fault handling measures.
10. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 9 is characterized in that: The method of vectorizing the extracted entities and relationships based on the preliminary knowledge graph structure using the SProjE model and constructing the knowledge graph based on the vectorized representation results includes the following steps: S421, initializing the SProjE model, including configuring the model architecture, configuring hyperparameters, and initializing model parameters; S422, converting the preliminary knowledge graph structure to extract triple data, and constructing a positive sample set and a negative sample set based on the triple data, wherein the triple data includes a head entity, an entity relationship, and a tail entity; S423, using the cross entropy-based column sorting error loss function as the optimization target, and using the positive sample set and the negative sample set to train the SProjE model; S424. Using the trained SProjE model, transform the entities and entity relationships in the preliminary knowledge graph structure into low-dimensional vector representations and construct a knowledge graph.
11. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 10, characterized in that: The expression of the column sorting error loss function of the cross entropy is: Where G(e,r,y) represents the column-wise sorting error loss function of the cross entropy, y represents the binary label vector, and y i Indicates that the i-th tail entity is correct, e represents the head entity, r represents the relationship, (e,r) i represents the i-th entity relationship pair, b(e,r) i represents the score of the i-th candidate entity given the head entity e and relation r.
12. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 11, characterized in that: The method of using the distance translation model to detect and filter the noise in the knowledge graph and patching the knowledge graph by pre-defining constraint relationships and inference rules to obtain the final knowledge graph includes the following steps: S431, extracting structure information, path information and triple information according to the knowledge graph; S432, calculating the energy function of the triples using the distance translation model, and calculating the association strength between entities; S433, extracting a long-tail path containing multiple hops from the knowledge graph, and calculating the semantic relationship strength on the long-tail path using a temporal network with a memory gating mechanism; S434. Calculate the overall structural environment score of each entity in the knowledge graph through a fully connected network by combining the entity association strength and the path semantic relationship strength; S435, according to the association strength between entities, the path semantic relationship strength and the overall structural environment score, using a pre-set threshold to identify noise in the knowledge graph, and delete the noise from the knowledge graph; S436, based on the knowledge configuration constraint relationship in the electric power field, the triples of the knowledge graph are checked and the triples that do not satisfy the constraint relationship are deleted; S437. Use logical reasoning rules to infer the missing triples in the knowledge graph, and patch the knowledge graph based on the inference results to obtain the final knowledge graph.
13. The intelligent operation and maintenance method of the electric power automation monitoring system based on multimodal data according to claim 12, characterized in that: The calculation formula for calculating the overall structural environment score of each entity in the knowledge graph through the fully connected network is: In the formula, P(e) represents the overall structural environment score of entity e in the knowledge graph. Represents the adjacent entity e i The semantic strength of the long-tail path, w ei Represents the adjacent entity e i Weight, H(e i ) indicates the entity association strength.
Citation Information
Cited By
Robot body intelligent control method and system based on multi-mode perception
CN120516727A
Visualization method and system based on big data platform
CN121301628A
Intelligent verification method and system for power transmission line design specifications based on artificial intelligence
CN121435433A
Multi-service system automatic centralized monitoring management method and system
CN121501609A
A method and apparatus for industrial energy consumption data governance based on blockchain-based trusted evidence storage
CN122507719A