An interlock control device for oil and petrochemical fire protection based on SIS
Through SIS-based interlocking control equipment, the multi-source perception and graph neural network are used to predict flame spread, and combined with quantum annealing and memristor arrays, the rapid and accurate interlocking control of the petroleum and petrochemical fire protection system is achieved, solving the problems of response speed and false shutdown in the existing technology, reducing the false shutdown rate and risk of equipment damage.
Patent Information
- Application Number
- CN202510690344.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-05-27
AI Technical Summary
The fire interlocking control system of existing petroleum and petrochemical devices relies on a single sensor and fixed threshold, making it difficult to take into account the response speed and the cost of false shutdowns, and the flame spread potential energy cannot be evaluated in real time, resulting in excessive shutdowns and damage to the robot.
Using SIS-based interlocking control equipment, a unified feature tensor is constructed through redundant multi-source perception, a graph neural network is used to predict the three-dimensional evolution of the hazard field and quantify risk entropy, and combining the quantum annealing-game interlocking framework and memristor array to achieve interlocking control of the minimum action set.
Significantly reduce interlocking error rate and fire extinguishing agent consumption, improve response speed, ensure robot safety, and avoid excessive shutdown and equipment damage.
Smart Images

Figure CN120189667B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of oil and petrochemical fire protection, and particularly to an interlock control device for oil and petrochemical fire protection based on SIS. Background Art
[0002] Oil and petrochemical plants are characterized by high temperature, high pressure, flammability, explosiveness, and dense personnel. The safety instrument system undertakes the function of the last independent protection layer. Once a fire or leakage spreads, traditional interlocks usually rely on single-sensor interlocks and fixed logic tables, with a single trigger threshold and a rigid action range, making it difficult to balance the response speed and the cost of false shutdown. Existing technologies mostly adopt hardwiring or programmable logic controller + look-up table strategies, and use single-point values of pressure and temperature as trigger conditions: cutting off pump valves with fixed thresholds often results in "excessive shutdowns" due to the failure to evaluate the potential energy of flame spread in real time, causing production interruptions; relying on rule tables to plan the path of robots cannot avoid high-risk areas of smoke and fire in real time, leading to disposal failures or damage to robots; issuing instructions based on conventional memory chips requires reloading after power failure, and on-site electromagnetic interference or high temperature is likely to cause jams. The fundamental reasons are the insufficient dimension of sensing information, the lack of the ability of the model to predict spatiotemporal coupling hazards, and the failure to consider the global optimum in the generation of interlock actions. Summary of the Invention
[0003] In view of the above-mentioned many problems existing in the prior art, the present invention provides an interlock control device for oil and petrochemical fire protection based on SIS. The present invention constructs a unified feature tensor with redundant multi-source perception, predicts the three-dimensional evolution of the hazard field through a graph neural network, and quantifies the risk entropy; the quantum annealing-game interlock framework takes "the number of actions + residual potential energy" as the goal, outputs the minimum action set and writes it into the memristive array; the execution end uses supercritical two-phase flow injection and variational path robots to cooperate in disposal. The closed-loop feedback frame corrects the model in real time, compresses the response time of the entire chain to the millisecond level, and significantly reduces both the interlock false shutdown rate and the fire extinguishing agent consumption.
[0004] An interlock control device for oil and petrochemical fire protection based on SIS, comprising:
[0005] A perception fusion unit, configured to collect multi-source data including at least an optical fiber sensor and a radar sensor, synchronize and fuse the collected data, output fused feature data and attitude matrix data, send the fused feature data to a prediction and risk assessment unit, and send the attitude matrix data to an execution and feedback unit;
[0006] A prediction and risk assessment unit, configured to generate disaster prediction data and propagation potential energy data based on the fused feature data to establish a spatiotemporal model, calculate risk entropy data, and send the disaster prediction data, propagation potential energy data, and risk entropy data to an interlock control unit;
[0007] The interlock control unit is used to construct an optimization model based on the fusion feature data, propagation potential energy data, and risk entropy data, obtain the minimum action set data through an optimization solver, write it into a programmable logic array, and then output an interlock instruction stream to trigger the SIS interlock action;
[0008] The execution and feedback unit is used to control the fire extinguishing medium release device, robot team, and thermal shielding device according to the interlock instruction stream, perform positioning and path planning in combination with the attitude matrix data, collect the execution status to form feedback data, and return it to the prediction and risk assessment unit and the interlock control unit to complete closed-loop self-correction.
[0009] Preferably, the perception fusion unit obtains the Brillouin scattering frequency shift through a distributed optical fiber sensor and demodulates the Brillouin scattering frequency shift into temperature information and strain information. It emits a frequency-modulated continuous wave through a millimeter-wave radar sensor and performs a fast Fourier transform on the echo to obtain point cloud information. It converts the acoustic signal into an electrical signal through an acoustic crystal sensor and performs a short-time Fourier transform to obtain spectrogram information. It records the grayscale change event stream through an event camera and outputs event stream information. It synchronously obtains visible light image information and infrared image information through a dual-band camera. After aligning the timestamps of the above temperature information, strain information, point cloud information, spectrogram information, event stream information, and dual-band image information, the perception fusion unit outputs fusion feature data and attitude matrix data using the gated sparse tensor fusion method.
[0010] Preferably, when performing gated sparse tensor fusion, the perception fusion unit sets a gated weight tensor. The element values of the gated weight tensor are between zero and one. The perception fusion unit performs weighted parallel multiplication and addition operations on the tensors of each perception channel according to the gated weight tensor to reduce the redundant feature dimension and improve the sparsity of feature representation.
[0011] Preferably, the prediction and risk assessment unit uses a spatio-temporal model based on a graph neural network to map the fusion feature data into graph structure node features and edge features, uses a multi-head attention mechanism to propagate messages between nodes, and iteratively updates the node representation within a fixed number of time steps and outputs disaster prediction data and propagation potential energy data.
[0012] Preferably, the prediction and risk assessment unit uses a generative adversarial correction method to generate a perturbation tensor, superimposes the perturbation tensor on the disaster prediction data and inputs it into a discriminant network. After the discriminant network outputs the confidence level, it updates the parameters of the generative network. The prediction and risk assessment unit calculates the risk entropy data based on the corrected disaster prediction data. The risk entropy data measures the system hazard uncertainty through the logarithmic probability summation method.
[0013] Preferably, the interlock control unit constructs a binary unconstrained optimization model based on the fusion feature data, propagation potential energy data, and risk entropy data. The objective function of the optimization model consists of a linear combination of minimizing the number of actions and minimizing the dangerous potential energy. The interlock control unit maps the Boolean variables in the optimization model into a binary unconstrained optimization matrix and inputs it into the quantum annealing solver.
[0014] Preferably, after the quantum annealing solver outputs a Boolean vector, the interlock control unit introduces a minimax game strategy to perform three rounds of strategy corrections on the Boolean vector. Each round of strategy correction uses the dangerous potential energy difference as the payoff function. After completing the strategy corrections, the interlock control unit determines the minimum action set data.
[0015] Preferably, the interlock control unit writes the minimum action set data into the memristive programmable logic array. The cross-wire voltage of the memristive programmable logic array is set by the interlock control unit to a first high level and a second low level. The first high level is used to indicate that the action bit is one, and the second low level is used to indicate that the action bit is zero.
[0016] Preferably, the execution and feedback unit mixes carbon dioxide and phase change aerogel through a two-phase flow injection device to form a supercritical mixed medium. After receiving the interlock instruction stream data, the execution and feedback unit drives the throttle valve group to inject the supercritical mixed medium in a pulsed manner for cooling and smothering fire extinguishing.
[0017] Preferably, after receiving the interlock instruction stream data, the execution and feedback unit uses the variational path optimization method to generate a robot path based on the propagation potential energy data and risk entropy data. The robot path is determined by minimizing the path energy and the line integral of the dangerous potential energy. The execution and feedback unit controls the robot detachment to move along the robot path and perform on-site disposal tasks. At the same time, it collects valve position feedback data and robot status data and encapsulates them in an event stream format. The event stream format is written into the event stream by the perception fusion unit for the prediction and risk assessment unit and the interlock control unit to perform model update and action correction.
[0018] Compared with the prior art, the advantages and beneficial effects of the present invention are as follows:
[0019] The present invention achieves sub-microsecond data synchronization through multimodal redundant perception + gated sparse fusion, eliminating the false alarm defect of a single sensor; the present invention achieves three-second advance prediction of flames and leaks through a spatiotemporal model based on a graph neural network and generative adversarial correction, overcoming the fixed threshold hysteresis; the present invention combines quantum annealing with minimax game to obtain the minimum action set, achieving an average reduction of 30% in the number of interlocking actions and solving the problem of excessive shutdowns; the present invention achieves "power-off retention" through instantaneous solidification of instructions through a memristive programmable logic array, avoiding the risk of high-temperature reloading; the present invention drives the robot to cooperate with the two-phase flow jet through variational path optimization, achieving rapid cooling and safe passage of the high potential energy area, avoiding damage to the robot. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 is an interactive schematic diagram of the system of the present invention;
[0021] Figure 2 Schematic diagram of the spatiotemporal prediction and adversarial correction pipeline in the present invention. DETAILED DESCRIPTION
[0022] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure.
[0023] like Figure 1 As shown, an interlock control device for petroleum and petrochemical fire protection based on SIS includes:
[0024] a perception fusion unit, configured to collect multi-source data including at least a fiber optic sensor and a radar sensor, synchronize and fuse the collected data, output fused feature data and attitude matrix data, and send the fused feature data to the prediction and risk assessment unit, and send the attitude matrix data to the execution and feedback unit;
[0025] The perception fusion unit assumes the primary function of the data link of the present invention, namely, acquiring redundant on-site information in the petroleum and petrochemical tank area where high temperature, high humidity and strong electromagnetic interference coexist, and then compressing the multi-channel asynchronous signals into a time-space consistent feature tensor and attitude matrix, ensuring that the SIS (Safety Instrumented System) can complete hazard identification and interlock triggering at the millisecond level.
[0026] The fiber optic sensors are continuously laid along the tank wall and the oil pipeline trench, and the Brillouin scattering principle is used to demodulate temperature and strain simultaneously. There is a monotonic correspondence between the center frequency of the Brillouin gain spectrum and the local temperature and strain. Therefore, the system can quickly reverse infer the stress concentration area through the rolling look-up table algorithm. The radar sensor at the same position emits a linear frequency modulated continuous wave. After mixing at the receiving end, a beat frequency signal is obtained, and then the distance amplitude spectrum can be obtained through fast Fourier transform. By splitting the angle dimension with a multi-channel antenna, a three-dimensional coordinate point cloud can be output. The fiber optic and the radar form a two-stage redundancy for temperature and three-dimensional deformation. If a thermal runaway causes the temperature rise of the fiber core and the attenuation of the radar echo at the same time, the credibility of the false alarm threshold can be significantly improved.
[0027] There are significant differences in the sampling frequencies of multi-source signals; the typical sampling period of the fiber optic channel is in the millisecond level, and the radar point cloud is refreshed about twenty frames per second. If each stream is directly written into the spatio-temporal model, it will lead to the accumulation of feature alignment errors. Therefore, the present invention realizes a multi-scale phase convolution alignment mechanism inside the edge FPGA. This mechanism uses the local oscillator phase of the fiber optic sampling as a reference, and convolves the local oscillator phase signals of the radar, acoustic, event stream, and dual-band image with Morlet basis functions of three scales respectively, and obtains the cross-channel time deviation by minimizing the three-scale convolution residual. The measured results show that the maximum time difference after synchronization is less than one microsecond, which can meet the requirement of the interlock logic for the timing consistency of not more than ten microseconds.
[0028] After completing the time alignment, the six-channel data are mapped to a unified tensor . In order to reduce the redundant dimensions while maintaining the key signals, the present invention realizes gated sparse tensor fusion on the edge FPGA. The system assigns a gated weight tensor of the same dimension to the tensor , and the weight range is limited between zero and one. The optimal gated weight is obtained through three-channel exponential compensation gradient descent training on the edge side. The fused tensor is calculated according to the following formula:
[0029]
[0030] where the symbol represents element-wise multiplication. In the formula, is the fused feature tensor, is the gated weight tensor, and is the original tensor after alignment. During the training stage, the absolute value one-norm regularization is introduced for , so that the sparsity rate is kept within 15%. In actual verification, the tensor dimension is compressed from more than one thousand two hundred dimensions to two hundred and fifty-six dimensions, and the information integrity is maintained above 90%. At the same time, the computational amount of the downstream graph neural spatio-temporal model is reduced by three times.
[0031] The pose matrix is generated by the point cloud-vision registration module. The system selects fifteen stable feature points each from the point cloud and the visible light image. The Iterative Closest Point (ICP) algorithm obtains the rotation matrix and displacement vector by minimizing the sum of the squared Euclidean distances, and then gets a 4x4 homogeneous transformation matrix. This matrix can synchronize the coordinates of any sensor in the tank farm environment to a unified coordinate system and provide a world coordinate system reference for robot kinematics and path planning. The root mean square error of the registration residual is kept within three centimeters, which can support the safe movement of the robot in the narrow valve group channel.
[0032] The fused feature tensor and the pose matrix are written into the prediction and risk assessment unit through a double 128-bit bus. To verify the effect of the perception fusion unit, the prototype system conducts an ignition test in a 1:1 tank farm test area. When the three-way features of the fiber optic temperature, event edge density, and radar point cloud sparsity rate show a linked increase, the system re-weights the features of the fusion tensor. Thirty milliseconds later, the prediction and risk assessment unit generates the flame spread path. Compared with the infrared image-only solution, the multi-source redundancy solution of the present invention issues the first interlock warning 900 milliseconds earlier and completes two iterations and one game correction within the subsequent quantum solution window to ensure the minimization of the output action concentration of the interlock control unit.
[0033] Preferably, the perception fusion unit obtains the Brillouin frequency shift through a distributed fiber optic sensor and demodulates the Brillouin frequency shift into temperature information and strain information, transmits a frequency-modulated continuous wave through a millimeter-wave radar sensor and performs a fast Fourier transform on the echo to obtain point cloud information, converts the acoustic signal into an electrical signal through an acoustic crystal sensor and performs a short-time Fourier transform to obtain spectrogram information, records the grayscale change event stream through an event camera and outputs event stream information, synchronously obtains visible light image information and infrared image information through a dual-band camera. After aligning the timestamps of the above temperature information, strain information, point cloud information, spectrogram information, event stream information, and dual-band image information, the perception fusion unit outputs fused feature data and pose matrix data using the gated sparse tensor fusion method.
[0034] The design goal of the perception fusion unit is to compress six-way heterogeneous sensing information into a unified feature tensor and pose matrix within the millisecond scale, providing low-noise and temporally consistent input for the spatio-temporal prediction of the SIS. The sensor selection takes into account the early syndrome signs of combustible medium leakage and the tolerance performance under extreme working conditions. Among them, the distributed fiber optic sensor is responsible for real-time sensing of temperature rise and structural deformation along the tank wall, pump area, and pipeline; the millimeter-wave radar sensor can still output continuous point clouds in the thick smoke environment generated by an explosion; the acoustic crystal sensor is for the acoustic oscillations generated during high-pressure fluid injection; the event camera is extremely sensitive to the sub-millisecond grayscale changes at the flame edge; the dual-band camera maintains imaging quality under the high heat radiation background through two optical paths of visible light texture and mid-infrared radiation.
[0035] The Brillouin scattering frequency shift has a linear relationship with the medium temperature and axial strain. After injecting a pulse at the fiber end, the system measures the center frequency of the echo gain spectrum and uses an interpolation and look-up table algorithm to convert the tank wall temperature and local stress in real time. The radar end adopts a frequency-modulated continuous wave system. The transmitted and received signals are mixed to obtain a beat frequency signal, and then the fast Fourier transform is performed to separate the distances of multiple targets. The pitch angle of the point cloud is inverted from the phase difference of the antenna array, and the temperature sensitivity of the radar hardware gate drift is compensated by a phase-locked loop. The acoustic crystal sensor body is a high-quality factor optical microcavity. The refractive index change caused by acoustic strain is converted into a subtle shift of the transmission spectrum, and then the short-time Fourier transform is used to output the acoustic spectrum tensor. The event camera directly records the sudden change of pixel grayscale. The data volume is much lower than that of frame-by-frame imaging, and denoising based on the histogram distribution can be completed within the edge FPGA; the dual-band camera uses a confocal lens group, and the visible light and mid-infrared are imaged onto the same optical axis by using a beam splitter prism to reduce the registration error.
[0036] When the six-channel data arrives at the FPGA, it first enters the multi-scale phase convolution alignment module. Taking the sampling clock of the fiber channel as a reference, the local oscillator phase signal is convolved with three-level Morlet wavelets respectively, and the position with the minimum sum of squared residuals is the cross-channel time difference. This method maintains sub-microsecond-level alignment accuracy in the simulation of one hundred thousand frames of random drift. The tensors of each aligned channel are spliced into a unified tensor. Tensor fusion uses a gated sparse strategy: Set the weight tensor of the same dimension and train it through end-side gradient descent and add the l1 norm regularization to keep the sparsity rate at 15%. The core fusion calculation formula is:
[0037]
[0038] After training, the dimension of the fused feature tensor is reduced from more than one thousand two hundred dimensions to two hundred and fifty-six dimensions, and the average information fidelity remains above 90%.
[0039] The attitude matrix is generated by using the fast iterative closest point algorithm. Fifteen groups of corner points are extracted from the point cloud and the visible light image respectively. The rotation matrix and translation vector are obtained through least squares optimization and combined into a four-by-four homogeneous coordinate transformation matrix, which is directly used as the benchmark for the robot path planning and the deployment angle of the thermal shield. The actual verification in the tank area shows that the root mean square error of the registration residual is less than three centimeters, so that the deviation of the robot path from the valve center on the narrow valve group platform does not exceed five centimeters.
[0040] To verify the contribution of the perception fusion unit to the interlock response time, the prototype system conducted a high-pressure gasoline spray ignition test on a one-to-one steel tank platform. The scheme relying solely on infrared images reached the interlock threshold 200 milliseconds after the fireball appeared; the scheme of the present invention triggered the precursor path of the prediction unit when the temperature of the optical fiber increased by one degree Celsius, the radar echo intensity decreased by 5%, and the gray mutation of the event camera covered 3% of the tank opening, completing the calculation window of the interlock action about one second earlier than the image scheme. This time difference allows the quantum annealing solver to perform an additional minimax search based on a 500-microsecond annealing, further reducing the redundancy of the minimum action set by 30%.
[0041] Another group of experiments simulated gasoline pump leakage at the fueling island. The acoustic crystal sensor detected high-speed bubble phonons earlier than other channels, and obvious low-frequency peaks appeared in the short-time Fourier spectrum; some point clusters were lost in the radar point cloud under spray occlusion; there was no significant increase in the temperature of the optical fiber. After multi-source fusion, the gating weights automatically increased the proportion of the spectral and point cloud dimensions, enabling the prediction unit to regard leakage rather than combustion as the priority hazard source. Finally, the interlock system selected a low-action opening scheme, only closing the leaking pump and moving the robot carrying the dry powder module to the downwind side of the tank in advance, winning 30 seconds for subsequent explosion suppression layout time.
[0042] Preferably, when the perception fusion unit performs gated sparse tensor fusion, it sets a gating weight tensor. The element values of the gating weight tensor are between zero and one. The perception fusion unit performs weighted parallel multiplication and addition operations on the tensors of each perception channel according to the gating weight tensor to reduce the redundant feature dimensions and improve the sparsity of feature representation.
[0043] The key to the perception fusion unit to complete tensor fusion lies in the adaptive learning of the gating weight tensor. First, the multi-source channel data aligned by timestamps are sequentially concatenated into a unified tensor . The system creates a weight register array inside the edge field programmable gate array. The size of the array is exactly the same as the tensor . Each storage unit in the register array corresponds to an element of the gating weight tensor . In the initialization stage, all storage units are written with 0.5, indicating that the feature contributions of each channel are the same. Subsequently, it enters the online training process: on the continuously collected new data stream, the system takes the disaster prediction error as the objective function and updates the weights through element-wise gradient descent. To ensure sparsity, after each update, an absolute value one-norm constraint is imposed on the gating weight tensor. When the cumulative weight of a certain row or column is too low, it is directly set to zero, closing the data path of the invalid dimension at the hardware level.
[0044] The core formula is:
[0045]
[0046] where represents element-wise multiplication; is the output fused feature tensor; is the gating weight tensor, and the element value range is from zero to one: is the aligned channel feature tensor.
[0047] During calculation, the edge field programmable gate array completes multiplication and accumulation in a pipelined manner, and a row of tensor results can be obtained in a single cycle. Since a large number of elements have been sparsely set to zero, the corresponding multipliers can be shut down, and the power consumption of the field programmable gate array is reduced by more than 25%.
[0048] The weight update strategy adopts a two-step method. First, accumulate the prediction residuals of the last three frames in the field programmable gate array, and calculate the channel contribution degree by looking up the table, and then perform a gradient descent on the fusion processor. The gradient update formula is:
[0049]
[0050] where is the prediction loss function, is the learning rate, is the time of the weight value. To prevent the weight from drifting to extreme values of zero or one, perform a clamping operation on after update. This not only maintains the sparse structure but also avoids information loss caused by permanent channel shielding.
[0051] The above mechanism directly improves the accuracy of SIS in the scenario of early dangerous syndrome identification. Taking the ignition of hydrocarbon gas leakage in a crude oil tank area as an example: Before the formation of the flame, the acoustic crystal sensor first detects the high-frequency whistling sound of the shell microcrack, and the radar point cloud also shows obvious fluctuations in the refraction distortion caused by the leakage airflow, while the fiber optic temperature has not yet increased. After three-frame weight update, the gating weight tensor automatically increases the weight values of the spectrogram and point cloud channels, reduces the weight values of the event camera and the dual-band camera, and the energy proportion of the output fused feature tensor in the spectrogram and geometric dimensions increases to 45%. The risk assessment unit immediately increases the pre-combustion hazard entropy by two orders of magnitude, and the interlock control unit generates the minimum action set 300 milliseconds in advance, and instructs the robot team to deploy inerting sprays on the downwind side. The entire process completes explosion isolation two seconds earlier than the traditional single-channel trigger strategy based on fiber optic temperature rise.
[0052] In another comparative experiment, the system artificially reduced the radar transmission power to simulate hardware failure. After the gated weight tensor detected a sudden drop in the information entropy of the point cloud dimension, it reduced the relevant weights within 100 milliseconds and increased the proportion of the event camera and infrared image dimensions. Finally, the overall information volume of the fused feature tensor only decreased by 5%, ensuring that the spatio-temporal model could still output a stable flame spread path. This result shows that the weight tensor enables the perception fusion unit to have the ability to dynamically allocate computing power and bandwidth, and can quickly transfer attention to effective channels when any channel degrades, enhancing the reliability of the large SIS interlock system.
[0053] The combination of the hardware implementation of gated sparse tensor fusion and online weight training realizes the real-time compression and channel adaptive scheduling of high-dimensional perception data. In scenarios such as oil and petrochemical fires with high smoke, high heat radiation, and easy sensor failure, this design significantly reduces data bus congestion, improves prediction accuracy, provides low-dimensional inputs with high credibility for subsequent quantum optimization and interlock decision-making, thereby shortening the overall closed-loop delay of the system and ensuring the safety and efficiency of multi-robot collaborative fire extinguishing.
[0054] As Figure 2 shown, a prediction and risk assessment unit is used to establish a spatio-temporal model based on the fused feature data to generate disaster prediction data and propagation potential energy data, calculate risk entropy data, and send the disaster prediction data, propagation potential energy data, and risk entropy data to the interlock control unit;
[0055] The prediction and risk assessment unit plays the role of "foresight + quantification" in the SIS. It uses the fused feature data to restore the three-dimensional topology and thermal-mass coupling state of the tank farm, gives the disaster evolution trend several seconds in advance, and measures the overall uncertainty with a single scalar, providing a directly comparable input basis for the interlock control unit. The system first maps the fused feature data into a heterogeneous graph according to the physical positions of the sensors: the nodes correspond to storage tanks, pipe manifolds, valve islands, and robots, and the edges represent heat transfer, combustible diffusion, and shock wave coupling. Subsequently, a spatio-temporal model is run on the graph, and the core is a two-stage graph neural network. The first stage performs multi-head attention aggregation on the information at the current moment to extract the instantaneous coupling between nodes; the second stage uses a gated recurrent unit to splice the historical hidden state and the instantaneous coupling to obtain the first-order time derivative, thereby outputting the disaster prediction data, that is, the estimated values of the temperature, concentration, and shock pressure of each node at future moments. The propagation potential energy data is converted from the disaster prediction data by accumulating the temperature gradient and combustible concentration gradient of the node pairs on each edge. The edges with larger gradients have higher potential energy weights, which can intuitively represent the spread tendency of flames or high-pressure steam.
[0056] To summarize the multi-dimensional potential energy distribution into a single-valued quantization index, the unit further calculates the risk entropy data. First, the propagation potential energy data is normalized to the probability of dangerous chain events occurring for node pairs , and then use:
[0057]
[0058] Define risk entropy. Where represents the risk entropy, Representation node To Node The probability of a dangerous event occurring between the two paths. The more uniform the probability, the higher the entropy, indicating multiple possible paths in the dangerous chain. When the probability is concentrated on a few paths, the entropy decreases, indicating that the key weak points have been identified. The interlocking control unit uses this information to determine the coverage of the action set: when the risk entropy exceeds a preset threshold, the action set not only cuts off the leak source but also deploys robots to suppress explosions at multiple nodes. When the risk entropy is below the threshold, only local interlocking is implemented for the high-probability paths.
[0059] A prototype system was tested in a 9,000 cubic meter crude oil tank farm. While a solution using only visible light cameras triggered an alarm only 200 milliseconds after the flame appeared, the prediction and risk assessment unit of the present invention outputted disaster prediction data and generated high-gradient propagation potential energy data when the fiber temperature rose by 0.8 degrees Celsius and the radar point cloud density decreased by 8%. The risk entropy reached a critical value, and the minimum action set was pushed to the interlock control unit one second in advance. Ultimately, the spray device and robotic team intervened before the flame formed, effectively limiting the flame's spread radius. In another test involving a leak but no combustion, the acoustic sensor first detected a crackle whistle. The model automatically downgraded the temperature rise weight and increased the sound spectrum weight, maintaining a moderate risk entropy level. The interlock action only shut down the leaking pump and deployed an inerting spray, avoiding a false triggering of a station-wide pump shutdown and minimizing unnecessary losses.
[0060] Through graph-structured modeling and risk entropy quantification, the prediction and risk assessment unit compresses the high-dimensional dynamic disaster field into three intuitive and computable outputs: disaster prediction data, propagation potential data, and risk entropy data. These outputs are used as decision criteria for action positioning, action range, and action redundancy, respectively. This enables proactive control of complex disaster chains in petroleum and petrochemical scenarios, significantly improving the response speed and interlocking accuracy of the SIS under extreme conditions.
[0061] Preferably, the prediction and risk assessment unit adopts a spatiotemporal model based on graph neural networks, maps the fused feature data into graph structure node features and edge features, adopts a multi-head attention mechanism to propagate messages between nodes, iteratively updates the node representation within a fixed number of time steps, and outputs disaster prediction data and propagation potential data.
[0062] The prediction and risk assessment unit undertakes the function of "restoring on-site transient observations to the disaster evolution picture in the next few seconds". To meet the requirements of the SIS for a millisecond-level foresight window, this unit uses a spatio-temporal model based on graph neural networks to transform the fused feature data into iteratively updatable node representations and edge representations, and then uses multi-head attention to propagate information in the graph. This method can not only maintain the physical interpretability of the topological structure but also give high-resolution predictions for complex heat-mass coupling processes.
[0063] The fused feature data output by the perception fusion unit is first mapped to a heterogeneous graph. The node set covers five categories: storage tanks, pipeline pumps, inlet and outlet manifolds, robots, and personnel; the edge set corresponds to four types of interactions: heat conduction, combustible gas diffusion, shock wave radiation, and personnel movement. Each node is attached with the current temperature, combustible gas concentration, pressure, and local three-dimensional pose, and each edge is attached with the Euclidean distance, damping coefficient, and relative orientation between node pairs. This graph is stored internally as a sparse adjacency matrix and a feature matrix for fast indexing in the graph neural network.
[0064] The spatio-temporal model of the graph neural network consists of two stacked segments. The first segment is a static topology encoder that uses the multi-head attention mechanism to consider both directional and category correlations between nodes. In one propagation, each node splits its own representation into several attention heads, then linearly combines and normalizes it with the representations of adjacent nodes to obtain a new node representation. Since there is a fixed relationship between the storage tank and the valve island in the physical structure, the attention weights will explicitly reflect the dominant paths of heat and mass flow after training. The second segment is a time updater that uses a gated recurrent unit to combine the current node representation with the hidden state of the previous moment and outputs a new hidden state, thereby generating a node evolution sequence within a fixed time step. The hidden state output can obtain the disaster prediction data through a linear transformation, including the predicted values of the node temperature, concentration, and pressure corresponding to several future time steps. The propagation potential energy data accumulates the temperature gradient and concentration gradient of node pairs on each edge and multiplies by the damping coefficient. Edges with high values indicate that the fire or shock wave is more likely to spread.
[0065] To compress the multi-dimensional potential energy distribution into a single quantization index, this invention introduces risk entropy. First, the propagation potential energy data is normalized to obtain the probability of a dangerous chain reaction. If the distribution of dangerous propagation paths is relatively uniform, the risk entropy increases, indicating that the interlock control unit needs to prepare actions with a wider coverage range; if the probability is concentrated on a few paths, the risk entropy decreases, and the interlock action can be locked on key nodes to achieve the minimum action principle. In this expression, the natural logarithm is selected for the logarithmic operation, and the entropy unit is dimensionless, which is easy to normalize with other indicators.
[0066] During online operation, the prediction and risk assessment unit receives new fused feature data every 100 milliseconds for a node update, and then outputs the disaster prediction data and propagation potential energy data from the next second to the next three seconds through a sliding window. At the same time, the latest risk entropy is pushed to the interlock control unit together with the other two types of data. The interlock control unit directly adds the risk entropy to the objective function to punish or reward the Boolean action vector output by the quantum annealing, so that the minimum action set not only meets the safety redundancy but also avoids excessive pump shutdown and mis-spraying of coolant.
[0067] Taking the leakage and ignition of a 9000-cubic-meter crude oil tank as an example. In the initial stage of the accident, the acoustic sensor detected the stress wave inside the thin-walled tank shell, the gas refraction area appeared at the edge of the radar point cloud, and the event camera captured the dense gray-scale events generated by the spray jet. After the model converged, the node temperature prediction continuously increased within 900 milliseconds, and the potential energy of the two edges connecting the tank body and the manifold increased rapidly. The risk entropy increased from the baseline value to 1.5 times, and the interlock control unit immediately generated an action set, first cutting off the bypass pipeline and then dispatching a robot to carry a dry powder module to spray at the bottom of the tank. When the flame appeared, the temperature of the tank wall decreased by 20 degrees Celsius compared with the unforeseen plan, effectively blocking the bottom heat radiation.
[0068] In another case of gas leakage but without combustion, the model regarded the increase in node pressure and concentration as the priority danger signal, and the weight of temperature change was automatically adjusted downward by the multi-head attention. As a result, the propagation potential energy was concentrated on the edge from the leakage point to the personnel passage downstream of the wind direction, and the risk entropy remained at a medium level. The interlock action only closed the leakage pump and arranged an inerting spray, without triggering a total station shutdown, avoiding economic losses to the normal loading area. This case demonstrates that the spatio-temporal model of the graph neural network can adaptively adjust the contribution ratio of different node features to the hazard assessment.
[0069] In summary, the prediction and risk assessment unit realizes the fine prediction of node local evolution through the spatio-temporal model of the graph neural network, and realizes the quantifiable assessment of the overall danger chain through the propagation potential energy and risk entropy. This design not only significantly shortens the warning delay of the SIS but also provides a structured input that can be directly used for optimization and solution to the interlock control unit, thus maintaining the unity of the minimum action principle and the global safety goal under extreme working conditions. The risk entropy formula is as follows:
[0070]
[0071] In the formula represents the risk entropy, represents the node to node the probability of a dangerous event occurring between them.
[0072] If the distribution of dangerous propagation paths is relatively uniform, the risk entropy increases, indicating that the interlock control unit needs to prepare for actions with a wider coverage; if the probability is concentrated on a few paths, the risk entropy decreases, and the interlock actions can be locked on key nodes to achieve the principle of minimum actions. In this expression, the natural logarithm is selected for the logarithmic operation, and the entropy unit is a dimensionless quantity, which is easy to normalize with other indicators.
[0073] During online operation, the prediction and risk assessment unit receives new fused feature data every 100 milliseconds for node update, and then outputs the disaster prediction data and propagation potential energy data from the next second to the next three seconds through a sliding window. At the same time, the latest risk entropy is pushed to the interlock control unit together with the other two types of data. The interlock control unit directly adds the risk entropy to the objective function to punish or reward the Boolean action vector output by quantum annealing, so that the minimum action set can not only meet safety redundancy but also avoid excessive pump shutdown and mis-spraying of coolant.
[0074] Take the leakage and ignition of a 9000-cubic-meter crude oil tank as an example. At the initial stage of the accident, the acoustic sensor detected the stress wave inside the thin-walled tank shell, a gas refraction area appeared at the edge of the radar point cloud, and the event camera captured the dense gray-scale events generated by the spray jet. After the model converged, the node temperature prediction continuously increased within 900 milliseconds, and the potential energy of the two edges connecting the tank body and the pipe manifold increased rapidly. The risk entropy increased from the baseline value to 1.5 times, and the interlock control unit immediately generated an action set, first cutting off the bypass pipeline, and then dispatching a robot to carry a dry powder module to spray at the bottom of the tank. When the flame appeared, the temperature of the tank wall was 20 degrees Celsius lower than that of the unforeseen plan, effectively blocking the bottom heat radiation.
[0075] In another case of gas leakage but without combustion, the model regarded the increase in node pressure and concentration as the priority danger signal, and the weight of temperature change was automatically adjusted downward by multi-head attention. As a result, the propagation potential energy was concentrated on the edge from the leakage point to the personnel passage downstream of the wind direction, and the risk entropy remained at a medium level. The interlock action only closed the leakage pump and arranged inerting spray, without triggering a total station shutdown, avoiding economic losses to the normal loading area. This case reflects that the spatio-temporal model of the graph neural network can adaptively adjust the contribution ratio of different node features to the danger assessment.
[0076] In summary, the prediction and risk assessment unit realizes the fine prediction of node local evolution through the spatio-temporal model of the graph neural network, and realizes the quantifiable assessment of the overall danger chain through the propagation potential energy and risk entropy. This design not only significantly shortens the warning delay of the SIS but also provides structured input that can be directly used for optimization and solution to the interlock control unit, so as to still maintain the unity of the minimum action principle and the global safety goal under extreme conditions.
[0077] Preferably, the prediction and risk assessment unit uses the generative adversarial correction method to generate a perturbation tensor, superimposes the perturbation tensor on the disaster prediction data and inputs it into the discriminant network. After the discriminant network outputs the confidence level, the parameters of the generative network are updated. The prediction and risk assessment unit calculates the risk entropy data based on the corrected disaster prediction data, and the risk entropy data measures the system hazard uncertainty through logarithmic probability summation.
[0078] The prediction and risk assessment unit in the SIS is responsible for converting the fused feature data into a credible prediction of the disaster evolution in the next few seconds, and at the same time quantifying the uncertainty of the prediction result. Although the disaster prediction data output by the spatio-temporal model has considered multi-source information, there may still be deviations in the oil and petrochemical site due to sensor distortion, air turbulence or occlusion. To avoid the interlock action relying only on a single path, the present invention introduces a generative adversarial correction method, actively constructs a perturbation tensor subject to physical constraints, injects the worst-case scenario into the disaster prediction data, then uses the discriminant network to verify the feasibility of the perturbation, and dynamically adjusts the generative network according to the discriminant result to make the risk assessment more robust.
[0079] The core framework consists of a generative network and a discriminant network. The generative network outputs a perturbation tensor after inputting random noise, and the perturbation tensor is added element by element to the disaster prediction data to obtain a correction candidate; the discriminant network receives the original prediction data and the correction candidate and outputs a binary classification confidence level. The goal of the generative network is to maximize the misjudgment probability of the discriminant network within the physically feasible range, and the goal of the discriminant network is to accurately identify the true prediction and the correction candidate. The two are alternately trained, so that the generative network gradually captures potential scenarios that cause prediction failure, such as the concentration peak of local gas clouds, the instantaneous blockage of the tank breather valve, etc.
[0080] To ensure that the perturbation tensor conforms to the heat and mass conservation constraints, the system sets an energy upper limit on the output of the generative network, that is, the temperature increment and concentration increment of the perturbation tensor at each node must be kept within the range of the on-site sensor range, and the overall heat increment must not exceed the initial latent heat budget. If the output of the generative network exceeds the constraint, it is directly scaled to the upper limit. This strategy not only prevents the model from diverging, but also allows the discriminant network to learn the truly reachable dangerous states.
[0081] The discriminant network structure is a double-layer convolutional kernel plus a fully connected layer. The first layer extracts local spatial gradient features, and the second layer focuses on overall connectivity. The cross-entropy loss of the discrimination result is used to update the parameters of the generative network. In the inference stage, the network is no longer updated, only a perturbation tensor is generated once and overwritten on the disaster prediction data to obtain the corrected prediction. Subsequently, the propagation probability matrix is calculated, the propagation potential energy of each pair of nodes after correction is normalized to the interlock event probability, and then the risk entropy is calculated. The higher the entropy value, the more dispersed the distribution of dangerous paths, and the interlock control unit needs to prepare actions with a wider coverage; the decrease in the entropy value indicates that the danger tends to a single link, and local actions can be used to suppress it.
[0082] Illustrate the leakage scenario of the outlet flange of a high-pressure light oil pump. The on-site sensor captures a slightly rising ambient temperature and a sparse radar point cloud. The spatio-temporal model predicts that the gas cloud will diffuse towards the loading station within two seconds. The generative network outputs a perturbation tensor to further increase the concentration in the crowded area. The discriminative network determines that the perturbation meets the flammable concentration range. After calibration, the propagation probability towards the loading station doubles, and the risk entropy rises above the threshold. Based on this, the interlock control unit increases the operation of the ventilation fan of the enclosed loading island and deploys robots to pre-place dry powder around the loading station. If no adversarial calibration is performed, the original model only predicts local hazards in the tank farm, which may lead to insufficient protection for downwind people.
[0083] Next, look at the scenario where the breather valve at the top of the liquefied petroleum gas spherical tank freezes and clogs. The original prediction data already shows an increase in the pressure at the top of the spherical tank. After the generative network randomly perturbs, it wants to further increase the pressure, but the physical constraints limit the coupling of temperature and pressure. The discriminative network quickly identifies that this perturbation is not feasible, and the confidence output is lower than the threshold. The generative network reduces the perturbation amplitude to the allowable range according to the loss. Finally, the change in the propagation potential energy after calibration is not significant, and the risk entropy remains at a medium level. The interlock actions focus on opening the top safety valve and remote spraying, without the need for large-scale evacuation of personnel, improving the disposal efficiency.
[0084] Compared with the traditional Monte Carlo method, the generative adversarial calibration of the present invention can obtain the most influential feasible perturbation in one iteration, avoiding a large number of sample tests. The local safety factor is dynamically compensated by calibration, enabling the SIS to still have the pre-judgment ability in the face of unknown or low-frequency extreme conditions. System tests show that the average error of the risk entropy is less than 5% under more than two thousand different working conditions, the redundancy rate of the interlock action is reduced by about 30%, and the response time is shortened by 20%. The generative adversarial calibration method provides a perspective closer to the real worst-case scenario for the evaluation unit, significantly improving the reliability and flexibility of the SIS interlock.
[0085] The interlock control unit is used to construct an optimization model based on the fused feature data, propagation potential energy data, and risk entropy data, obtain the minimum action set data through an optimization solver, write it into a programmable logic array, and then output an interlock instruction stream to trigger the SIS interlock action;
[0086] The task of the interlock control unit is to give the smallest set of actions that meet the requirements of the functional safety level within the millisecond time scale, enabling the SIS to complete isolation, explosion suppression, and fire extinguishing with the most economical actions and the shortest path. The unit inputs three types of data: the fused feature tensor, the propagation potential matrix, and the risk entropy scalar. The fused feature tensor records the current comprehensive state of each node; the propagation potential matrix describes the spreading ability of the hazard along the edges; the risk entropy scalar reflects the concentration of the hazard path distribution. The interlock control unit first maps the above inputs to a weighted directed graph: the nodes inherit the features such as temperature, pressure, and concentration in the tensor, and the edge weights are equal to the propagation potential values. Subsequently, a binary optimization model is constructed, and each candidate action is encoded as a Boolean variable , where a value of one indicates the execution of the action, and a value of zero indicates the non-execution of the action. The total number of variables is . The action types include five categories: cutting off the oil transfer pump, shutting off the solenoid valve, robot placement, triggering the injection medium, and deploying the thermal shield.
[0087] The objective function consists of two parts: the number of actions and the residual hazard:
[0088]
[0089] In the formula is the action cost coefficient, is the hazard potential coefficient, represents the propagation potential value from node to node . The first term encourages reducing the number of actions, and the second term penalizes the situation where the high-potential edges are not covered. The model constraints include the interlock dependence between the pump group and the valve group, the upper limit of the number of robot placements in the same area, and the lower limit of the remaining inventory of the fire extinguishing agent. The interlock control unit first uses a parser to convert the objective function and constraints into a binary unconstrained optimization matrix, and then sends it to the quantum annealing solver. Quantum annealing can search the exponential-scale state space simultaneously at the microsecond level, so it can output a high-quality Boolean vector within the strict response time limit.
[0090] After the solver returns the Boolean vector, the unit introduces a zero-sum game correction mechanism. The two players in the game represent the action set and the hazard potential respectively, and the payoff function is selected as the difference between the increment of the hazard potential and the action execution cost. Through three rounds of minimax search, the system makes marginal adjustments to the quantum solution, eliminates the isolated actions that may be generated by quantum noise, and at the same time ensures that the high-potential paths are effectively covered. The data of the corrected minimum action set is immediately written into the memristive programmable logic array. The memristive array represents the action bit one and zero with high and low levels respectively, and the writing time is on the order of nanoseconds, ensuring that the subsequent signal chain will not miss the interlock window due to configuration delay.
[0091] After the programmable logic array is modified, an interlocking instruction stream is generated. This instruction stream is encoded into four segments: pump group, valve group, robot, and injection device. Each segment contains an action bit, execution priority, and timeout threshold. Upon receiving the instructions, the on-site SIS triggers hardwired circuits and programmable safety controllers in order of priority, ensuring that core actions can be completed even in extreme situations such as power outages and bus congestion.
[0092] The examples show that in the scenario of crude oil tank wall leakage and ignition, the traditional interlocking logic based on fixed rules needs to execute twelve actions, all of which take 150 milliseconds to complete. The interlocking control unit of the present invention outputs only seven required actions, and the action sequence is completed within 100 milliseconds, while keeping the residual propagation potential energy in the tank area below the safety threshold. In another set of liquefied petroleum gas ball tank top pressure rise scenarios, the initial value of the risk entropy is low. This unit can eliminate the danger by outputting four local actions, avoiding the economic losses caused by the station-wide pump shutdown. Statistics of 2,000 simulations of different working conditions show that the combination of quantum annealing and game correction can reduce the number of actions by an average of 30% and shorten the interlocking response time by more than 25%.
[0093] By combining quantum global search, local game correction and instant writing of memristive logic, the interlocking control unit achieves a dynamic balance between the minimum action principle and functional safety redundancy, significantly improving the SIS's ability to make rapid decisions and reliable execution in high-risk scenarios in the petroleum and petrochemical industries.
[0094] Preferably, the interlocking control unit constructs a binary unconstrained optimization model based on the fused feature data, propagation potential energy data and risk entropy data, wherein the objective function of the optimization model is composed of a linear combination of minimizing the number of actions and minimizing the hazard potential energy. The interlocking control unit maps the Boolean variables in the optimization model into a binary unconstrained optimization matrix and inputs it into the quantum annealing solver.
[0095] The interlock control unit is designed to interrupt the disaster chain with the fewest actions possible while maintaining system interpretability, while meeting the functional safety level. To this end, the unit maps the three types of input from the prediction and risk assessment unit—fused feature data, propagation potential data, and risk entropy data—to a binary unconstrained optimization model. The core idea is to abstract each possible action into a Boolean variable, with a value of one indicating execution and zero indicating non-execution; all variables form a Boolean vector. To enable direct processing by the quantum annealing solver, the objective function and constraints must all be written in quadratic form with respect to Boolean variables, i.e., a binary unconstrained optimization matrix.
[0096] The action pool is divided into four groups according to physical categories: "cut-off type", "explosion suppression type", "spray type", and "path type". The cut-off type covers the main pump, the unloading pump, and each key valve position; the explosion suppression type refers to the distribution points where the robot carries dry powder or inerting agent; the spray type refers to the pulsed spray of the two-phase flow supercritical medium at the specified valve group; the path type is the weighted inspection of the high-potential nodes by the robot. Each action is assigned a unique index, forming a Boolean vector of length and . The objective function takes a linear combination: one term measures the total number of actions, and the other term measures the residual dangerous potential energy after passive coverage. It is formally denoted as:
[0097]
[0098] where is the action cost weight, is the dangerous potential energy weight; is a column vector of all ones; is a symmetric matrix, and the element is jointly derived from the propagation potential energy matrix and the risk entropy: when the propagation potential energy between node pairs is high and the risk entropy is prominent, the corresponding element is large, to encourage the selection of actions covering this path.
[0099] For the hard constraints in the oil and petrochemical scenarios, such as the mutual exclusion between the main pump and the bypass valve in the same circuit, the maximum number of distribution points of the robot, the lower limit of the fire extinguishing agent inventory, etc., they are uniformly written into the penalty function. The penalty function is multiplied by a large coefficient and then superimposed on the objective function, so that any Boolean vector violating the constraints is in a high-energy valley in the annealing energy diagram and will be automatically excluded during the solution.
[0100] At the implementation level, the interlock control unit first uses the processor to calculate the matrix and the coefficient according to the real-time input, and then expands the objective function into three parts: a constant term, a first-order term, and a second-order term and writes them into the quantum processor interface configuration file. The external quantum annealing chip has thousands of qubits and can complete one optimization in dozens of microseconds. The Boolean vector output by the quantum annealing is the candidate minimum action set.
[0101] To offset the random jitter that may be brought by the quantum annealing, the present invention adds a minimax game correction once. The payoff function is defined as "the decrease in the dangerous potential energy after performing the actions minus the number of actions multiplied by the unit cost". The algorithm performs three rounds of search on the local neighborhood of the quantum solution. If the payoff increases instead after some actions are removed, these actions will be removed in the next round; if adding a small number of actions can significantly reduce the dangerous potential energy, they will also be added. This can not only ensure the global optimal approximation but also filter out isolated and redundant actions.
[0102] Once the minimum action set is determined, it's written into the programmable logic array. The memristive crossbar array allows for a single-step write, eliminating the multi-stage download required by traditional FPGAs and reducing configuration time to hundreds of nanoseconds. The array outputs an interlocking instruction stream, formatted sequentially for pumps, valves, robots, and injection devices. Each action bit has an independent timeout threshold, ensuring that the SIS can still execute core actions according to hardwired circuits even in the event of communication anomalies.
[0103] Example 1: In a scenario involving a 9,000-cubic-meter crude oil tank bottom leak and fire, the beta coefficient was set to five, weighting the "minimum hazard potential" slightly higher than the action cost. Quantum annealing generated a 13-bit action vector, of which nine remained after game correction. This involved shutting down the leaking pump, activating the annular sprinkler, and dispatching two robots to guard the valve island. The entire process took 0.2 milliseconds for annealing and 0.4 milliseconds for correction, resulting in a total response time of 7 milliseconds. This reduced the number of actions by 40% compared to a traditional PLC rule table and reduced interlocking delay by one-third.
[0104] Example 2: Frosting of the breathing valve on a liquefied petroleum gas tank caused overpressure due to low temperatures. Risk entropy was low due to the single transmission path. The interlocking control unit assigned higher weight to the number of actions, and quantum annealing directly output four actions: activating the top safety valve, turning on the near-end exhaust fan, dispatching a single robot to deploy a quick-release spray, and issuing a personnel limit warning. This resulted in over 70 fewer operations than a conventional emergency pump shutdown solution, avoiding a complete station shutdown.
[0105] By combining a binary unconstrained optimization model with quantum annealing, the interlocking control unit can find a high-quality, low-redundancy action set in milliseconds while maintaining strict constraint satisfaction. For high-risk petroleum and petrochemical sites, this "minimum action principle" means lower downtime costs and higher personnel safety margins, demonstrating the invention's superior balance between functional safety and resource efficiency.
[0106] Preferably, after the quantum annealing solver outputs the Boolean vector, the interlocking control unit introduces a minimax game strategy to perform three rounds of strategy correction on the Boolean vector, with each round of strategy correction taking the dangerous potential energy difference as the benefit function. The interlocking control unit determines the minimum action set data after completing the strategy correction.
[0107] After the interlock control unit obtains the Boolean vector returned by the quantum annealing solver, it does not immediately use this vector as the final action set. Instead, it introduces a minimax game strategy to perform three rounds of strategy correction, aiming to further compress redundant actions and improve the coverage of critical danger chains without increasing the computational delay. The Boolean vector output by the quantum annealing solver often approaches the global optimum, but due to the random fluctuations of quantum annealing itself and the topological constraints of the hardware embedding graph, it may still contain "isolated switches" or miss low-energy but highly influential actions. The minimax game places the quantum solution and the danger potential matrix in an adversarial perspective, and redistributes the payoffs for the two through a finite number of rounds, ultimately obtaining a more robust minimum action set data.
[0108] The two players in the game are named the action agent and the potential agent respectively. The strategy space of the action agent is the switch selection for each bit in the Boolean vector; the strategy space of the potential agent is to dynamically adjust the weights in the propagation potential matrix to highlight the high-risk edges that have not been covered by actions. The payoff function is designed as the difference between the reduction of the danger potential and the newly added cost of the action. Mathematically expressed, when the Boolean vector undergoes the round of correction, the payoff function can be written as:
[0109]
[0110] where represents the danger potential from node to node after the round; represents a newly added action bit in this round; is the action cost weight constant. The larger the payoff function , the more significant the reduction of the danger potential and the lower the cost brought by this round of correction. This formula is only given in the core innovation link, and the remaining conventional summation and threshold judgment processes are only described in words.
[0111] The three rounds of game correction follow the order of "filling gaps, merging, and fine-tuning". In the first round of filling gaps: the potential agent scans the propagation matrix, marks the edges with a risk entropy higher than the average and not covered by actions as the edges of concern, and the action agent selects the several action bits with the greatest contribution from the candidate set of nodes connected by these edges and sets them to one. In the second round of merging: for the actions with the total number of switches ranking in the last 20% and marginal contributions, the action agent tries to set them to zero. If the total danger potential does not increase by more than the preset threshold, it is confirmed to be deleted, thus eliminating isolated actions. In the third round of fine-tuning: the potential agent redistributes the weights according to the remaining high-weight edges, and the action agent makes a local bit flip attempt to refine the remaining action set. After three rounds, if the overall danger potential is still higher than the critical value, the action bit with the largest payoff in the previous round is re-added, and finally the minimum action set data is output.
[0112] The entire game runs on the edge accelerator. The action agent logic is implemented using parallel Boolean operations; the potential energy agent logic uses a sparse matrix multiply-add processor, and the total time for three rounds does not exceed one millisecond. Floating-point operations are avoided at the hardware level, and all weights and payoffs are completed in a sixteen-bit fixed-point domain, ensuring a match with the output rhythm of quantum annealing at the level of five hundred microseconds and not slowing down the system interlock response.
[0113] Example 1: In the scenario of a methanol vapor cloud fire occurring in a 50,000-cubic-meter floating roof tank, quantum annealing initially gives twelve actions, including three independent injection valve positions. In the first round of the game, it is found that the high-potential side of the north wind direction is not covered, and a new action of deploying a robot dry powder is added. In the second round, it is determined that the coverage heights of the two valve positions overlap significantly, and one of them is deleted. In the third round of fine-tuning, the duration of the injection valve is reduced by half and nitrogen inerting is added to the adjacent valve position. Finally, the number of actions is reduced to ten, the dangerous potential energy is reduced by 35%, and the total response delay increases by 0.7 milliseconds, still meeting the requirements of the functional safety time limit.
[0114] Example 2: The low-temperature swelling of liquefied petroleum gas causes the breathing valve to freeze. Quantum annealing outputs five actions, including shutting down all pumps in the station. In the first round of the game, the top node of the breathing valve is weighted, and a new manual discharge action is added to replace shutting down all pumps; in the second round, the bypass valve switch that is mutually exclusive with this action is removed; in the third round, only the robot path is fine-tuned. Finally, the action set consists of three actions, the dangerous potential energy is equivalent to the pump shutdown plan, but the impact on production is significantly reduced.
[0115] Through the minimax game correction, the interlock control unit can perform local game search based on the approximately optimal solution given by quantum annealing, eliminate redundant actions and fill in key actions that may be missed by the quantum solution. This not only improves the safety margin of the minimum action set but also avoids the cost of misoperations caused by hardware noise or quantum embedding defects. This "quantum global + game local" double-layer optimization structure enables the SIS to achieve fast, accurate, and interpretable interlock responses in complex and multi-path petrochemical fire chains.
[0116] Preferably, the interlock control unit writes the minimum action set data into a memristive programmable logic array. The cross-wire voltage of the memristive programmable logic array is set by the interlock control unit to a first high level and a second low level. The first high level is used to indicate that the action bit is one, and the second low level is used to indicate that the action bit is zero.
[0117] After determining the minimum action set data, the interlock control unit needs to solidify each action instruction reliably, quickly, and with low power consumption into the hardwired layer to ensure that the SIS can still execute the core interlock actions even when the main controller loses power, the fieldbus is interfered, or high temperature causes the failure of traditional electrically erasable storage. The present invention uses a memristive programmable logic array as the hardware carrier of the interlock instruction. Its core advantages are that the writing speed is in nanoseconds, the conductance state remains unchanged after power-off, and the unit density is much higher than that of traditional static random access memories or lookup table arrays.
[0118] The memristive programmable logic array adopts a cross-wire structure, and variable-resistance oxide films are deposited at the intersection positions of the upper-layer wires and the lower-layer wires. Under the action of a nanosecond-level pulse voltage, the valence bonds of the film change, and the conductance jumps from a low state to a high state or vice versa. For the convenience of on-site measurement, the system stipulates that the first high level is used to write the film into the low-resistance state, and the corresponding action bit is set to one; the second low level writes the film into the high-resistance state, and the corresponding action bit is set to zero. The writing process is completed by a dedicated drive module of the interlock control unit. First, it parses the minimum action set data, maps Boolean one to + , and maps Boolean zero to + . Subsequently, write pulses are sequentially applied to the cross nodes according to the Cartesian coordinates of the row select line and the column select line. The pulse width is 30 nanoseconds, and the amplitude is accurately output by a digital programmable voltage controller.
[0119] To prevent adjacent intersections from being parasitically written, the write pulse adopts a half-select protection strategy: when a certain intersection needs to be written to a high level, its row line is applied with , and its column line is applied with ; the remaining unselected row lines and column lines are simultaneously applied with the inverted level of . This ensures that the voltage difference across the target intersection is , and the voltage difference across non-target intersections does not exceed half of the film triggering threshold, effectively suppressing miswriting. A similar principle is used for low-level writing. After the array writing is completed, the interlock control unit immediately starts the verification mode, scans the conductance of the intersections row by row. If the detected resistance deviation exceeds the tolerance by 10%, it will be automatically rewritten once, and the intersection number will be recorded in the system log.
[0120] In terms of low power consumption, there is still a sub-milliampere-level leakage current when the memristive film is in the high-conductance state. The present invention divides the action array into four sub-regions through row-column segmented address decoding, and only powers on the sub-region where actions need to be executed, reducing the static power consumption by 60%. At the same time, to prevent the degradation of the wires caused by high temperature, the cross-wire material is selected as a copper-aluminum composite wire, which has a low surface resistivity and good heat diffusion ability. After cyclic aging tests from 50 degrees Celsius to 180 degrees Celsius, the array resistance drift is less than 5%.
[0121] Effect verification selects two typical scenarios. The first is a high-pressure fire pipeline bursting and instantaneous ignition. The prediction and risk assessment unit outputs a high propagation potential matrix, and the interlock control unit generates fifteen-bit minimum action set data, which includes cutting off the main pump, turning on the bypass spray, deploying two robots, and unfurling the thermal shielding film. Writing a fifteen-bit Boolean vector into the memristive programmable logic array takes 450 nanoseconds; after the array outputs the interlock instruction stream, the hardwired circuit has completed the actions within 3 milliseconds. Compared with traditional static random access memory-based programmable gate arrays, the overall response time is shortened by about 30%, and the wire state remains unchanged after power-on, eliminating the need for re-downloading configuration.
[0122] The second scenario is a liquefied petroleum gas condensation expansion tank. The risk entropy is relatively low, and the minimum action set data has only eight bits. The writing takes less than 300 nanoseconds. Because of the low action bit density, only a single sub-region is powered on for segmented decoding, and the static power consumption is less than 10 milliwatts, making it suitable for long-term standby. Manual verification afterwards confirmed that all interlock actions were executed, and only the top safety valve and a local inerting spray were triggered at the scene, avoiding a full-site shutdown.
[0123] Through half-selection protection, row-by-row verification, and segmented decoding, the present invention solidifies the minimum action set generated by quantum annealing and game correction into a physical conductance state at the sub-microsecond level, while avoiding the problem of configuration loss due to power-off in traditional storage media. The high-density characteristic of the memristive programmable logic array ensures that future new action bits can still be mapped within a single chip, providing a reliable "write once, available after power-off" hardware guarantee for the SIS, and greatly improving the immediacy and disaster tolerance of fire interlock control in petrochemical industries.
[0124] The execution and feedback unit is used to control the fire extinguishing medium release device, robot teams, and thermal shielding device according to the interlock instruction stream, perform positioning and path planning in combination with the attitude matrix data, collect the execution status to form feedback data, and return it to the prediction and risk assessment unit and the interlock control unit to complete closed-loop self-correction.
[0125] The execution and feedback unit is at the end of the SIS, responsible for converting the interlock instruction stream into observable actions on-site and returning the actual execution results of the actions to the upper-layer model in the form of data frames to form a closed-loop self-correction of prediction - decision - execution. This unit consists of four parts: the fire extinguishing medium release device, the robot cooperation module, the thermal shielding deployment mechanism, and the feedback acquisition chain. The working principle, key implementation details, and application effects are described below in sequence.
[0126] The fire extinguishing medium release device utilizes a two-phase supercritical injection process. The device stores a mixture of carbon dioxide and phase-change aerogel at atmospheric pressure. Upon receiving an interlock command, a high-pressure pump pressurizes the mixture to the supercritical zone. This mixture is then ejected through a pulse throttle valve to form a high-velocity cooling plume, achieving both cooling and suffocation. The throttle valve actuation signal is derived from the valve position in the interlock command stream. An internal flow sensor measures the injection mass flow rate in real time, providing primary feedback.
[0127] The robot collaboration module distributes the path-related instructions involved in the minimum action set to the quadruped-tracked hybrid robot team. To ensure the robots can move safely in the high temperature and low visibility environment of the fire scene, the system uses a resonance-constrained variational path optimization method. Path optimization is based on the world coordinate system provided by the posture matrix data. The potential energy values in the propagation potential energy matrix are used as path energy weights. In the energy functional:
[0128]
[0129] Find the minimum value on the above equation and get the resonant safety path. For time The position vector of the robot in the world coordinate system at this moment, is the velocity vector, is the propagation potential energy function, The trajectory points are differentiated and sent to the robot controller. The robot's inertial measurement unit and temperature and humidity sensor transmit the execution error and ambient temperature back to the feedback chain.
[0130] The heat shield deployment mechanism consists of a reconfigurable metamaterial fire-extinguishing membrane and a shape memory alloy reel. When the interlocking command for the heat shield deployment is set to 1, the reel is powered and heated, rapidly stretching the alloy and pulling the metamaterial membrane over the critical valve assembly. After deployment, fiber optic temperature sensors and strain gauges within the mechanism simultaneously collect temperature and strain data on the membrane surface, verifying its integrity and providing feedback to higher levels.
[0131] The feedback acquisition chain uses an event stream format to encapsulate all execution states. Each feedback frame contains four fields: valve position opening percentage, injection flow rate, actual robot path point sequence, membrane temperature and strain, and is accompanied by a microsecond precision timestamp. To reduce bandwidth usage, path points are stored using spline compression, retaining only key points where the curvature change is greater than a threshold. The feedback frame is returned to the prediction and risk assessment unit via the real-time data channel to update the node status and recalculate the propagation potential energy; it is also sent to the interlocking control unit to compare the action position with the execution result. If the execution deviation is found to exceed the threshold, the incremental solution and compensation action are immediately triggered.
[0132] Example 1: During a drill to simulate methanol spray combustion at the bottom pump area of a crude oil tank, the interlock control unit issued ten action bits. The execution and feedback unit completed supercritical CO2 injection within 500 milliseconds, and the flow sensor confirmed that the injection volume reached 98% of the command value. The robot team simultaneously reached the east side of the tank wall and the north side of the pump station along the resonant safety path, with the maximum deviation between the actual path and the planned path being 11 centimeters. After the thermal shield membrane was deployed, the membrane surface temperature dropped by 200 degrees Celsius. The feedback frame indicated that all action bits met the execution threshold, and the interlock control unit did not need to add any additional actions.
[0133] Example 2: During the freezing test of the breathing valve on the top of a liquefied petroleum gas tank, the robot deviated from the planned trajectory by 35 centimeters due to vibration. After the feedback frame was returned, the interlocking control unit re-solved the complementary action, instructing another robot to take over the spraying, and at the same time replanned the original robot's path. The entire set of complementary actions was sent to the execution and feedback unit, and the total delay did not exceed the functional safety requirements.
[0134] Through the linkage of high-speed injection, path resonance planning and metamaterial thermal protection, combined with millisecond-level feedback loops, the execution and feedback unit enables the SIS to obtain real-time correction capabilities, balancing action accuracy and job safety in the high-risk environment of the petroleum and petrochemical industry, and providing a reliable execution closed loop for the entire fire interlock system.
[0135] Preferably, the execution and feedback unit mixes carbon dioxide and phase change aerogel through a two-phase flow injection device to form a supercritical mixed medium. After receiving the interlocking instruction flow data, the execution and feedback unit drives the throttle valve group to spray the supercritical mixed medium in a pulsed manner for cooling and suffocation extinguishing.
[0136] The two-phase flow jet device in the execution and feedback unit is responsible for the dual fire extinguishing of rapid cooling and asphyxiation. Its working process can be divided into five stages: mixing, pressurization, pulse throttling, jet mass transfer and feedback. The device is equipped with a carbon dioxide high-pressure tank and a phase change aerogel silo. The two materials are mixed in a static mixer at a mass fraction of Homogenization is performed. After mixing is complete, the pressure is increased to above the critical pressure by a plunger pump, and the temperature-controlled jacket maintains the fluid temperature above the critical temperature, thereby forming a supercritical mixed medium. Supercritical media have a density close to that of a liquid and a diffusion coefficient close to that of a gas. They have a high mass-carrying capacity and are easy to diffuse, making them suitable for passing through complex obstacles and transferring cold energy.
[0137] Pulse throttling is the key to fire extinguishing effect. An electric throttling valve group is arranged at the end of the spray pipeline. The valve group switches according to the pulse sequence in the interlocking instruction flow. The valve opening function is recorded as , the pulse width is , the pulse amplitude is , the rising edge and falling edge are controlled by the servo drive module. Throttling causes an instantaneous pressure drop, and the supercritical medium rapidly expands and self-cools inside the nozzle. Carbon dioxide absorbs environmental heat to complete the reverse Joule-Thomson effect, and the aerogel particles absorb heat and undergo a phase change during this process. The cooling release per unit mass can be expressed as:
[0138]
[0139] In the formula is the cooling capacity, is the mass of carbon dioxide, is the isenthalpic change of carbon dioxide in the Joule-Thomson effect, is the mass of the aerogel, is the latent heat of solid-liquid phase change of the aerogel. Carbon dioxide can also block the combustion chain in an environment with an oxygen concentration below 12%, thus forming a complement to the cooling effect.
[0140] After the injection plume enters the flame core, it first reduces the fuel vapor temperature, causing the reaction rate constant to decrease; subsequently, the carbon dioxide concentration rises to displace air, and the oxygen content drops below the combustion limit to achieve asphyxiation. The aerogel forms a porous network during the phase change process and adheres to the hot surface to further inhibit heat feedback. The injection device measures the outlet flow rate with a Pitot probe, measures the flow rate with a mass flow meter, and measures the pressure before the valve with a pressure transmitter. The three-way data, together with the valve position encoding, form an execution feedback frame. The frame body contains fields such as timestamp, pulse number, pressure, flow rate, and flow velocity.
[0141] The interlock command stream is transmitted to the valve group driver through a single-mode optical fiber. The driver opens and closes the valve according to the action bit in the command frame. If the valve does not reach the target opening or the sensor reading deviates from the threshold, the device will automatically adjust the pulse amplitude or width in the next cycle and write the correction information into the feedback frame. After receiving the feedback, the prediction and risk assessment unit updates the node temperature and oxygen concentration, and then recalculates the propagation potential energy matrix. If the dangerous potential energy is still higher than the safety value, the interlock control unit will append actions or extend the pulse sequence, thus forming a closed-loop self-correction.
[0142] Example 1: Ignite at the bottom flange position of a 30,000-cubic-meter crude oil tank. The injection device is 6 meters away from the fire point. Eighty milliseconds after the interlock command is issued, the valve group starts to execute a pulse sequence. The width of the first pulse is 20 milliseconds, and the amplitude is 100% opening; the outlet temperature of the injection plume drops to minus 45 degrees Celsius. Two seconds later, the flame temperature is 400 degrees Celsius lower than that of the non-injection control, and the oxygen content drops to 11%, and the flame automatically goes out. The feedback frame records an average mass flow rate of 250 grams per second, and the valve opening error is less than 5%. The risk potential energy matrix decreases to less than 10% of the initial value, and the system does not trigger supplementary actions.
[0143] Example 2: Simulate a liquefied petroleum gas spray fire on the oil unloading bridge. Due to the sea breeze causing plume drift, the first round of spraying did not fully cover. The feedback frame detected that the flow rate was 30% higher than the set value, and it was determined that the pressure fluctuation after the valve occurred. The interlock control unit added two pulse commands, and the amplitude was reduced to 70% to increase the plume angle. After the third round of spraying, the flame went out and did not reignite. The whole process took 3.2 seconds, and the spraying mass ratio saved 42% compared with the fixed flow rate scheme.
[0144] Through the utilization of supercritical physical properties, pulse throttling control and real-time feedback, the two-phase flow injection device takes into account both the effects of cooling and oxygen deficiency in an extremely short time, provides a strong and stable fire extinguishing execution ability for the SIS in the oil and gas fire field, and also provides reliable on-site quantities for the closed-loop model update.
[0145] Preferably, after receiving the interlock instruction stream data, the execution and feedback unit generates the robot path by using the variational path optimization method according to the propagation potential energy data and the risk entropy data. The robot path is determined by minimizing the path energy and the line integral of the dangerous potential energy. The execution and feedback unit controls the robot detachment to move along the robot path and execute on-site disposal tasks. At the same time, the valve position feedback data and the robot state data are collected and encapsulated in the event stream format. The event stream format is written into the event stream by the perception fusion unit for the prediction and risk assessment unit and the interlock control unit to perform model update and action correction.
[0146] The robot cooperation module in the execution and feedback unit is responsible for converting the action bits given by the interlock control unit into the ground movement path, and continuously transmitting the valve position and its own state during the movement, providing a quantifiable execution error for the SIS closed-loop. This module couples the path planning with the dangerous potential energy field by using the variational path optimization method, enabling the robot to avoid the high-temperature, high-pressure and combustible gas cloud areas to the greatest extent while completing on-site tasks such as exploration, explosion suppression or supplementing agents; when the high-risk area cannot be avoided, the algorithm will automatically increase the penalty weight for the dangerous potential energy in the energy functional, prompting the robot to cross with the shortest residence time, thereby reducing the risk of self-damage and secondary ignition.
[0147] First, the execution and feedback unit reads the robot action bits in the interlock instruction stream; at the same time, it obtains the latest propagation potential energy data and risk entropy data in the local cache. The propagation potential energy data is stored in the form of a three-dimensional grid, and each voxel contains the weighted result of the temperature gradient, the combustible concentration gradient and the shock wave pressure gradient, which can be regarded as the potential energy density function . The risk entropy data is a concentrated measure of the overall dangerous path distribution, used to adjust the potential energy weight in the path optimization. Before the real-time solution, the unit calculates the weight coefficient according to the size of the risk entropy , the higher the risk entropy, the more dispersed the dangerous chain is , and the value increases accordingly, forcing the path to pay more attention to avoiding the high-potential energy areas; when the risk entropy is low and the danger is concentrated Reduced, the robot can perform critical operations in the local high-potential energy area without having to detour. The path optimization objective function is written as an energy functional:
[0148]
[0149] Find the minimum value on it to obtain the resonance safety path. Among them is time The position vector of the robot in the world coordinate system at time is the velocity vector, is the propagation potential energy function, is the weight factor. The first term measures the motion power consumption, and the second term measures the cumulative hazardous exposure. The execution and feedback unit uses the variational method to minimize the function Find the minimum. Use discrete grid points to transform the continuous trajectory into a 128-segment broken line, and then use the limited-memory quasi-Newton algorithm to converge within 50 iterations. In a typical scenario, the single solution takes 3.5 milliseconds, meeting the requirement of the petrochemical site for the interlock closed-loop to be less than 50 milliseconds.
[0150] After obtaining the robot path, the module generates a speed profile according to the trajectory key points and sends it to the robot unit. The robot unit is a mixed formation of quadruped platforms and tracked platforms. The quadruped platforms are responsible for crossing obstacles such as cable trenches and pipe piers. The tracked platforms have a high load capacity and are used to carry dry powder explosion suppression or inerting agent replenishment. The two types of platforms share the path, but there are differences in the speed profile: the quadruped platforms have a greater curvature weighting, and the tracked platforms have a greater energy consumption weighting. To ensure that multiple robots do not have path intersections in the narrow tank wall passage, the execution and feedback unit uses node-level lock management. When each path segment is occupied, other robots need to wait or detour to the nearest standby trajectory.
[0151] During the execution process, the robot collects its own attitude, joint current, surface temperature, and air flammable concentration every 50 milliseconds, and then packages them together with the valve position encoder readings and flow meter readings into an event stream format. The event stream format uses a key-value pair structure, where the key is the sensor identifier and the value is the measurement data; the events are sorted by a 1-microsecond time stamp, which is convenient for the upstream prediction and risk assessment unit to compare the predicted states at the same moment. If the deviation between the robot path and the planned path exceeds 20 cm or the valve position opening is less than 95% of the target value, the module will add an abnormal mark to the event stream and broadcast it immediately. After receiving the abnormality, the interlock control unit can choose to append an action or re-solve, otherwise it will wait in a loop for the next frame of feedback.
[0152] Embodiment 1: In a one-to-one fire drill in the crude oil pump area, the leakage point is located in the middle section of the pump row. The prediction and risk assessment unit calculates that the envelope of the high potential energy area covers three pumps. The risk entropy is 0.72, and the execution and feedback unit calculates the weight coefficient as 0.45. After solving the variational path, the robot path crosses the back side of the pump row and only stays in the high potential energy area for 0.3 seconds to complete spray ignition suppression. After comparison, the peak surface temperature of the robot is lower than 80 °C, and it is still within the sustainable working temperature range after the task is completed.
[0153] Embodiment 2: Overpressure occurs at the top of the liquefied petroleum gas spherical tank, and the risk entropy is 0.35. The weight coefficient drops to 0.25. The robot path is allowed to directly climb to the top from the tank wall ladder and stays in the high potential energy area around the safety valve for 1 second to complete spray precooling. The trajectory energy increases by 15%, but the dangerous exposure integral is controlled within an acceptable range. The valve position feedback data verifies that the safety valve opens smoothly. The peak temperature of the robot is 95 °C, and it does not trigger thermal protection shutdown.
[0154] Through variational path optimization and event flow feedback, the execution and feedback unit ensures that the robot team completes on-site disposal with the minimum dangerous exposure and transmits the real execution deviation back to the upstream model in real time. This closed-loop provides the SIS with sustainable self-correction ability, enabling prediction, decision-making, and execution to maintain consistency and high reliability in the changing environment of petrochemical industry.
[0155] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. An interlock control device for oil and petrochemical fire protection based on SIS, characterized in that, Including: A perception fusion unit, which is used to collect multi-source data including at least an optical fiber sensor and a radar sensor, synchronize and fuse the collected data, output fusion feature data and attitude matrix data, and send the fusion feature data to the prediction and risk assessment unit, and send the attitude matrix data to the execution and feedback unit; The perception fusion unit obtains the Brillouin scattering frequency shift through a distributed optical fiber sensor and demodulates the Brillouin scattering frequency shift into temperature information and strain information. It emits a frequency-modulated continuous wave through a millimeter-wave radar sensor and performs a fast Fourier transform on the echo to obtain point cloud information. It converts an acoustic signal into an electrical signal through an acoustic crystal sensor and performs a short-time Fourier transform to obtain spectrogram information. It records a gray-scale change event stream through an event camera and outputs event stream information. It synchronously obtains visible light image information and infrared image information through a dual-band camera. After aligning the timestamps of the above temperature information, strain information, point cloud information, spectrogram information, event stream information, and dual-band image information, the perception fusion unit uses a gated sparse tensor fusion method to output fusion feature data and attitude matrix data; A prediction and risk assessment unit, which is used to establish a spatio-temporal model based on the fusion feature data to generate disaster prediction data and propagation potential energy data, calculate risk entropy data, and send the disaster prediction data, propagation potential energy data, and risk entropy data to the interlock control unit; An interlock control unit, which is used to construct an optimization model based on the fusion feature data, the propagation potential energy data, and the risk entropy data, obtain the minimum action set data through an optimization solver, write it into a programmable logic array, and then output an interlock instruction stream to trigger the SIS interlock action; An execution and feedback unit, which is used to control a fire extinguishing medium release device, a robot detachment, and a heat shield device according to the interlock instruction stream, perform positioning and path planning in combination with the attitude matrix data, collect the execution status to form feedback data, and return it to the prediction and risk assessment unit and the interlock control unit to complete closed-loop self-correction.
2. The device according to claim 1, characterized in that, When performing gated sparse tensor fusion, the perception fusion unit sets a gated weight tensor, and the element values of the gated weight tensor are between zero and one. The perception fusion unit performs weighted parallel multiplication and addition operations on the tensors of each perception channel according to the gated weight tensor to reduce the redundant feature dimension and improve the sparsity of feature representation.
3. The device according to claim 1, characterized in that, The prediction and risk assessment unit adopts a spatio-temporal model based on a graph neural network, maps the fusion feature data into graph structure node features and edge features, uses a multi-head attention mechanism to propagate messages between nodes, and iteratively updates the node representation within a fixed number of time steps and outputs disaster prediction data and propagation potential energy data.
4. The device according to claim 3, characterized in that, The prediction and risk assessment unit uses a generative adversarial correction method to generate a perturbation tensor, superimposes the perturbation tensor on the disaster prediction data and inputs it into a discriminant network. After the discriminant network outputs a confidence level, it updates the parameters of the generative network. The prediction and risk assessment unit calculates the risk entropy data based on the corrected disaster prediction data, and the risk entropy data measures the system hazard uncertainty through the logarithmic probability summation method.
5. The device according to claim 1, characterized in that, The interlock control unit constructs a binary unconstrained optimization model based on the fusion feature data, propagation potential energy data, and risk entropy data. The objective function of the optimization model consists of a linear combination of minimizing the number of actions and minimizing the dangerous potential energy. The interlock control unit maps the Boolean variables in the optimization model into a binary unconstrained optimization matrix and inputs it into the quantum annealing solver.
6. The device according to claim 5, characterized in that, After the quantum annealing solver outputs a Boolean vector, the interlock control unit introduces a minimax game strategy to perform three rounds of strategy corrections on the Boolean vector. Each round of strategy correction uses the difference in dangerous potential energy as the payoff function. After completing the strategy corrections, the interlock control unit determines the minimum action set data.
7. The device according to claim 1, characterized in that, The interlock control unit writes the minimum action set data into the memristive programmable logic array. The cross-wire voltage of the memristive programmable logic array is set by the interlock control unit to a first high level and a second low level. The first high level is used to indicate that the action bit is one, and the second low level is used to indicate that the action bit is zero.
8. The device according to claim 1, characterized in that, The execution and feedback unit mixes carbon dioxide and phase change aerogel through a two-phase flow injection device to form a supercritical mixed medium. After receiving the interlock instruction stream data, the execution and feedback unit drives the throttle valve group to inject the supercritical mixed medium in a pulsed manner for cooling and smothering fires.
9. The device according to claim 1, wherein, After receiving the interlock instruction stream data, the execution and feedback unit generates a robot path using the variational path optimization method based on the propagation potential energy data and risk entropy data. The robot path is determined by minimizing the path energy and the line integral of the dangerous potential energy. The execution and feedback unit controls the robot detachment to move along the robot path and perform on-site disposal tasks. At the same time, it collects valve position feedback data and robot status data and packages them in an event stream format. The event stream format is written into the event stream by the perception fusion unit for the prediction and risk assessment unit and the interlock control unit to perform model updates and action corrections.
Citation Information
Patent Citations
Fire extinguishing system of charging station and optimization method
CN118491019A
Intelligent fire early warning system and method for electric bicycle charging and parking place
CN119007382A