Power monitoring system risk dynamic disposal method and system based on multi-modal data fusion and knowledge graph
Through the method of multimodal data integration and knowledge graph, real-time access and convergence of power system data, building a knowledge graph model, risk reasoning and blocking, the problem of data silos and dynamic risk identification in the power system is solved, and real-time risk matching and strategy optimization are achieved.
Patent Information
- Application Number
- CN202510443872.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-25
AI Technical Summary
There is a data island problem in the power system, and the traditional rule base is difficult to dynamically identify new risks, resulting in passive response and unable to adapt to complex and changeable operating environments in real time.
By accessing multi-source heterogeneous data in real time, standardized processing and data fusion, building a power risk knowledge graph model, using the graph for risk reasoning and blocking, real-time matching strategies, and combining reinforcement learning optimization rules.
Real-time identification and prediction of new risks is achieved, manual intervention is reduced, rule base update cycle is shortened, and dynamic changes in the power system are adapted to.
Smart Images

Figure CN120373743A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field, and more specifically, to a method and system for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph. Background Art
[0002] With the continuous deepening of the social digitalization degree, the digital economy has become a rapidly growing economic pillar, and it is urgent to accelerate the construction of digital infrastructure and data resource systems. Data shows an explosive growth characteristic, becoming a new type of asset for many individuals, institutions, enterprises and even countries, affecting the way people interact, bringing about extensive social changes, and becoming the fifth production element in modern society.
[0003] The emergence of big data has awakened people's new understanding of data and the rational logic behind it, and the trend of cultivating big data thinking at the national strategic level has become a consensus. However, the problem of "data islands" has become increasingly prominent and has become a shackle for its development. "Data islands" refer to the asymmetric, redundant and other closed or semi-closed phenomena formed due to the incompleteness of the subject initiative, object technology, policy environment, system construction, etc. during the formation, analysis and use of data and data sets. Unconnected individual databases, repositories or systems make it difficult to access and analyze data as a whole, which leads to the existence of data islands.
[0004] In the power system, data such as the device status, network topology, and operation logs of the power system are stored separately, making it difficult to achieve multi-dimensional correlation analysis. The problem of power data islands is serious. The traditional rule base of the power system can only match known risks and cannot dynamically identify new risks, such as new network attacks or device anomalies, which leads to a passive response situation of the system when facing faults or risks. In addition, the rule base relies on manual maintenance and is difficult to adapt to the complex and changeable operating environment of the power system in real time, which also leads to a lag in data update of the power system.
[0005] To solve the above problems, there is an urgent need for a method and system for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph. Summary of the Invention
[0006] To solve the deficiencies in the prior art, the present invention provides a method and system for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph.
[0007] The present invention adopts the following technical solutions.
[0008] A dynamic risk disposal method for power monitoring systems based on multi-modal data integration and knowledge graphs, the method comprising the following steps: Step 1, real-time access to multi-source heterogeneous data, standardizing and fusing the multi-source heterogeneous data to obtain a fused data unit; Step 2, using the fused data unit to construct a power risk knowledge graph model, and storing and updating the power risk knowledge graph model; Step 3, performing risk reasoning and blocking based on the graph to generate real-time risk matching and strategies.
[0009] Real-time access to multi-source heterogeneous data, standardizing and fusing the multi-source heterogeneous data to obtain a fused data unit, including: The multi-source heterogeneous data includes device status data, network traffic data, operation log data, and external intelligence data; The device status data includes voltage, current, temperature, and vibration frequency collected by sensors; The network traffic data includes NetFlow logs, firewall interception records, source / destination IP, port, and protocol type fields; The operation log data includes SCADA system operation instructions, operator ID, and timestamp; The external intelligence data includes CVE vulnerability libraries and APT attack IoC indicators.
[0010] Real-time access to multi-source heterogeneous data, standardizing and fusing the multi-source heterogeneous data to obtain a fused data unit, including: Unifying timestamps based on the NTP protocol, associating the multi-source heterogeneous data with the power grid topology coordinates with the device as the coordinate, thereby implementing the spatio-temporal alignment of the multi-source heterogeneous data; Using regular expressions to extract device temperature and alarm codes from the logs; Extracting text semantic features based on a pre-trained BERT model to obtain a fused data unit.
[0011] Real-time access to multi-source heterogeneous data, standardizing and fusing the multi-source heterogeneous data to obtain a fused data unit, including: The format of the fused data unit at least includes device ID, timestamp unified based on the NTP protocol, measurement matrix, network events, and terminal risk labels.
[0012] Using the fused data unit to construct a power risk knowledge graph model, and storing and updating the power risk knowledge graph model, including: The power risk knowledge graph uses devices, alarms, and attack behaviors as entity types, uses device ID, device type, and device geographical location as entity attributes under the entity type of device, uses level, trigger time, and device ID as entity attributes under the entity type of alarm, and uses attack type and source IP as attack behaviors; The entity relationship between multiple entities under the entity type of device is belongs to, the entity relationship between the device entity and the alarm entity is cause, and the entity relationship between the device entity and the attack behavior entity is attack target.
[0013] Construct a power risk knowledge graph model using the fusion data unit, and implement storage and update of the power risk knowledge graph model, including: constructing an entity relationship extraction model using the improved BERT-BiLSTM-CRF, and training the entity relationship extraction model using the labeled power accident report text; inputting multi-source heterogeneous data into the trained entity relationship extraction model to obtain the power risk knowledge graph model; using a graph embedding learning algorithm to convert the power risk knowledge graph model into a low-dimensional vector representation.
[0014] Perform risk reasoning and blocking based on the graph to generate real-time risk matching and strategies, including: constructing the policy logic of the dynamic risk blocking rule, where the policy logic includes the association relationships between the rule type, trigger condition, blocking action, and priority.
[0015] Perform risk reasoning and blocking based on the graph to generate real-time risk matching and strategies, including: the reward function is designed according to the generated dynamic risk blocking rule, and returns the reward function value based on the agent's execution of the current policy and the state of the agent after executing the current policy; the state of the agent after executing the current policy includes success, misjudgment, and missed detection; the reward function value is blocking success, punishing mis-blocking, punishing missed detection, and encouraging exploration of new strategies.
[0016] Perform risk reasoning and blocking based on the graph to generate real-time risk matching and strategies, including: the state of the agent after executing the current policy includes success, misjudgment, and missed detection; the reward function value is blocking success, punishing mis-blocking, punishing missed detection, and encouraging exploration of new strategies.
[0017] A power monitoring system risk dynamic disposal system based on multi-modal data integration and knowledge graph, where the system is implemented using the power monitoring system risk dynamic disposal method described in the first aspect of the present invention; the system includes a fusion module, a modeling module, and a blocking module; among them, the fusion module is used to access multi-source heterogeneous data in real time, perform standardization processing and data fusion on the multi-source heterogeneous data, and obtain the fusion data unit; the modeling module is used to construct a power risk knowledge graph model using the fusion data unit, and implement storage and update of the power risk knowledge graph model; the blocking module is used to perform risk reasoning and blocking based on the graph to generate real-time risk matching and strategies.
[0018] The beneficial effects of the present invention are as follows. Compared with the prior art, a risk dynamic disposal method and system for a power monitoring system based on multi-modal data integration and knowledge graph in the present invention constructs a unified spatio-temporal tag data set by integrating multi-dimensional data such as device status, network traffic, and operation logs, generates real-time blocking strategies through knowledge graph reasoning, combines reinforcement learning to dynamically optimize rules, changes from "post-event matching" to "pre-event prediction", and identifies new types of attacks. The present invention collects real-time blocking feedback data, updates the knowledge graph and rule base through online learning to reduce manual intervention, shortens the update period of the rule base, and adapts to the dynamic changes of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 It is a schematic flow chart of a risk dynamic disposal method for a power monitoring system based on multi-modal data integration and knowledge graph of the present invention;
[0020] Figure 2 It is a schematic module structure diagram of a risk dynamic disposal system for a power monitoring system based on multi-modal data integration and knowledge graph of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] To make the objectives, technical solutions, and advantages of the present invention clearer and more accurate, the technical solutions of the present invention will be described in detail through multiple specific embodiments below. The embodiments adopted by the present invention are only used to explain the present invention and do not limit the content of the present invention.
[0022] In the first aspect of the present invention, it relates to a risk dynamic disposal method for a power monitoring system based on multi-modal data integration and knowledge graph, and the method includes the following steps 1 to 3.
[0023] Step 1, real-time access multi-source heterogeneous data, perform standardized processing and data fusion on the multi-source heterogeneous data, and obtain a fusion data unit.
[0024] In recent years, new technologies such as transmission and distribution coordination, source-network-load-storage coordination, virtual power plants, multi-load management, and carbon market trading have emerged. These technologies all rely on power system data, and the accuracy and usability of the data will greatly affect the development of these technologies. How to efficiently integrate multi-source data and extract effective information for application in different scenarios has become an urgent problem to be solved. Data fusion aggregates, correlates, and integrates data from multiple sensors or other types of information sources to improve the accuracy of the detection and feature estimation of a certain target, or even extends to the prediction of a certain event. Usually, data fusion includes three aspects of work: 1) data association, determining that multi-source data reflects the same target; 2) multi-source data estimation, comprehensively using multi-source data to improve the estimation of the target; 3) data source management, given the environmental state of the data source (such as sensors, etc.), allocate the data collection and processing sources to minimize the operation cost.
[0025] At present, data fusion technology has achieved good application results in the fields of remote sensing, image processing, etc., and still has great development prospects in the field of power systems. In recent years, scholars have successively pointed out that deep data fusion has become the future research trend. For power grid fault analysis, by integrating and comprehensively analyzing the data of 7 application modules in the production control area and management information area of the dispatching master station, the alarm accuracy rate can be significantly improved compared with the traditional fault judgment method with a relatively single data source. In data-driven power quality analysis, fusing redundant data from different monitoring systems can improve the robustness of decision-making. Fusing power monitoring data with meteorological, geographical, economic and other data can obtain the relationship between power quality disturbance events and non-electrical quantities. There are many application scenarios in the new power system, and the types of multi-source heterogeneous data fusion technology are complex, which will face a series of problems when carrying out research on new power system data fusion technology.
[0026] According to the business field, the data of the new power system can be divided into 4 categories: system operation data, enterprise operation and management data, non-electric energy data, and non-energy data. System operation data includes power production data, system operation status monitoring data, etc., from various aspects of power generation, grid, load, and energy storage. The wide access of distributed power sources and power electronic devices in the new power system makes the operation of the power system more complex, the amount of system operation data greatly increased, and the types of monitored data more abundant. Enterprise operation and management data includes enterprise power generation and sales volume, power market price data, user power consumption data, etc., mainly concentrated in marketing business application systems, power consumption information collection systems, 95598 systems, etc. The gradual popularization of devices such as smart gateways and smart homes in the new power system [5] has greatly improved the convenience of user power consumption data collection and storage. Enterprise management data includes data such as resource planning management, capital operation management, human resources management, and material management of various businesses of power enterprises, mainly from production management systems, enterprise resource planning systems, etc.
[0027] Non-electric energy data includes various primary energy data, non-electric secondary energy data, etc. With the construction of the integrated energy system, as the core of the energy hub and energy transformation, the new power system is physically coupled with different energy systems such as the natural gas system and the heating system, and also requires them to share and co-govern data resources. The integrated energy data of cooling, heating, electricity, and gas centered on electricity is continuously enriched and refined.
[0028] Non - energy data includes macro - policy data such as industrial structure, traffic network planning data, environmental and meteorological data, etc. The structural adjustment, load forecasting, planning and dispatching of the new power system rely on the support of non - energy data. Moreover, the improvement of the informatization level also provides conditions for the expansion of data sources in the new power system, which will promote the common development of the energy field and other fields. Such data mainly comes from geographical information systems, power grid meteorological information systems, government regulatory departments, etc.
[0029] In addition, the data of the new power system can also be classified into historical data, online measurement data, simulation and deduction data, and prediction data according to the time dimension, and into structured data, unstructured data, and semi - structured data according to the data structure.
[0030] In the present invention, for the above - mentioned new power system data, the method for real - time access to multi - source heterogeneous data, standardizing and fusing the multi - source heterogeneous data to obtain a fused data unit includes: the multi - source heterogeneous data includes equipment status data, network traffic data, operation log data, and external intelligence data; the equipment status data includes voltage, current, temperature, and vibration frequency collected by sensors, and the sampling frequency ≥ 100Hz; the network traffic data includes NetFlow logs, firewall interception records, source / destination IP, port, and protocol type fields; the operation log data includes SCADA system operation instructions (such as breaker opening and closing), operator ID, and timestamp; the external intelligence data includes CVE vulnerability libraries and APT attack IoC (Indicator of Compromise) indicators.
[0031] Real - time access to multi - source heterogeneous data, standardizing and fusing the multi - source heterogeneous data to obtain a fused data unit includes: unifying the timestamp based on the NTP protocol, associating the multi - source heterogeneous data with the power grid topology coordinates with the equipment as the coordinate, so as to implement the spatio - temporal alignment of the multi - source heterogeneous data; using regular expressions to extract equipment temperature and alarm codes from the logs; extracting text semantic features based on the pre - trained BERT model and obtaining the fused data unit.
[0032] Unify the timestamp based on the NTP protocol and associate the equipment data with the power grid topology coordinates, such as "#3 transformer @ Substation A". For unstructured data, use regular expressions to extract equipment temperature and alarm codes from the logs, and extract text semantic features based on the pre - trained BERT model, such as "abnormal login" → entity type: attack behavior.
[0033] Real - time access to multi - source heterogeneous data, standardizing and fusing the multi - source heterogeneous data to obtain a fused data unit includes: the format of the fused data unit at least includes equipment ID, the timestamp unified based on the NTP protocol, measurement matrix, network events, and terminal risk labels.
[0034] In one embodiment, the fused data unit is described as follows:
[0035] {
[0036] "device_id":"TRANSFORMER_003",
[0037] "timestamp":"2023-10-01T14:23:05Z",
[0038] "metrics":{"temperature":85.2,"load_rate":0.92},
[0039] "network_events":[{"src_ip":"192.168.1.100","action":"SSH login failed"}],
[0040] "external_risk_tags":["CVE-2023-1234"]
[0041] }
[0042] The data is stored in json.
[0043] Step 2: Use the fused data unit to construct a power risk knowledge graph model, and implement storage and update of the power risk knowledge graph model.
[0044] Using the fused data unit to construct a power risk knowledge graph model, and implementing storage and update of the power risk knowledge graph model, including: The power risk knowledge graph uses devices, alarms, and attack behaviors as entity types, uses device ID, device type, and device geographical location as entity attributes under the entity type of device, uses level, trigger time, and device ID as entity attributes under the entity type of alarm, and uses attack type and source IP as attack behaviors; The entity relationship between multiple entities under the entity type of device is belongs to, the entity relationship between the device entity and the alarm entity is the cause, and the entity relationship between the device entity and the attack behavior entity is the attack target.
[0045] Using the fused data unit to construct a power risk knowledge graph model, and implementing storage and update of the power risk knowledge graph model, including: Adopt an improved BERT-BiLSTM-CRF to construct an entity relationship extraction model, and use the labeled power accident report text to train the entity relationship extraction model; Input multi-source heterogeneous data into the trained entity relationship extraction model to obtain a power risk knowledge graph model; Use a graph embedding learning algorithm to convert the power risk knowledge graph model into a low-dimensional vector representation.
[0046] The model architecture of the present invention is BERT - Base (12 - layer Transformer) + BiLSTM - CRF. The training data is 5000 annotated power accident report texts (manually annotated entities and relationships).
[0047] Step 3: Perform risk reasoning and blocking based on the knowledge graph to generate real - time risk matching and strategies.
[0048] Performing risk reasoning and blocking based on the knowledge graph to generate real - time risk matching and strategies, including: constructing the policy logic of dynamic risk blocking rules, where the policy logic includes the association relationships between rule types, trigger conditions, blocking actions, and priorities.
[0049] The Graph Embedding algorithm is Node2Vec, with parameters: p = 1 (BFS tendency), q = 0.5 (DFS tendency), dimension = 128, used to mine potential patterns in historical faults (such as the implicit association between "load factor > 90%" and "circuit breaker failure").
[0050] In the actual application process of the present invention, the power system will exhibit different states under different sensor parameters. Therefore, the present invention also supports extracting part of the scenario data during the training of the deep neural network constructed in Step 1 to obtain a sub - network for a specific scenario. When optimizing the strategy, perform operation analysis based on the sub - network of the expected scenario to obtain the optimized scheduling under the expected scenario.
[0051] To guide the learning process of the agent, the design and implementation of the reward function are crucial, as it directly affects the learning direction and optimization goal of the agent. By constructing a multi - objective reward function and applying it to the deep reinforcement learning framework, effective balance and optimization of multiple goals are achieved.
[0052] In one embodiment, performing risk reasoning and blocking based on the knowledge graph to generate real - time risk matching and strategies, including: the reward function is designed according to the generated dynamic risk blocking rules, and returns the reward function value based on the agent's execution of the current policy and the state of the agent after executing the current policy; the state of the agent after executing the current policy includes success, misjudgment, and missed judgment; the reward function values are successful blocking, penalty for mis - blocking, penalty for missed detection, and encouragement to explore new strategies.
[0053] Performing risk reasoning and blocking based on the knowledge graph to generate real - time risk matching and strategies, including: the state of the agent after executing the current policy includes success, misjudgment, and missed judgment; the reward function values are successful blocking, penalty for mis - blocking, penalty for missed detection, and encouragement to explore new strategies.
[0054] In practical applications, designing a multi-objective reward function usually requires considering how to convert different objectives into a unified quantitative index and determining the weight of each objective for optimization during the reinforcement learning process.
[0055] Use reinforcement learning to input the potential patterns in historical faults into the power system environment and obtain the reward of the dynamic risk blocking policy logic, so as to obtain the optimal power policy logic under different scenarios. The optimal power policy logic is measured by the degree of change in the return calculated by the multi-objective reward function.
[0056] As the scale of the power system continues to expand, traditional optimization algorithms face problems such as high computational complexity and slow convergence speed when dealing with large-scale systems. The present invention uses a deep reinforcement learning algorithm to train an intelligent agent, enabling it to perform autonomous learning and optimization during the decision-making process of power system scheduling. The policy network can be a deterministic policy or a stochastic policy based on the value function. The selected algorithms include Deep Q-Network (DQN), Deep Deterministic Policy Gradient (DDPG), Proximal Policy Optimization (PPO), etc., which can effectively handle high-dimensional inputs and outputs, as well as continuous or discrete action spaces.
[0057] In deep reinforcement learning, the intelligent agent learns the optimal policy through interaction with the environment. Through interaction with the environment, the intelligent agent continuously tries different actions and learns according to the reward function, gradually forming the optimal power scheduling policy.
[0058] Use reinforcement learning to input the potential patterns in historical faults into the power system environment and obtain the reward of the dynamic risk blocking policy logic, so as to obtain the optimal power policy logic under different scenarios, including: using the current risk score, device importance, and network bandwidth occupancy rate as the state space, using historical faults as the intelligent agent, and using the blocking, release, and delay of the intelligent agent, that is, historical faults, as actions, and the multi-objective reward function as the reward.
[0059] Screen out the current associated data from multi-source heterogeneous data, construct a sub-network of the current scenario through a neural network, and use the sub-network to simulate the power system environment under the current scenario. Use the intelligent agent to interact with the power system environment under the current scenario to calculate the state transition probability of the intelligent agent, and calculate the reward of the current action of the intelligent agent through state transition; train the intelligent agent through reinforcement learning to obtain the state transition trajectory of the intelligent agent during the training process and the return corresponding to the state transition trajectory; calculate the degree of change in the return of all intelligent agents, and use the state transition trajectory of the intelligent agent whose degree of change in return exceeds the preset amount as the optimal policy logic under the current scenario.
[0060] During the reinforcement learning process, the parameters of the agent, such as the weights of the neural network, are randomly initialized or obtained through pre-training to complete the initialization of reinforcement learning. Subsequently, the agent needs to find a balance between exploration, such as trying new and unknown actions to discover better strategies, and exploitation, which is the process of using the currently known best strategy to obtain rewards.
[0061] In one embodiment, the DQN algorithm is used to update the state of the agent. In the DQN algorithm, at each step, the agent selects an action from the current state, which is achieved through a Q-network. The Q-network takes the current state as input and outputs the Q-values of each possible action, that is, the expected return. The agent executes the selected action, and then returns a new state, a reward, and a signal indicating whether the session has ended through interaction with the environment. The agent stores the experience of this interaction in an experience replay buffer. The experience includes the correspondence between the current state, action, reward, and new state.
[0062] In DQN, the agent randomly samples a batch of experiences from the experience replay buffer at regular intervals and uses them to update the Q-network. During the update process, the loss function is calculated, usually determined by the reward function under the current action, etc.
[0063] To stabilize the training process, DQN uses a target network whose parameters θ are copied from the main network every once in a while. The target Q-value y is calculated through this target network. Here, the target Q-value and the main network can simulate the power system environment by the neural network mentioned above. The update of the parameter θ is implemented according to the learning progress of DQN and the environmental feedback. When calculating the Q-value, future rewards are reduced in influence by a discount factor γ to reflect that recent rewards are more important than distant rewards. The agent repeats the above steps and gradually improves its strategy through continuous learning.
[0064] In another embodiment, the PPO algorithm is used to update the state of the agent. PPO is a policy gradient method that optimizes the policy through stochastic gradient ascent and ensures the stability of policy updates through a reward function.
[0065] In the PPO algorithm, the agent first executes the current policy and collects the state, action, probability ratio, that is, the ratio of the new and old policy probabilities, and collects the cumulative reward. For each state-action pair, the algorithm calculates the PPO clip value, and then uses the PPO clip value and the probability ratio to update the policy through stochastic gradient ascent. At the same time, a value function is updated to estimate the state value under the current policy. Repeat the above steps until the policy converges.
[0066] In the present invention, the reward function is designed according to the generation of dynamic risk blocking rules.
[0067] As shown in the following code logic:
[0068]
[0069] The learning process of the agent requires tens of thousands of iterations, and each step involves a large amount of computation and data processing. In addition, the learning process of the agent also needs to be monitored and adjusted to ensure that it progresses in the correct direction.
[0070] The uncertainties and real-time changes in the operation of the power system require the strategy to be able to respond quickly and adapt to new situations. In order to enable the agent to adapt to the real-time changes in the operation of the power system, the present invention introduces an adaptive adjustment mechanism, which allows the agent to dynamically adjust its strategy according to the latest system state and environmental feedback, ensuring that the agent continuously optimizes its decision-making in a changing environment.
[0071] The adaptive mechanism continuously monitors the real-time operation state of the power system, collects key performance indicators and operation data, ensuring that the data collection system can effectively capture all important changes within the system, such as temperature, load rate, etc. On this basis, the performance of the agent's current scheduling strategy is evaluated regularly, using predefined evaluation metrics, such as the current risk score, device importance, network bandwidth occupancy rate, etc. mentioned above, to evaluate the agent's scheduling strategy. The current risk score includes multi-source data such as comprehensive device anomalies, network attacks, and vulnerability exploitation, and the security risk level of the system at the current moment is obtained through an algorithm. The security risk level is 0 - 1 point, and the higher the score, the more dangerous. The device importance includes pre-classifying the levels according to the functions and influence ranges of the devices in the power grid, etc., and determining the strictness of the security policy. The classification levels are critical, important, or ordinary.
[0072] By comparing the historical data with the expected goals, the effectiveness of the current strategy is judged. The current risk score uses multi-source data such as comprehensive device anomalies, network attacks, and vulnerability exploitation, and the security risk level of the system at the current moment is obtained through an algorithm. The risk level is 0 - 1 point, and the higher the score, the more dangerous. The device importance level is pre-classified according to the functions and influence ranges of the devices in the power grid, such as critical / important / ordinary, and determines the strictness of the security policy.
[0073] The algorithm is a rule engine + weighted fusion algorithm, and the identification of the security risk level is implemented through a predefined rule library and dynamic weight allocation. The weight scores are corrected according to parameters such as device importance and historical attack frequency. For example, the risk event weight of critical devices is higher. According to the identification rules of the security risk level of the rule engine with adjustable weights. For example: A simplified calculation logic is: risk score = device anomaly score (adjustable weight = 40%) + network attack score (adjustable weight = 30%) + vulnerability score (adjustable weight = 20%) + historical similar case score (adjustable weight = 10%).
[0074] Quantify device functions using the importance of the device in the network topology:
[0075]
[0076] σ st is the total number of shortest paths from node s to t, and σ st (v) is the number of shortest paths passing through node v. The higher the value, the stronger the role of the device as a power transmission hub in the power grid.
[0077] The scope of influence includes the proportion of affected devices, time persistence, etc. For example, the spread = the total number of devices affected by cascading failures / the total number of system devices. The spread = 0 - 0.1, low risk level, and the countermeasure is local isolation without global intervention; the spread = 0 - 0.1, low risk level, and the countermeasure is to start the standby capacity and modulate the power flow; the spread is greater than 0.3, high risk level, and the countermeasure is emergency load shedding to prevent the collapse of the entire network. The time persistence = the historical repair time / the number of failures. The scope of influence index = 0.4 * spread + 0.6 * time persistence (the coefficient is adjustable). The importance of the device = 0.6 * device function + 0.4 * scope of influence. The importance of the device = 0.8 - 1, critical level; the importance of the device = 0.5 - 0.79, important level; the importance of the device = 0 - 0.49, ordinary level.
[0078] The knowledge base is dynamically updated using an incremental update mechanism. The update is triggered when the new data meets any of the following conditions. For example, when an alarm event that does not match the known rules is found, the knowledge base is dynamically updated; or, when the success rate of the same blocking policy is less than 60% for 3 consecutive times, the knowledge base is dynamically updated. The content of the dynamic update of the knowledge base is to add new graph nodes / edges, or to adjust the confidence weight of the rules.
[0079] In one embodiment, new graph nodes are added, such as adding a new attack type "supply chain attack", and the confidence weight of the rules is adjusted, such as reducing the weight of "load rate > 90% → alarm".
[0080] In the second aspect of the present invention, it relates to a power monitoring system risk dynamic disposal system based on multi-modal data integration and knowledge graph. The system is implemented using a power monitoring system risk dynamic disposal method in the first aspect of the present invention; the system includes a fusion module, a modeling module, and a blocking module; wherein, the fusion module is used to access multi-source heterogeneous data in real time, perform standardized processing and data fusion on the multi-source heterogeneous data, and obtain a fusion data unit; the modeling module is used to construct a power risk knowledge graph model using the fusion data unit, and perform storage and update on the power risk knowledge graph model; the blocking module is used to perform risk reasoning and blocking based on the graph to generate real-time risk matching and strategies.
[0081] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that there are still contents in the technical solutions of the present invention that can modify the specific implementation manners of the present invention or make equivalent replacements. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A dynamic risk disposal method for a power monitoring system based on multi-modal data integration and knowledge graph, characterized in that, The method includes the following steps: Step 1, access multi-source heterogeneous data in real time, perform standardization processing and data fusion on the multi-source heterogeneous data, and obtain a fusion data unit; Step 2, use the fusion data unit to construct a power risk knowledge graph model, and implement storage and update of the power risk knowledge graph model; Step 3, perform risk reasoning and blocking based on the graph to generate real-time risk matching and strategies.
2. The method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 1, characterized in that: The real-time access to multi-source heterogeneous data, performing standardization processing and data fusion on the multi-source heterogeneous data, and obtaining a fusion data unit includes: The multi-source heterogeneous data includes device status data, network traffic data, operation log data, and external intelligence data; The device status data includes voltage, current, temperature, and vibration frequency collected by sensors; The network traffic data includes NetFlow logs, firewall interception records, source / destination IP, port, and protocol type fields; The operation log data includes SCADA system operation instructions, operator ID, and timestamp; The external intelligence data includes CVE vulnerability libraries and APT attack IoC indicators.
3. The method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 2, characterized in that: The real-time access to multi-source heterogeneous data, performing standardization processing and data fusion on the multi-source heterogeneous data, and obtaining a fusion data unit includes: Based on the NTP protocol, unify the timestamp, and associate the multi-source heterogeneous data to the power grid topology coordinates with the device as the coordinate, so as to implement the spatio-temporal alignment of the multi-source heterogeneous data; Use regular expressions to extract device temperature and alarm codes from the logs; Extract text semantic features based on the pre-trained BERT model and obtain a fusion data unit.
4. The method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 3, characterized in that: The real-time access to multi-source heterogeneous data, performing standardization processing and data fusion on the multi-source heterogeneous data, and obtaining a fusion data unit includes: The format of the fusion data unit includes at least device ID, timestamp unified based on the NTP protocol, measurement matrix, network event, and terminal risk label.
5. The method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 4, characterized in that: The use of the fusion data unit to construct a power risk knowledge graph model, and implementing storage and update of the power risk knowledge graph model includes: The power risk knowledge graph uses devices, alarms, and attack behaviors as entity types, uses device ID, device type, and device geographical location as entity attributes under the entity type of device, uses level, trigger time, and device ID as entity attributes under the entity type of alarm, and uses attack type and source IP as attack behaviors; The entity relationship between multiple entities under the entity type of device is belonging, the entity relationship between the device entity and the alarm entity is the cause, and the entity relationship between the device entity and the attack behavior entity is the attack target.
6. A method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 5, characterized in that: The method of constructing a power risk knowledge graph model by using the fusion data unit and storing and updating the power risk knowledge graph model includes: An entity relationship extraction model is constructed by using an improved BERT-BiLSTM-CRF, and the entity relationship extraction model is trained by using the labeled power accident report text; The multi-source heterogeneous data is input into the trained entity relationship extraction model to obtain a power risk knowledge graph model; A graph embedding learning algorithm is used to convert the power risk knowledge graph model into a low-dimensional vector representation.
7. A method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 6, characterized in that: The method of performing risk reasoning and blocking based on the graph to generate real-time risk matching and strategies includes: Construct the policy logic of the dynamic risk blocking rule, and the policy logic includes the association relationship between the rule type, trigger condition, blocking action and priority.
8. A method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 7, characterized in that: The method of performing risk reasoning and blocking based on the graph to generate real-time risk matching and strategies includes: The reward function is designed according to the generation of the dynamic risk blocking rule, and returns the reward function value according to the execution of the current policy by the agent and the state of the agent after executing the current policy; The state of the agent after executing the current policy includes success, misjudgment, and missed judgment; The reward function value is blocking success, punishing mis-blocking, punishing missed detection, and encouraging exploration of new strategies.
9. A method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to claim 8, characterized in that: The method of performing risk reasoning and blocking based on the graph to generate real-time risk matching and strategies includes: The state of the agent after executing the current policy includes success, misjudgment, and missed judgment; The reward function value is blocking success, punishing mis-blocking, punishing missed detection, and encouraging exploration of new strategies.
10. A power monitoring system risk dynamic disposal system based on multi-modal data integration and knowledge graph, characterized in that: The system is implemented by using the method for dynamically disposing risks of a power monitoring system based on multi-modal data integration and knowledge graph according to any one of claims 1-9; The system includes a fusion module, a modeling module and a blocking module; wherein, The fusion module is used to access multi-source heterogeneous data in real time, perform standardized processing and data fusion on the multi-source heterogeneous data, and obtain a fusion data unit; The modeling module is used to construct a power risk knowledge graph model by using the fusion data unit and store and update the power risk knowledge graph model; The blocking module is used to perform risk inference and blocking based on the map to generate real-time risk matching and strategies.
Citation Information
Cited By
Electric power work order intelligent processing method with RPA fused with multi-mode large model
CN120563072A
A method for intelligent processing of power work orders using RPA and multimodal large model
CN120563072B
Intelligent question and answer implementation method and system based on large model and semantic map
CN120723876A
Complete-flow customs clearance cooperation method and system for generating intelligent customs declaration form of comprehensive service
CN120806886A
Supply chain risk quantitative evaluation method and system based on dynamic affair graph
CN120996569A