Dynamic risk analysis method based on bayesian network
By integrating historical information and real-time data into a Bayesian network approach, the problems of time-consuming and labor-intensive construction of traditional Bayesian networks and the lack of interpretability of purely data-driven models are solved, enabling dynamic risk assessment and interpretable risk analysis for power systems and data centers.
Patent Information
- Application Number
- CN202511159002.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-08-19
AI Technical Summary
In risk assessment of critical infrastructures such as power systems and data centers, existing technologies are often inadequate. Traditional Bayesian network construction is highly subjective, time-consuming, and labor-intensive. Static models cannot dynamically adapt to equipment aging and environmental changes, while purely data-driven models lack interpretability and reliability.
By constructing historical information Bayesian networks and data-driven Bayesian networks, and combining them with a weighted fusion algorithm for dynamic probability updates, a comprehensive Bayesian network is generated. Mutual information and conditional independence are used to test and uncover risk associations, thereby achieving dynamic adaptability and interpretability of the model.
It improves the objectivity and dynamic adaptability of risk assessment, and the generated model can quickly respond to system changes, provide clear risk propagation paths and key node protection priorities, and support precise risk prevention and control decisions.
Smart Images

Figure CN120725457B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a risk analysis method, and more specifically, to a dynamic risk analysis method based on Bayesian networks. Background Technology
[0002] In risk assessments of critical infrastructure such as power systems and data centers, Bayesian networks (BNs) are widely used due to their powerful uncertainty reasoning capabilities and intuitive graphical representations. Traditional Bayesian network construction methods primarily rely on the knowledge and experience of domain experts, manually defining the network topology and conditional probability tables using methods such as fault trees (FTs). However, this approach has significant limitations: First, the network construction process is highly subjective, time-consuming, and labor-intensive, and struggles to fully capture all potential, especially nonlinear, implicit risk associations within the system; second, the probability parameters in the network are typically set once based on historical statistical data, forming a static model that cannot dynamically adapt to real-time system conditions such as equipment aging, environmental changes, and operational condition adjustments, leading to delayed and distorted risk assessment results.
[0003] In recent years, with the development of big data technology, purely data-driven risk analysis methods (such as deep learning and machine learning) have emerged. These methods can automatically learn complex patterns from massive amounts of monitoring data, but their "black box" nature leads to a lack of interpretability in the models. The relationships they learn may contradict the inherent physical logic of the system, making them difficult for operations and maintenance personnel to trust and adopt. At the same time, in scenarios with sparse data or insufficient fault samples, purely data-driven models are prone to overfitting, making it difficult to guarantee reliability.
[0004] Therefore, how to effectively integrate well-defined historical knowledge models with objective real-time data to construct a risk analysis model that is both physically logically rigorous, dynamically adaptive, and highly interpretable is a technical challenge that urgently needs to be addressed in the field. Summary of the Invention
[0005] The main objective of this invention is to provide a dynamic risk analysis method based on Bayesian networks to solve the problems in related technologies.
[0006] To achieve the above objectives, according to one aspect of the present invention, a dynamic risk analysis method based on Bayesian networks is provided, comprising the following steps:
[0007] Constructing a Bayesian network of historical information: Based on the historical risk knowledge model, risk influencing factors are transformed into the first group of network nodes, and the initial topology of the first group of network nodes is established according to the logical relationship in the knowledge model.
[0008] Constructing a data-driven Bayesian network: Acquire and process multi-source real-time monitoring data, and learn the correlation between variables in the data through data mining algorithms to generate a second set of network nodes and their data-driven topology;
[0009] Network fusion and probability update: The historical information Bayesian network and the data-driven Bayesian network are connected through shared risk nodes to construct a comprehensive Bayesian network; and a dynamic probability update mechanism is established, which adopts a weighted fusion algorithm to dynamically adjust the probability parameters in the comprehensive Bayesian network by combining the prior probability determined by historical information and the posterior probability calculated by real-time monitoring data.
[0010] Risk quantification and analysis: Based on the dynamically updated integrated Bayesian network, risk inference is performed to output at least one risk quantification indicator.
[0011] Furthermore, the step of constructing the historical information Bayesian network further includes: reconstructing the static logic gates in the historical risk knowledge model into dynamic logic gates with time-varying parameters, and dynamically adjusting the trigger threshold of the dynamic logic gates according to the system state through a feedback control loop.
[0012] Furthermore, the step of constructing the data-driven Bayesian network further includes: calculating the mutual information values between variables in the multi-source real-time monitoring data to identify potential dependencies, and applying a conditional independence test algorithm to verify the potential dependencies to filter out false associations, thereby generating the data-driven topology.
[0013] Furthermore, the weight coefficients in the weighted fusion algorithm are adaptively adjusted, and the adjustment of the weight coefficients is based on at least the device's uptime or the system's health status indicators.
[0014] Furthermore, the risk quantification indicators include risk propagation path ranking, critical node failure probability, or critical node protection priority.
[0015] Furthermore, the calculation of the protection priority of critical nodes is based on the posterior probability and centrality of the nodes calculated by the integrated Bayesian network.
[0016] Furthermore, it also includes an incremental learning step: after the integrated Bayesian network is constructed, new real-time monitoring data is continuously received, and the topology of the integrated Bayesian network is optimized and the parameters are iterated using the incremental learning module.
[0017] Furthermore, when constructing a historical information Bayesian network, if the cross-validation score of expert knowledge is lower than a preset threshold, the construction process of the data-driven Bayesian network is triggered to supplement and correct the expert knowledge.
[0018] On the other hand, the present invention also provides a risk analysis system, comprising:
[0019] Memory, used to store program instructions;
[0020] A processor for executing the program instructions to implement the above method.
[0021] On the other hand, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method as described in any of the preceding claims.
[0022] Compared with the prior art, the present invention has the following beneficial effects:
[0023] Compared with existing technologies, the dynamic risk analysis method based on Bayesian networks provided by this invention has the following advantages:
[0024] This invention improves the objectivity and automation of model construction: Through a data-driven approach, it automatically mines implicit risk correlations from massive amounts of monitoring data using algorithms such as mutual information and conditional independence tests, and constructs the network topology. This overcomes the shortcomings of traditional methods, which rely entirely on expert experience, are highly subjective, and may miss unknown risks. It reduces the workload of manual construction and significantly improves the efficiency and objectivity of network construction.
[0025] Enhanced Dynamic Adaptability of Risk Assessment: This invention establishes a dynamic fusion and update mechanism for prior and posterior probabilities, utilizing real-time monitoring data to dynamically correct probability parameters set based on historical information. Through an adaptively adjusted weighted algorithm, the model can quickly respond to dynamic changes such as equipment aging and sudden environmental changes, making the risk assessment results closer to the current real state of the system and improving the accuracy and timeliness of dynamic risk prediction.
[0026] This invention achieves interpretable risk quantification and precise decision support: By combining data-driven learning structures with physical logic based on historical knowledge, the resulting comprehensive Bayesian network is not a "black box" model. It clearly outputs risk propagation paths, and its analysis results are consistent with physical mechanisms, making it easy for engineers to understand and verify. Furthermore, this invention not only provides the probability of risk occurrence but also quantifies the protection priorities of key nodes, providing multi-dimensional and interpretable quantitative data for developing preventative maintenance and emergency response strategies, thus assisting in more precise risk prevention and control decisions. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] The structures, proportions, sizes, etc., shown in the accompanying drawings of this specification are only for the purpose of assisting those skilled in the art in understanding and reading the content disclosed in the specification, and are not intended to limit the conditions under which the present invention can be implemented. Therefore, they have no substantial technical significance. Any modifications to the structure, changes in the proportions, or adjustments to the size, without affecting the effects and objectives that the present invention can produce, should still fall within the scope of the technical content disclosed in the present invention.
[0029] Figure 1 This is a flowchart of the method of the present invention;
[0030] Figure 2 This is a fault tree diagram of a data center abnormal fire according to a preferred embodiment of the present invention;
[0031] Figure 3 This is a Bayesian network diagram after parameter learning in a preferred embodiment of the present invention. Detailed Implementation
[0032] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described below are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0033] The technical solution of the present invention will be further described below with reference to the accompanying drawings and specific embodiments.
[0034] This invention provides a dynamic risk analysis method based on Bayesian networks, the specific implementation process of which can be divided into the following three core parts:
[0035] Part 1: Building Bayesian Networks Based on Historical Information
[0036] This section aims to transform expert knowledge and historical incident logic into an initial, physically meaningful Bayesian network structure.
[0037] (1) Node Transformation and Structure Construction: First, the fault tree (FT), commonly used in historical accident analysis, is deconstructed. The top event in the fault tree (e.g., "data center fire") is transformed into the root node of a Bayesian network, intermediate events (e.g., "UPS overload") are transformed into hidden layer nodes, and basic events are transformed into leaf nodes. These basic event nodes cover four dimensions: equipment type, failure mode, environmental parameters, and human factors. For example, "equipment type" is structured hierarchically through classification coding, and continuous variables such as "environmental parameters" (e.g., temperature, humidity) are quantified using fuzzy membership functions. A typical S-shaped membership function can be expressed as:
[0038] ;
[0039] in, The input environmental parameter values are a, b, and c, which are function shape parameters set based on expert experience. For "human factors," the evaluation results can be transformed into fuzzy weights in the [0,1] interval using methods such as Likert scales.
[0040] (2) Dynamic Logic Gate Reconstruction: To overcome the static nature of Boolean logic gates in traditional fault trees, this invention dynamically reconstructs them. For example, the traditional OR gate is transformed into a fuzzy OR gate with time-varying parameters, such as introducing a temperature-related sensitivity coefficient β. Its logical operation can be designed as follows: In addition, a feedback control loop is established, using a PID (proportional-integral-derivative) control algorithm to dynamically adjust the trigger thresholds of logic gates based on real-time feedback from the system (such as equipment load rate), enabling the model to adapt to changes in operating conditions.
[0041] (3) Knowledge verification and triggering mechanism: After the historical information network is constructed, an expert cross-validation mechanism is introduced. If the expert group scores the cross-validation matrix of the network structure or parameters below the preset threshold (e.g., 0.8), it is considered that the current expert knowledge has great uncertainty or incompleteness. At this time, the data-driven learning in the second part will be actively triggered to supplement and correct the knowledge model.
[0042] In the specific implementation process, taking the initial network construction for data center electrical fire risk as an example:
[0043] First, we construct the fault tree (FT) and transform the nodes:
[0044] This method takes electrical fires in data centers as the analysis object and summarizes risk influencing factors (RIFs) from four dimensions: equipment, environment, management, and human factors.
[0045] Based on risk factor analysis and references, a fault tree (FT) for electrical fires in data centers was constructed, such as... Figure 2As shown in the diagram. In this fault tree, the top event T is "data center fire", intermediate events include A1 "environmental problems", A2 "internal failure of the computer room", etc., and basic events include X1 "flammable materials ignite", X6 "excessive resistance", X11 "failure to follow operating procedures", etc.
[0046] Table 1 Event descriptions in the fault tree
[0047]
[0048] Subsequently, the fault tree was successfully mapped to the initial physical information Bayesian network, where the top event, intermediate event, and basic event of the FT correspond to the root node, intermediate node, and leaf node of the BN, respectively.
[0049] Then perform knowledge verification and data-driven triggering:
[0050] After the physical information Bayesian network is constructed, a cross-validation mechanism is introduced to score the reliability of the parent-child node relationship.
[0051] The scoring results (see Table 2) show that the cross-validation score between the parent node X1 (combustible material ignition) and the child node A1 is 0.63, which is lower than the preset threshold of 0.8.
[0052] In addition, although node X8 (system failure) scored up to standard (0.83), it was also identified as a node that needed to be further trained because its status was greatly affected by real-time operating conditions and lacked dynamism.
[0053] According to the preset triggering mechanism, the above scoring results (X1 score < 0.8) and dynamic analysis (X8 insufficient dynamics) jointly triggered the data-driven learning process in the second part to supplement and correct the knowledge models related to these two nodes.
[0054] Table 2 Cross-validation matrix scoring table
[0055]
[0056] Part Two: Building Bayesian Networks Through Data-Driven Approach
[0057] This section aims to automatically uncover potential risk associations that are not covered by expert knowledge from massive amounts of real-time data.
[0058] (1) Standardization of multi-source heterogeneous data: Preprocessing of multi-source heterogeneous data such as electrical parameters (e.g., voltage, current harmonics), environmental variables (e.g., temperature, humidity), and equipment status logs collected from the monitoring system. For example, Min-Max Normalization is used for voltage, current, and other data; dynamic binning discretization is performed for continuous variables such as humidity, for example, by dividing them into intervals of 0.5%RH; and linear interpolation and other methods are used to achieve second-level alignment for time-series data with different sampling frequencies.
[0059] (2) Latent association mining and network structure learning:
[0060] First, a mutual information (MI) algorithm based on the Kraskov estimator is used to calculate the nonlinear correlation between pairs of variables. For example, in a data center scenario, the mutual information value MI between abnormal humidity and cable short circuits might be calculated to be 0.47. When the MI value exceeds a preset threshold (e.g., 0.35), a potential correlation between the two is considered to exist.
[0061] Secondly, to rule out spurious associations caused by indirect influences (such as "A→C→B" leading to a correlation between A and B), a conditional independence test algorithm, such as the Hilbert-Schmidt independence criterion (HSIC), is used to test whether the two variables are independent given other variables. If the p-value is less than the significance level (e.g., 0.05), then a direct association between the two variables is confirmed.
[0062] Finally, based on the above test results, a constraint learning algorithm such as the PC algorithm (Peter-Clark algorithm) is used to generate an initial directed acyclic graph (DAG), and the confirmed direct dependencies (such as "abnormal humidity → cable short circuit") are dynamically added to the network as edges.
[0063] (3) Adaptive adjustment and probability update:
[0064] The prior probabilities determined by the historical information Bayesian network are updated using the posterior probabilities calculated from real-time monitoring data, and the probability parameters in the comprehensive Bayesian network are dynamically adjusted through a weighted fusion algorithm.
[0065] (4) Network Optimization and Incremental Learning: To ensure network reliability, a second-order conditional independence test is implemented to further filter out spurious associations. For example, if the intermediate path "humidity → insulation degradation → short circuit" is found, the direct edge "humidity → short circuit" is removed. To adapt to scenarios with high real-time requirements such as edge computing, hardware such as FPGAs can be used to accelerate computationally intensive algorithms such as HSIC, enabling real-time incremental learning of the network.
[0066] In the specific implementation process, data-driven modeling is used for uncertain nodes:
[0067] Multi-source heterogeneous data acquisition and processing:
[0068] To supplement the learning of the uncertain nodes (X1 "combustible material fire" and X8 "system failure") identified in the first part, a month of operational data from a data center from January 24 to February 24, 2025, was collected, totaling 5222 records.
[0069] The data source includes real-time monitoring data from sensors, covering seven key variables: temperature, humidity, current, voltage, UPS room battery internal resistance, residual current, and combustible material level.
[0070] These multi-source heterogeneous data were standardized, and continuous variables were discretized into different states. For example, "temperature" was divided into three states: "much higher than room temperature", "near room temperature", and "much lower than room temperature".
[0071] Network structure and parameter learning:
[0072] Before structural learning, mandatory relationships were set according to physical mechanisms. For example, temperature, humidity, and flammable load were placed in time layer 1, battery internal resistance was placed in time layer 2, voltage and current were placed in time layer 3, and residual current was placed in time layer 4 to guide the learning process.
[0073] A score-based Bayesian search algorithm was employed, and the network was trained on a dataset of 5222 data points using the Bayesian network software GeNIe 2.3. This automatically generated a data-driven Bayesian network structure. The learning results revealed the intrinsic relationships between variables. For example, the learned network showed that "battery internal resistance" is the parent node of both "voltage" and "current," while "voltage" and "current" together serve as the parent node of "residual current."
[0074] The Expectation-Maximization (EM) algorithm was used for parameter learning, and the Conditional Probability Table (CPT) of each node was accurately estimated, ultimately obtaining a Bayesian network model driven by real data and possessing probability propagation capabilities. For example, the probability of "Flammable Load" (FL) being in an abnormal state (State2) was learned to be 17%, and the probability of "Battery Internal Resistance" (BIR) being in an abnormal state was learned to be 19%.
[0075] Part Three: Network Convergence and Probability Update
[0076] This section aims to merge the two networks mentioned above and enable risk probability updates.
[0077] Network fusion and probability propagation: By connecting historical information Bayesian networks and data-driven Bayesian networks through shared risk nodes (such as "UPS overload," which is both a node in historical knowledge and a monitorable variable in the data), a probability propagation channel is established. KL divergence is used to evaluate the consistency of the probability distributions of the two networks at shared nodes, serving as a reference for fusion.
[0078] Dual-engine probability dynamic update:
[0079] The final probability of a node is determined by both historical information and real-time data. A weighted fusion algorithm is used for updating, and its core formula is:
[0080] ;
[0081] in, It is the prior probability obtained from historical information networks. It is the posterior probability calculated from real-time data. Weighting coefficients It is adaptive; for example, it can be designed as a function related to the lifespan of the equipment.
[0082] ;
[0083] in, The current service life of the equipment. For design life, and This is the aging sensitivity coefficient. This mechanism makes new equipment rely more on real-time data, while aging equipment relies more on historical experience. This is a regularization term used to penalize the differences in distributions between the two networks.
[0084] To handle high-dimensional conditional probability tables (CPTs), a conditional probability tensor within a sliding time window (e.g., 24 hours) can be constructed. And dimensionality reduction is achieved using tensor decomposition technology.
[0085] In the specific implementation process, dual-network fusion and probabilistic updates are adopted:
[0086] Network Convergence and Probability Transmission:
[0087] This method successfully integrates historical information-based Bayesian networks with data-driven Bayesian networks.
[0088] The key to the integration lies in the replacement of shared nodes: the "Residual Current" (RC) node in the data-driven network replaced the X8 (System Failure) node in the original physical information network; at the same time, the "Flammable Load" (FL) node in the data-driven network replaced the X1 (Flammable Fire) node in the original physical information network.
[0089] The relevant nodes in the data-driven network (such as temperature T, humidity H, battery internal resistance BIR, etc.) and their learned probabilistic relationships are integrated into the final comprehensive network, establishing a probability transmission channel.
[0090] Dual-engine probability dynamic update results:
[0091] During the fusion process, the prior probabilities and conditional probability tables learned in the data-driven network are used to update and replace the corresponding parameters in the original network, thus realizing dual-engine probability updates.
[0092] For example, in the merged network, the anomaly probability of the "Flammable Load" (FL) node was updated to 0.168, and the anomaly probability of the "Residual Current" (RC) node was updated to 0.092, both of which are derived from calculations based on real data.
[0093] The resulting integrated Bayesian network (such as Figure 3 (As shown) It combines the determinism of physical logic with the objectivity of data mining, and its parameters are the result of the combined effect of historical information and real-time data.
[0094] Part Four: Risk Analysis and Critical Node Protection
[0095] This section is designed to provide dynamic risk assessment and decision support.
[0096] Incremental Learning and Risk Analysis Output: An incremental learning module is established to periodically (e.g., quarterly) execute the GES (Greedy Equivalence Search) algorithm and optimize the fused network structure using the BIC (Bayesian Information Criterion) criterion. Simultaneously, the parameters are iterated using the Bayesian EM algorithm. When a risk analysis is detected... When the abnormal increase occurs, an anomaly detection alarm is triggered.
[0097] Finally, inference is performed based on the dynamically updated integrated Bayesian network, and the output is:
[0098] a) Risk propagation path analysis: such as identifying and sorting high-probability paths such as "distribution cabinet temperature exceeds standard → UPS overload → fire risk".
[0099] b) Quantification of protection priority for critical nodes: The protection priority of each node is calculated, and the calculation formula can be defined as:
[0100] ;
[0101] in, Let be the posterior failure probability of the node. This represents the marginal impact of the node's failure on the total system loss. This quantitative indicator provides a scientific basis for the allocation of preventative maintenance resources.
[0102] Finally, dynamic risk assessment and quantification of protection effectiveness are conducted:
[0103] Risk analysis and effect evaluation:
[0104] Based on the fused integrated Bayesian network, this method can perform effective risk analysis. Case studies show that the model can identify key risk propagation paths, such as "abnormal UPS battery internal resistance → current and voltage fluctuations → ignition of flammable materials".
[0105] To quantify risks and assess the effectiveness of protective measures, an event tree model was introduced, comprising three levels of safety barriers (S1: detectors, S2: emergency response, S3: fire suppression systems). The failure probability of each barrier was set according to actual conditions; for example, the failure probability of detectors was 0.012, and the failure probability of emergency response was 0.007.
[0106] The overall risk value under different combinations of barriers was quantified through calculation. The results show that the overall risk increases exponentially with the successive failure of safety barriers:
[0107] Level 1 Consequence (All Barriers Effective): Overall Risk is 0.53.
[0108] Secondary consequence (one barrier fails): Overall risk is 41.93.
[0109] Level 3 consequences (failure of both barriers): Overall risk is 7234.62.
[0110] Level 4 consequences (all barriers fail): The overall risk is 24223.60.
[0111] This result clearly demonstrates the effectiveness of the security barriers and provides a quantitative basis for the allocation of protective resources. Prioritizing the reliability of front-end barriers such as "detectors" and "emergency response" can achieve significant risk reduction benefits at a lower cost. This risk assessment result validates the powerful capabilities of this method in risk analysis and decision support.
[0112] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments according to this application. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0113] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0114] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A dynamic risk analysis method based on Bayesian networks, characterized in that, Includes the following steps: Constructing a Bayesian network of historical information: Based on the historical risk knowledge model, risk influencing factors are transformed into the first group of network nodes, and the initial topology of the first group of network nodes is established according to the logical relationship in the knowledge model. Constructing a data-driven Bayesian network: Acquire and process multi-source real-time monitoring data, and learn the correlation between variables in the data through data mining algorithms to generate a second set of network nodes and their data-driven topology; Network fusion and probability update: The historical information Bayesian network and the data-driven Bayesian network are connected through shared risk nodes to construct a comprehensive Bayesian network; the residual current nodes in the data-driven network replace the system fault nodes in the original physical information network; simultaneously, the combustible load nodes in the data-driven network replace the combustible ignition nodes in the original physical information network, and a dynamic probability update mechanism is established. This mechanism uses a weighted fusion algorithm, combining the prior probability determined by historical information and the posterior probability calculated by real-time monitoring data, to dynamically adjust the probability parameters in the comprehensive Bayesian network. The relevant nodes in the data-driven network and their learned probability relationships are integrated into the final comprehensive network, establishing a probability transmission channel. Risk quantification and analysis: Based on the dynamically updated integrated Bayesian network, risk inference is performed to output at least one risk quantification indicator; The step of constructing the historical information Bayesian network further includes: reconstructing the static logic gates in the historical risk knowledge model into dynamic logic gates with time-varying parameters, and dynamically adjusting the trigger thresholds of the dynamic logic gates according to the system state through a feedback control loop; the step of constructing the data-driven Bayesian network further includes: calculating the mutual information values between variables in the multi-source real-time monitoring data to identify potential dependencies, and applying a conditional independence test algorithm to verify the potential dependencies to filter out false associations, thereby generating the data-driven topology; When constructing a historical information Bayesian network, if the cross-validation score of expert knowledge is lower than a preset threshold, the construction process of the data-driven Bayesian network is triggered to supplement and correct the expert knowledge.
2. The method according to claim 1, characterized in that, The weighting coefficients in the weighted fusion algorithm are adaptively adjusted, and the adjustment of the weighting coefficients is based on at least the device's uptime or the system's health status indicators.
3. The method according to claim 1, characterized in that, The risk quantification indicators include risk propagation path ranking, critical node failure probability, or critical node protection priority.
4. The method according to claim 3, characterized in that, The calculation of the protection priority of critical nodes is based on the posterior probability and centrality of nodes calculated by the integrated Bayesian network.
5. The method according to claim 1, characterized in that, It also includes an incremental learning step: after the integrated Bayesian network is constructed, new real-time monitoring data is continuously received, and the topology of the integrated Bayesian network is optimized and the parameters are iterated using the incremental learning module.
Citation Information
Patent Citations
QAR data and Bayesian network-based flight risk analysis method
CN108711005A
High-speed railway risk assessment method based on Bayesian network
CN110991855A