Electricity stealing identification method based on graph calculation

By constructing a multidimensional behavioral graph model and performing dynamic perturbation analysis, the propagation path of electricity theft in the power user graph is simulated, which solves the problems of insufficient accuracy and robustness in existing electricity theft identification technologies, and enables accurate identification and efficient investigation of potential electricity theft users.

CN121010073APending Publication Date: 2025-11-25黄志春
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202511003000.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2025-11-25

AI Technical Summary

Technical Problem

Existing electricity theft detection technologies struggle to identify well-concealed electricity theft behaviors with "pseudo-normal" patterns, and fail to effectively and dynamically mine temporal behavioral differences and graph structure anomalies among users, resulting in limited accuracy and robustness.

Method used

A multidimensional behavioral graph model is constructed, which combines local structural perturbation analysis, behavioral propagation field model and graph embedding offset evaluation. By integrating the behavioral characteristics of electricity users with the relationship of power supply structure, the propagation path of abnormal behavior in the graph is simulated to identify potential electricity theft users.

Benefits of technology

It improves the accuracy and robustness of electricity theft detection, especially in scenarios involving group-based disguised electricity theft and chain-like propagation behaviors, demonstrating higher adaptability and discriminative power, reducing inspection costs and improving response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121010073A_ABST
    Figure CN121010073A_ABST
Patent Text Reader

Abstract

The invention discloses an electricity larceny identification method based on graph calculation, and particularly relates to the technical field of electricity utilization anomaly detection of an electric power system. Historical power consumption data and a power supply topological relation of power consumers are collected, and a multi-dimensional behavior graph model fusing behavior characteristics and structural information is constructed; performing structure disturbance analysis on each node in the graph, calculating information entropy change before and after node removal, performing attention fusion on a time sequence behavior feature of the node and a structure disturbance vector, constructing a joint feature vector, and enhancing feature expression through spectral clustering and linear reconstruction; a behavior propagation field and a disturbance adjustment mechanism are introduced into the graph to form a disturbance response graph, and an abnormal gathering area is identified through path energy analysis and focusing area fitting; calculating confidence scores of the nodes and outputting a suspicious user list; the method can realize efficient identification of electricity stealing behaviors with strong concealment and complex transmissibility, and has the advantages of high precision, strong interpretability and wide application scene adaptability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system power consumption anomaly detection technology, specifically to a graph computing-based method for identifying electricity theft. Background Technology

[0002] Electricity theft, a long-standing and covert problem in the power system, not only causes economic losses but also disrupts power load distribution and affects power supply security. Current common electricity theft detection technologies are mostly based on statistical analysis, rule engines, or machine learning models, identifying abnormal patterns in user electricity consumption data to determine if theft is occurring. However, these methods generally rely on single-point user characteristics and lack modeling of structural relationships between users, making it difficult to identify highly concealed electricity theft behaviors with "pseudo-normal" patterns. Therefore, their accuracy and robustness remain limited.

[0003] Although recent studies have attempted to enhance recognition performance by introducing graph neural networks or neighborhood analysis methods, most of these methods only focus on the static features of the graph structure, failing to dynamically mine the temporal behavioral differences between users, nor explicitly model the degree of structural anomalies of users in the graph. In addition, existing methods generally only consider physical topological relationships in the graph construction stage, ignoring the propagation and heterogeneity of electrical behavior patterns among neighboring users, which is insufficient to reveal the "perturbation trajectory" of anomalous behavior in the graph.

[0004] Therefore, there is an urgent need for an electricity theft identification method that combines behavioral pattern propagation graphs, structural disturbance measurement, and distributed embedding analysis. This method can systematically model the influence of electricity users on local structures in the graph and identify potential electricity theft users based on graph disturbance response behavior, thereby improving identification accuracy and interpretability. Summary of the Invention

[0005] The purpose of this invention is to provide a graph-based electricity theft identification method to address the shortcomings of the prior art.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a graph computation-based method for identifying electricity theft, comprising: S100. Obtain historical electricity consumption data of all power users in the target area, power supply topology connection information between users, and transformer cascading relationship, and construct a multi-dimensional behavioral graph model G, where nodes represent power users and edge weights represent the joint function of power supply topology strength and behavioral similarity. S200. Perform local structural perturbation analysis on the graph model G, construct the structural perturbation vector S for each node, and S represents the degree of change in graph structural entropy when the node is removed, which is used to calculate the impact of the node on the stability of the local graph. S300. Based on the historical behavior sequence of nodes, extract the dynamic behavior feature B of users and fuse it with the structural perturbation vector S to obtain a multi-dimensional joint feature vector W. S400. Introduce a behavior propagation field model on the graph model G to simulate the propagation path of abnormal behavior in the graph, construct a disturbance response graph, and perform coupling matching between W and the disturbance propagation path to identify the set of suspicious nodes C with dual abnormal behavior structures. S500. Perform graph embedding projection on each node in set C, identify its embedding offset in the disturbance response graph, and use the embedding offset as a confidence score to output the final list of suspected electricity theft users L.

[0007] Preferably, step S100 includes: extracting multi-scale behavioral pattern feature vectors based on the electricity consumption time series of each electricity user, including daily periodic fluctuation features, sudden change response features, and stability indicators; for any two electricity users, calculating the dynamic mutual information between their path connectivity indicators and behavioral features in the physical power supply topology, and fusing them to form a weighted edge weight function to construct a multi-dimensional behavioral graph model G containing heterogeneous relationships; in the process of constructing the graph model, an adaptive edge filtering mechanism is adopted to prune low-confidence edge weights, thereby retaining highly correlated paths and compressing the graph structure dimension.

[0008] Preferably, step S200 includes: in the graph model G, performing a node removal operation for each power user node, and calculating the change in information entropy ΔH of the local subgraph before and after node deletion based on the principle of minimum description length; the local subgraph consists of the first-order neighborhood and edge set of the target node, and the information entropy is calculated jointly based on the node degree distribution and edge weight distribution, with the entropy change ΔH serving as a node perturbation metric; after standardizing the ΔH of all nodes, a perturbation vector S is constructed as a feature input characterizing the degree of influence of nodes on the stability of the graph structure.

[0009] Preferably, step S300 includes: inputting the historical electricity consumption behavior sequence of the node into a temporal convolutional network to extract cross-scale dynamic behavior features B, the features including periodic stability, abnormal pulse frequency, and load sliding gradient; inputting the dynamic behavior features B and the structural perturbation vector S into a dual-channel attention fusion module, strengthening the highly coupled feature dimension and suppressing invalid interference terms through a gated residual mechanism, and outputting a joint feature vector W; the joint feature vector W contains an interactive representation of the dynamic response of behavior and structural stability, serving as the input node features in the graph propagation path.

[0010] Preferably, after constructing the joint feature vector W, the process includes: W is input to the multi-scale subspace decomposition module, which divides it into multiple sub-feature clusters with similar perturbation-behavior coupling patterns based on the feature spectrum clustering method. Linear separability reconstruction is performed on each sub-cluster to generate the reconstructed feature code W′. The spectral clustering constructs a feature affinity matrix based on the perturbation value gradient and the similarity of behavioral trends. The reconstruction process enhances the discriminative power between groups through orthogonal projection. W′ is used as the feature enhancement input for anomaly propagation modeling.

[0011] Preferably, S400 includes: Construct a node activation field based on the joint feature vector W, assign initial behavior activation values ​​to all nodes in the graph, and construct a dynamic behavior propagation field by combining edge weight propagation probability; During the propagation process, the activation attenuation factor in the propagation path is dynamically adjusted according to the graph structure perturbation vector S to form a perturbation response graph R, which reflects the asymmetric diffusion trajectory of abnormal behavior in the graph. Perform path energy-based response matching analysis on the disturbance response map R, define the path coupling index of the nodes, and combine it with the projection direction in W to determine the abnormal focusing on the path, and screen out the suspicious node set C with high structural disturbance and large behavioral deviation. The path energy is a function of the cumulative activation response intensity of the node in the propagation path and the perturbation suppression gradient, which is used to improve the sensitivity of anomaly identification to the impact of structural damping.

[0012] Preferably, the perturbation response map R is transformed into a multi-order path tensor structure, and cross-path propagation patterns are extracted based on a path-level attention mechanism. A structural sensitivity score is then performed on each propagation path. The score combines the positional entropy of the node in the path, the perturbation entropy gradient at the path's starting point, and the behavioral activation intensity at the endpoint. An anomaly focus matrix is ​​formed by merging these values ​​through a path-node aggregation function. Based on this matrix, a focal region fitting operation is performed on the graph to generate an anomaly influence domain mapping map. High-density focal regions are used as the boundaries of suspicious source behavior clusters, and the node set C is refined accordingly.

[0013] Preferably, S500 includes: Perform a two-view graph embedding on each node in set C in the perturbation response graph R, including the original graph embedding representation v0 and the perturbation response graph embedding representation v′; Based on the embedding trajectory offset of nodes in both types of graphs We construct a perturbation-aware confidence function to measure the representational variability of nodes under structural perturbation. The trajectory perturbation gain ratio index is introduced, and the ratio of Δv to the neighborhood average perturbation response amplitude is normalized to form a node-level confidence score γ. Output a list L of suspected nodes within the confidence boundary, sorted by confidence score γ.

[0014] Preferably, the node embedding offset Δv is used as the perturbation response dependent variable, and the dynamic behavior features B of the users of its neighboring nodes are combined with the structural perturbation vector S to construct a perturbation causal graph. A perturbation-aware causal graph convolutional network is introduced on the perturbation causal graph. By modeling the structural causal path with attention weighting, the dominant causal path and attribution strength of each node's embedding offset are inferred. The attribution strength serves as a node confidence correction factor γ″ and is used to reorder and update the list of suspected electricity theft nodes L.

[0015] The technical effects and advantages provided by the present invention in the above technical solution are as follows: 1. This invention constructs a multi-dimensional graph model that integrates the behavioral characteristics of electricity users with the relationship between power supply structure. It innovatively introduces mechanisms such as structural disturbance analysis, behavioral propagation response simulation, and graph embedding offset evaluation to achieve accurate identification of potential electricity theft users. Compared to the limitations of traditional methods that rely solely on behavioral anomalies or static graph analysis, this invention improves the sensitivity and robustness of anomaly detection from the dual dimensions of structural dynamics and behavioral evolution. It exhibits higher adaptability and discriminative power, especially in complex scenarios such as identifying group-based disguised electricity theft and chain-like propagation behaviors.

[0016] 2. By introducing causal graph convolutional inference and trajectory perturbation gain ratio modeling, this invention achieves stronger interpretability and accuracy in the suspicious node scoring and ranking stages. This mechanism not only improves the credibility of abnormal outputs but also provides practical maintenance personnel with logically based troubleshooting priority suggestions, thereby significantly reducing inspection costs and improving response efficiency. It has broad application prospects and technological promotion value in the fields of smart grid security monitoring and energy auditing. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0018] Figure 1 This is a mind map of the method of the present invention. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] Example 1, please refer to Figure 1 As shown in this embodiment, a graph computation-based electricity theft detection method includes: S100. Obtain historical electricity consumption data of all power users in the target area, power supply topology connection information between users, and transformer cascading relationship, and construct a multi-dimensional behavioral graph model G, where nodes represent power users and edge weights represent the joint function of power supply topology strength and behavioral similarity. S200. Perform local structural perturbation analysis on the graph model G, construct the structural perturbation vector S for each node, and S represents the degree of change in graph structural entropy when the node is removed, which is used to calculate the impact of the node on the stability of the local graph. S300. Based on the historical behavior sequence of nodes, extract the dynamic behavior feature B of users and fuse it with the structural perturbation vector S to obtain a multi-dimensional joint feature vector W. S400. Introduce a behavior propagation field model on the graph model G to simulate the propagation path of abnormal behavior in the graph, construct a disturbance response graph, and perform coupling matching between W and the disturbance propagation path to identify the set of suspicious nodes C with dual abnormal behavior structures. S500. Perform graph embedding projection on each node in set C, identify its embedding offset in the disturbance response graph, and use the embedding offset as a confidence score to output the final list of suspected electricity theft users L.

[0021] In this embodiment of the invention, electricity consumption time-series data for each electricity user within the target area is first collected from the smart meter system. Assuming that for each user... The daily electricity consumption time series is denoted as n represents the total number of time points, and its time granularity can be at the hour level or a finer 15-minute level in order to capture its power consumption fluctuation patterns more precisely.

[0022] For this time series, the following three types of multi-scale behavioral pattern features are extracted: Daily periodic fluctuation characteristics: By performing a Fourier transform on the time series, the dominant periodic frequency component is identified, thereby obtaining the typical load variation trend of users on weekdays and weekends. The period amplitude ratio is used to characterize the stability and predictability of their electricity consumption behavior.

[0023] Sudden Response Characteristics: Peak events are identified through gradient change detection within a sliding window. The peak intensity, frequency of occurrence, and pre-peak to post-peak change rate are calculated to quantify the short-term fluctuation characteristics of electricity consumption behavior. This characteristic is particularly useful for identifying suspicious behavior such as "sudden large-scale power withdrawals."

[0024] Behavioral stability indicators: Based on indicators such as time series variance, load change rate and differences between adjacent periods, the overall stationarity and nonlinear trend of user behavior series are comprehensively evaluated to distinguish between users with regular load and users who may be strategically disguising their behavior.

[0025] The above behavioral features will be encoded into fixed-length vectors. d serves as the semantic representation of the behavior of each node. R is the set of real numbers, and d is the vector dimension.

[0026] This invention further integrates power supply topology information. Power users are connected to the distribution network through transformers and low-voltage lines, forming a natural physical adjacency. For any two users... and This invention defines its physical path connectivity index. It can be represented in one of the following forms: Topology hop distance: Tracing the path of each user backward from the power supply transformer level, and calculating the number of relay nodes contained in the shortest connection path between them; Line impedance estimation: The electrical distance between the two nodes is calculated based on the GIS map and cable parameters.

[0027] Meanwhile, to characterize the potential correlations between user behaviors, the Dynamic Mutual Information (DMI) metric is introduced: ;in, and users respectively and The time-series feature window value, P Its joint probability density is obtained from the sliding window sequence distribution statistics. Indicates electricity user and The dynamic mutual information value within a certain time window is used as an indicator of behavioral similarity. The higher the value, the stronger the synchronicity of the behavioral changes between the two. k represents the sliding time slice index within the time window (such as hour or 15-minute granularity), and the total number depends on the sequence length and the sliding window parameters. Indicates user Behavior value at time slice k The marginal probability distribution. Indicates user Behavior value at time slice k The edge probability distribution. This mutual information index can effectively measure the degree of behavioral coupling between users, that is, the synchronicity or correlation of their load changes.

[0028] Ultimately, the physical topology connectivity index will be used. Mutual information indicators with behavior Perform weighted fusion and define a composite edge weight function among users. Where α∈[0,1] is an adjustable fusion parameter, and ϵ is a constant term to prevent division by zero. This edge weight function takes into account both structural connectivity and behavioral similarity, reflecting the comprehensive correlation between users.

[0029] Based on the above definition of edge weights, all users are constructed into an undirected graph G=(V,E,W), where the node set V represents all electricity users, the edge set E consists of all user pairs that satisfy the edge weight threshold, and the edge weight set W={ } indicates the strength of the association between them.

[0030] To prevent low-quality edges or accidental high mutual information connections from introducing noise into the graph structure, this invention introduces an adaptive edge selection mechanism, which includes the following two steps: Local edge confidence assessment: For each node, based on the weight distribution of all its edges, calculate the local confidence quantiles of the edges (such as the quartiles above), and mark edges that are less than the dynamic threshold as redundant edges; Graph pruning and compression strategy: Combine the local deviation coefficient of node degree distribution to reduce redundant edges, ensuring that each node retains representative high-quality edge connections, reducing graph structural redundancy, and improving graph computation efficiency and robustness.

[0031] This adaptive mechanism differs from the traditional static edge weight pruning method. It can dynamically adjust the edge selection criteria to adapt to the heterogeneity of different regional densities and behavioral characteristics, and is especially suitable for power consumption scenarios with sparse structures or discrete behaviors.

[0032] Through the above processing, the constructed multidimensional behavioral graph model G has the following significant technical effects: Strong structural behavior integration: Each edge not only represents a physical connection, but also embeds behavioral similarity semantics, which helps to capture features of "behavioral proximity but physical distance" or "physical adjacency but abnormal behavior"; The graph structure has good stability: the adaptive pruning mechanism ensures the simplicity and robustness of the graph and avoids overfitting and propagating noise; Strong information carrying capacity: After node embedding, multiple types of information such as its behavioral semantics, structural centrality, and perturbation response can be obtained simultaneously, providing a solid foundation for subsequent embedding learning, clustering, and anomaly detection.

[0033] Based on the completed construction of the multidimensional behavioral graph model G of power users, this invention proposes a method based on local structural disturbance response analysis in step S200 to further evaluate the impact of each node on the stability of the local graph structure, used to construct the structural disturbance vector S corresponding to each node. This method not only considers the node topological attributes but also introduces the minimum description length principle and joint entropy theory to quantify the changes in structural information before and after node removal, thereby forming a highly discriminative structural stability index and providing structural support features for subsequent behavior-structure anomaly detection.

[0034] The core of this step is to perform a "node removal perturbation" operation on each power user node in the graph model G, and analyze the change in information entropy of its first-order neighborhood with and without the node, denoted as ΔH. This perturbation value serves as a metric for the impact of a node on the local stability of the graph at the structural level, reflecting its "structural sensitivity" or "perturbation coreness" in the graph. After standardization, the ΔH values ​​corresponding to all nodes form a global perturbation vector set S, which serves as the input feature vector for subsequent modeling processes.

[0035] Let the graph model be G=(V,E,W), where: V represents the set of nodes, i.e., all electricity users; E represents the set of edges, each edge representing the structural / behavioral relationship between two users; W={ } represents the set of edge weights, which is calculated by integrating physical topological connectivity and behavioral dynamic mutual information.

[0036] For any node Define its first-order neighborhood subgraph It has the following structure: ;in: , is a set containing itself and its first-order neighbors; : indicates with The set of edges whose endpoints are midpoints; To and The corresponding set of edge weights. Perform a node perturbation operation, that is, temporarily remove a node from graph G. And all its associated edges, construct the perturbed subgraph .

[0037] Information entropy is a measure of graph structural complexity, used to gauge the degree of disorder in the distribution of nodes or edges. To evaluate the changes in structural information caused by node removal, this invention constructs an information entropy index before and after the perturbation based on the joint entropy of node degree distribution and edge weight distribution, as follows: Define the node degree probability distribution as follows: ;in Represents a node The degree of the edge. After edge weight normalization, the edge weight distribution is defined as: In the formula, The edge weight represents the normalized proportion of the edge weight in the current local subgraph, i.e., the proportion of the "information" carried by that edge in the overall edge set. This indicator is used to construct the information entropy of the graph structure and is a key variable for evaluating structural perturbations. w represents the edge weight, which in this invention is jointly calculated from "physical power supply connectivity" and "behavioral feature similarity," reflecting the comprehensive correlation strength between two power users.

[0038] Joint entropy is defined as: Similarly, when removing a node... Then, the node degree distribution and edge weight distribution are recalculated to obtain the perturbed entropy. Structural disturbance is defined as the change in entropy. The expression is: This indicator reflects the strength of a node's contribution to the distribution of structural information. The larger ΔH is, the more crucial the node's role is in maintaining the orderliness of its local graph structure.

[0039] To keep all node perturbation values ​​within a comparable range, for all The value is Z-score standardized: ;in: This represents the mean of all node perturbation values; This represents the standard deviation of the disturbance value. For standardization Values. Finally, the perturbation response vector for each node is obtained. This serves as the structural feature input for subsequent joint feature construction (see step S300).

[0040] The scheme proposed in this invention, which constructs a structural stability vector S based on structural perturbation, has the following technical advantages: Asymmetric perturbation modeling: Employing a node removal approach, this method simulates the asymmetric response process of local graph structures, which differs from conventional static centrality analysis. Information-theoretic quantification mechanism: Based on the principle of minimum description length, it uses joint entropy to measure the change in graph structure complexity, with a clear theoretical basis and strong computational stability; High sensitivity to local structure: By analyzing only the first-order neighborhood of a node, the structural context is preserved, balancing local representation capability and global computational efficiency; Enhanced interpretability: The visualization of ΔH values ​​reveals the distribution pattern of highly disturbed core nodes, providing support for focused detection of structures under electricity theft patterns.

[0041] Building upon graph model construction (S100) and structural disturbance assessment (S200), this invention proposes a cross-scale temporal modeling and graph structure awareness joint modeling method in step S300 to construct a highly expressive joint feature vector W, aiming to achieve deep integration of power user behavior characteristics and structural features. By introducing a multi-channel network structure and a spectral clustering subspace decomposition strategy, the model's ability to identify complex abnormal behaviors is effectively enhanced.

[0042] Historical electricity consumption behavior of power users typically exhibits various dynamic characteristics, including periodicity, volatility, and abrupt changes. To fully extract these temporal features, this invention inputs the historical electricity consumption behavior sequence of each node into a Temporal Convolutional Network (TCN) for feature extraction. Compared to traditional recurrent neural networks, TCN possesses stronger parallelism and more stable gradient propagation capabilities, enabling it to capture electricity consumption behavior patterns across different temporal scales.

[0043] Specifically, the following three types of core behavioral features are extracted from TCN and uniformly constitute the dynamic behavioral feature vector B: Periodic stability: measures the periodic consistency of electricity load, obtained by analyzing the intensity and trend of the dominant frequency component in the sequence, reflecting the stability of user behavior.

[0044] Abnormal pulse frequency: Counts the number of sudden power consumption peaks in a short period of time, used to detect suspicious behavior patterns such as abnormal startup and power surge.

[0045] Load sliding gradient: By setting the window step size, the average slope and fluctuation range of the sliding load change are calculated to identify the rate and trend of change of the electricity consumption curve.

[0046] After the above feature encoding, the behavior representation vector B of each user node is formed, which serves as a one-dimensional semantic channel in the graph input.

[0047] To integrate structural and behavioral feature information, this invention proposes a dual-channel attention fusion mechanism. Specifically, the aforementioned dynamic behavioral feature vector B and structural perturbation vector S are input into two independent attention channels, and a cross-attention mechanism is used to model the higher-order coupling relationship between the two.

[0048] The fusion module mainly includes the following two key components: Attention channel mechanism: Channel weighting is applied to B and S respectively to identify feature dimensions with high representational value in behavioral changes and structural perturbations; Gated residual mechanism: A gating function is introduced to control the gain effect of the structural channel on the behavioral channel, and the original distribution information of the low-dimensional channel features is preserved through residual connection to suppress invalid interference.

[0049] The final output is a joint feature vector W, which integrates the dynamic response capability of node behavior and the stability of structural perturbation, and serves as the input feature in the subsequent graph propagation path model.

[0050] To further enhance feature representation capabilities and optimize the input stability of the graph propagation model, this invention introduces a multi-scale subspace decomposition module after constructing W, which is used to identify the clustering structure between features, purify the core dimensions, and reconstruct a feature representation W′ with good separability.

[0051] The process includes the following core technical steps: Spectral clustering divides the feature space into sub-feature clusters: Using W as input, a feature affinity matrix is ​​constructed. This affinity matrix construction considers not only the gradient differences in structural perturbation values ​​but also the similarity between behavioral trends to form a similarity measure in a multi-dimensional feature space. The spectral clustering algorithm is used to divide the feature space into sub-clusters, resulting in subsets of multiple similar perturbation-behavior coupling patterns.

[0052] Linear separability reconstruction mechanism: For each sub-feature cluster, an orthogonalization operation is performed using the feature projection matrix to make it as linearly separable as possible in the new low-dimensional space. This projection process is based on the principle of maximizing inter-class distance and minimizing intra-class compactness, improving classification stability and clustering clarity in the subspace.

[0053] Reconstructed feature encoding output: The feature vectors after projection of all subspaces are aggregated again into an enhanced joint feature vector W′. This vector retains the coupling structure information in the original features, while improving the discriminative and generalization abilities in graph propagation path modeling.

[0054] The proposed process for constructing the multidimensional enhanced feature W′ from the original power consumption sequence has the following significant technical advantages: Deep fusion of behavioral structure: By introducing a dual-channel attention mechanism and residual enhancement strategy, the noise interference and redundancy problems existing in the traditional fusion of structure and behavioral features are effectively overcome; Multi-scale dynamic response modeling: The TCN architecture and sliding feature design enable the system to jointly model sudden power consumption behavior and long-term power consumption trends; Enhanced subspace representation capability: Through spectral clustering and orthogonal projection processes, it significantly improves the distinguishability of features in anomaly detection and adapts to the different manifestations of various types of electricity theft. Both adaptability and interpretability are emphasized: The reconstructed vector W′ can not only be used as input to the propagation model, but also has structural interpretive value for the behavior-perturbation coupling relationship, which is conducive to building an interpretable anomaly recognition system.

[0055] To accurately identify potential electricity thieves, this invention, after obtaining a joint feature vector W that integrates behavioral and structural perturbation features, designs a behavior response identification model based on a graph propagation mechanism. This model models the propagation path and diffusion characteristics of abnormal behavior within a global graph structure, thereby filtering out suspicious nodes with high structural influence and behavioral deviation. This step not only simulates the propagation process of abnormal behavior but also introduces perturbation modulation and path energy analysis mechanisms to ensure high robustness and structural sensitivity in the identification process.

[0056] This step first assigns an initial behavioral activation value to each node in the graph based on the joint feature vector W. This activation value comprehensively reflects the changing trend of the node's electricity consumption behavior and its ability to respond to structural disturbances. Based on this, and combined with the edge weight information in the graph model (representing the comprehensive correlation strength between users), a behavioral propagation field is constructed.

[0057] The core mechanism of the propagation field is as follows: the initial activation value gradually diffuses along the edges of the graph, and the propagation intensity is weighted according to the edge weights, simulating the process of abnormal behavior propagating outward from the source node in the graph. Unlike ordinary graph diffusion algorithms, this invention introduces a dynamic adjustment mechanism for each propagation path to form an asymmetric, structure-response-driven propagation trajectory.

[0058] During the behavior activation propagation process, this invention introduces a graph structure perturbation vector S to regulate the propagation path. Specifically: For each propagation path, the propagation attenuation factor is dynamically adjusted based on the perturbation values ​​of the nodes it passes through. The higher the node perturbation value, the greater the impact of that node on the stability of the local structure, and therefore the stronger its "damping effect" in propagation, making the propagated signal more prone to attenuation. Conversely, for nodes with lower perturbation values, the propagation path allows for longer distance propagation, simulating the risk of “long-distance penetration” of anomalous behavior in regions with low structural dependence.

[0059] Through the above perturbation adjustment mechanism, the final perturbation response graph R is formed, which is consistent with the original graph in terms of edge structure. Figure 1 While the propagation intensity between nodes is uniform, it can accurately reflect the interference effect of graph structure on behavior propagation.

[0060] In the perturbation response diagram R, this invention identifies potential anomalous nodes by analyzing the "cumulative response energy" along the behavior propagation path. The energy index comprehensively considers the following two aspects: Cumulative activation intensity: This represents the sum of the activation values ​​of each node along the path starting from the propagation source node, reflecting the degree of aggregation of abnormal behavior along that path. Perturbation suppression gradient: This refers to the degree to which structural perturbation affects the propagation at each step of the path, reflecting the "persistent penetration capability" of anomalies under structural intervention.

[0061] Combining the two factors mentioned above, the path energy value is calculated to measure the "degree of abnormal focusing" on the propagation path. The higher the energy, the more likely the path is carrying abnormal signals that have not been adequately suppressed by the graph structure, and its terminal node is very likely to be a manifestation node or propagation source of electricity theft.

[0062] To further improve the accuracy of anomaly node identification, this invention also introduces a path coupling index, which compares the consistency of a node's energy distribution across multiple propagation paths and combines this with its directional projection result in the joint feature vector W to evaluate the degree of anomalous fusion in both the behavioral and structural domains. Finally, a set C of nodes with high focus and high coupling is selected as a candidate set of suspected anomaly nodes.

[0063] To achieve full-map-level modeling and visualization of abnormal propagation trajectories, this invention further tensors and encodes multiple propagation paths in the perturbation response map R, forming a multi-order path tensor structure. This structure can describe the multi-hop propagation relationships between nodes at different depths and is used for feature learning of higher-order paths.

[0064] Based on this tensor structure, a path-level attention mechanism is introduced to comprehensively extract the propagation pattern from the following three dimensions: Node position entropy in a path: used to identify whether a node's structural position in a path has an informational advantage, such as being located at the beginning, middle, or end of the path; Perturbation entropy gradient at the path origin: to assess the intensity and rate of change of structural perturbation at the propagation source, in order to determine the driving force of abnormal behavior; Activation intensity at the end of the path: used to determine whether the abnormal signal has been "effectively landed" on the path, that is, whether a high-intensity activation has been formed at the terminal node.

[0065] After fusing the above features, a path structure sensitivity scoring mechanism is constructed, ultimately outputting the anomaly focus degree of each path. These path features are then projected back onto the nodes in the graph using a path-node aggregation function, forming an anomaly focus degree matrix.

[0066] Based on this, a region-fitting operation is performed on the graph to locate sub-regions exhibiting high-density anomaly clusters in the anomaly focus matrix, constructing an anomaly influence domain mapping map. This mapping map is used to identify the main cluster boundaries of anomaly propagation and to screen out the key nodes most likely to be anomaly sources or anomaly forwarders.

[0067] Finally, based on the characteristics of the influence domain boundary and node coupling, the node set C is refined to form a more reliable and clustered set of suspected electricity theft users.

[0068] This step integrates three mechanisms—behavior propagation simulation, perturbation regulation modeling, and path focusing analysis—within the graph computing framework, resulting in the following significant technical effects: Dynamic modeling of abnormal propagation process: Simulating the diffusion trajectory of abnormal behavior, rather than static clustering, to improve the effectiveness of identifying chain-like electricity theft; Enhanced interpretability of structural disturbance control mechanisms: The degree of response along the propagation path is directly related to structural disturbance indicators, facilitating source tracing and decision interpretation; Path energy + attention mechanism high-dimensional feature fusion: cross-path and cross-scale aggregation analysis to improve the ability to identify complex behavioral patterns; The graph focusing mechanism enables cluster-level identification: it supports spatial modeling and visual boundary fitting of areas affected by anomalies, which helps to quickly identify clusters of abnormal behavior from user groups.

[0069] Based on the construction of a perturbation response map and the identification of a set of suspicious nodes C, this invention proposes a confidence scoring mechanism (S500) based on graph embedding trajectory offset analysis and causal attribution learning to achieve more accurate and interpretable anomaly node identification. This method enhances the discriminative power and credibility ranking ability of anomaly node identification through unconventional techniques such as dual-view embedding comparison, perturbation gain ratio modeling, and structural causal inference networks.

[0070] To accurately characterize the impact of graph structure perturbations on node representation, this invention first performs graph embedding operations on each node in set C on two separate graph structures: The first is the embedded representation generated in the original graph G, denoted as v0, which reflects the normal structure and behavior of the nodes when they are not subjected to perturbation. Second, the embedded representation generated in the perturbation response map R, denoted as v′, describes the changes in the characteristic expression of nodes under the control of structural perturbations.

[0071] By comparing the two embedding representations, the embedding offset trajectory Δv of each node is calculated. This indicates the degree of variation in the characteristic projection under structural perturbation. The larger the offset value, the more sensitive the node is to structural changes, the more unstable its behavior, and the higher its potential anomaly.

[0072] To transform the embedded offset value Δv into a scoring metric that can be used for ranking, this invention proposes a method for constructing the trajectory perturbation gain ratio. This mechanism not only focuses on the offset intensity of an individual node but also considers its relative performance differences within its neighborhood, thereby suppressing scoring bias in densely structured local regions.

[0073] The specific method is as follows: For each node, obtain the average response magnitude of its first-order neighbor nodes in the perturbation response graph; The perturbation gain ratio is obtained by normalizing the ratio of the embedding offset value of this node to the average value of its neighborhood, which represents the relative strength of the abnormal offset of this node in its structural context.

[0074] Based on this normalization, an initial confidence score γ is generated for each node to reflect its abnormal confidence level under perturbation conditions. Subsequently, the node set C is sorted in descending order according to the γ value, and nodes within the confidence boundary are selected as the preliminary list of suspected electricity theft users L.

[0075] To further improve the explanatory power and accuracy of the scoring mechanism, this invention introduces a perturbation causal modeling mechanism based on the embedded offset value Δv, and proposes a perturbation-aware causal graph convolutional network (PC-GCN) to perform causal attribution analysis on the embedded offset of each node.

[0076] The specific steps are as follows: The embedded offset Δv is regarded as the output dependent variable of the node's perturbation response. The behavioral characteristics B (periodicity, mutation frequency, load gradient) of its neighboring nodes and the structural perturbation value S are combined as causal input variables to establish a causal dependency path under the constraints of the graph structure. Based on the aforementioned causal graph structure, a graph convolutional network with attention weights is used to model the causal influence of input features on output offset, learning the weighted causal contribution of each input variable on the structural path.

[0077] Output the dominant causal path and its influence weight for each node, that is, identify the main neighborhood variables and structural factors that cause a node to have a significant embedding shift.

[0078] This attribution mechanism not only provides a quantitative explanation of behavioral perturbations and structural changes for anomalous responses, but also identifies potential transmission nodes that are “non-abnormal behaviors but affected by anomalous propagation,” thus enhancing the robustness of the model.

[0079] After obtaining the causal attribution strength of each node, it is used as a confidence correction factor to generate a corrected confidence score γ″, which is used to replace the original γ to perform the final reordering of suspicious nodes.

[0080] This correction process combines two dimensions: First, there is the difference between the node's own embedding offset and the neighborhood response; Second, the actual interpretability of this offset in the causal path.

[0081] Finally, based on γ″, the node set C is reordered to output a list L of suspected electricity theft users with higher judgment confidence and attribution interpretability.

[0082] The anomaly node scoring mechanism proposed in this step, which combines graph embedding offset and causal graph modeling, demonstrates the following significant technical advantages in practical applications: By integrating dual-image perspectives and embedding them together, the sensitivity to structural disturbances is enhanced. By utilizing the trajectory perturbation gain ratio to introduce a neighborhood comparison mechanism, the fairness of the scoring is improved; Combining cause-effect graph modeling to explain the causes of deviation improves the interpretability and accuracy of the scores; A revised confidence scoring system was constructed, which significantly improved the final anomaly output ranking effect.

[0083] Compared with traditional clustering offset scoring or single-point graph convolution, this invention has made significant breakthroughs in structural perturbation perception, scoring accuracy and model interpretability, and is particularly suitable for identifying electricity theft patterns with high latency, ambiguous boundaries or propagation abnormal behavior.

[0084] Example 2: To demonstrate the effectiveness and technical advantages of the method of the present invention in identifying electricity theft, a distribution network in a certain urban area was selected for implementation. This included 1,000 smart meter users, with an electricity consumption time series spanning 4 months, and a sampling frequency of one record every 15 minutes, totaling approximately 115,000 data points per user; Known electricity theft samples: Through historical inspections and verifications by the power distribution company, a total of 20 genuine electricity theft users were identified as "Ground Truth" users.

[0085] System platform environment: Python 3.9 + PyTorch 1.12, 4 TCN layers, kernel size of 3 per layer, and PyTorch Geometric is used for graph computation module.

[0086] S100 multidimensional graph construction: Extract power consumption characteristics such as periodic stability, pulse frequency, and load sliding gradient according to the S100 specification; calculate the path connectivity and dynamic mutual information between nodes, generate weighted edges, and the average degree of the graph after pruning is 6.4.

[0087] S200 structural disturbance calibration: Statistical node disturbance values ​​ΔH are used, and after standardization, the distribution has a mean of 0 and a standard deviation of 1. Nodes with abnormal ΔH > 2.5 are selected, accounting for 3% of the total.

[0088] S300 Feature Fusion and Enhancement: TCN extracts behavioral features, fuses structural perturbation vectors, performs spectral clustering and orthogonal reconstruction, generates enhanced features W′, and improves the class separability index (Davies–BouldinIndex) by 15%.

[0089] S400 Anomaly Propagation Mapping: Construct a disturbance response map R, extract path energy and focal regions, determine the node set C, and select an average of 80 suspicious nodes.

[0090] S500 Embedding Analysis and Causal Assessment: The mean value of the dual-view embedding offset Δv is 0.028, and the mean value of the neighborhood gain ratio γ is 1.2; the causal attribution network determines the important path features, and after outputting γ″, 60 nodes within the confidence boundary are selected.

[0091] Comparison of experimental results: method Precision Recall F1 Score AUC Rule-based model (threshold + time series anomalies) 0.42 0.55 0.48 0.64 GCN Anomaly Detection 0.55 0.60 0.57 0.72 Method of the present invention 0.78 0.80 0.79 0.88 Experimental results show that: Precision is significantly improved from 42% to 78% in the traditional threshold method, indicating a significant decrease in false alarm rate; Recall is improved to 80%, indicating that this method can more comprehensively capture potential electricity theft users; AUC (area under the ROC curve) is close to 0.9, indicating that the model has excellent recognition performance.

[0092] Further verification analysis: The coupling of abnormal behavior and structural disturbance can identify electricity theft nodes 3-7 days earlier, which is 2 days earlier on average compared with traditional time series analysis; the confidence ranking accuracy can be used for priority screening: among the top 20 suspected users, the matching rate of real electricity theft users reaches 95%.

[0093] The experimental results of this embodiment demonstrate that the graph-based electricity theft identification method described in this application significantly improves both identification efficiency and accuracy compared to traditional rule-based or single-graph models. Furthermore, the early warning and confidence ranking mechanisms effectively reduce the cost and operational risks of abnormal inspections. In addition, the coupled detection of structural disturbances and behaviors provides more interpretable judgment criteria, making it highly valuable for practical application.

[0094] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A graph computation-based method for identifying electricity theft, characterized in that: include: S100. Obtain historical electricity consumption data of all power users in the target area, power supply topology connection information between users, and transformer cascading relationship, and construct a multi-dimensional behavioral graph model G, where nodes represent power users and edge weights represent the joint function of power supply topology strength and behavioral similarity. S200. Perform local structural perturbation analysis on the graph model G, construct the structural perturbation vector S for each node, and S represents the degree of change in graph structural entropy when the node is removed, which is used to calculate the impact of the node on the stability of the local graph. S300. Based on the historical behavior sequence of nodes, extract the dynamic behavior feature B of users and fuse it with the structural perturbation vector S to obtain a multi-dimensional joint feature vector W. S400. Introduce a behavior propagation field model on the graph model G to simulate the propagation path of abnormal behavior in the graph, construct a disturbance response graph, and perform coupling matching between W and the disturbance propagation path to identify the set of suspicious nodes C with dual abnormal behavior structures. S500. Perform graph embedding projection on each node in set C, identify its embedding offset in the disturbance response graph, and use the embedding offset as a confidence score to output the final list of suspected electricity theft users L.

2. The graph computation-based electricity theft identification method according to claim 1, characterized in that: S100 includes: extracting multi-scale behavioral pattern feature vectors based on the electricity consumption time series of each electricity user, including daily periodic fluctuation features, sudden change response features, and stability indicators; for any two electricity users, calculating the dynamic mutual information between their path connectivity indicators and behavioral features in the physical power supply topology, and fusing them to form a weighted edge weight function to construct a multi-dimensional behavioral graph model G containing heterogeneous relationships; in the process of constructing the graph model, an adaptive edge filtering mechanism is adopted to prune low-confidence edge weights, thereby retaining highly correlated paths and compressing the graph structure dimension.

3. The graph computation-based electricity theft identification method according to claim 1, characterized in that: S200 includes: in the graph model G, for each power user node, performing a node removal operation, and calculating the change in information entropy ΔH of the local subgraph before and after node deletion based on the principle of minimum description length; the local subgraph is composed of the first-order neighborhood and edge set of the target node, and the information entropy is calculated jointly based on the node degree distribution and edge weight distribution, and the entropy change ΔH is used as a node perturbation metric; after standardizing the ΔH of all nodes, a perturbation vector S is constructed as a feature input characterizing the degree of influence of the node on the stability of the graph structure.

4. The graph computation-based electricity theft identification method according to claim 1, characterized in that: S300 includes: inputting the historical power consumption behavior sequence of the node into a temporal convolutional network to extract cross-scale dynamic behavior features B, the features including periodic stability, abnormal pulse frequency, and load sliding gradient; inputting the dynamic behavior features B and the structural perturbation vector S into a dual-channel attention fusion module, strengthening the highly coupled feature dimension and suppressing invalid interference terms through a gated residual mechanism, and outputting a joint feature vector W; the joint feature vector W contains an interactive representation of the dynamic response of behavior and structural stability, and serves as the input node features in the graph propagation path.

5. The graph computation-based electricity theft identification method according to claim 4, characterized in that: After constructing the joint feature vector W, the following steps are included: W is input to the multi-scale subspace decomposition module, which divides it into multiple sub-feature clusters with similar perturbation-behavior coupling patterns based on the feature spectrum clustering method. Linear separability reconstruction is performed on each sub-cluster to generate the reconstructed feature code W′. The spectral clustering constructs a feature affinity matrix based on the perturbation value gradient and the similarity of behavioral trends. The reconstruction process enhances the discriminative power between groups through orthogonal projection. W′ is used as the feature enhancement input for anomaly propagation modeling.

6. The graph computation-based electricity theft identification method according to claim 1, characterized in that: The S400 includes: Construct a node activation field based on the joint feature vector W, assign initial behavior activation values ​​to all nodes in the graph, and construct a dynamic behavior propagation field by combining edge weight propagation probability; During the propagation process, the activation attenuation factor in the propagation path is dynamically adjusted according to the graph structure perturbation vector S to form a perturbation response graph R, which reflects the asymmetric diffusion trajectory of abnormal behavior in the graph. Perform path energy-based response matching analysis on the disturbance response map R, define the path coupling index of the nodes, and combine it with the projection direction in W to determine the abnormal focusing on the path, and screen out the suspicious node set C with high structural disturbance and large behavioral deviation. The path energy is a function of the cumulative activation response intensity of the node in the propagation path and the perturbation suppression gradient, which is used to improve the sensitivity of anomaly identification to the impact of structural damping.

7. The graph computation-based electricity theft identification method according to claim 6, characterized in that: The perturbation response graph R is transformed into a multi-order path tensor structure. Cross-path propagation patterns are extracted based on the path-level attention mechanism, and structural sensitivity scores are performed on each propagation path. The scoring combines the position entropy of the node in the path, the perturbation entropy gradient at the starting point of the path, and the behavioral activation intensity at the ending point, and is merged into an anomaly focus matrix through a path-node aggregation function. Based on the matrix, a focal region fitting operation is performed on the graph to generate an anomaly influence domain mapping map. The high-density focal region is used as the boundary of the cluster of suspected source behaviors, and the node set C is refined accordingly.

8. The graph computation-based electricity theft identification method according to claim 1, characterized in that: The S500 includes: Perform a two-view graph embedding on each node in set C in the perturbation response graph R, including the original graph embedding representation v0 and the perturbation response graph embedding representation v′; Based on the embedding trajectory offset of nodes in both types of graphs We construct a perturbation-aware confidence function to measure the representational variability of nodes under structural perturbation. The trajectory perturbation gain ratio index is introduced, and the ratio of Δv to the neighborhood average perturbation response amplitude is normalized to form a node-level confidence score γ. Output a list L of suspected nodes within the confidence boundary, sorted by confidence score γ.

9. The graph computation-based electricity theft identification method according to claim 8, characterized in that: By using the node embedding offset Δv as the dependent variable of the perturbation response, and combining the dynamic behavior features B of the users of its neighboring nodes with the structural perturbation vector S, a perturbation causal graph is constructed. A perturbation-aware causal graph convolutional network is introduced on the perturbation causal graph. By modeling the structural causal path with attention weighting, the dominant causal path and attribution strength of each node's embedding offset are inferred. The attribution strength serves as a node confidence correction factor γ″ and is used to reorder and update the list of suspected electricity theft nodes L.

Citation Information

Cited By

  • Trigger node detection method and device, equipment and storage medium

    CN121256790A

  • Trigger node detection method, device, apparatus and storage medium

    CN121256790B

  • Network encryption attack detection method based on deep learning

    CN121309209A

  • A deep learning-based network encryption attack detection method

    CN121309209B

  • Special transformer user electricity consumption anomaly chain construction method fused with deep learning

    CN121328048A