A main network monitoring method based on eventized intelligent research and judgment

By employing an event-based intelligent analysis method to perform multi-level classification and fusion processing on the main network monitoring system, and combining Bayesian network inference and intelligent anti-leakage monitoring mechanisms, the problems of excessive signals, high analysis difficulty, and insufficient intelligence in the monitoring system are solved, thereby achieving intelligent and precise main network monitoring.

CN122371453APending Publication Date: 2026-07-10NORTH CHINA UNIV OF WATER RESOURCES & ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NORTH CHINA UNIV OF WATER RESOURCES & ELECTRIC POWER
Filing Date
2026-04-10
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

The existing main network monitoring system suffers from problems such as excessive monitoring signals, difficulty in analysis, difficulty in event identification, and insufficient intelligence, leading to monitor fatigue, missed monitoring, and difficulty in handling faults.

Method used

An event-based intelligent analysis method is adopted, which processes the original alarm signals through multi-level classification and fusion, uses Bayesian network inference algorithm to analyze the fault, and activates intelligent anti-leakage monitoring mechanism to build a monitoring closed loop from perception to optimization.

Benefits of technology

It has enabled intelligent and precise monitoring of the main grid, reduced the risk of missed monitoring, and improved the efficiency of fault handling and the ability to perceive power grid trends.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122371453A_ABST
    Figure CN122371453A_ABST
Patent Text Reader

Abstract

This invention discloses a main grid monitoring method based on event-driven intelligent analysis, comprising: collecting raw alarm signals and related measurement data reported by the monitoring system; classifying the raw alarm signals and related measurement data according to a preset classification rule base, generating standardized alarm signals with fault labels, and then performing information filtering and related signal fusion operations to generate comprehensive alarm events; further generating structured fault events by performing event matching and probabilistic reasoning through a Bayesian network inference algorithm based on a preset event knowledge base and power grid topology; subsequently initiating and executing an intelligent leak prevention monitoring mechanism to generate leak prevention monitoring closed-loop records; and generating standardized event archives and updating the event knowledge base based on the leak prevention monitoring closed-loop records, thereby realizing closed-loop management of main grid monitoring based on event-driven intelligent analysis. This invention constructs a monitoring closed loop from perception and analysis to continuous optimization, realizing intelligent and precise main grid monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a main network monitoring method based on event-driven intelligent analysis, belonging to the field of main network monitoring technology. Background Technology

[0002] With the continuous expansion of the power grid and the rapid increase in the number of substations, traditional manual monitoring methods face significant challenges. Currently, main grid monitoring suffers from the following technical pain points:

[0003] 1. Too many monitoring signals: There are up to a hundred substations, with an average of 30,000 monitoring alarm information points per day. Monitors need to rely on their experience to identify and judge these signals, which can easily lead to monitoring fatigue and missed monitoring.

[0004] 2. High difficulty in analysis: Alarm information is listed in chronological order, which cannot intuitively reflect the actual equipment failure, lacks early warning of power grid trends, and makes it difficult to identify complex faults.

[0005] 3. Difficulty in event identification: The randomness and complexity of system operation are becoming increasingly prominent, making fault handling decisions difficult, the signal verification process is complicated, and telephone communication is inefficient.

[0006] 4. Insufficient level of intelligence: Current power grid monitoring mainly relies on manual labor. When faced with sudden alarm information, the degree of manual involvement is high and the cost is too high, resulting in a low level of intelligence.

[0007] While some intelligent monitoring systems exist in the current technology, they still have shortcomings in areas such as event-based analysis of alarm signals, intelligent anti-missed monitoring mechanisms, and multi-source data fusion and analysis. There is an urgent need for an intelligent system that can effectively prevent important alarm signals from being missed. Summary of the Invention

[0008] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a main grid monitoring method based on event-driven intelligent analysis. First, the original alarm signals are classified and fused at multiple levels to form comprehensive alarm events. Second, based on the power grid topology and event knowledge base, intelligent fault analysis is achieved through Bayesian network reasoning to generate structured fault events. Finally, an intelligent anti-leakage monitoring mechanism is used to achieve closed-loop handling and knowledge updates, constructing a monitoring closed loop from perception and analysis to continuous optimization, thereby realizing intelligent and precise main grid monitoring.

[0009] To achieve the above objectives, the present invention is implemented using the following technical solution:

[0010] This invention discloses a mainnet monitoring method based on event-driven intelligent analysis, characterized by the following steps:

[0011] Collect raw alarm signals and related measurement data reported by the monitoring system;

[0012] Based on the original alarm signals and associated measurement data, classification processing is performed according to a preset classification rule base to generate standardized alarm signals with fault labels.

[0013] Based on the standardized alarm signals with fault labels, information filtering and correlation signal fusion operations are performed to generate a comprehensive alarm event;

[0014] Based on the comprehensive alarm events, and using a preset event knowledge base and power grid topology, a Bayesian network inference algorithm is used to perform event matching and probabilistic inference to generate structured fault events containing fault type, global confidence level and related equipment information.

[0015] Based on the structured fault events, the intelligent leak prevention and monitoring mechanism is initiated and executed to generate a leak prevention and monitoring closed-loop record.

[0016] Based on the leak prevention and monitoring closed-loop records, standardized event files are generated and the event knowledge base is updated to realize closed-loop management of main network monitoring based on event-based intelligent analysis.

[0017] Furthermore, the classification process based on the preset classification rule base includes:

[0018] If the description information of the original alarm signal contains preset fault trip keywords or conforms to preset trip logic rules, then the original alarm signal is marked as a fault trip category, and a standardized alarm signal with a fault trip category label is obtained.

[0019] If the original alarm signal contains information about changes in the operating status of the switch or disconnector, then the original alarm signal is marked as a change information type, resulting in a standardized alarm signal with a change information type label.

[0020] If the original alarm signal matches the feature pattern in the preset abnormal pattern library, the original alarm signal is marked as an abnormal information class, and a standardized alarm signal with an abnormal information class label is obtained.

[0021] If the voltage, current or load measurement value in the original alarm signal exceeds the corresponding preset threshold, the original alarm signal is marked as an over-limit information class, and a standardized alarm signal with an over-limit information class label is obtained.

[0022] If the description information of the original alarm signal corresponds to a preset notification operation type, then the original alarm signal is marked as a notification information type, resulting in a standardized alarm signal with a notification information type label.

[0023] Furthermore, the generation of the comprehensive alarm event includes:

[0024] Based on a preset monitoring rule base, the standardized alarm signals with fault tags are filtered to remove interference information, invalid information and accompanying information, and the filtered alarm signals are obtained.

[0025] The filtered alarm signals that meet the preset correlation conditions in the time and space dimensions will be fused to generate a comprehensive alarm event.

[0026] Furthermore, the generation of structured fault events containing fault type, global confidence level, and associated device information includes:

[0027] Based on the comprehensive alarm events, they are matched with the device fault characteristic rules pre-stored in the pre-built event knowledge base for various types of main network devices to obtain a preliminary judgment result set for specific main network devices;

[0028] Based on the preliminary judgment result set, combined with the power grid topology relationship, it is matched with the system fault judgment rules for various power grid faults in the pre-built event knowledge base, and the Bayesian network inference algorithm is applied for probabilistic inference and comprehensive verification to calculate the global confidence of each candidate power grid fault type.

[0029] Based on the global confidence level and corresponding threshold of each candidate power grid fault type, the final power grid fault type is determined, and the list of associated equipment is determined based on the power grid topology.

[0030] Based on the power grid fault type, the corresponding global confidence level, and the list of associated devices, a structured fault event is generated.

[0031] Furthermore, the main grid equipment includes power transformers, high-voltage circuit breakers, disconnect switches, busbars, transmission lines, current transformers, voltage transformers, shunt reactors, shunt capacitor banks, GIS switchgear, surge arresters, switch cabinets, static var compensators, and DC converter equipment.

[0032] The power grid faults include single-phase grounding faults, two-phase short-circuit faults, two-phase ground short-circuit faults, three-phase short-circuit faults, line or equipment disconnection faults, equipment insulation damage faults, switch failure or malfunction, voltage abnormality faults, and equipment overload faults.

[0033] Furthermore, the calculation yields the global confidence level for each candidate power grid fault type, including:

[0034] The alarm signal characteristics, electrical measurement data, and power grid topology in the comprehensive alarm event are used as a set of evidence variables.

[0035] Use the fault types defined by the pre-stored system-level fault assessment rules in the event knowledge base as the set of query variables;

[0036] The state variables corresponding to the fault states of each device in the preliminary assessment results set are taken as the set of latent variables;

[0037] Based on the set of evidence variables, the set of query variables, and the set of latent variables, and combined with the predefined causal relationships in the event knowledge base, a Bayesian network reasoning model is constructed; wherein, the nodes of the Bayesian network reasoning model include variables from the set of evidence variables, the set of query variables, and the set of latent variables, and the directed edges between nodes are determined by the predefined causal relationships in the event knowledge base and the power grid topology;

[0038] Based on the Bayesian network inference model, probabilistic inference is performed using variable elimination to calculate the global confidence level of each candidate power grid fault type.

[0039] Furthermore, in response to the number of nodes in the Bayesian network inference model being less than a preset node threshold, the global confidence score for each candidate power grid fault type is calculated using a first confidence formula; the expression for the first confidence formula is as follows:

[0040]

[0041] In the formula, Indicates that given evidence Under the condition of querying variables The global confidence level of the corresponding candidate power grid fault types;

[0042] Represents the set of latent variables;

[0043] Indicates a set of query variables;

[0044] Represents the set of evidence variables;

[0045] This represents the specific observed value of the evidence variable;

[0046] Indicates that given evidence Under the condition, node The conditional probability.

[0047] Furthermore, in response to the number of nodes in the Bayesian network inference model being greater than or equal to a preset node threshold, approximate inference is performed using the Gibbs sampling algorithm to calculate the global confidence level of each candidate power grid fault type.

[0048] The Gibbs sampling algorithm includes:

[0049] Initialize the values ​​of each latent variable in the latent variable set and enter the iterative sampling process until the preset iteration termination condition is met, and output the final sampling sequence;

[0050] Based on the final sampling sequence, the frequency value of each candidate power grid fault type as a query variable is counted, and the frequency value is used as an approximate estimate of the global confidence of the corresponding candidate power grid fault type.

[0051] The iterative sampling process includes:

[0052] In each iteration, for each latent variable to be updated in the set of latent variables, the conditional probability is calculated given the evidence variable and the current values ​​of all other latent variables except that latent variable.

[0053] Based on the conditional probability, the latent variable to be updated is sampled and the corresponding latent variable value is updated.

[0054] Furthermore, the expression for the conditional probability is as follows:

[0055]

[0056] In the formula, Indicates that given evidence Under the condition that all other latent variables Values Latent variables Values The conditional probability; Represents the set of evidence variables; This represents the specific observed value of the evidence variable;

[0057] Representing latent variables The corresponding y-th value;

[0058] Representing latent variables The total number of all possible values;

[0059] This represents the x-th hidden variable that needs to be updated.

[0060] Representing hidden variables The set of all other hidden variables;

[0061] This indicates that in the (t-1)th iteration, excluding the latent variables... The current values ​​of all other hidden variables;

[0062] Indicates when the hidden variable Values All other hidden variables Values And given evidence Under the given conditions, the joint probability value of all variables in the Bayesian network inference model;

[0063] t represents the iteration index of the Gibbs sampling process.

[0064] Furthermore, the activation and execution of the intelligent leak prevention monitoring mechanism includes:

[0065] Based on the fault type, global confidence level, and associated device information contained in the structured fault event, the corresponding priority is determined through a pre-set event classification rule base.

[0066] In response to the structured fault event reaching a preset priority threshold, a one-click inspection function is activated, and an inspection report is generated based on the inspection results.

[0067] If the priority of the structured fault event does not reach the preset priority threshold, the structured fault event is included in the queue to be processed for sorting, and a corresponding reminder operation is triggered based on the corresponding priority to generate an event reminder record.

[0068] Based on the structured fault events and the generated inspection reports or event reminder records, a closed-loop record for preventing leaks is generated.

[0069] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:

[0070] The main grid monitoring method based on event-driven intelligent analysis of this invention firstly standardizes and merges raw alarm signals to form comprehensive alarm events by constructing a multi-level classification and filtering mechanism. Secondly, based on the power grid topology and a pre-built event knowledge base, a Bayesian network inference algorithm is used to achieve intelligent mapping and probabilistic analysis from comprehensive alarm events to structured fault events. Finally, by activating and executing an intelligent leakage prevention monitoring mechanism and archiving and updating the entire handling process, a complete monitoring closed loop is constructed, from signal perception, intelligent analysis, proactive leakage prevention to continuous optimization, ultimately achieving intelligent, accurate, and reliable main grid monitoring. Attached Figure Description

[0071] Figure 1 This is a flowchart of a main network monitoring method based on event-driven intelligent analysis provided by an embodiment of the present invention. Detailed Implementation

[0072] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the scope of protection of the present invention.

[0073] This embodiment provides a mainnet monitoring method based on event-driven intelligent analysis, such as... Figure 1 As shown, it includes the following steps:

[0074] Collect raw alarm signals and related measurement data reported by the monitoring system;

[0075] Based on the original alarm signals and related measurement data, the system performs classification processing according to a preset classification rule base to generate standardized alarm signals with fault labels.

[0076] Based on standardized alarm signals with fault labels, information filtering and correlation signal fusion operations are performed to generate comprehensive alarm events;

[0077] Based on the comprehensive alarm events, and using a pre-set event knowledge base and power grid topology, the Bayesian network inference algorithm is used to perform event matching and probabilistic inference, generating structured fault events that include fault type, global confidence level and related equipment information.

[0078] Based on structured fault events, the intelligent leak prevention and monitoring mechanism is activated and executed to generate a leak prevention and monitoring closed-loop record.

[0079] Based on the closed-loop records of leak prevention monitoring, standardized event files are generated and the event knowledge base is updated to achieve closed-loop management of main network monitoring based on event-based intelligent analysis.

[0080] The technical concept of this invention is as follows: First, by constructing a multi-level classification and filtering mechanism, the original alarm signals are standardized and fused to form a comprehensive alarm event. Second, based on the power grid topology and a pre-built event knowledge base, a Bayesian network inference algorithm is used to achieve intelligent mapping and probabilistic judgment from the comprehensive alarm event to the structured fault event. Finally, by activating and executing an intelligent leakage prevention monitoring mechanism and archiving and updating the entire handling process, a complete monitoring closed loop is constructed, from signal perception, intelligent analysis, proactive leakage prevention to continuous optimization, ultimately achieving intelligent, accurate, and reliable monitoring of the main grid.

[0081] The specific steps are as follows:

[0082] Step 1: Collect the original alarm signals and related measurement data reported by the monitoring system.

[0083] Specifically, it connects to the substation monitoring system through standard protocols such as IEC61850 and 104, and collects raw alarm signals and related measurement data in real time, including primary equipment alarms, auxiliary control system signals and fault waveforms. Among them, telemetry-related measurement data is collected at a frequency of once per second, and remote signaling raw alarm signals are reported immediately when the status changes.

[0084] Step 2: Based on the original alarm signals and related measurement data, classify them according to the preset classification rule library to generate standardized alarm signals with fault labels.

[0085] Classification processing based on a pre-defined classification rule base includes:

[0086] If the description information of the original alarm signal contains preset fault trip keywords or conforms to preset trip logic rules, then the original alarm signal is marked as a fault trip category, and a standardized alarm signal with a fault trip category label is obtained.

[0087] If the original alarm signal contains information about changes in the operating status of the switch or disconnector, then the original alarm signal is marked as a change information type, resulting in a standardized alarm signal with a change information type label.

[0088] If the original alarm signal matches the feature pattern in the preset abnormal pattern library, the original alarm signal is marked as an abnormal information class, and a standardized alarm signal with an abnormal information class label is obtained.

[0089] If the voltage, current or load measurement value in the original alarm signal exceeds the corresponding preset threshold, the original alarm signal is marked as an over-limit information class, and a standardized alarm signal with an over-limit information class label is obtained.

[0090] If the description information of the original alarm signal corresponds to a preset notification operation type, then the original alarm signal is marked as a notification information type, resulting in a standardized alarm signal with a notification information type label.

[0091] Specifically, fault tripping refers to equipment experiencing faults such as short circuits or overloads, causing protection devices to activate and switches to trip, directly affecting power supply safety and requiring urgent investigation and repair.

[0092] Change information refers to changes in the operating status of equipment such as switches and disconnectors, such as changing from closed to open. It is necessary to confirm whether the change is due to normal operation or a fault.

[0093] Abnormal information refers to equipment operating status deviating from the normal range, such as abnormal indicator lights or communication interruptions. Although these may not directly cause a fault, they may be a precursor to potential problems.

[0094] Exceeding limits information refers to operating parameters such as voltage, current, or load exceeding set thresholds, such as voltage being too high or too low. Timely monitoring and adjustment are required to prevent malfunctions.

[0095] Notification information refers to routine operational feedback or system notifications, such as inspection completion or successful parameter settings. These do not affect system security and only need to be archived for future reference.

[0096] Step 3: Based on the standardized alarm signals with fault tags, perform information filtering and correlation signal fusion operations to generate a comprehensive alarm event.

[0097] Generate comprehensive alarm events, including:

[0098] Based on a preset monitoring rule base, standardized alarm signals with fault labels are filtered to remove interference, invalid information and accompanying information, resulting in filtered alarm signals.

[0099] The filtered alarm signals that meet the preset correlation conditions in the time and space dimensions will be fused to generate a comprehensive alarm event.

[0100] Specifically, based on the monitoring rule base, interference information, invalid information, and accompanying information are filtered out, comprehensive alarm events are generated, and pushed out according to their severity and urgency.

[0101] Step 4: Based on the comprehensive alarm events, and using a preset event knowledge base and power grid topology, perform event matching and probabilistic reasoning through Bayesian network inference algorithm to generate structured fault events containing fault type, global confidence level and related equipment information.

[0102] Generate structured fault events that include fault type, global confidence level, and associated device information, including:

[0103] 4.1 Based on the comprehensive alarm events, match them with the device fault characteristic rules pre-stored in the pre-built event knowledge base for various types of main network devices to obtain a preliminary judgment result set for specific main network devices.

[0104] The main grid equipment includes power transformers, high-voltage circuit breakers, disconnect switches, busbars, transmission lines, current transformers, voltage transformers, shunt reactors, shunt capacitor banks, GIS switchgear, surge arresters, switchgear, static var compensators, and DC converter equipment.

[0105] The pre-stored device fault characteristic rules for each type of mainnet device are as follows:

[0106] 1. Power transformers, including oil-immersed power transformers and dry-type power transformers, have core monitoring signals such as oil temperature, oil level, winding temperature, differential current, zero-sequence current, gas concentration, insulation resistance, and tap changer position signal.

[0107] Related faults mainly include insulation damage, overload, abnormal oil temperature, and gas protection activation.

[0108] The implementation logic is as follows: by integrating the current and voltage signals of the primary equipment with the oil temperature and oil level signals of the auxiliary control system, redundant alarms generated during normal operations such as tap changer switching are filtered out.

[0109] The knowledge base pre-stores rules, including determining insulation damage faults when the gas concentration exceeds the threshold, the differential current surges, and the winding temperature exceeds the limit; determining overload faults when the load current remains at 1.1 times the rated value and the winding temperature exceeds 95 degrees Celsius; then, combining the topological connection relationship between the transformer and the bus and the line, signal interference caused by faults in adjacent equipment is eliminated; finally, the matching degree is calculated through the correlation formula, and the corresponding fault event is generated when the confidence level meets the standard.

[0110] The core technologies for fault diagnosis of power transformers include oil chromatography analysis, electrical testing, and temperature monitoring. The implementation steps are as follows: First, online oil chromatography data is collected, including the concentrations of gases such as hydrogen, methane, ethylene, ethane, carbon monoxide, and carbon dioxide. Simultaneously, electrical parameters such as winding DC resistance, turns ratio, dielectric loss, and insulation resistance, as well as winding temperature, oil temperature, and ambient temperature, are collected. Second, in the feature extraction stage, gas ratios are calculated to establish characteristic gas fingerprints, the gas generation rate per unit time is analyzed, and the deviation rate of electrical parameters relative to historical data or standard values ​​is calculated. Third, fault identification is based on ratio-based diagnosis, or machine learning and deep neural network methods are employed, such as using convolutional neural networks-long short-term memory networks or graph transformer models to capture temporal and spatial features.

[0111] 2. High-voltage circuit breakers, including SF6 high-voltage circuit breakers and vacuum high-voltage circuit breakers. The core monitoring signals include the opening and closing position, operating circuit current, SF6 gas pressure, arc-extinguishing chamber temperature, and trip coil status.

[0112] Related faults include switch failure to operate, malfunction, SF6 leakage, and arc-extinguishing chamber malfunction.

[0113] The implementation logic is as follows: the signal is labeled with operation, status and fault categories through a multi-level classification module.

[0114] The knowledge base rules include determining a failure to operate fault when there is no feedback on the opening / closing position after the control command is issued and the operating circuit current is zero; determining a false operation fault when there is a sudden change in the opening / closing position without a control command; filtering out instantaneous alarms caused by fluctuations in operating power supply through main and auxiliary filters, and retaining continuous abnormal signals; and confirming the fault attribution by combining the linkage topology of the circuit breaker with the line and bus.

[0115] The core technologies for circuit breaker fault diagnosis include mechanical characteristic monitoring, electrical characteristic monitoring, and temperature rise monitoring. The implementation steps are as follows: acquiring the current waveform of the opening and closing coils to monitor the operating time, current peak value, and duration; obtaining the stroke speed curve through a displacement sensor; measuring the circuit resistance to determine the contact state; monitoring the pressure or stroke of the operating mechanism; and acquiring the temperature rise of the contacts and connection points through an infrared thermal imager. Feature extraction includes comparing the opening and closing time with standard values, analyzing the opening and closing speed characteristics, extracting features such as current waveform distortion rate and peak offset, and calculating the circuit resistance change rate. Fault identification can be based on threshold judgment, waveform analysis, or machine learning methods such as support vector machines and decision trees to identify mechanical faults such as failure to open, failure to close, and malfunction.

[0116] 3. Disconnecting switch: The core monitoring signals include the opening and closing position, operating motor current, contact temperature, and insulation rod status.

[0117] Related faults include failure to operate, malfunction, contact overheating, and insulation damage.

[0118] The implementation logic is as follows: collect operation commands and device status feedback signals and perform consistency comparison.

[0119] The knowledge base pre-stores the corresponding curves of operating current and position. If the deviation from the curve is determined to be a failure to operate caused by mechanical jamming, the topology verification is performed in combination with the coordination logic of the disconnecting switch and the circuit breaker to locate the scope of the fault. Finally, the event engine integrates the signals to generate a disconnecting switch failure to operate event and marks the priority.

[0120] Fault diagnosis of disconnecting switches is mainly carried out by infrared monitoring of contact temperature, acquisition of operating torque and auxiliary contact status. The diagnostic method combines temperature threshold judgment, operating torque curve analysis and auxiliary contact status logic judgment.

[0121] 4. Busbars, including flexible busbars and rigid busbars. The core monitoring signals include three-phase voltage, zero-sequence voltage, busbar temperature, insulation monitoring signals, and partial discharge signals at connection points.

[0122] Associated faults include single-phase grounding, phase-to-phase short circuit, insulation damage, and overheating.

[0123] The implementation logic is as follows: collect voltage signals from each section of the busbar and alarms from adjacent circuit breakers, transformers, and other equipment.

[0124] The knowledge base rules include determining a single-phase grounding fault when there is a three-phase voltage imbalance and a sudden rise in zero-sequence voltage, and determining a phase-to-phase short circuit when there is a sudden drop in three-phase voltage and a sudden increase in current; based on the connection topology of the busbar, transformer, and line, it distinguishes between busbar faults and branch equipment faults; and then, through confidence calculation, it eliminates misjudgments caused by single transformer anomalies.

[0125] Busbar fault assessment mainly involves monitoring busbar voltage, branch currents, joint temperatures, and insulator leakage current. Diagnostic methods include power flow imbalance analysis, infrared thermal imaging, and insulator leakage current monitoring.

[0126] 5. Transmission lines, including overhead lines and cable lines, with core monitoring signals including three-phase current, zero-sequence current, line voltage, arc detection signal, cable sheath grounding current, and lightning strike monitoring signal.

[0127] Related faults include single-phase grounding, two-phase short circuit, two-phase ground short circuit, open circuit, and lightning strike.

[0128] The implementation logic is as follows: the alarm signals from protection devices such as line longitudinal protection and distance protection are integrated with the inspection system signals through the main and auxiliary combined module.

[0129] The knowledge base rules include determining a single-phase ground fault when the zero-sequence current suddenly increases and the line voltage drops and the protection trips, and determining a three-phase short circuit when the three-phase current suddenly increases and the voltage suddenly drops and the protection trips quickly; topology verification is performed by combining the signal consistency of the circuit breakers and transformers at both ends of the line to confirm the fault section; finally, the event engine generates a single-phase ground fault event of the line through multi-signal association and triggers leakage prevention inspection.

[0130] The core technologies for transmission line fault assessment include traveling wave localization, impedance method, and fault waveform analysis. The implementation steps are as follows: fault waveform recorders are installed at both ends of the line to synchronously acquire three-phase voltage and current waveforms; parallel wave sensors capture transient traveling wave signals of the fault; fault type identification is based on current surges and voltage drops to determine short-circuit faults, zero-sequence or negative-sequence components are used to identify asymmetrical faults, and the specific fault type is determined by the phase relationship between the fault phase voltage and current; fault localization employs the traveling wave method and impedance method, and intelligent fusion localization improves accuracy and reliability.

[0131] 6. Current transformer: The core monitoring signals include secondary current, winding temperature, insulation resistance, secondary circuit open circuit signal, and partial discharge signal.

[0132] Related faults include secondary open circuit, insulation damage, overload, and accuracy abnormality.

[0133] The implementation logic is as follows: collect the primary current and secondary current and verify whether the transformation ratio is normal. For example, if there is current in the primary current but no current in the secondary current, it is determined that the secondary is open circuit.

[0134] The knowledge base pre-stores the corresponding curves of load current and winding temperature. If the temperature exceeds the limit, it is judged as an overload or internal fault. The topology verification is carried out in combination with the matching relationship between current transformers, lines and circuit breakers to eliminate secondary signal anomalies caused by primary equipment failures. High-risk signals such as secondary open circuits are triggered for graded inspection to avoid missed monitoring.

[0135] In the fault diagnosis of instrument transformers, current transformer faults are diagnosed by monitoring the secondary circuit current and temperature rise, while voltage transformer faults are diagnosed by monitoring the secondary voltage and identifying ferroresonant characteristics.

[0136] 7. Voltage transformer: The core monitoring signals include secondary voltage, winding temperature, insulation resistance, fuse status, and resonance alarm signal.

[0137] Related faults include secondary short circuits, blown fuses, insulation damage, and ferroresonance.

[0138] The implementation logic is as follows: voltage anomaly and protection signal types are labeled through a multi-level classification module.

[0139] The knowledge base rules include determining a fuse fault when the secondary voltage drops to zero and a fuse blow signal is generated, and determining a ferroresonance when the three-phase voltage is distorted and a resonant characteristic frequency appears. Instantaneous voltage fluctuations are eliminated through a main-auxiliary joint filtering process, while continuous abnormal signals are retained. Finally, the event-driven engine calculates the signal correlation and generates a fault event, which is then pushed to the closed-loop management module.

[0140] 8. Parallel reactors: The core monitoring signals include operating current, winding temperature, insulation resistance, oil level, partial discharge signal, and cooling system status.

[0141] Associated faults include overload, insulation damage, cooling system failure, and inter-turn short circuit.

[0142] The implementation logic is as follows: collect reactor current, temperature, and status signals of cooling system fan and oil pump.

[0143] The knowledge base rules include determining an overload fault when the current exceeds 1.2 times the rated value, the winding temperature exceeds 85 degrees Celsius, and the cooling system is not started; determining insulation damage when the partial discharge signal exceeds the standard and the insulation resistance decreases; topology verification is performed in conjunction with the connection relationship between the reactor and the bus to confirm whether the reactor overload is caused by abnormal bus voltage; finally, the intelligent notification module pushes alarms to the operation and maintenance personnel according to the event priority.

[0144] The fault diagnosis of reactors mainly involves measuring the DC resistance and inductance of the windings and monitoring vibration.

[0145] 9. Parallel capacitor banks: The core monitoring signals include three-phase current, capacitor voltage, dielectric loss angle, casing temperature, fuse status, and switching status.

[0146] Related faults include overload, blown fuse, capacitor breakdown, and abnormal switching.

[0147] The implementation logic is as follows: collect the operating current, voltage, and switching control signals of the capacitor bank.

[0148] The knowledge base pre-stores the correspondence between current, voltage and capacity. If the correspondence deviates, it is judged as capacitor breakdown or fuse blown. The topology relationship is analyzed by combining the coordination logic of the switching switch and the bus to eliminate abnormalities within the group caused by switch malfunction. Finally, the event engine integrates multi-phase capacitor signals to generate capacitor bank fault events and tracks the progress of handling.

[0149] Capacitor fault diagnosis mainly focuses on measuring capacitor capacitance, dielectric loss angle, temperature rise, and unbalanced voltage.

[0150] 10. GIS switchgear, the core monitoring signals include SF6 gas pressure and humidity, the opening and closing positions of each bay, partial discharge signals, operating mechanism current and winding temperature.

[0151] Related faults include insulation damage, switch failure and malfunction, SF6 leakage, and excessive partial discharge.

[0152] The implementation logic is as follows: the signals of circuit breakers, disconnect switches, current transformers and other equipment in each bay of the GIS are integrated through the main and auxiliary combined module to avoid alarm dispersion.

[0153] The knowledge base rules include determining leakage faults when SF6 pressure continuously decreases and humidity exceeds the standard, and determining insulation damage when the amplitude of a partial discharge signal exceeds the threshold and the duration exceeds 5 seconds; topology verification is performed based on the physical connection relationship of the internal GIS bays to locate the specific fault bay; finally, after the confidence level calculation meets the standard, an insulation fault event of the GIS combined electrical appliance is generated and closed-loop management is initiated.

[0154] 11. Surge arresters: The core monitoring signals include leakage current, number of operations, valve plate temperature, and insulation jacket condition.

[0155] Related faults include insulation aging, valve plate damage, and abnormal operation due to lightning overvoltage.

[0156] The implementation logic is as follows: collect the leakage current and action signal of the surge arrester.

[0157] The knowledge base rules include determining insulation aging when leakage current exceeds 3 mA and valve plate temperature rises, and determining abnormal operation when lightning strike signal is generated, surge arrester fails to operate, and line insulation is damaged; topology verification is performed by combining the protection range of surge arrester with line and busbar to confirm the impact of faults; and leakage current exceeding the standard signal is classified, with high-priority signals triggering real-time inspection.

[0158] Surge arrester fault diagnosis mainly involves monitoring leakage current, including total current and resistive current, number of trips, and continuous operating voltage. Diagnostic methods include determining whether the resistive component of the leakage current exceeds 1.3 times the initial value and whether the number of trips is abnormally frequent in a short period of time.

[0159] 12. Switchgear, suitable for medium and high voltage systems. Core monitoring signals include cabinet temperature and humidity, bus voltage and current, switch position, grounding switch status, and arc flash signal.

[0160] Related faults include internal short circuits, overloads, arcing faults, and condensation damage.

[0161] The implementation logic is as follows: the signal is labeled with environmental, electrical and fault categories through a multi-level classification module.

[0162] The knowledge base rules include determining an internal short circuit when an arc light signal is generated, the current surges, and the voltage drops sharply; determining condensation damage when the humidity inside the cabinet exceeds 85% and the insulation resistance decreases; filtering out redundant alarms caused by instantaneous temperature fluctuations inside the cabinet through a main and auxiliary filter; and finally, the event engine integrates the signals to generate a switchgear arc fault event and pushes it to the operation and maintenance terminal.

[0163] 13. Static var compensator, the core monitoring signals include reactive power output, thyristor temperature, bus voltage, firing angle and cooling system status.

[0164] Related faults include overload, thyristor damage, abnormal voltage, and cooling system failure.

[0165] The implementation logic is as follows: the input and output current, voltage and control signals of the acquisition device are collected.

[0166] The knowledge base rules include determining overload when reactive power output exceeds the rated value and thyristor temperature exceeds 120 degrees Celsius, and determining thyristor damage when the firing angle is abnormal and reactive power fluctuates greatly; topology verification is performed in conjunction with the connection relationship between the device and the bus to confirm whether the device failure is caused by abnormal bus voltage; and intelligent closed-loop management is used to track operation and maintenance until the device returns to normal and is archived.

[0167] 14. DC converter equipment, suitable for large AC / DC hybrid power grids.

[0168] The core monitoring signals include converter valve temperature, trigger pulse signal, commutation voltage and current, DC bus voltage, and filter status.

[0169] Related faults include converter valve damage, abnormal voltage, commutation failure, and overload.

[0170] The implementation logic is as follows: the alarm signals of the converter valve, filter device and cooling system are integrated through the main and auxiliary combined module.

[0171] The knowledge base rules include determining commutation failure when commutation voltage distortion occurs, DC current fluctuates, and converter valve temperature rises sharply; and determining voltage anomaly when DC bus voltage exceeds ±10% of the rated value. Verification is performed using AC / DC tie-line topology to rule out commutation anomalies caused by AC-side faults. Finally, event levels are marked using a priority formula, with higher-level events notified first.

[0172] 4.2 Based on the preliminary judgment result set, combined with the power grid topology relationship, the system fault judgment rules for various power grid faults are matched with the pre-built event knowledge base. The Bayesian network inference algorithm is then applied for probabilistic inference and comprehensive verification to calculate the global confidence of each candidate power grid fault type.

[0173] 4.2.1 Power grid faults include single-phase grounding faults, two-phase short-circuit faults, two-phase ground short-circuit faults, three-phase short-circuit faults, line or equipment disconnection faults, equipment insulation damage faults, switch failure or malfunction, voltage abnormality faults, and equipment overload faults.

[0174] The system fault assessment rules are matched against pre-stored rules for various power grid faults in a pre-built event knowledge base, as follows:

[0175] 1. Single-phase grounding faults involve transmission lines, busbars, transformers, switchgear, and cable lines. Key signal combinations include a sudden increase in zero-sequence current in the line or equipment, a rise in zero-sequence voltage on the busbar, insulation monitoring alarms, and the activation of grounding protection devices. The implementation logic is as follows: The event-driven engine receives alarm signals from multiple devices and calculates the matching degree between each signal and the single-phase grounding pattern using a correlation formula. Based on the equipment connection topology, the fault section is located using the consistency principle of signals at both ends; for example, if the zero-sequence current at both ends of the line is abnormal, it is determined to be a fault in the middle section of the line. Typical features are matched using a knowledge base to eliminate false alarm scenarios such as reversed transformer polarity. When the confidence level reaches or exceeds 0.8, a single-phase grounding fault event is generated and intelligent leakage prevention inspection is triggered.

[0176] 2. Two-phase short-circuit faults involve transmission lines, busbars, transformers, and GIS switchgear. Key signal combinations include sudden rise in fault phase current, sudden drop in fault phase voltage, phase-to-phase voltage imbalance, and the activation of distance protection or longitudinal protection. The implementation logic is as follows: The primary equipment electrical quantity signals and protection device alarm signals are integrated through a main and auxiliary combined module; the signal fitting degree is determined using pre-stored two-phase short-circuit electrical quantity characteristic curves in the knowledge base; if the fitting degree meets the standard, the fault is preliminarily confirmed; topology verification is performed by combining the connection relationship between the fault point and the power supply side and load side to confirm the fault's impact range; finally, an event is generated by the event engine, and key information such as the fault phase and fault section are labeled.

[0177] 3. Two-phase-to-ground short-circuit faults involve transmission lines, busbars, and cable lines. Key signal combinations include sudden increases in two-phase current, rises in zero-sequence current or voltage, phase-to-phase voltage imbalance, and simultaneous operation of grounding protection and phase-to-phase protection. The implementation logic is as follows: integrate the electrical quantity signals of the faulty phases with the zero-sequence protection signals to form a composite characteristic of phase-to-phase short-circuit superimposed grounding; perform topology analysis through the linkage of signals from multiple devices such as lines, busbars, and instrument transformers to eliminate misjudgments caused by single-device faults; increase the weighting coefficient of the zero-sequence signal in the correlation calculation to strengthen grounding characteristic matching; after the event is generated, push it to the closed-loop management module for tracking and handling.

[0178] 4. Three-phase short-circuit faults involve transmission lines, busbars, transformers, and GIS switchgear. Key signal combinations include a sudden increase in three-phase current to 3 to 10 times the rated current, a sudden drop in three-phase voltage to near zero, instantaneous overcurrent protection activation, and circuit breaker tripping. The implementation logic is as follows: the main and auxiliary modules prioritize collecting key signals such as instantaneous overcurrent protection activation and circuit breaker tripping and mark them as high priority; based on knowledge base rules, situations where the three-phase current and voltage are synchronously abnormal and the protection activates instantly are judged as three-phase short circuits; the fault point is quickly located through topology verification, for example, a three-phase short circuit on the busbar will cause abnormal current in all connected lines; the event-driven engine determines it as a priority level of up to 5 based on the priority formula and immediately triggers notifications through multiple channels such as SMS, APP, and monitoring screen.

[0179] 5. Line or equipment open-circuit faults, involving transmission lines, disconnect switches, and cable lines. Key signal combinations include a sudden drop in current to zero in the open-circuit phase, an increase in current in other phases due to load transfer, voltage imbalance, and the activation of the open-circuit protection. The implementation logic is as follows: Collect current and voltage signals of each phase of the line or equipment, and compare whether there is a characteristic of no current in one phase while other phases have overcurrent; verify the rationality of current changes using a pre-stored open-circuit and load transfer correlation model in the knowledge base; perform topology verification by combining signals from equipment at both ends of the line, for example, locating the open-circuit section based on a sudden drop in current at one end; simultaneously, an intelligent leakage prevention mechanism triggers a special inspection based on the signal of a sudden drop in current to zero to avoid missing single-phase open-circuit faults.

[0180] 6. Equipment insulation damage faults involve transformers, GIS switchgear, surge arresters, cable lines, and instrument transformers. Key signal combinations include excessive partial discharge signals, decreased insulation resistance, increased winding or casing temperature, and transformer gas protection activation or SF6 partial discharge signals from GIS equipment. The implementation logic is as follows: integrate partial discharge, insulation resistance, and temperature signals related to equipment insulation to form an insulation degradation characteristic chain; according to knowledge base rules, insulation damage is determined when the local discharge amplitude exceeds the threshold, the duration is greater than 10 seconds, and the insulation resistance is lower than the specified value; signal interference caused by insulation faults in adjacent equipment is eliminated through topology verification; after the confidence level calculation meets the standard, a fault event is generated and associated with equipment ledger information.

[0181] 7. Switch failure to operate or maloperation faults, involving high-voltage circuit breakers, disconnecting switches, GIS switchgear, and switchgear. For failure to operate faults, key signal combinations include control command issuance, no open / close position feedback, and abnormal operating circuit current; for maloperation faults, key signal combinations include sudden changes in open / close position without control command and abnormal current or voltage in related equipment. The implementation logic is as follows: compare the consistency between control commands and equipment status feedback for preliminary judgment; compare the pre-stored operating circuit current with the normal position curve in the knowledge base, and determine mechanical or electrical faults if the deviation from the curve is found; perform topology verification by combining the linkage logic between the switch and adjacent equipment; after the event is generated, the closed-loop management module tracks the maintenance process.

[0182] 8. Voltage anomaly faults, including overvoltage and undervoltage, involve buses, transformers, static var compensators (SVCs), DC converters, and instrument transformers. Key signal combinations include bus voltage exceeding the rated value by ±10%, voltage anomaly duration exceeding 3 seconds, and abnormal adjustment of related reactive power compensation devices. The implementation logic is as follows: voltage anomaly signals are labeled using a multi-level classification module, and transient fluctuations are filtered out using a main-auxiliary combined filtering approach; knowledge base rules define overvoltage as voltage exceeding 1.1 times the rated value for 3 seconds and constituting overvoltage, and undervoltage as voltage below 0.9 times the rated value for 3 seconds; the voltage anomaly range is analyzed in conjunction with the grid topology to distinguish between global power supply problems and local equipment failures; an event-driven engine correlates the reactive power compensation device status to analyze the specific causes of voltage anomalies.

[0183] 9. Equipment overload faults involve transformers, transmission lines, reactors, capacitor banks, and static var compensators. Key signal combinations include current continuously exceeding 1.1 times the rated value, equipment temperature rise, and cooling system operating at full load. The implementation logic is as follows: collect equipment operating current, temperature, and cooling system status signals; determine the overload current and duration curve based on pre-stored overload current in the knowledge base, for example, allowing 1.2 times the rated current for 15 minutes, and triggering an alarm if the timeout is exceeded; perform topology verification based on the equipment load source to analyze whether the load transfer is caused by power outages on adjacent lines; the intelligent leakage prevention mechanism classifies overload signals, triggering real-time inspections for high-risk signals exceeding 1.3 times the rated current to prevent equipment burnout.

[0184] 4.2.2 Calculate the global confidence level for each candidate power grid fault type, including:

[0185] The alarm signal characteristics, electrical measurement data, and power grid topology in the comprehensive alarm event are used as the set of evidence variables.

[0186] Use the fault types defined by the pre-stored system-level fault assessment rules in the event knowledge base as the set of query variables;

[0187] The state variables corresponding to the fault states of each device in the preliminary assessment results are used as a set of latent variables.

[0188] Based on the evidence variable set, query variable set, and latent variable set, and combined with the predefined causal relationships in the event knowledge base, a Bayesian network reasoning model is constructed. The nodes of the Bayesian network reasoning model include variables from the evidence variable set, query variable set, and latent variable set, and the directed edges between nodes are determined by the predefined causal relationships in the event knowledge base and the power grid topology.

[0189] Based on the Bayesian network inference model, probabilistic inference is performed using variable elimination to calculate the global confidence level of each candidate power grid fault type.

[0190] The principle of the Bayesian network inference model is as follows:

[0191]

[0192] In the formula, This represents the high-dimensional joint probability distribution of all variables in a Bayesian network inference model. This represents the i-th node in the Bayesian network inference model; Represents a node The set of parent nodes; Represents a node The conditional probability; This represents the total number of nodes in a Bayesian network inference model. This represents the chain multiplication operator;

[0193] In this embodiment, in response to the number of nodes in the Bayesian network inference model being less than a preset node threshold, the global confidence of each candidate power grid fault type is calculated using a first confidence formula; the expression of the first confidence formula is as follows:

[0194]

[0195] In the formula, Indicates that given evidence Under the condition of querying variables The global confidence level of the corresponding candidate power grid fault types;

[0196] Represents the set of latent variables;

[0197] Indicates a set of query variables;

[0198] Represents the set of evidence variables;

[0199] This represents the specific observed value of the evidence variable;

[0200] Indicates that given evidence Under the condition, node The conditional probability.

[0201] If the number of nodes in the Bayesian network inference model is greater than or equal to a preset node threshold, then approximate inference is performed using the Gibbs sampling algorithm to calculate the global confidence of each candidate power grid fault type.

[0202] The Gibbs sampling algorithm includes:

[0203] Initialize the values ​​of each latent variable in the latent variable set and enter the iterative sampling process until the preset iteration termination condition is met, and output the final sampling sequence;

[0204] Based on the final sampling sequence, the frequency value of each candidate power grid fault type as a query variable is counted, and the frequency value is used as an approximate estimate of the global confidence of the corresponding candidate power grid fault type.

[0205] The iterative sampling process includes:

[0206] In each iteration, for each latent variable to be updated in the latent variable set, the conditional probability is calculated given the evidence variable and the current values ​​of all other latent variables except that latent variable.

[0207] Based on conditional probability, the latent variable to be updated is sampled and the corresponding latent variable value is updated.

[0208] The expression for conditional probability is as follows:

[0209]

[0210] In the formula, Indicates that given evidence Under the condition that all other latent variables Values Latent variables Values The conditional probability;

[0211] Representing latent variables The corresponding y-th value;

[0212] Representing latent variables The total number of all possible values;

[0213] This represents the x-th hidden variable that needs to be updated.

[0214] Representing hidden variables The set of all other hidden variables;

[0215] This indicates that in the (t-1)th iteration, excluding the latent variables... The current values ​​of all other hidden variables;

[0216] Indicates when the hidden variable Values All other hidden variables Values And given evidence Under the given conditions, the joint probability value of all variables in the Bayesian network inference model;

[0217] t represents the iteration index of the Gibbs sampling process.

[0218] 4.3. Based on the global confidence level and corresponding threshold of each candidate power grid fault type, determine the final power grid fault type, and determine the list of associated equipment based on the power grid topology.

[0219] The specific steps are as follows:

[0220] Among the calculated global confidence scores of each candidate power grid fault type, the candidate type with the highest global confidence score is selected as the initial type.

[0221] Determine whether the global confidence level of the initially selected type is greater than or equal to the preset confidence threshold;

[0222] If the global confidence level of the initially selected type is greater than or equal to the confidence threshold, then it is determined as the final grid fault type.

[0223] If the global confidence level of the initially selected type is less than the confidence threshold, the final power grid fault type will be marked as undetermined or unknown.

[0224] After determining the final type of power grid fault, a correlation analysis is performed on the abnormal signal source devices involved in the integrated alarm event based on the power grid topology.

[0225] Based on the fault impact range and propagation path corresponding to the final power grid fault type, all logically related electrical devices are retrieved and identified from the power grid topology to form a list of related devices.

[0226] 4.4 Generate structured fault events based on the power grid fault type, the corresponding global confidence level, and the list of associated equipment.

[0227] Step 5: Based on the structured fault events, initiate and execute the intelligent leak prevention monitoring mechanism to generate a leak prevention monitoring closed-loop record.

[0228] Activate and execute the intelligent leak prevention monitoring mechanism, including:

[0229] Based on the fault type, global confidence level, and associated device information contained in the structured fault events, the corresponding priority is determined through a pre-set event classification rule base.

[0230] When the priority of a structured fault event reaches a preset priority threshold, the one-click inspection function is activated, and an inspection report is generated based on the inspection results.

[0231] If the priority of a structured fault event does not reach the preset priority threshold, the structured fault event will be included in the pending queue for sorting, and the corresponding reminder operation will be triggered based on the corresponding priority to generate an event reminder record.

[0232] Based on structured fault events and generated inspection reports or event alerts, a closed-loop record for leak prevention monitoring is generated.

[0233] Specifically, in response to the priority reaching a preset priority threshold, the following operations are performed: within 1 minute of the generation of the structured fault event, a first SMS message containing detailed fault information is automatically pushed to a preset terminal; simultaneously, the voice assistant is automatically activated and broadcasts the incident content to notify the maintenance personnel; then, the one-click inspection function is activated, and an inspection report is generated based on the inspection results; within 5 minutes of receiving a manual confirmation instruction, a second SMS message containing a fault waveform summary is pushed to the relevant terminal.

[0234] If the priority does not reach the priority threshold, the structured fault event is included in the pending queue for sorting and management, and corresponding in-system reminders or message pushes are triggered according to its priority.

[0235] Finally, by integrating the structured fault events, related inspection reports or reminder records, and all push notifications and handling feedback, a closed-loop record for preventing leaks is generated, completing the entire closed-loop management process from event generation, intelligent notification, on-site handling to record archiving.

[0236] Step 6: Based on the closed-loop record of leak prevention monitoring, generate standardized event files and update the event knowledge base to realize closed-loop management of main network monitoring based on event-based intelligent analysis.

[0237] Specifically, this embodiment employs a deep learning algorithm to construct an event knowledge base, the core function of which is to achieve automated extraction of event information. Specifically, the algorithm can accurately identify event trigger words and their types from natural language text, and extract key elements such as participants, time, and location, thereby transforming unstructured text into structured event records. This process is typically modeled as a sequence labeling task: the input is a vectorized representation of each word in a sentence and its context; after processing by bidirectional LSTM and other network layers, the model outputs a predefined label for each word, forming a label sequence.

[0238] Building such models falls under the category of supervised learning tasks, which rely on large-scale, high-quality labeled data. Current mainstream practices employ pre-trained language models such as BERT (Bidirectional Encoder Representations from Transformers) for fine-tuning. Through transfer learning, the dependence on the amount of labeled data is significantly reduced, achieving excellent performance with only a few thousand high-quality samples, thus effectively addressing issues such as domain dependence and long-tail distribution.

[0239] This embodiment implements multi-source data fusion analysis based on topological relationships. Its core lies in abstracting data from different sources into a unified network of nodes and edges, and utilizing the similarity of the network structure itself for connection and integration. Specifically, various types of data, such as text entities, spatial objects, and sensor readings, are first transformed into graph structures, making each data point a node, and the relationships between data, such as co-occurrence, adjacency, or causal relationships, become edges. Subsequently, by analyzing topological features such as the matching degree of subgraph patterns and the similarity of node connection structures in different networks, nodes pointing to the same real-world entity are intelligently identified and merged, thereby breaking down data silos and forming a globally interconnected knowledge network. On this unified topological network after fusion, further in-depth analysis can be conducted, such as using graph algorithms to discover hidden communities, predict links, trace propagation paths, or using spatial topological rules such as inclusion and adjacency as constraints for reasoning, thereby discovering complex patterns and relationships that cannot be observed from a single data source, providing support for decision-making.

[0240] In a practical application at a provincial power grid centralized control station, the method provided in this embodiment demonstrated significant comprehensive effectiveness. Fault assessment efficiency was fundamentally improved, with the average assessment time drastically reduced from 15 minutes to 30 seconds, and the assessment accuracy increasing from 85% to 98.5%. Simultaneously, this method effectively suppressed signal omissions, reducing the rate of missed detections of important signals from 3% to below 0.1%.

[0241] In terms of operational efficiency, the intelligent functions of this method significantly save human resources, reducing the number of monitoring personnel by three per centralized control station, with an estimated annual saving of approximately 600,000 yuan in labor costs. Furthermore, emergency response efficiency is significantly improved, with the average fault handling time shortened by 40% and user power outage time reduced by 35%, effectively enhancing power supply reliability and user satisfaction.

[0242] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0243] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0244] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0245] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0246] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A mainnet monitoring method based on event-driven intelligent analysis, characterized in that, Includes the following steps: Collect raw alarm signals and related measurement data reported by the monitoring system; Based on the original alarm signals and associated measurement data, classification processing is performed according to a preset classification rule base to generate standardized alarm signals with fault labels. Based on the standardized alarm signals with fault labels, information filtering and correlation signal fusion operations are performed to generate a comprehensive alarm event; Based on the comprehensive alarm events, and using a preset event knowledge base and power grid topology, the Bayesian network inference algorithm is used to perform event matching and probabilistic inference to generate structured fault events containing fault type, global confidence level and related equipment information. Based on the structured fault events, the intelligent leak prevention and monitoring mechanism is initiated and executed to generate a leak prevention and monitoring closed-loop record. Based on the leak prevention and monitoring closed-loop records, standardized event files are generated and the event knowledge base is updated to realize closed-loop management of main network monitoring based on event-based intelligent analysis.

2. The main network monitoring method based on event-driven intelligent analysis according to claim 1, characterized in that, The classification process based on a preset classification rule base includes: If the description information of the original alarm signal contains preset fault trip keywords or conforms to preset trip logic rules, then the original alarm signal is marked as a fault trip category, and a standardized alarm signal with a fault trip category label is obtained. If the original alarm signal contains information about changes in the operating status of the switch or disconnector, then the original alarm signal is marked as a change information type, resulting in a standardized alarm signal with a change information type label. If the original alarm signal matches the feature pattern in the preset abnormal pattern library, the original alarm signal is marked as an abnormal information class, and a standardized alarm signal with an abnormal information class label is obtained. If the voltage, current or load measurement value in the original alarm signal exceeds the corresponding preset threshold, the original alarm signal is marked as an over-limit information class, and a standardized alarm signal with an over-limit information class label is obtained. If the description information of the original alarm signal corresponds to a preset notification operation type, then the original alarm signal is marked as a notification information type, resulting in a standardized alarm signal with a notification information type label.

3. The main network monitoring method based on event-driven intelligent analysis according to claim 1, characterized in that, The generation of the comprehensive alarm event includes: Based on a preset monitoring rule base, the standardized alarm signals with fault tags are filtered to remove interference information, invalid information and accompanying information, and the filtered alarm signals are obtained. The filtered alarm signals that meet the preset correlation conditions in the time and space dimensions will be fused to generate a comprehensive alarm event.

4. The main network monitoring method based on event-driven intelligent analysis according to claim 1, characterized in that, The generation of structured fault events, which include fault type, global confidence level, and associated device information, includes: Based on the comprehensive alarm events, they are matched with the device fault characteristic rules pre-stored in the pre-built event knowledge base for various types of main network devices to obtain a preliminary judgment result set for specific main network devices; Based on the preliminary judgment result set, combined with the power grid topology relationship, it is matched with the system fault judgment rules for various power grid faults in the pre-built event knowledge base, and the Bayesian network inference algorithm is applied for probabilistic inference and comprehensive verification to calculate the global confidence of each candidate power grid fault type. Based on the global confidence level and corresponding threshold of each candidate power grid fault type, the final power grid fault type is determined, and the list of associated equipment is determined based on the power grid topology. Based on the power grid fault type, the corresponding global confidence level, and the list of associated devices, a structured fault event is generated.

5. The main network monitoring method based on event-driven intelligent analysis according to claim 4, characterized in that, The main grid equipment includes power transformers, high-voltage circuit breakers, disconnect switches, busbars, transmission lines, current transformers, voltage transformers, shunt reactors, shunt capacitor banks, GIS switchgear, surge arresters, switchgear, static var compensators, and DC converter equipment. The power grid faults include single-phase grounding faults, two-phase short-circuit faults, two-phase ground short-circuit faults, three-phase short-circuit faults, line or equipment disconnection faults, equipment insulation damage faults, switch failure or malfunction, voltage abnormality faults, and equipment overload faults.

6. The main network monitoring method based on event-driven intelligent analysis according to claim 4, characterized in that, The calculation yields the global confidence level for each candidate power grid fault type, including: The alarm signal characteristics, electrical measurement data, and power grid topology in the comprehensive alarm event are used as a set of evidence variables. Use the fault types defined by the pre-stored system-level fault assessment rules in the event knowledge base as the set of query variables; The state variables corresponding to the fault states of each device in the preliminary assessment results set are taken as the set of latent variables; Based on the set of evidence variables, the set of query variables, and the set of latent variables, and combined with the predefined causal relationships in the event knowledge base, a Bayesian network reasoning model is constructed; wherein, the nodes of the Bayesian network reasoning model include variables from the set of evidence variables, the set of query variables, and the set of latent variables, and the directed edges between nodes are determined by the predefined causal relationships in the event knowledge base and the power grid topology; Based on the Bayesian network inference model, probabilistic inference is performed using variable elimination to calculate the global confidence level of each candidate power grid fault type.

7. The main network monitoring method based on event-driven intelligent analysis according to claim 6, characterized in that, If the number of nodes in the Bayesian network inference model is less than a preset node threshold, the global confidence score for each candidate power grid fault type is calculated using a first confidence formula. The expression for the first confidence formula is as follows: ; In the formula, Indicates that given evidence Under the condition of querying variables The global confidence level of the corresponding candidate power grid fault types; Represents the set of latent variables; Indicates a set of query variables; Represents the set of evidence variables; This represents the specific observed value of the evidence variable; Indicates that given evidence Under the condition, node The conditional probability.

8. The main network monitoring method based on event-driven intelligent analysis according to claim 6, characterized in that, If the number of nodes in the Bayesian network inference model is greater than or equal to a preset node threshold, then approximate inference is performed using the Gibbs sampling algorithm to calculate the global confidence level of each candidate power grid fault type. The Gibbs sampling algorithm includes: Initialize the values ​​of each latent variable in the latent variable set and enter the iterative sampling process until the preset iteration termination condition is met, and output the final sampling sequence; Based on the final sampling sequence, the frequency value of each candidate power grid fault type as a query variable is counted, and the frequency value is used as an approximate estimate of the global confidence of the corresponding candidate power grid fault type. The iterative sampling process includes: In each iteration, for each latent variable to be updated in the set of latent variables, the conditional probability is calculated given the evidence variable and the current values ​​of all other latent variables except that latent variable. Based on the conditional probability, the latent variable to be updated is sampled and the corresponding latent variable value is updated.

9. The main network monitoring method based on event-driven intelligent analysis according to claim 8, characterized in that, The expression for the conditional probability is as follows: ; In the formula, Indicates that given evidence Under the condition that all other latent variables Values Latent variables Values The conditional probability; Represents the set of evidence variables; This represents the specific observed value of the evidence variable; Representing latent variables The corresponding y-th value; Representing latent variables The total number of all possible values; This represents the x-th hidden variable that needs to be updated. Representing hidden variables The set of all other hidden variables; This indicates that in the (t-1)th iteration, excluding the latent variables... The current values ​​of all other hidden variables; Indicates when the hidden variable Values All other hidden variables Values And given evidence Under the given conditions, the joint probability value of all variables in the Bayesian network inference model; t represents the iteration index of the Gibbs sampling process.

10. The main network monitoring method based on event-driven intelligent analysis according to claim 1, characterized in that, The activation and execution of the intelligent leak prevention monitoring mechanism includes: Based on the fault type, global confidence level, and associated device information contained in the structured fault event, the corresponding priority is determined through a pre-set event classification rule base. In response to the structured fault event reaching a preset priority threshold, a one-click inspection function is activated, and an inspection report is generated based on the inspection results. If the priority of the structured fault event does not reach the preset priority threshold, the structured fault event is included in the queue to be processed for sorting, and a corresponding reminder operation is triggered based on the corresponding priority to generate an event reminder record. Based on the structured fault events and the generated inspection reports or event reminder records, a closed-loop record for preventing leaks is generated.