A method and system for identifying power grid alarm events
By analyzing the real-time alarm data of the power grid, using the alarm rule base and type identification model, the cause of the power grid alarm event is accurately identified, and the alarm identification problem caused by the frequency and voltage regulation operation is solved, and the fault is accurately identified and handled.
Patent Information
- Application Number
- CN202411525334.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-30
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-10-30
AI Technical Summary
In the power grid, frequency regulation and voltage regulation operations will trigger a large number of instantaneous alarms. It is difficult for the prior art to accurately identify which of these alarms are caused by normal frequency regulation and voltage regulation operations and which are caused by real faults, resulting in the possibility of missing the real fault or misjudging it as a equipment failure.
By acquiring the real-time alarm data of the power grid, a pre-established alarm rule base is used to identify instantaneous alarm events suspected to be caused by frequency regulation and voltage regulation operations and alarm events caused by non-frequency regulation operations, and the target time series data is input into the pre-trained type identification model to determine whether the instantaneous alarm event is caused by normal frequency regulation and voltage regulation operations or abnormal frequency regulation operations.
Accurate identification of power grid alarm events is achieved, and true faults occurring simultaneously with frequency regulation and voltage regulation operation are avoided. At the same time, alarm events caused by abnormal frequency regulation and voltage regulation operation are discovered in a timely manner, which improves the accuracy of fault identification.
Smart Images

Figure CN119089360B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power grids. Specifically, it relates to a method and system for identifying power grid alarm events. Background Art
[0002] In a power grid, it is necessary to adjust the frequency and voltage to maintain the safety and stability of the power grid. The frequency and voltage regulation operations of the power grid will trigger a large number of instantaneous alarms. It is necessary to classify these alarms triggered by normal frequency and voltage regulation operations as "normal" alarms to avoid misjudging them as equipment failures. Currently, usually all the alarm events that occur during frequency and voltage regulation are ignored. Although this method avoids the situation where alarms caused by normal frequency and voltage regulation operations are misjudged as equipment failures, it will miss some real faults that occur simultaneously with the frequency and voltage regulation operations. Therefore, it is necessary to be able to deeply analyze the causal relationship between normal frequency and voltage regulation operations and alarms, and distinguish which alarms are directly triggered by normal frequency and voltage regulation, and which alarms only occur simultaneously with normal frequency and voltage regulation but have no direct correlation. Summary of the Invention
[0003] Based on this, the present invention provides a method and system for identifying power grid alarm events, which can identify whether an alarm event is caused by a normal frequency and voltage regulation operation by analyzing real-time alarm data, so as to achieve the purpose of accurately identifying faults.
[0004] To achieve the above object, an embodiment of the present invention provides a method for identifying power grid alarm events, including:
[0005] Obtain real-time alarm data of the power grid; wherein, the real-time alarm data includes device attribute information of the alarm device, real-time alarm records, and real-time operation data of the alarm device, and the real-time alarm records include alarm types and alarm times;
[0006] Based on a pre-established alarm rule library, identify instantaneous alarm events suspected of being caused by frequency and voltage regulation operations and alarm events not caused by frequency and voltage regulation operations according to the alarm type and the real-time operation data; wherein, the alarm rule library defines the device operation data characteristics of alarm events caused by frequency and voltage regulation operations.
[0007] Extract target time series data of the instantaneous alarm events from the real-time alarm data; wherein, the target time series data includes the alarm type, device attribute information of the alarm device, and real-time operation data.
[0008] Input the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation.
[0009] To achieve the above object, an embodiment of the present invention further provides a power grid alarm event recognition system, including:
[0010] A data acquisition module, configured to acquire real-time alarm data of the power grid; wherein, the real-time alarm data includes device attribute information of the alarm device, real-time alarm records, and real-time operation data of the alarm device, and the real-time alarm records include alarm types and alarm times;
[0011] An event classification module, configured to identify instantaneous alarm events suspected to be caused by frequency and voltage regulation operations and alarm events not caused by frequency and voltage regulation operations based on a pre-established alarm rule library according to the alarm type and the real-time operation data; wherein, the alarm rule library defines device operation data characteristics of alarm events caused by frequency and voltage regulation operations;
[0012] A data extraction module, configured to extract target time series data of the instantaneous alarm events from the real-time alarm data; wherein, the target time series data includes the alarm type, device attribute information of the alarm device, and real-time operation data;
[0013] The event classification module is further configured to input the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an abnormal frequency and voltage regulation operation.
[0014] Compared with the prior art, the power grid alarm event recognition method and system disclosed in the embodiments of the present invention first obtain real-time alarm data of the power grid; wherein, the real-time alarm data includes device attribute information of the alarm device, real-time alarm records, and real-time operation data of the alarm device, and the real-time alarm records include alarm types and alarm times; then, based on a pre-established alarm rule library, instantaneous alarm events suspected of being caused by frequency and voltage regulation operations and alarm events not caused by frequency and voltage regulation operations are identified according to the alarm types and the real-time operation data; wherein, the alarm rule library defines the device operation data characteristics of alarm events caused by frequency and voltage regulation operations; then, target time series data of the instantaneous alarm events is extracted from the real-time alarm data; wherein, the target time series data includes the alarm type, device attribute information of the alarm device, and real-time operation data; finally, the target time series data is input into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation. It can be seen that the embodiments of the present invention analyze the obtained real-time alarm data of the power grid by using a pre-established alarm rule library to identify instantaneous alarm events suspected of being caused by frequency and voltage regulation operations and alarm events not caused by frequency and voltage regulation operations, and then further analyze the instantaneous alarm events suspected of being caused by frequency and voltage regulation operations to determine whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation, thereby avoiding missing real faults that occur simultaneously with frequency and voltage regulation operations and being able to timely discover alarm events caused by abnormal frequency and voltage regulation operations, achieving accurate identification of faults. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings without creative efforts based on these drawings.
[0016] Figure 1 is a schematic flowchart of a power grid alarm event recognition method provided by an embodiment of the present invention;
[0017] Figure 2 is a schematic structural diagram of an alarm propagation path provided by an embodiment of the present invention;
[0018] Figure 3 is a schematic structural diagram of a power grid alarm event recognition system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0020] See Figure 1 , which is a schematic flowchart of a method for identifying grid alarm events provided by an embodiment of the present invention. Specifically, the method for identifying grid alarm events includes steps S1 to S4:
[0021] S1. Obtain the real-time alarm data of the grid; wherein, the real-time alarm data includes the device attribute information of the alarm device, the real-time alarm record, and the real-time operation data of the alarm device, and the real-time alarm record includes the alarm type and the alarm time.
[0022] Specifically, the grid is composed of multiple power devices, and the real-time alarm data includes at least one alarm event. Each alarm event corresponds to an alarm power device (referred to as an alarm device). Each alarm event has the device attribute information, alarm type, and alarm time of the corresponding alarm device. Optionally, the real-time alarm record also includes the alarm level.
[0023] S2. Based on a pre-established alarm rule library, identify the instantaneous alarm events suspected to be caused by frequency and voltage regulation operations and the alarm events not caused by frequency and voltage regulation operations according to the alarm type and the real-time operation data; wherein, the alarm rule library defines the device operation data characteristics of the alarm events caused by frequency and voltage regulation operations.
[0024] Specifically, obtain the alarm event samples caused by frequency and voltage regulation operations, extract the device operation data characteristics from the alarm types and operation data of these samples, construct an alarm rule library according to the extracted device operation data characteristics. When identifying grid alarm events, analyze whether the alarm type and real-time operation data of the alarm events in the real-time alarm data conform to the device operation data characteristics defined in the alarm rule library. If they conform, it is determined that the alarm event is an instantaneous alarm event suspected to be caused by frequency and voltage regulation operations. If they do not conform, it is determined that the alarm event is an alarm event not caused by frequency and voltage regulation operations, thereby realizing the identification of alarm events not caused by frequency and voltage regulation operations.
[0025] S3. Extract the target time series data of the instantaneous alarm event from the real-time alarm data; wherein, the target time series data includes the alarm type, the device attribute information of the alarm device, and the real-time operation data.
[0026] S4. Input the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by normal frequency and voltage regulation operations or an alarm event caused by abnormal frequency and voltage regulation operations.
[0027] Specifically, after identifying an instantaneous alarm event suspected to be caused by frequency and voltage regulation operations, extract the alarm type of the instantaneous alarm event, the device attribute information of the alarm device, and the real-time operation data, and further analyze whether the instantaneous alarm event is caused by normal frequency and voltage regulation operations, so as to accurately identify the alarm event caused by abnormal frequency and voltage regulation operations.
[0028] Compared with the prior art, the embodiment of the present invention analyzes the real-time alarm data of the power grid obtained by using a pre-established alarm rule library to identify an instantaneous alarm event suspected to be caused by frequency and voltage regulation operations and an alarm event not caused by frequency and voltage regulation operations, and then further analyzes the instantaneous alarm event suspected to be caused by frequency and voltage regulation operations to determine whether the instantaneous alarm event is an alarm event caused by normal frequency and voltage regulation operations or an alarm event caused by abnormal frequency and voltage regulation operations, thereby avoiding missing a real fault that occurs simultaneously with frequency and voltage regulation operations and being able to timely discover an alarm event caused by abnormal frequency and voltage regulation operations, achieving accurate identification of the fault.
[0029] In a second preferred embodiment, on the basis of steps S1 to S4, the method further includes:
[0030] Based on a pre-constructed device topology structure diagram, construct an alarm dependency graph for carrying the alarm association degree between each of the abnormal devices according to the real-time alarm records of all abnormal devices; wherein, the abnormal device is the alarm device corresponding to the abnormal event, and the abnormal event includes the alarm event not caused by frequency and voltage regulation operations and the alarm event caused by abnormal frequency and voltage regulation operations;
[0031] Identify potential fault root cause alarm events according to the alarm dependency graph;
[0032] Input the real-time alarm data corresponding to the potential fault root cause alarm event into a pre-trained root cause recognition model; wherein, the root cause recognition model is obtained by training according to root cause recognition samples, and the root cause recognition samples are the historical operation data and historical alarm records when the potential fault root cause device is the real fault root cause device, and the potential fault root cause device is the alarm device corresponding to the potential fault root cause alarm event;
[0033] When the root cause identification model determines that the potential fault root cause alarm event is a real fault root cause alarm event, starting from the potential fault root cause device, traverse the alarm dependency graph to obtain all abnormal devices related to the potential fault root cause device, so as to generate an alarm analysis result and feedback it to the user.
[0034] Specifically, in the power grid, when a power device fails, it often causes some other related power devices to malfunction. Therefore, it is necessary to analyze all abnormal devices to determine the root cause of the fault. In this embodiment, the training method of the root cause identification model is as follows: First, obtain the historical operation data and historical alarm records of each power device in the power grid as the root cause identification samples when it is used as the real fault root cause device. Then, train the root cause identification model based on these samples. The above samples can be obtained through simulation or from the power grid, and there is no limitation here. The process of identifying the fault root cause is as follows: First, obtain the device topology structure diagram of the power grid. Based on this device topology structure diagram, analyze the real-time alarm records of abnormal devices to determine the alarm dependency relationship between each abnormal device, so as to construct a dynamic alarm dependency graph. Traverse this alarm dependency graph to identify potential fault root cause devices. Then, input the real-time alarm data corresponding to the potential fault root cause device into the pre-trained root cause identification model to calculate the probability that the potential fault root cause device is the real fault root cause. When this probability is greater than the set high probability threshold, it is determined that the potential fault root cause device is the real fault root cause, otherwise it is not the real fault root cause. If the potential fault root cause device is not the real fault root cause, it is necessary to re-traverse the alarm dependency graph and re-select the potential fault root cause device from the remaining abnormal devices until the real fault root cause is found. Finally, starting from the real fault root cause, traverse the alarm dependency graph to find all abnormal devices related to the fault root cause, generate an alarm analysis result and feedback it to the user, and the user can repair each abnormal device according to the alarm analysis result.
[0035] In a preferred embodiment, on the basis of steps S1 to S4, the obtaining of the real-time alarm data of the power grid in step S1 includes:
[0036] Obtain the unique identifier of the power device in the power grid from the monitoring system database;
[0037] According to the unique identifier, retrieve the real-time alarm record of the alarm device from the alarm management module; wherein, the real-time alarm record includes the alarm type and the alarm time;
[0038] According to the unique identifier, obtain the device attribute information of the alarm device from the asset management module;
[0039] Obtain the real-time operation data of the alarm device from the time series database according to the unique identifier of the alarm device; wherein, the real-time operation data includes active power, reactive power, grid frequency and voltage.
[0040] Specifically, 1. In the monitoring system database, the power equipment list is stored in a relational data structure, including fields such as the unique identifier of the power equipment, equipment type, installation location, etc. Batch extract the unique identifiers in the monitoring system database through SQL query statements, where the full Chinese name of SQL is Structured Query Language and the full English name is Structured Query Language. 2. Pass the unique identifiers batch-extracted from the monitoring system database to the alarm management module. This module uses an object-oriented data model and records multiple alarm records. Each alarm record contains attributes such as an alarm identifier, the unique identifier of the alarm device, alarm type, alarm level, alarm time, etc. Use the RESTful API interface to obtain the alarm records within the last 24 hours from the alarm management module and return an array of alarm records in JSON format (i.e., real-time alarm records); where the RESTful API is an application programming interface that conforms to the design principles of the representational state transfer architecture style; the JSON format is a lightweight data exchange format that is easy for humans to read and write and is also convenient for machines to parse and generate. 3. Call the Web service of the asset management system through the Simple Object Access Protocol (SOAP) to obtain the device attribute information of the alarm device, such as model, manufacturer, installation date, etc. 4. The time series database stores the real-time operation data of the collected power equipment, using the unique identifier of the power equipment and the timestamp as indexes. The real-time operation data of the alarm device within the last 24 hours can be extracted according to the unique identifier of the alarm device. It can be understood that for the convenience of data management, different information is stored in different locations. Therefore, when obtaining the real-time alarm data of the power grid, different information needs to be obtained from different locations.
[0041] Further, before obtaining the real-time operation data of the alarm device from the time series database according to the unique identifier of the alarm device, it further includes:
[0042] Use a supervisory control and data acquisition system or a remote terminal unit to collect the real-time operation data of the power equipment in the power grid at a preset frequency and store it in the time series database, where the real-time operation data includes active power, reactive power, grid frequency and voltage.
[0043] Specifically, the real-time operation data of power equipment, including active power, reactive power, grid frequency, voltage and other data, are collected at a fixed frequency through a Supervisory Control And Data Acquisition (SCADA) system or a remote terminal unit. The collection frequency is set to once every 10 seconds. The collected data is preprocessed using the Pandas library in Python, including missing value filling and outlier detection, and then the preprocessed data is stored in a time series database (such as InfluxDB). The exponential moving average technique is used to calculate the short-term trend of the real-time operation data in the time series database. The open-source rule engine Drools is used to implement the definition and execution of warning trigger rules. The preprocessed data, the short-term trend of the real-time operation data, etc. are input into the rule engine, and the status of the power equipment is evaluated according to the preset warning trigger rules. The comprehensive operation status result, including the unique identifier of the power equipment, the current status of the power equipment (such as normal, attention, warning or danger), and the warning type, etc., is stored in the Redis cache in the form of key-value pairs for real-time query and update. Among them, the power equipment with the current status of attention, warning or danger is regarded as an alarm device, or the power equipment with the current status of warning or danger is regarded as an alarm device. Redis is an open-source high-performance non-relational key-value pair database.
[0044] In a preferred embodiment, on the basis of steps S1 to S4, based on the pre-established alarm rule library, the instantaneous alarm events suspected to be caused by frequency modulation and voltage regulation operations and the alarm events not caused by frequency modulation and voltage regulation operations are identified according to the alarm type and the real-time operation data, including:
[0045] Extract the rule set from the pre-established alarm rule library. The rule set includes several groups of rules, and the rules include alarm categories, parameter trends, and device parameter thresholds;
[0046] Select the first rule from the rule set; wherein, the alarm category of the first rule is the same as the alarm type in the real-time alarm record;
[0047] Calculate the power parameter change rate and power parameter change trend of the alarm device according to the real-time operation data;
[0048] When the power parameter change trend conforms to the parameter trend of the first rule and the power parameter change rate is greater than the device parameter threshold of the first rule, it is determined that the alarm event of the alarm device is an instantaneous alarm event suspected to be caused by frequency modulation and voltage regulation operations;
[0049] When the change trend of the power parameter does not conform to the parameter trend of the first rule, it is determined that the alarm event of the alarm device is an alarm event not caused by the frequency modulation and voltage regulation operation.
[0050] Specifically, the alarm rule library defines the device operation data characteristics of the alarm event caused by the frequency modulation and voltage regulation operation. The device operation data characteristics exist in the form of a rule set. The rule set includes multiple rules, and each rule includes the corresponding alarm category, parameter trend, and device parameter threshold. It can be understood that through experiments, when the frequency modulation and voltage regulation operation occurs, if there is no device failure, the alarm category and corresponding operation data that the power device will present are determined. By analyzing the corresponding operation data, the parameter trend and device parameter threshold are determined, and the alarm category, device parameter threshold, and parameter trend are integrated to form the alarm rule library. The specific process of identifying whether the alarm event is caused by the frequency modulation and voltage regulation operation is as follows: 1. Extract the rule set from the pre-established alarm rule library, and select the first rule in the rule set whose alarm category is the same as the alarm type; 2. Set a sliding time window of 60 seconds (the window length can be set according to the actual situation), use the rolling() function of the pandas library to analyze the real-time operation data, calculate the change rate of the power parameters of the alarm device (such as the voltage change rate and frequency change rate), and determine the change trend of the power parameters (such as the voltage change trend and frequency change trend) according to the real-time operation data; 3. Compare the change trend of the power parameters with the parameter trend of the first rule. If the two match, compare the change rate of the power parameters with the device parameter threshold of the first rule (such as the voltage change threshold and frequency change threshold). For example, check whether the voltage change rate exceeds the preset voltage change threshold (assuming the voltage change threshold is 2% / minute, this value can be set according to the actual situation), and check whether the frequency change rate exceeds the frequency change threshold (assuming the frequency change threshold is 0.1 Hz / s, this value can be set according to the actual situation). If the alarm type, the change trend of the power parameters match the alarm category and parameter trend defined in the rule set, and there is a change rate of the power parameters exceeding the corresponding device parameter threshold, then this alarm event is marked as an instantaneous alarm event suspected of being caused by the frequency modulation and voltage regulation operation. For the marked instantaneous alarm event, record its start and end times, frequency, and duration.
[0051] In a preferred embodiment, on the basis of steps S1 to S4, inputting the target time series data into the pre-trained type recognition model in step S4 to identify that the instantaneous alarm event is an alarm event caused by a normal frequency modulation and voltage regulation operation or an abnormal frequency modulation and voltage regulation operation includes:
[0052] Input the target time series data into the pre-trained type recognition model;
[0053] In the type recognition model, calculate the time-domain statistical features of the power parameters according to the real-time operation data in the target time series data;
[0054] Perform Fourier transform on the time-domain statistical features to obtain frequency-domain features;
[0055] Retrieve the corresponding typical time series pattern features from the normal frequency and voltage regulation operation mode library according to the alarm type and the device attribute information of the alarm device; wherein, the normal frequency and voltage regulation operation mode library pre-stores the typical time series pattern features corresponding to the alarm category and the device attribute, and the typical time series pattern features are pre-trained by alarm event samples caused by normal frequency and voltage regulation operations;
[0056] Calculate the similarity between the frequency-domain features and the retrieved typical time series pattern features to obtain a similarity value;
[0057] When the similarity value is greater than the preset similarity threshold, the instantaneous alarm event is an alarm event caused by normal frequency and voltage regulation operations;
[0058] When the similarity value is less than or equal to the preset similarity threshold, the instantaneous alarm event is an alarm event caused by abnormal frequency and voltage regulation operations.
[0059] It should be noted that in order to keep the operating voltages and frequencies of the voltage central points of the power grid within the specified allowable range, normal frequency and voltage regulation operations need to be carried out on the power grid. The adjustment intensity of normal frequency and voltage regulation operations is limited within a certain range. Alarm events caused by normal frequency and voltage regulation operations can be left unhandled, but alarm events caused by abnormal frequency and voltage regulation operations should not be ignored. Therefore, after identifying a suspected instantaneous alarm event caused by frequency and voltage regulation operations, it should also be determined whether it is an alarm event caused by abnormal frequency and voltage regulation operations.
[0060] Specifically, the implementation process of step S4 is as follows: Input the target time series data into a pre-trained type recognition model. The type recognition model performs a series of operations and finally determines whether the instantaneous alarm event is an alarm event caused by normal frequency and voltage regulation operations or an alarm event caused by abnormal frequency and voltage regulation operations. Specifically, the series of operations of the target time series data in the type recognition model are as follows: 1. Assume that the real-time operation data includes data sorted by time such as grid frequency, voltage, and power. Calculate the frequency deviation, voltage deviation, and power fluctuation data based on the real-time operation data, and perform cleaning processing on the frequency deviation, voltage deviation, and power fluctuation data to obtain a normalized time series data set. 2. For the normalized time series data set, set a sliding time window, and use the numpy library to calculate the time-domain statistical features of the frequency deviation, voltage deviation, and power fluctuation data on different time scales, including mean, variance, skewness, and kurtosis, etc. Perform Fourier transform on the time-domain statistical features to obtain frequency-domain features, convert the frequency-domain features into feature vectors, and use the principal component analysis algorithm to perform dimensionality reduction processing on the feature vectors. Among them, the numpy library is an extension library of Python that supports a large number of dimensional array and matrix operations. 3. Retrieve the typical time series pattern features with the alarm category being the alarm type and the attribute being the device attribute information from the normal frequency and voltage regulation operation mode library. It should be noted that the normal frequency and voltage regulation operation mode library pre-stores a variety of typical time series pattern features, and each typical time series pattern feature has a corresponding alarm category and device attribute. The typical time series pattern features are pre-trained through samples of alarm events caused by normal frequency and voltage regulation operations. The sample includes the alarm category, device attributes, and corresponding operation data. 4. Calculate the similarity between the dimensionality-reduced feature vector and the retrieved typical time series pattern features to obtain a similarity value. If the similarity value is greater than the preset similarity threshold, it is determined that the instantaneous alarm event is an alarm event caused by normal frequency and voltage regulation operations. If the similarity value is less than or equal to the preset similarity threshold, it is determined that the instantaneous alarm event is an alarm event caused by abnormal frequency and voltage regulation operations. It should be noted that the preset similarity threshold is set according to the actual situation, such as 80%, 86%, or 92%, etc.
[0061] In a preferred implementation manner, on the basis of steps S1 to S4, the inputting of the target time series data into the pre-trained type recognition model in step S4 to identify that the instantaneous alarm event is an alarm event caused by normal frequency and voltage regulation operations or an alarm event caused by abnormal frequency and voltage regulation operations includes:
[0062] Input the target time series data into the pre-trained type recognition model;
[0063] In the type recognition model, adopt a clustering algorithm to cluster all the alarm devices according to the target time series data;
[0064] For each cluster of alarm devices, calculate the similarity between each alarm device in the cluster and the cluster center according to the real-time operation data;
[0065] Determine that the instantaneous alarm event corresponding to the first alarm device is an alarm event caused by a normal frequency and voltage regulation operation; wherein, the similarity between the first alarm device and the cluster center is greater than a preset similarity threshold;
[0066] Determine that the instantaneous alarm event corresponding to the second alarm device is an alarm event caused by an abnormal frequency and voltage regulation operation; wherein, the similarity between the second alarm device and the cluster center is less than or equal to the preset similarity threshold.
[0067] Specifically, for different power devices of the same type during the same frequency and voltage regulation operation (such as step-down operation, step-up operation, frequency-down operation, frequency-up operation), there are the same characteristics in the alarm type and real-time operation data. Therefore, by clustering the alarm devices corresponding to the instantaneous alarm events according to the target time series data, several clusters are obtained. Since most of the instantaneous alarm events identified as suspected to be caused by frequency and voltage regulation operations in actual applications are instantaneous alarm events caused by normal frequency and voltage regulation operations, the instantaneous alarm event corresponding to the cluster center of each cluster can be regarded as an instantaneous alarm event caused by a normal frequency and voltage regulation operation. For the same cluster, the real-time operation data corresponding to the alarm events caused by normal frequency and voltage regulation operations has a relatively high degree of similarity. Therefore, calculate the similarity between each alarm device in the cluster and the cluster center according to the real-time operation data. If the similarity is greater than the preset similarity threshold, it indicates that the alarm event corresponding to the alarm device is an alarm event caused by a normal frequency and voltage regulation operation. Otherwise, the alarm event is an alarm event caused by an abnormal frequency and voltage regulation operation. It should be noted that the preset similarity threshold is set according to the actual situation. Optionally, it is set according to the weather condition. The worse the weather, the smaller the preset similarity threshold. For example, if the weather is clear, the preset similarity threshold is 90%, and if the weather is bad, the preset similarity threshold is 80%.
[0068] In a preferred implementation manner, on the basis of the second implementation manner, the alarm dependency graph for carrying the alarm association degree between each abnormal device is constructed according to the real-time alarm records of all abnormal devices based on the pre-constructed device topology structure diagram, including:
[0069] Obtain the physical connection relationship and logical association relationship data of each power device in the power grid, and construct a device topology structure diagram using the adjacency matrix representation method;
[0070] Based on the device topology structure diagram, construct an alarm dependency graph for carrying the alarm association degree between each abnormal device according to the real-time alarm records;
[0071] Identifying potential fault root cause alarm events according to the alarm dependency graph includes:
[0072] Traverse the alarm dependency graph, and use the PageRank algorithm to rank the importance of abnormal devices in the alarm dependency graph;
[0073] Select the alarm event corresponding to the abnormal device with the highest importance as the potential fault root cause alarm event.
[0074] Specifically, obtain the physical connection relationship and logical association relationship data between various power devices in the power grid, construct a device topology structure diagram using the adjacency matrix representation method. In the device topology structure diagram, nodes represent power devices, and edges represent the connection relationships between devices. According to the device topology structure diagram, extract the real-time alarm data of abnormal devices to obtain the device attribute information and real-time alarm records of abnormal devices, which are used to construct a dynamic alarm dependency graph based on the device topology structure diagram. The alarm dependency graph is represented by a directed weighted graph, and the weight calculation of the edges uses a time decay function, w = exp(-Δt / τ), where Δt is the alarm time difference between nodes, and τ is the time constant. Simplify the alarm dependency graph model, merge duplicate edges, and remove self-loop edges to obtain a simplified alarm dependency graph. Use the depth-first search algorithm to traverse the simplified alarm dependency graph, and use the PageRank algorithm to rank the importance of each node in the alarm dependency graph. During the ranking process, different weights need to be introduced for different power devices. For example, set the weight of the substation to be higher than that of other power devices. Finally, calculate the sorted alarm node list; regard the power device corresponding to the node with the highest score in the alarm node list as the potential fault root cause alarm.
[0075] In a preferred implementation manner, based on the second implementation manner, when the root cause identification model determines that the potential fault root cause alarm event is a real fault root cause alarm event, starting from the potential fault root cause device, traverse the alarm dependency graph to obtain all abnormal devices related to the potential fault root cause device, so as to generate an alarm analysis result and feedback it to the user, including:
[0076] When the root cause identification model determines that the potential fault root cause alarm event is a real fault root cause alarm event, traverse the alarm dependency graph to construct an alarm propagation path starting from the potential fault root cause device;
[0077] Based on the alarm propagation path, calculate the path length between the abnormal device and the potential fault root cause device, and count the downstream node influence scores of the abnormal device; among them, the downstream node influence scores are positively correlated with the set scores of the downstream nodes of the abnormal device and the number of downstream nodes;
[0078] Calculate the criticality score of the abnormal device according to the path length, the influence score of the downstream node, and the preset score of the abnormal device obtained in advance; wherein, the criticality score of the abnormal device is negatively correlated with the path length, and the criticality score is positively correlated with the influence score of the downstream node and the preset score of the abnormal device respectively;
[0079] Generate an alarm analysis result according to the alarm propagation path, the criticality score of the abnormal device, and the real-time alarm data of the abnormal device, and feedback the alarm analysis result to the user.
[0080] Specifically, the preset score of the abnormal device is set in advance according to the actual situation. In addition, referring to Figure 2 the shown alarm propagation path, A1~A8 are all abnormal devices in this alarm propagation path. A1 represents the abnormal device corresponding to the real fault root cause alarm event. A2~A8 are all downstream nodes of A1. A4~A8 are downstream nodes of A2. A7 and A8 are downstream nodes of A6. When determining that the potential fault root cause alarm event is the real fault root cause alarm event, take it as the root cause, combine with the alarm dependency graph, and use the graph traversal algorithm to trace all alarm events related to the root cause to form a complete alarm propagation path, and calculate the number of downstream nodes of each abnormal device respectively, and calculate the path length between each abnormal device and the root cause; for a certain abnormal device, add up the preset scores of all its downstream nodes to obtain the comprehensive score of the downstream nodes of this abnormal device. Normalize all path lengths to obtain the normalized length between each abnormal device and the potential fault root cause device; normalize the number of downstream nodes of all abnormal devices to obtain the normalized number of nodes of each abnormal device, normalize the comprehensive scores of the downstream nodes of all abnormal devices to obtain the normalized node scores of each abnormal device, add the normalized number of nodes and the normalized node scores of a certain abnormal device to obtain the influence score of the downstream nodes of this abnormal device; normalize the preset scores of all abnormal devices to obtain the normalized scores of the abnormal devices; for a certain abnormal device, perform weighted calculation on its influence score of the downstream nodes, the normalized score, and the normalized length to obtain the criticality score of this abnormal device. Finally, generate an alarm analysis result according to the alarm propagation path, the criticality score of the abnormal device, and the real-time alarm data of the abnormal device, and feedback it to the user.
[0081] In a preferred implementation manner, on the basis of the second implementation manner, it further includes:
[0082] Generate a maintenance work order for the abnormal device according to the alarm analysis result, and send the maintenance work order to the maintenance client so that the maintenance personnel can repair the abnormal device; wherein, the higher the criticality score of the abnormal device, the higher the level of the maintenance work order, and the shorter the processing time limit of the maintenance work order.
[0083] Specifically, generate a maintenance work order according to the alarm analysis result. Among them, the higher the criticality score of the abnormal device, the higher the level of the maintenance work order, the shorter the allocated processing time limit, and the maintenance work order also records the device attribute information of the specific abnormal device. Based on the pre-set correspondence between the device type and the maintenance personnel, distribute it to the maintenance client of the corresponding maintenance personnel according to the device attribute information recorded in the maintenance work order.
[0084] Compared with the prior art, the power grid alarm event recognition method disclosed in the embodiments of the present invention first obtains the real-time alarm data of the power grid; wherein, the real-time alarm data includes the device attribute information of the alarm device, the real-time alarm record, and the real-time operation data of the alarm device, and the real-time alarm record includes the alarm type and the alarm time; then, based on the pre-established alarm rule library, identify the instantaneous alarm events suspected to be caused by frequency modulation and voltage regulation operations and the alarm events not caused by frequency modulation and voltage regulation operations according to the alarm type and the real-time operation data; wherein, the alarm rule library defines the device operation data characteristics of the alarm events caused by frequency modulation and voltage regulation operations; then, extract the target time series data of the instantaneous alarm events from the real-time alarm data; wherein, the target time series data includes the alarm type, the device attribute information of the alarm device, and the real-time operation data sorted by time; finally, input the target time series data into the pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency modulation and voltage regulation operation or an abnormal frequency modulation and voltage regulation operation. It can be seen that the embodiments of the present invention analyze the obtained real-time alarm data of the power grid by using the pre-established alarm rule library to identify the instantaneous alarm events suspected to be caused by frequency modulation and voltage regulation operations and the alarm events not caused by frequency modulation and voltage regulation operations, and then further analyze the instantaneous alarm events suspected to be caused by frequency modulation and voltage regulation operations to determine whether the instantaneous alarm event is an alarm event caused by a normal frequency modulation and voltage regulation operation or an abnormal frequency modulation and voltage regulation operation, so as to avoid missing real faults occurring simultaneously with frequency modulation and voltage regulation operations and timely discover alarm events caused by abnormal frequency modulation and voltage regulation operations, realizing accurate fault identification.
[0085] See Figure 3 , the embodiments of the present invention further provide a power grid alarm event recognition system, including:
[0086] A data acquisition module 21, configured to acquire real-time alarm data of a power grid; wherein, the real-time alarm data includes device attribute information of an alarm device, real-time alarm records, and real-time operation data of the alarm device, and the real-time alarm records include an alarm type and an alarm time;
[0087] An event classification module 22, configured to identify, based on a pre-established alarm rule library, an instantaneous alarm event suspected to be caused by a frequency and voltage regulation operation and an alarm event not caused by a frequency and voltage regulation operation according to the alarm type and the real-time operation data; wherein, the alarm rule library defines device operation data characteristics of an alarm event caused by a frequency and voltage regulation operation;
[0088] A data extraction module 23, configured to extract target time series data of the instantaneous alarm event from the real-time alarm data; wherein, the target time series data includes the alarm type, device attribute information of the alarm device, and real-time operation data;
[0089] The event classification module 22 is further configured to input the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation.
[0090] It should be noted that the working principle of the power grid alarm event recognition system provided in the above embodiment can refer to the working process of the power grid alarm event recognition method provided in any of the above embodiments, which will not be elaborated here.
[0091] Compared with the prior art, the power grid alarm event recognition system provided in the embodiment of the present invention analyzes the acquired real-time alarm data of the power grid by using a pre-established alarm rule library to identify an instantaneous alarm event suspected to be caused by a frequency and voltage regulation operation and an alarm event not caused by a frequency and voltage regulation operation, and then further analyzes the instantaneous alarm event suspected to be caused by a frequency and voltage regulation operation to determine whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation, thereby avoiding missing a real fault that occurs simultaneously with the frequency and voltage regulation operation and being able to timely discover an alarm event caused by an abnormal frequency and voltage regulation operation, achieving accurate fault recognition.
[0092] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.
Claims
1. A method for identifying power grid alarm events, characterized in that: include: Acquire real-time alarm data of the power grid; wherein the real-time alarm data includes device attribute information of the alarm device, real-time alarm records and real-time operation data of the alarm device, and the real-time alarm records include alarm type and alarm time; Based on a pre-established alarm rule base, instantaneous alarm events suspected to be caused by frequency and voltage regulation operations and alarm events caused by non-frequency and voltage regulation operations are identified according to the alarm type and the real-time operation data; wherein the alarm rule base defines the equipment operation data characteristics of the alarm events caused by frequency and voltage regulation operations; Extracting target time series data of the instantaneous alarm event from the real-time alarm data; wherein the target time series data includes the alarm type, device attribute information of the alarm device and real-time operation data; Inputting the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation; Based on the pre-constructed device topology diagram, an alarm dependency diagram for carrying the alarm correlation degree between each abnormal device is constructed according to the real-time alarm records of all abnormal devices; wherein the abnormal device is an alarm device corresponding to an abnormal event, and the abnormal event includes an alarm event caused by the non-frequency and voltage regulation operation and an alarm event caused by the abnormal frequency and voltage regulation operation; Identify potential fault root cause alarm events according to the alarm dependency graph; Input the real-time alarm data corresponding to the potential fault root source alarm event into a pre-trained root source identification model; wherein the root source identification model is obtained by training according to a root source identification sample, the root source identification sample is the historical operation data and historical alarm record when the potential fault root source device is a real fault root source device, and the potential fault root source device is the alarm device corresponding to the potential fault root source alarm event; When the root cause identification model determines that the potential fault root cause alarm event is a real fault root cause alarm event, the alarm dependency graph is traversed with the potential fault root cause device as the starting point to obtain all abnormal devices related to the potential fault root cause device, so as to generate an alarm analysis result and feed it back to the user.
2. The method for identifying power grid alarm events according to claim 1, characterized in that: The obtaining of real-time alarm data of the power grid includes: Obtaining a unique identifier of an electric power device in the power grid from a monitoring system database; Retrieving a real-time alarm record of an alarm device from an alarm management module according to the unique identifier; wherein the real-time alarm record includes an alarm type and an alarm time; Acquire device attribute information of the alarm device from an asset management module according to the unique identifier; The real-time operation data of the alarm device is obtained from a time series database according to the unique identifier of the alarm device; wherein the real-time operation data includes active power, reactive power, grid frequency and voltage.
3. The method for identifying power grid alarm events according to claim 1, characterized in that: The method of identifying, based on the pre-established alarm rule library, instantaneous alarm events suspected to be caused by frequency and voltage regulation operations and alarm events caused by non-frequency and voltage regulation operations according to the alarm type and the real-time operation data, includes: Extracting a rule set from a pre-established alarm rule library, the rule set comprising a plurality of groups of rules, the rules comprising alarm categories, parameter trends and device parameter thresholds; Selecting a first rule from the rule set; wherein the alarm category of the first rule is the same as the alarm type in the real-time alarm record; Calculate the power parameter change rate and power parameter change trend of the alarm device according to the real-time operation data; When the power parameter change trend conforms to the parameter trend of the first rule, and the power parameter change rate is greater than the device parameter threshold of the first rule, determining that the alarm event of the alarm device is an instantaneous alarm event suspected to be caused by frequency and voltage regulation operation; When the power parameter variation trend does not conform to the parameter trend of the first rule, it is determined that the alarm event of the alarm device is an alarm event caused by a non-frequency and voltage regulation operation.
4. The method for identifying power grid alarm events according to claim 1, characterized in that: The step of inputting the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation includes: Inputting the target time series data into a pre-trained type recognition model; In the type recognition model, time-domain statistical characteristics of power parameters are calculated based on real-time operating data in the target time series data; Performing Fourier transform on the time domain statistical features to obtain frequency domain features; Retrieving corresponding typical timing pattern features from a normal frequency modulation and voltage regulation operation mode library according to the alarm type and the device attribute information of the alarm device; wherein the normal frequency modulation and voltage regulation operation mode library pre-stores typical timing pattern features corresponding to the alarm category and attribute, and the typical timing pattern features are pre-trained according to alarm event samples caused by normal frequency modulation and voltage regulation operations; Calculating the similarity between the frequency domain feature and the retrieved typical time series pattern feature to obtain a similarity value; When the similarity value is greater than a preset similarity threshold, the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation; When the similarity value is less than or equal to the preset similarity threshold, the instantaneous alarm event is an alarm event caused by abnormal frequency and voltage regulation operation.
5. The method for identifying power grid alarm events according to claim 1, characterized in that: The step of inputting the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation includes: Inputting the target time series data into a pre-trained type recognition model; In the type recognition model, a clustering algorithm is used to cluster all the alarm devices according to the target time series data; For each cluster of alarm devices, calculating the similarity between each of the alarm devices in the cluster and the cluster center according to the real-time operation data; Determining that the instantaneous alarm event corresponding to the first alarm device is an alarm event caused by a normal frequency and voltage modulation operation; wherein the similarity between the first alarm device and the cluster center is greater than a preset similarity threshold; It is determined that the instantaneous alarm event corresponding to the second alarm device is an alarm event caused by abnormal frequency and voltage modulation operation; wherein the similarity between the second alarm device and the cluster center is less than or equal to the preset similarity threshold.
6. The method for identifying power grid alarm events according to claim 1, characterized in that: The alarm dependency graph for carrying the alarm correlation degree between each abnormal device is constructed based on the pre-constructed device topology structure graph according to the real-time alarm records of all abnormal devices, including: Obtain the physical connection relationship and logical association relationship data of each power device in the power grid, and use the adjacency matrix representation method to construct the device topology diagram; Based on the device topology diagram, an alarm dependency diagram for carrying the alarm correlation degree between each of the abnormal devices is constructed according to the real-time alarm records; The step of identifying a potential fault root cause alarm event according to the alarm dependency graph includes: Traversing the alarm dependency graph, and using the PageRank algorithm to sort the importance of abnormal devices in the alarm dependency graph; The alarm event corresponding to the abnormal device with the highest importance is selected as the potential fault root cause alarm event.
7. The method for identifying power grid alarm events according to claim 1, characterized in that: When the root cause identification model determines that the potential fault root cause alarm event is a real fault root cause alarm event, taking the potential fault root cause device as a starting point, traversing the alarm dependency graph, obtaining all abnormal devices related to the potential fault root cause device, so as to generate an alarm analysis result and feed it back to the user, including: When the root cause identification model determines that the potential fault root cause alarm event is a real fault root cause alarm event, traverse the alarm dependency graph to construct an alarm propagation path starting from the potential fault root cause device; Based on the alarm propagation path, the path length between the abnormal device and the potential fault root device is calculated, and the downstream node impact score of the abnormal device is counted; wherein the downstream node impact score is positively correlated with the set score of the downstream node of the abnormal device and the number of nodes of the downstream node; Calculating the criticality score of the abnormal device according to the path length, the downstream node impact score and the pre-acquired set score of the abnormal device; wherein the criticality score of the abnormal device is negatively correlated with the path length, and the criticality score is positively correlated with the downstream node impact score and the set score of the abnormal device respectively; An alarm analysis result is generated according to the alarm propagation path, the criticality score of the abnormal device and the real-time alarm data of the abnormal device, and the alarm analysis result is fed back to the user.
8. The method for identifying power grid alarm events according to claim 1, characterized in that: Also includes: A maintenance work order is generated for the abnormal equipment according to the alarm analysis result, and the maintenance work order is sent to a maintenance client so that maintenance personnel can repair the abnormal equipment; wherein, the higher the criticality score of the abnormal equipment, the higher the level of the maintenance work order, and the shorter the processing time limit of the maintenance work order.
9. A power grid alarm event identification system, characterized in that: include: A data acquisition module, used to acquire real-time alarm data of the power grid; wherein the real-time alarm data includes device attribute information of the alarm device, real-time alarm records and real-time operation data of the alarm device, and the real-time alarm records include alarm type and alarm time; An event classification module is used to identify, based on a pre-established alarm rule base, instantaneous alarm events suspected to be caused by frequency and voltage regulation operations and alarm events caused by non-frequency and voltage regulation operations according to the alarm type and the real-time operation data; wherein the alarm rule base defines the equipment operation data characteristics of the alarm events caused by frequency and voltage regulation operations; A data extraction module, used to extract target time series data of the instantaneous alarm event from the real-time alarm data; wherein the target time series data includes the alarm type, device attribute information of the alarm device and real-time operation data; The event classification module is further used to input the target time series data into a pre-trained type recognition model to identify whether the instantaneous alarm event is an alarm event caused by a normal frequency and voltage regulation operation or an alarm event caused by an abnormal frequency and voltage regulation operation; The power grid alarm event identification system is also used for: Based on the pre-constructed device topology diagram, an alarm dependency diagram for carrying the alarm correlation degree between each abnormal device is constructed according to the real-time alarm records of all abnormal devices; wherein the abnormal device is an alarm device corresponding to an abnormal event, and the abnormal event includes an alarm event caused by the non-frequency and voltage regulation operation and an alarm event caused by the abnormal frequency and voltage regulation operation; Identify potential fault root cause alarm events according to the alarm dependency graph; Input the real-time alarm data corresponding to the potential fault root source alarm event into a pre-trained root source identification model; wherein the root source identification model is obtained by training according to a root source identification sample, the root source identification sample is the historical operation data and historical alarm record when the potential fault root source device is a real fault root source device, and the potential fault root source device is the alarm device corresponding to the potential fault root source alarm event; When the root cause identification model determines that the potential fault root cause alarm event is a real fault root cause alarm event, the alarm dependency graph is traversed with the potential fault root cause device as the starting point to obtain all abnormal devices related to the potential fault root cause device, so as to generate an alarm analysis result and feed it back to the user.
Citation Information
Patent Citations
Event-based autonomous identification method for power grid monitoring alarm information
CN110263172A