Power anomaly detection method and system

By improving the isolated forest model to a differentiable form, combined with bidirectional gated cyclic network and spatiotemporal attention calculation, the problem of lack of interpretability of abnormal feature expression in power abnormality detection is solved, and more accurate abnormality detection and fault tracing are achieved.

CN120123937APending Publication Date: 2025-06-10国网安徽省电力有限公司营销服务中心 +1
View PDF 0 Cites 7 Cited by

Patent Information

Application Number
CN202510210210.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In the detection of power abnormality, the expression of abnormal features lacks interpretability and is difficult to support fault tracing.

Method used

The isolated forest model is improved into a differentiable form, combining Sigmoid smooth transition and dual gradient optimization strategies, sample anomaly scores with gradient information are output, and timing features are captured through a bidirectional gating recurrent network, space-time attention calculation is performed, and thresholds are dynamically adjusted.

Benefits of technology

It improves feature interpretation and timing feature capture capabilities, optimizes dynamic threshold adjustment, and achieves more accurate abnormal detection and fault tracing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120123937A_ABST
    Figure CN120123937A_ABST
Patent Text Reader

Abstract

The invention discloses a power anomaly detection method and system, and the method comprises the steps: obtaining multi-source power data, carrying out the preprocessing of the multi-source power data, and obtaining a data stream after the time-space alignment; establishing an improved isolated forest model, and obtaining a sample anomaly score with gradient information; in combination with the abnormal score of the sample, capturing time sequence characteristics of the sample by adopting a bidirectional gating loop network, obtaining forward data characteristics and reverse data characteristics, and performing space-time attention calculation to obtain a space-time attention weight vector; acquiring an anomaly score according to the data features, counting the input feature data by adopting a sliding window to serve as an anomaly judgment initial threshold value, and dynamically adjusting the anomaly judgment initial threshold value in combination with a neural network correction item to obtain a dynamic correction threshold value; the initial threshold value and the dynamic correction threshold value are synthesized, a time-varying anomaly judgment threshold value is obtained, the three-level anomaly level of the operation state of the electric power system is formulated in combination with anomaly evaluation, and the detection precision can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power anomaly detection, and specifically to a power anomaly detection method and system. Background Art

[0002] With the continuous expansion of the scale of the power system, the grid structure is becoming increasingly complex, the power load fluctuates frequently, and power anomaly detection technology has become the key to ensuring power supply stability and reliability. Power system anomalies such as voltage sags, current overloads, and equipment overheating, if not identified and processed in a timely manner, may trigger cascading failures, causing significant economic losses and social impacts. Therefore, accurate and efficient power anomaly detection methods have important value for the operation and maintenance management of smart grids.

[0003] Currently, the power anomaly detection field mainly faces three major technical bottlenecks: insufficient feature interpretability, lack of temporal feature modeling, and rigid threshold setting, which are specifically manifested as follows:

[0004] 1. Insufficient feature interpretability, making it difficult to support fault tracing

[0005] Mainstream anomaly detection models (such as Isolation Forest, Deep Autoencoder) mostly rely on "black box" - type feature extraction, resulting in the lack of interpretability of anomaly criteria. When using the Isolation Forest algorithm, although anomalies can be detected quickly, its binary path partitioning mechanism cannot quantify the continuous change of the anomaly degree of samples, and it cannot trace the spatio - temporal correlation features of the anomaly source. In addition, although deep - learning - based models can improve the detection accuracy, the hidden - layer features lack physical meaning, making it difficult to guide maintenance personnel to conduct targeted fault troubleshooting, which limits the practical application value of the technology.

[0006] 2. Lack of temporal feature modeling, unable to capture the spatio - temporal propagation characteristics of anomaly patterns

[0007] Traditional anomaly detection methods (such as those based on statistical process control or simple threshold rules) are difficult to effectively capture the dynamic temporal correlation characteristics of power data. The operation data of the power system has strong spatio - temporal correlation. For example, the propagation of fault current, the cumulative effect of equipment temperature, etc., all need to reveal their internal laws through temporal modeling. Existing technologies use static sliding - window statistical methods, which only focus on local data segments and cannot model long - term dependencies, resulting in insufficient detection sensitivity for sudden anomalies or slow - changing faults. In addition, although convolutional neural networks can extract spatial features, they lack the ability to model the evolution of time series and are difficult to adapt to the dynamic characteristics of power data.

[0008] 3. Rigid threshold setting, unable to track the dynamic changes of the power system in real - time

[0009] Existing methods mostly rely on fixed thresholds or static statistical thresholds based on historical data and cannot adapt to the dynamic fluctuations and baseline drifts of the power system load. By setting thresholds using the sliding mean and standard deviation, the impact of long-term factors such as equipment aging and environmental temperature changes on the baseline is not considered, which easily leads to false alarms in high-load scenarios or missed alarms in low-load scenarios. In addition, although the adaptive threshold method proposed by current technologies introduces linear regression correction, its model lacks the ability of non-linear fitting and is difficult to meet the requirements of dynamic threshold adjustment under complex working conditions.

[0010] In the paper "Anomaly Detection and Repair of Power Big Data Based on Isolation Forest", a time series data set is constructed by collecting historical data, and the isolation forest algorithm is used to quickly and accurately detect outlier data to help discover potential data problems. The accuracy of the data repair algorithm for adjacent time moments is verified and the method is applied to data repair. However, the isolation forest in this paper adopts a binary path partitioning mechanism. Summary of the Invention

[0011] The technical problem to be solved by the present invention is: to solve the problem that when the current isolation forest algorithm is used for anomaly detection, the anomaly feature expression lacks interpretability and it is difficult to support fault tracing.

[0012] To solve the above technical problems, the present invention provides the following technical solutions:

[0013] A power anomaly detection method includes:

[0014] Obtain multi-source power data and preprocess it to obtain a data stream after spatio-temporal alignment;

[0015] Establish an improved isolation forest model, take the data stream as the input of the improved isolation forest model, and output a sample anomaly score with gradient information;

[0016] Combined with the sample anomaly score, use a bidirectional gated recurrent network to capture the temporal features of the sample, obtain forward data features and reverse data features; and perform spatio-temporal attention calculation on the obtained data features to obtain a spatio-temporal attention weight vector;

[0017] Obtain an anomaly score according to the forward data features, reverse data features, and spatio-temporal attention weight vector, use a sliding window to statistically analyze the input feature data as the initial threshold for anomaly determination, and combine it with a neural network correction term to dynamically adjust the initial threshold for anomaly determination to obtain a dynamically corrected threshold; then combine the initial threshold and the dynamically corrected threshold to obtain a time-varying anomaly determination threshold;

[0018] Based on the anomaly score combined with the time-varying anomaly determination threshold, formulate a three-level anomaly grade for the operating state of the power system.

[0019] In one embodiment of the present invention, establishing an improved isolation forest model includes: transforming the binary path judgment of the traditional isolation forest model into a sigmoid smooth transition form, so that the traditional isolation forest method is transformed into a differentiable form; wherein, the improved isolation forest model is:

[0020]

[0021] In the formula, P l (x) is the probability that the input sample x is divided into a certain subset when the l-th layer of the isolation forest is divided, ρ is the sigmoid function, w l is the normal vector of the l-th layer division hyperplane, T is the vector transpose, b l is the bias term of the l-th layer division hyperplane, and the input sample x is a sample in the data stream after spatio-temporal alignment.

[0022] In one embodiment of the present invention, when training the improved isolation forest model, a dual-gradient optimization strategy is adopted to update the normal vector of the division hyperplane;

[0023] Among them, the dual-gradient optimization formula is:

[0024]

[0025] Update the normal vector of the division hyperplane to:

[0026]

[0027] In the formula, is the abnormal classification cross-entropy loss, is the path length consistency loss, and η is the learning rate.

[0028] In one embodiment of the present invention, the abnormal score of the sample with gradient information is obtained through the following formula:

[0029]

[0030] In the formula, P(x t ) is the abnormal score of the sample with gradient information, L is the maximum layer of the division level, ω l is the weight coefficient of the l-th layer, t is the time, and P l (x t ) is the probability that the input sample x at time t is divided into a certain subset when the l-th layer is divided.

[0031] In one embodiment of the present invention, the forward data feature and the reverse data feature are obtained through the following formula:

[0032]

[0033] Obtain the spatio-temporal attention weight vector through the following formula:

[0034]

[0035] In the formula, are the forward data features at times t and t-1 respectively, are the reverse data features at times t and t-1 respectively, GRU is a bidirectional gated recurrent network, P(x t ) is the sample anomaly score, α t is the spatio-temporal attention weight vector, softmax is an activation function, and ⊙ is the Hadamard product.

[0036] In an embodiment of the present invention, the initial anomaly determination threshold is obtained through the following formula:

[0037]

[0038] Obtain the dynamic correction threshold through the following formula:

[0039] Δτ = ReLU(W τ [μ t ; σ t ; α t );

[0040] In the formula, the mean μ t and the standard deviation σ t of the data within the sliding window are used as the initial anomaly determination threshold, t is the time, s m is the anomaly score at time m; Δτ is the correction threshold, ReLU is an activation function, W τ is the neural network weight matrix, α t is the spatio-temporal attention weight vector;

[0041] The time-varying anomaly determination threshold is obtained in the following manner:

[0042] τ t = μ t + 0.25σ t + Δτ;

[0043] In the formula, τ t is the time-varying anomaly determination threshold.

[0044] In an embodiment of the present invention, the anomaly score is obtained through the following formula:

[0045]

[0046] In the formula, s t is the anomaly score of the sample at time t, |·| 2 is the norm, is the forward data feature at time t, are the reverse data features at time t respectively, α t is the spatio-temporal attention weight vector.

[0047] In an embodiment of the present invention, the three-level abnormal level of the operating state of the power system is:

[0048]

[0049] In the formula, CLass is the operating state level of the power system, s t is the abnormal score of the sample at time t, τ t is the time-varying abnormal decision threshold.

[0050] In an embodiment of the present invention, the power anomaly detection method further includes:

[0051] Parameter update strategy:

[0052] Update the normal vector of the division hyperplane of the improved isolation forest model based on the false alarm rate, as well as the time-varying abnormal decision threshold;

[0053] Model update strategy:

[0054] Adopt update strategies with two different time scales of daily and monthly; update the time-varying abnormal decision threshold daily, and perform full-model incremental training monthly.

[0055] The present invention also provides a power anomaly detection system, which applies the above-mentioned power anomaly detection method, including:

[0056] A data module, used to obtain multi-source power data, preprocess it, and obtain a data stream after spatio-temporal alignment;

[0057] A differentiable anomaly encoding module, used to establish an improved isolation forest model, input the data stream into the improved isolation forest model, and output the sample abnormal score with gradient information;

[0058] A time series feature module, used to combine the sample abnormal score, capture the time series features of the sample by using a bidirectional gated recurrent network, obtain forward data features and reverse data features; and perform spatio-temporal attention calculation on the obtained data features to obtain a spatio-temporal attention weight vector;

[0059] A dynamic threshold module, used to obtain an abnormal score according to the forward data feature, reverse data feature, and spatio-temporal attention weight vector, use a sliding window to statistically process the input feature data as the initial abnormal decision threshold, and combine the neural network correction term to dynamically adjust the initial abnormal decision threshold to obtain a dynamically corrected threshold; then combine the initial threshold and the dynamically corrected threshold to obtain a time-varying abnormal decision threshold;

[0060] A status level module, which is used to formulate a three - level abnormal level of the operation status of the power system based on the abnormal score combined with the time - varying abnormal determination threshold.

[0061] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0062] 1. Improve feature interpretability: Improve the traditional Isolation Forest into a differentiable form, replace the binary path judgment with Sigmoid smooth transition, and combine with Xavier initialization to make the abnormal path division clearer and more interpretable. The dual - gradient optimization mechanism takes into account the losses of both abnormal classification and path length, making the abnormal score calculation more transparent while improving the classification accuracy, facilitating the maintenance personnel to understand the basis of abnormal judgment and trace the root cause of the abnormality. Transform the Isolation Forest into a differentiable form, enhance the interpretability of abnormal path division, and improve the classification accuracy based on dual - gradient optimization.

[0063] 2. Strengthen the ability to capture time - series features: The bidirectional GRU network, with gating weights shared and the forget - gate bias set to 1, processes data from both positive and negative directions, effectively capturing the long - period dependence relationship of power data and being more sensitive to the detection of sudden and slow - changing faults. The spatio - temporal attention mechanism calculates weights in combination with the output of the bidirectional GRU, highlighting the spatio - temporal correlation of abnormal features, enabling the model to focus on key areas and better grasp the spatio - temporal propagation characteristics of abnormal patterns. Introduce the bidirectional GRU network and the spatio - temporal attention mechanism to accurately model the long - term time - series dependence and spatial correlation features of power data.

[0064] 3. Optimize the dynamic adjustment of the threshold: The dynamic threshold generation module combines the sliding - window statistics and the neural - network correction term. The sliding window calculates the mean and standard deviation as the baseline, and the neural network uses its non - linear fitting ability to dynamically adjust the threshold in combination with multiple features, which can adapt to the complex changes of the power system and reduce false alarms and missed alarms. The generated time - varying threshold can track the system status in real time and provide an accurate standard for abnormal decision - making. Design the dynamic threshold generation, combine the sliding - window statistics and the neural - network correction term, and realize the adaptive adjustment of the threshold with the system working conditions.

[0065] 4. Realize the continuous optimization of the model: Trigger parameter update based on the false - alarm rate monitoring. When the false - alarm rate exceeds the set value for 10 consecutive minutes, adjust the abnormal coding parameters and the dynamic threshold to reduce the false - alarm rate. Update the parameters of the threshold generation module daily to adapt to daily changes, and perform full - model incremental training monthly to learn new feature patterns. Through this closed - loop optimization, the model continuously improves itself to ensure the performance of abnormal detection. Brief Description of the Drawings

[0066] Figure 1 It is a schematic flowchart of a power anomaly detection method according to an embodiment of the present invention.

[0067] Figure 2It is a block diagram of a power anomaly detection system according to an embodiment of the present invention. Specific Embodiments

[0068] To facilitate those skilled in the art to understand the technical solution of the present invention, the technical solution of the present invention will be further described below in conjunction with the accompanying drawings of the specification.

[0069] The terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present application, "a plurality" means two or more, unless otherwise specifically defined.

[0070] Please refer to Figure 1 As shown, the present invention discloses a power anomaly detection method, including:

[0071] S10. Obtain multi-source power data, preprocess it, and obtain a data stream after spatio-temporal alignment.

[0072] Data Acquisition:

[0073] In an embodiment of the present invention, with the help of a voltage sensor, a current transformer, and an infrared thermometer, the three-phase voltage three-phase current temperature are synchronously collected. In this embodiment, the sampling frequency is 4 kHz, which corresponds to 8 cycles / cycle of the power system and can comprehensively and finely capture the dynamic changes of power signals, providing a high-resolution data basis for subsequent analysis.

[0074] Where i is the phase identifier of the three-phase voltage, and the value range is {1, 2, 3}, corresponding to the acquisition of A / B / C three-phase voltage signals. j is the phase identifier of the three-phase current, and the value range is {1, 2, 3}, distinguishing the measured values of different phase line currents. k is the spatial distribution position number of the temperature sensor, and the value range is {1,..., n}, representing the distribution of different temperature measurement points of the transformer winding.

[0075] Spatio-Temporal Alignment Compensation:

[0076] In an embodiment of the present invention, in the actual operating environment of the power system, due to asynchronous sampling of multiple devices, a spatio-temporal inconsistency problem will occur. When it is detected that the time delay Δt between devices > 0.1 ms, the cubic spline interpolation compensation technology is adopted. Specifically, the cubic spline interpolation compensation function is as follows:

[0077]

[0078] Where the coefficient a 0 、a1 、a 2 、a 3 Solve the continuity equation by constructing it from 4 adjacent sampling points. t n is a reference time point. During the cubic spline interpolation process, the time of a certain known sampling point is usually used as a reference. t n is the time of this reference sampling point. It is generally the time of a sampling point adjacent to the time point t for which interpolation compensation is currently required. In this way, it can ensure that the delay error after compensation is controlled within ≤0.05 ms, enabling the data collected by different devices to be accurately aligned in both the time and space dimensions, and finally outputting the aligned data stream Provide synchronous and accurate data input for subsequent steps.

[0079] S20. Establish an improved isolation forest model, use the data stream as the input of the improved isolation forest model, and output the sample anomaly score with gradient information.

[0080] In an embodiment of the present invention, the traditional isolation forest is an unsupervised anomaly detection algorithm. It constructs a binary tree by randomly dividing the data space and determines the degree of anomaly of a sample according to the path length of the sample in the tree. However, the division process of the traditional isolation forest is based on binary path judgment and is not differentiable, which makes it difficult to combine with optimization algorithms in deep learning, such as gradient descent, and unable to perform end-to-end training. End-to-End Training is a training strategy widely used in the fields of machine learning and deep learning. It refers to starting from the original input data and directly reaching the final output result, and the whole process is trained as a whole, rather than splitting the task into multiple independent subtasks for separate training and optimization. In this step, the traditional isolation forest method is transformed into a differentiable form, thereby realizing end-to-end training and enhancing the learning ability of the anomaly detection model.

[0081] The traditional isolation forest has certain advantages in anomaly detection. However, in order to achieve end-to-end training and better integrate it into the deep neural network architecture, the present invention improves it. Specifically, the binary path judgment of the traditional isolation forest model is transformed into a Sigmoid smooth transition form, so that the traditional isolation forest method is transformed into a differentiable form; among them, the improved isolation forest model is:

[0082]

[0083] In the formula, P l (x) is the probability that the input sample x is divided into a certain subset during the l-th layer division of the isolation forest, ρ is the Sigmoid function, w l is the normal vector of the l-th layer division hyperplane, T is the vector transpose, b lis the bias term of the l-th layer partitioning hyperplane. The input sample x is a sample of the spatio-temporally aligned data stream, which contains the characteristic information of multi-source power data such as three-phase voltage, current, and temperature.

[0084] In this embodiment, the traditional isolation forest uses binary path judgment, that is, the sample is either divided into the left subset or the right subset. In the high-dimensional space, the partitioning hyperplane is determined by the normal vector w l and the bias b l together. The bias b l determines the position of the hyperplane in space, and it, together with the normal vector w l affects the result of the input sample x being partitioned at the l-th layer.

[0085] In this embodiment, the normal vector w l of the l-th layer partitioning hyperplane is initialized by Xavier, which can not only ensure that each layer of neurons has a more appropriate gradient in the initial stage of training, but also lay a foundation for the subsequent optimization of the model, making the abnormal detection path judgment more continuous and differentiable. Since w l has been initialized by Xavier, the initialization of the bias b l can be considered to match the initialization method of w l to ensure the stability and rationality of the differential path function in the initial stage of training. The initial value of w l can be adjusted according to the variance of w l so that the output of the neuron is within a reasonable range.

[0086] In an embodiment of the present invention, the double-gradient optimization strategy is mainly used to update the normal vector w l of the partitioning hyperplane, and the w l in P l (x) determines the probability that the input sample x is partitioned at the l-th layer. Therefore, updating w l by the double-gradient optimization formula will directly affect the calculation result of P l (x), and further affect the accuracy of the entire abnormal coding process and abnormal scoring. The double-gradient optimization formula is introduced as follows:

[0087]

[0088] In the formula, is the abnormal classification cross-entropy loss, which mainly focuses on the classification accuracy of the model for abnormal samples, is the path length consistency loss, which focuses on ensuring the stability and rationality of path generation in the abnormal coding process.

[0089] During the training process, after calculating according to the double-gradient optimization formula, the gradient descent is used to update w lThe value, that is, update the normal vector of the division hyperplane to:

[0090]

[0091] In the formula, η is the learning rate. The updated w l will be substituted into P l (x), thereby changing the probability that the input sample x is divided at the l-th layer.

[0092] Through differentiable anomaly coding to achieve end-to-end training, the entire anomaly detection model can directly perform overall training from the original input data obtained from multi-source power data collection and preprocessing to the final anomaly score. This method has the following advantages: automatically learning features, reducing error accumulation, and improving model performance.

[0093] In an embodiment of the present invention, the sample anomaly score P(x t ) is during the division process of each layer of the isolation forest for the sample x t , and is comprehensively obtained from the division probability P l (x t ) of each layer. In the isolation forest, the more abnormal a sample is, the faster it is usually isolated, that is, it reaches the leaf node after fewer division steps. The P l (x t ) of each layer reflects the division situation of the sample x t at this layer. Integrating this probability information can obtain a score reflecting the overall abnormality degree of the sample.

[0094] Based on the comprehensive consideration of the path length, in the traditional isolation forest, the anomaly score is related to the path length that the sample passes through to reach the leaf node. In differentiable anomaly coding, we can draw on this idea and combine the P l (x t ) of each layer to construct the anomaly score. Consider the influence of the division probability of the sample x t at each layer on the path length. Assume that the isolation forest has L layers. We can define a weighted summation method to calculate the sample anomaly score with gradient information, and the formula for the sample anomaly score with gradient information is as follows:

[0095]

[0096] In the formula, P(x t ) is the sample anomaly score with gradient information, L is the maximum number of layers of the division hierarchy, ω l is the weight coefficient of the l-th layer, t is the time, and P l (x t ) is the probability that the input sample x at time t is divided into a certain subset during the division at the l-th layer. The weight coefficient ω lUsed to adjust the contribution degree of the probability of each layer division to the final anomaly score. Weight coefficient ω l The determination of can be adjusted according to the actual situation. For example, it can be determined according to the depth of the layer. Shallow layers may be more critical for anomaly judgment, so larger weights can be assigned.

[0097] In this embodiment, as the training progresses, by continuously adjusting w l , so that P l (x) can more accurately reflect the abnormal characteristics of the sample, thereby improving the accuracy of the anomaly score P(x t ), and providing a discriminative abnormal feature representation for subsequent time series feature fusion.

[0098] S30. Combining the sample anomaly score, use a bidirectional gated recurrent network to capture the time series features of the sample, obtain forward data features and backward data features; and perform spatio-temporal attention calculation on the obtained data features to obtain a spatio-temporal attention weight vector.

[0099] In an embodiment of the present invention, the spatio-temporal propagation characteristics of the abnormal pattern of the power system are captured, and historical information is processed through a deep learning model to capture long-term dependencies. A bidirectional GRU (gated recurrent unit) network is used to capture the time series features in the power data. The purpose is to process the input time series data from different directions to comprehensively capture the time series information in the data. Specifically, the forward data features and backward data features are obtained through the following formula:

[0100]

[0101] In the formula, are the forward data features at times t and t - 1 respectively, are the backward data features at times t and t - 1 respectively, and GRU is a bidirectional gated recurrent network

[0102] It can also be understood as the hidden state at time t in the forward GRU network. The hidden state is an internal representation in the GRU network during the process of processing input data. It is continuously updated as the time step progresses, stores the historical information from the past to the current time step, and is used for subsequent feature extraction and analysis. It can also be understood as the hidden state at time t in the reverse GRU network. Different from the forward GRU network, the reverse forward GRU network processes data forward from the end of the sequence, so stores the information from the future to the current time t.

[0103] In this embodiment, the dimension of the hidden layer is set to 64. By processing sequence data in both forward and backward directions simultaneously, the gated weight sharing mechanism makes the model more efficient in learning temporal dependencies. And the forget gate bias is initialized to 1. This ingenious design can effectively alleviate the problem of gradient vanishing, ensuring that during the processing of long sequences, the model can still retain key historical information and accurately capture the propagation characteristics of abnormal patterns in the time dimension.

[0104] In one embodiment of the present invention, by combining the forward hidden state output by the bidirectional GRU network and the backward hidden state the attention weights at each time t are calculated to strengthen the correlation of abnormal features in the spatio-temporal dimension. Specifically, the spatio-temporal attention weight vector is calculated through the following formula:

[0105]

[0106] In the formula, α t is the spatio-temporal attention weight vector. Each element in the vector represents the importance of the corresponding feature in the spatio-temporal dimension. The larger the weight value, the more important the feature is in anomaly detection. Softmax is an activation function, and ⊙ is the Hadamard product. The activation function softmax converts each element in a vector into a probability value between 0 and 1, and the sum of these probability values is 1. Its role is to normalize the fused features so that each element represents the relative importance of the feature in the whole. The Hadamard product is an element-wise multiplication operation for matrices or vectors. For two vectors or matrices of the same dimension, the Hadamard product multiplies the corresponding elements to obtain a result with the same dimension as the original vector or matrix.

[0107] This mechanism enables the model to automatically focus on the feature regions most relevant to anomalies in the spatio-temporal dimension, highlight key information, suppress noise interference, and finally output the spatio-temporal attention weight vector α t and the output of the bidirectional GRU network to provide feature inputs rich in spatio-temporal information for subsequent dynamic threshold generation.

[0108] S40. Obtain an anomaly score based on the forward data features, backward data features, and spatio-temporal attention weight vector. Use a sliding window to statistically process the input feature data as the initial threshold for anomaly determination, and combine it with the neural network correction term to dynamically adjust the initial threshold for anomaly determination to obtain a dynamically corrected threshold; then comprehensively combine the initial threshold and the dynamically corrected threshold to obtain a time-varying anomaly determination threshold.

[0109] In an embodiment of the present invention, considering that the load of the power system fluctuates frequently, which may cause baseline drift and thus affect the accuracy of anomaly judgment. In this step, a sliding window statistical method is adopted, and the window size is set to 60, which covers 1 minute of data. By calculating the following formula, the mean μ of the data within the window is obtained respectively. t and the standard deviation μ t , so as to initially characterize the statistical characteristics of the data at the current moment and serve as the basis for baseline estimation. Specifically, the initial anomaly determination threshold is obtained through the following formula:

[0110]

[0111]

[0112] In the formula, the mean μ of the data within the sliding window t and the standard deviation μ t are used as the initial anomaly determination threshold, t is time, s m is the anomaly score at time m, and the anomaly score s m is represented discretely, and the anomaly score of the sample at time t

[0113] s t is represented continuously, and the application formulas for obtaining both are the same. The mean μ t reflects the average level of the data within 1 minute near the current time point and is an important indicator of the dynamic baseline. The standard deviation σ t reflects the fluctuation of the data, and combined with the mean, it can more comprehensively describe the distribution characteristics of the data.

[0114] The sliding window statistical method is a commonly used technique in time series data processing. It slides a fixed-size window over the data sequence and performs statistical analysis on the data within the window. By setting a fixed-size window, which is 60 in this invention, representing that the window covers 1 minute of data because 60 data points correspond to 1 minute due to factors such as the sampling frequency. This window slides along the time series data from left to right, each time sliding one time step, usually 1 data point. At each window position, statistical calculations are performed on the data within the window, calculating statistics such as the mean and standard deviation.

[0115] In an embodiment of the present invention, in order to further adapt to the complex and changeable power operation conditions, a neural network correction term is introduced. Utilizing the non-linear fitting ability of the neural network, combined with the statistical features μ t , σ t at the current moment and the spatio-temporal attention weight vector α t , the threshold is dynamically adjusted to make up for the limitations of the pure statistical method. Specifically, the dynamic correction threshold is obtained through the following formula:

[0116] Δτ = ReLU(W τ [μ t ; σ t ; α t );

[0117] In the formula, Δτ is the correction threshold. Since the mean and standard deviation obtained only by sliding window statistics may not fully adapt to the complex and changeable power operation conditions, a neural network correction term is introduced to dynamically adjust the threshold, and Δτ is a value used to correct the threshold obtained by preliminary calculation. ReLU is the activation function. In this formula, using the ReLU function can introduce non-linear characteristics, enhance the expression ability of the model, and avoid negative correction terms. W τ is the neural network weight matrix, specifically a 3*1 weight matrix, which belongs to the parameters of the neural network. It is used to perform a linear transformation on the input feature vector [μ t ; σ t ; α t . By training and adjusting the value of W τ , the neural network can learn the influence weights of different features on the threshold correction. α t is the spatio-temporal attention weight vector. This feature vector combines the statistical features of the data and spatio-temporal attention information, and is used as the input of the neural network to calculate the threshold correction term.

[0118] In an embodiment of the present invention, combining the above two items, the time-varying anomaly determination threshold is obtained: τ t = μ t + 0.25σ t + Δτ; This threshold can track the change of the operating state of the power system in real time and output the time-varying anomaly determination threshold τ t , providing an accurate determination standard for subsequent hierarchical anomaly decision-making.

[0119] In this embodiment, to cope with the baseline drift caused by the load fluctuation of the power system, the model's adaptability to the actual situation is improved by dynamically generating the threshold.

[0120] S50. Based on the anomaly score and the time-varying anomaly determination threshold, formulate the three-level anomaly grade of the operating state of the power system.

[0121] In an embodiment of the present invention, the anomaly score It comprehensively considers the difference between the forward and backward hidden states output by the bidirectional GRU network and the spatio-temporal attention weight vector, and quantifies the anomaly degree of the data at each time point.

[0122] The three-level anomaly grade of the operating state of the power system is:

[0123]

[0124] Wherein, CLass is the operation status level of the power system. In this way, the operation status of the power system is clearly divided into three levels: normal, warning, and emergency, and the abnormal level label is output.

[0125] In an embodiment of the present invention, the power anomaly detection method further includes:

[0126] Parameter update strategy:

[0127] Update the normal vector of the division hyperplane of the improved isolation forest model based on the false alarm rate, and the time-varying anomaly determination threshold. In order to reduce the false alarm rate and improve the adaptability of the model, a parameter update trigger mechanism based on false alarm rate monitoring is set. When the false alarm rate Ω > 5% for 10 consecutive minutes, the parameter update process is started. The specific update method is Wherein, is the gradient of the false alarm loss with respect to w l of the key parameter w in the model l is adjusted to optimize the anomaly coding module, and at the same time τ t ←0.95τ t to correct the time-varying anomaly determination threshold to make it more suitable for the current actual operation situation. The false alarm rate Ω, that is, the ratio of the number of samples misreported by the statistical model to the number of actual normal samples in this time period, can be expressed by the calculation formula:

[0128]

[0129] Model update strategy:

[0130] Adopt update strategies with two different time scales: daily and monthly. When updating daily, the time-varying anomaly determination threshold is updated, and when updating monthly, the full model is incrementally trained.

[0131] In this embodiment, update strategies with two different time scales: daily and monthly are adopted. The daily update focuses on optimizing the parameters of the threshold generation module. Since the daily load changes, environmental factors, etc. of the power system will affect the baseline drift, adjusting the time-varying anomaly determination threshold τ t generation parameters can ensure the daily anomaly detection accuracy; monthly, the full model is incrementally trained. Considering the possible deep changes such as equipment aging and operation mode changes in the power system over a long period, the full model update can enable the model to continuously learn new feature patterns and maintain long-term effectiveness. The updated model parameters are output to the corresponding steps to achieve self-iteration and optimization of the model.

[0132] Please refer to Figure 2 As shown, the present invention also provides a power anomaly detection system, which applies the above-mentioned power anomaly detection method, including:

[0133] The data module is used to acquire multi-source power data and pre-process it to obtain the data stream after time and space alignment.

[0134] The differentiable anomaly encoding module is used to establish an improved isolation forest model, take the data stream as the input of the improved isolation forest model, and output the sample anomaly score with gradient information.

[0135] The temporal feature module is used to combine the sample anomaly score and use a bidirectional gated recurrent network to capture the temporal features of the sample to obtain forward data features and reverse data features; and perform spatiotemporal attention calculations on the acquired data features to obtain the spatiotemporal attention weight vector.

[0136] The dynamic threshold module is used to obtain anomaly scores based on the forward data features, reverse data features, and spatiotemporal attention weight vectors. It uses a sliding window to count the input feature data as the initial threshold for anomaly judgment, and combines the neural network correction term to dynamically adjust the initial threshold for anomaly judgment to obtain the dynamic correction threshold. The initial threshold and the dynamic correction threshold are then combined to obtain the time-varying anomaly judgment threshold.

[0137] The status level module is used to formulate three levels of abnormality levels for the operation status of the power system based on the abnormality score combined with the time-varying abnormality judgment threshold.

[0138] It is obvious to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential features of the present invention. Therefore, the embodiments should be regarded as exemplary and non-limiting from any point of view, and the scope of the present invention is defined by the appended claims rather than the above description, and it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present invention, and any reference numerals in the claims should not be regarded as limiting the claims involved.

[0139] The above-described embodiments merely represent implementation methods of the invention. The protection scope of the present invention is not limited to the above-described embodiments. For those skilled in the art, several modifications and improvements may be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention.

Claims

1. A method for detecting power anomaly, characterized in that: include: Acquire multi-source power data and pre-process it to obtain a data stream that is aligned in time and space; Establish an improved isolation forest model, use the data stream as the input of the improved isolation forest model, and output the sample anomaly score with gradient information; Combined with sample anomaly scoring, a bidirectional gated recurrent network is used to capture the temporal characteristics of samples and obtain forward and reverse data features; And perform spatiotemporal attention calculation on the acquired data features to obtain the spatiotemporal attention weight vector; The anomaly score is obtained based on the forward data features, reverse data features, and spatiotemporal attention weight vector. The input feature data is counted using a sliding window as the initial threshold for anomaly determination. The initial threshold for anomaly determination is dynamically adjusted in combination with the neural network correction term to obtain a dynamic correction threshold. The initial threshold and the dynamic correction threshold are then combined to obtain a time-varying anomaly determination threshold. Based on the anomaly score combined with the time-varying anomaly judgment threshold, a three-level anomaly grade for the operating status of the power system is formulated.

2. The power anomaly detection method according to claim 1, characterized in that: Establishing the improved isolation forest model includes: transforming the binary path judgment of the traditional isolation forest model into a Sigmoid smooth transition form, so that the traditional isolation forest method is transformed into a differentiable form; wherein, the improved isolation forest model is: Where P l (x) is the probability of the input sample x being divided into a certain subset when the first layer of the isolation forest is divided, ρ is the Sigmoid function, and w l is the normal vector of the hyperplane partitioned at the lth layer, T is the vector transpose, b l is the bias term for partitioning the hyperplane at the lth layer, and the input sample x is a sample in the data stream after spatiotemporal alignment.

3. The power anomaly detection method according to claim 2, characterized in that: A dual gradient optimization strategy is used to train the improved isolation forest model to update the normal vector of the partitioning hyperplane; Among them, the dual gradient optimization formula is: Update the partition hyperplane normal vector to: In the formula, is the cross entropy loss for abnormal classification, is the path length consistency loss, and η is the learning rate.

4. The power anomaly detection method according to claim 2, characterized in that: The sample anomaly score with gradient information is obtained by the following formula: In the formula, P(x h ) is the sample anomaly score with gradient information, L is the maximum level of the division level, ω l is the weight coefficient of the lth layer, t is the time, P l (x t ) is the probability that the input sample x at time t is divided into a certain subset when it is divided at the lth layer.

5. The power anomaly detection method according to claim 1, characterized in that: Get the positive data features and reverse data features through the following formula: Get the spatiotemporal attention weight vector using the following formula: In the formula, are the positive data features at time t and t-1 respectively, are the reverse data features at time t and t-1 respectively, GRU is a bidirectional gated recurrent network, P(x t ) is the sample abnormality score, α t is the spatiotemporal attention weight vector, softmax is an activation function, and ⊙ is the Hadamard product.

6. The power anomaly detection method according to claim 1, characterized in that: The initial threshold for abnormality determination is obtained by the following formula: Get the dynamic correction threshold using the following formula: Δτ=ReLU(W τ [m t ;s t ;a t ]); In the formula, the mean μ of the data in the sliding window is t and standard deviation σ t As the initial threshold for abnormality determination, t is the time, s m is the abnormality score at time m; Δτ is the correction threshold, ReLU is the activation function, W τ is the neural network weight matrix, α t is the spatiotemporal attention weight vector; The time-varying anomaly determination threshold is obtained by: t t =μ t +0.25s t +Δt; In the formula, τ t is the time-varying anomaly determination threshold.

7. The power anomaly detection method according to claim 1, characterized in that: The anomaly score is obtained by the following formula: In the formula, s t is the abnormal score of the sample at time t, |·|2 is the norm, is the positive data feature at time t, are the reverse data features at time t, α t is the spatiotemporal attention weight vector.

8. The power anomaly detection method according to claim 1, characterized in that: The three abnormal levels of the power system's operating status are: In the formula, CLass is the operating status level of the power system, s t is the abnormal score of the sample at time t, τ t is the time-varying anomaly determination threshold.

9. The power anomaly detection method according to claim 1, characterized in that: The power anomaly detection method further includes: Parameter update strategy: The partition hyperplane normal vector of the improved isolation forest model and the time-varying anomaly determination threshold are updated based on the false alarm rate; Model update strategy: Two updating strategies with different time scales, daily and monthly, are adopted; the time-varying anomaly determination threshold is updated at the daily level, and incremental training of the full model is performed at the monthly level.

10. A power anomaly detection system, characterized in that: The power anomaly detection method according to any one of claims 1 to 9 comprises: The data module is used to obtain multi-source power data and pre-process it to obtain the data stream after time and space alignment; The differentiable anomaly encoding module is used to establish an improved isolation forest model, taking the data stream as the input of the improved isolation forest model and outputting the sample anomaly score with gradient information; The time series feature module is used to combine the sample anomaly score and use a bidirectional gated recurrent network to capture the time series features of the sample to obtain the forward data features and reverse data features; and perform spatiotemporal attention calculation on the acquired data features to obtain the spatiotemporal attention weight vector; The dynamic threshold module is used to obtain anomaly scores based on the forward data features, reverse data features, and spatiotemporal attention weight vectors. The sliding window is used to count the input feature data as the initial threshold for anomaly determination. The initial threshold for anomaly determination is dynamically adjusted in combination with the neural network correction term to obtain the dynamic correction threshold. The initial threshold and the dynamic correction threshold are then combined to obtain the time-varying anomaly determination threshold. The status level module is used to formulate three levels of abnormality levels for the operation status of the power system based on the abnormality score combined with the time-varying abnormality judgment threshold.

Citation Information

Cited By

  • Electric power and electric quantity anomaly detection method based on big data

    CN120296640A

  • Intelligent measuring switch with electric energy error monitoring function

    CN121069303A

  • Domestic environment-oriented power application performance anomaly detection method and system

    CN121302304A

  • Mental state data screening management method and system fused with machine learning

    CN121439256A

  • Energy internet hidden abnormal data identification and restoration method based on space-time logic

    CN122196837A