Petroleum and petrochemical fire-fighting interlocking control equipment based on SIS

By adopting SIS-based interlocking control equipment in petroleum and petrochemical fire protection systems, using multi-source perception, graph neural network and quantum annealing-game interlocking framework, the traditional system's lack of response speed and cost of false shutdown is solved, and efficient and reliable fire treatment is achieved.

CN120189667AActive Publication Date: 2025-06-24SHANGHAI ANCHEN LNFORMATION TECH CO LTD

Patent Information

Application Number
CN202510690344.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-24
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

In the event of fire or leakage of existing petroleum and petrochemical fire protection systems, traditional interlocking control equipment is difficult to take into account the response speed and the cost of false shutdown, and is susceptible to electromagnetic interference and power failure in high temperature and high voltage environments.

Method used

The interlocking control device based on SIS is adopted to construct a unified feature tensor through redundant multi-source perception, and a graph neural network is used to predict the three-dimensional evolution of the hazard field and quantify the risk entropy. Combined with the quantum annealing-game interlocking framework, the minimum action set is output, and the memristor array solidification instructions are used. The execution end uses supercritical biphasic flow jet and a variable path robot to deal with it.

Benefits of technology

Submicrosecond data synchronization is achieved, the interlocking error stop rate and fire extinguishing agent consumption is reduced, the system response speed and reliability are improved, and the risk of high-temperature reloading is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120189667A_ABST
    Figure CN120189667A_ABST
Patent Text Reader

Abstract

The invention relates to the field of petroleum and petrochemical fire fighting, in particular to an SIS-based interlocked control device for petroleum and petrochemical fire fighting, which comprises a sensing fusion unit for acquiring optical fiber, radar, acoustics, an event camera and dual-band images, and generating a feature tensor and an attitude matrix through multi-scale synchronization and gating sparse fusion. And the prediction and risk assessment unit outputs disaster prediction data, a propagation potential energy matrix and a risk entropy by using the graph neural network spatial-temporal model and the generative adversarial correction. The interlocking control unit constructs a binary optimization model by taking the minimum action number and the residual potential energy as targets, obtains a minimum action set by means of quantum annealing and a minimum-maximum game, and writes the minimum action set into the memristive programmable logic array to generate an interlocking instruction stream. And the execution and feedback unit controls the two-phase flow jetting device, the robot unit and the heat shielding device to complete treatment, and feedback event flow is used for model incremental learning and action deviation correction. According to the invention, millisecond interlocking triggering is realized, the action redundancy is reduced, and the fire spreading radius is obviously reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of oil and petrochemical fire protection, and particularly to an interlock control device for oil and petrochemical fire protection based on SIS. Background Art

[0002] Oil and petrochemical plants are characterized by high temperature, high pressure, flammability, explosiveness and dense personnel. The safety instrument system undertakes the function of the last independent protection layer. Once a fire or leakage occurs and spreads, traditional interlocks usually rely on single-sensor interlocks and fixed logic tables. The trigger threshold is single and the action range is rigid, making it difficult to balance the response speed and the cost of false shutdown. Existing technologies mostly adopt hard wiring or programmable logic controller + look-up table strategies, and use single-point values of pressure and temperature as trigger conditions: cutting off pump valves with fixed thresholds often results in "excessive shutdown" due to the failure to evaluate the potential energy of flame spread in real time, causing production interruption; relying on rule tables to plan the robot path cannot avoid high-risk areas of smoke and fire in real time, resulting in disposal failure or robot damage; issuing instructions based on conventional memory chips requires reloading after power failure, and on-site electromagnetic interference or high temperature is likely to cause jamming. The fundamental reasons are the insufficient dimension of sensing information, the lack of the ability of the model to predict spatiotemporal coupling hazards, and the failure to consider the global optimum in the generation of interlock actions. Summary of the Invention

[0003] In view of the above-mentioned many problems existing in the prior art, the present invention provides an interlock control device for oil and petrochemical fire protection based on SIS. The present invention constructs a unified feature tensor with redundant multi-source perception, predicts the three-dimensional evolution of the hazard field through a graph neural network and quantifies the risk entropy; the quantum annealing-game interlock framework takes "the number of actions + residual potential energy" as the goal, outputs the minimum action set and writes it into the memristive array; the execution end uses supercritical two-phase flow injection and variational path robots to cooperate in disposal. The closed-loop feedback frame corrects the model in real time, compresses the response time of the entire chain to the millisecond level, and significantly reduces the interlock false shutdown rate and the consumption of fire extinguishing agents.

[0004] An interlock control device for oil and petrochemical fire protection based on SIS, comprising: A perception fusion unit, configured to collect multi-source data including at least an optical fiber sensor and a radar sensor, synchronize and fuse the collected data, output fusion feature data and attitude matrix data, and send the fusion feature data to a prediction and risk assessment unit, and send the attitude matrix data to an execution and feedback unit; A prediction and risk assessment unit, configured to generate disaster prediction data and propagation potential energy data based on the fusion feature data, calculate risk entropy data, and send the disaster prediction data, propagation potential energy data and risk entropy data to an interlock control unit; The interlock control unit is used to construct an optimization model based on the fusion feature data, propagation potential energy data, and risk entropy data, obtain the minimum action set data through an optimization solver, write it into a programmable logic array, and then output an interlock instruction stream to trigger the SIS interlock action; The execution and feedback unit is used to control the fire extinguishing medium release device, robot team, and thermal shielding device according to the interlock instruction stream, perform positioning and path planning in combination with the attitude matrix data, collect the execution status to form feedback data, and return it to the prediction and risk assessment unit and the interlock control unit to complete closed-loop self-correction.

[0005] Preferably, the perception fusion unit obtains the Brillouin scattering frequency shift through a distributed optical fiber sensor and demodulates the Brillouin scattering frequency shift into temperature information and strain information. It emits a frequency-modulated continuous wave through a millimeter-wave radar sensor and performs a fast Fourier transform on the echo to obtain point cloud information. It converts the acoustic signal into an electrical signal through an acoustic crystal sensor and performs a short-time Fourier transform to obtain spectrogram information. It records the gray-scale change event stream through an event camera and outputs event stream information. It synchronously obtains visible light image information and infrared image information through a dual-band camera. After aligning the timestamps of the above temperature information, strain information, point cloud information, spectrogram information, event stream information, and dual-band image information, the perception fusion unit outputs fusion feature data and attitude matrix data using the gated sparse tensor fusion method.

[0006] Preferably, when performing gated sparse tensor fusion, the perception fusion unit sets a gated weight tensor. The element values of the gated weight tensor are between zero and one. The perception fusion unit performs weighted parallel multiplication and addition operations on the tensors of each perception channel according to the gated weight tensor to reduce the redundant feature dimension and improve the sparsity of feature representation.

[0007] Preferably, the prediction and risk assessment unit adopts a spatio-temporal model based on a graph neural network, maps the fusion feature data into graph structure node features and edge features, uses a multi-head attention mechanism to propagate messages between nodes, and iteratively updates the node representation within a fixed number of time steps and outputs disaster prediction data and propagation potential energy data.

[0008] Preferably, the prediction and risk assessment unit uses the generative adversarial correction method to generate a perturbation tensor, superimposes the perturbation tensor on the disaster prediction data and inputs it into a discriminant network. After the discriminant network outputs the confidence level, it updates the parameters of the generative network. The prediction and risk assessment unit calculates the risk entropy data based on the corrected disaster prediction data. The risk entropy data measures the system hazard uncertainty through the logarithmic probability summation method.

[0009] Preferably, the interlock control unit constructs a binary unconstrained optimization model based on the fusion feature data, propagation potential energy data, and risk entropy data. The objective function of the optimization model consists of a linear combination of minimizing the number of actions and minimizing the dangerous potential energy. The interlock control unit maps the Boolean variables in the optimization model to a binary unconstrained optimization matrix and inputs it into the quantum annealing solver.

[0010] Preferably, after the quantum annealing solver outputs a Boolean vector, the interlock control unit introduces a minimax game strategy to perform three rounds of strategy correction on the Boolean vector. Each round of strategy correction uses the difference in dangerous potential energy as the payoff function. After completing the strategy correction, the interlock control unit determines the minimum action set data.

[0011] Preferably, the interlock control unit writes the minimum action set data into the memristive programmable logic array. The cross-wire voltage of the memristive programmable logic array is set by the interlock control unit to a first high level and a second low level. The first high level is used to indicate that the action bit is one, and the second low level is used to indicate that the action bit is zero.

[0012] Preferably, the execution and feedback unit mixes carbon dioxide and phase change aerogel through a two-phase flow injection device to form a supercritical mixed medium. After receiving the interlock instruction flow data, the execution and feedback unit drives the throttle valve group to inject the supercritical mixed medium in a pulsed manner for cooling and asphyxiation fire extinguishing.

[0013] Preferably, after receiving the interlock instruction flow data, the execution and feedback unit uses the variational path optimization method to generate a robot path based on the propagation potential energy data and risk entropy data. The robot path is determined by minimizing the path energy and the line integral of the dangerous potential energy. The execution and feedback unit controls the robot detachment to move along the robot path and perform on-site disposal tasks. At the same time, it collects valve position feedback data and robot status data and packages them in an event stream format. The event stream format is written into the event stream through the perception fusion unit for the prediction and risk assessment unit and the interlock control unit to perform model update and action correction.

[0014] Compared with the prior art, the advantages and beneficial effects of the present invention are as follows: The present invention realizes sub-microsecond-level data synchronization through multi-modal redundant sensing + gated sparse fusion, eliminating the false alarm defect of a single sensor; the present invention realizes three-second-level advance prediction of flames and leaks through a spatio-temporal model based on a graph neural network and generative adversarial correction, overcoming the fixed threshold hysteresis; the present invention realizes an average 30% decrease in the number of interlock actions by combining quantum annealing with minimax game to obtain the minimum action set, solving the problem of excessive shutdown; the present invention realizes "power-off retention" through instantaneous solidification of instructions by the memristive programmable logic array, avoiding the risk of high-temperature reloading; the present invention realizes rapid cooling and safe passage in high-potential areas by driving the cooperation of robots and two-phase flow injection through variational path optimization, avoiding robot damage. Brief Description of the Drawings

[0015] Figure 1 It is an interaction schematic diagram of the system of the present invention; Figure 2 It is a schematic diagram of the space-time prediction and adversarial correction pipeline in the present invention. Detailed Embodiments

[0016] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth in order to provide a comprehensive understanding of the embodiments of the present disclosure.

[0017] As Figure 1 shown, an interlock control device for petrochemical fire protection based on SIS includes: A sensing and fusion unit for collecting multi-source data including at least an optical fiber sensor and a radar sensor, synchronizing and fusing the collected data, outputting fusion feature data and attitude matrix data, sending the fusion feature data to a prediction and risk assessment unit, and sending the attitude matrix data to an execution and feedback unit; The sensing and fusion unit undertakes the primary function of the data link of the present invention, that is, obtaining redundant on-site information in petrochemical tank farms with coexisting high temperature, high humidity and strong electromagnetic interference, and then compressing multiple asynchronous signals into a spatio-temporally consistent feature tensor and attitude matrix to ensure that the SIS (i.e., Safety Instrumented System) can complete hazard identification and interlock triggering within milliseconds.

[0018] The optical fiber sensors are continuously laid along the tank wall and the oil pipeline trench, and the Brillouin scattering principle is used to simultaneously demodulate temperature and strain. There is a monotonic correspondence between the center frequency of the Brillouin gain spectrum and the local temperature and strain. Therefore, the system can quickly invert the stress concentration area through a rolling look-up table algorithm. The radar sensor at the same position emits a linear frequency modulated continuous wave. After mixing at the receiving end, a beat frequency signal is obtained, and then the distance amplitude spectrum can be obtained through a fast Fourier transform. By splitting the angle dimension with a multi-channel antenna, a three-dimensional coordinate point cloud can be output. The optical fiber and the radar form two-level redundancy for temperature focusing and three-dimensional deformation. If a thermal runaway simultaneously causes the temperature rise of the fiber core and the attenuation of the radar echo at one place, the credibility of the false alarm threshold can be significantly improved.

[0019] There are significant differences in the sampling frequencies of multi-source signals. The typical sampling period of the fiber optic channel is in the millisecond level, and the radar point cloud is refreshed about twenty frames per second. If each stream is directly written into the spatio-temporal model, it will cause the accumulation of feature alignment errors. Therefore, the present invention implements a multi-scale phase convolution alignment mechanism inside the edge FPGA. This mechanism uses the local oscillator phase of the fiber optic sampling as a reference, convolves the local oscillator phase signals of the radar, acoustic, event stream, and dual-band image with Morlet basis functions of three scales respectively, and obtains the cross-channel time deviation by minimizing the three-scale convolution residual. The measured results show that the maximum time difference after synchronization is less than one microsecond, which can meet the requirement of the interlock logic for the timing consistency not greater than ten microseconds.

[0020] After completing the time alignment, the six-channel data is mapped to a unified tensor . To reduce the redundant dimensions while maintaining the key signals, the present invention implements gated sparse tensor fusion on the edge FPGA. The system assigns a gated weight tensor of the same dimension to the tensor , and the weight range is limited between zero and one. The optimal gated weight is obtained through three-channel exponential compensation gradient descent training on the edge side. The fused tensor is calculated according to the following formula:

[0021] where the symbol represents element-wise multiplication. In the formula, is the fused feature tensor, is the gated weight tensor, and is the original tensor after alignment. During the training stage, the absolute value one-norm regularization is introduced for , so that the sparsity rate is kept within 15%. In the actual verification, the tensor dimension is compressed from more than one thousand two hundred dimensions to two hundred and fifty-six dimensions, and the information integrity is maintained above 90%. At the same time, the computational workload of the downstream graph neural spatio-temporal model is reduced by three times.

[0022] The pose matrix is generated by the point cloud-vision registration module. The system selects fifteen stable feature points in both the point cloud and the visible light image. The iterative closest point algorithm obtains the rotation matrix and the displacement vector by minimizing the sum of the squares of the Euclidean distances, and then obtains a four-by-four homogeneous transformation matrix. This matrix can synchronize the coordinates of any sensor in the tank area environment to a unified coordinate system, and can also provide a world coordinate system reference for the robot kinematics and path planning. The root mean square error of the registration residual is kept within three centimeters, which can support the safe movement of the robot in the narrow valve group channel.

[0023] The fused feature tensor and attitude matrix are written to the prediction and risk assessment unit through a dual 128-bit bus. In order to verify the effect of the perception fusion unit, the prototype system conducted an ignition test in a one-to-one tank group test area. When the three-way features of optical fiber temperature, event edge density and radar point cloud sparsity rate increase in linkage, the system performs feature weighting on the fused tensor, and the prediction and risk assessment unit generates a flame spread path after 30 milliseconds. Compared with the infrared image only solution, the multi-source redundancy solution of the present invention issues the first interlocking warning 900 milliseconds in advance, and completes two iterations and one game correction in the subsequent quantum solution window to ensure that the output action concentration of the interlocking control unit is minimized.

[0024] Preferably, the perception fusion unit obtains Brillouin scatter radio frequency shift through a distributed optical fiber sensor and demodulates the Brillouin scatter radio frequency shift into temperature information and strain information, transmits a frequency modulated continuous wave through a millimeter wave radar sensor and performs a fast Fourier transform on the echo to obtain point cloud information, converts the acoustic signal into an electrical signal through an acoustic crystal sensor and performs a short-time Fourier transform to obtain spectrum information, records the grayscale change event stream through an event camera and outputs the event stream information, and synchronously obtains visible light image information and infrared image information through a dual-band camera. After the perception fusion unit aligns the timestamps of the above-mentioned temperature information, strain information, point cloud information, spectrum information, event stream information and dual-band image information, it uses a gated sparse tensor fusion method to output fused feature data and posture matrix data.

[0025] The design goal of the perception fusion unit is to compress the six-way heterogeneous sensor information into a unified feature tensor and attitude matrix within a thousandth of a second, providing low-noise, time-consistent input for SIS's spatiotemporal prediction. The sensor selection takes into account both the early comprehensive signs of flammable medium leakage and the tolerance performance under extreme working conditions. Among them, the distributed fiber optic sensor is responsible for real-time perception of temperature rise and structural deformation along the tank wall, pump area and pipeline; the millimeter wave radar sensor can still output continuous point clouds in the dense smoke environment generated by the explosion; the acoustic crystal sensor targets the acoustic oscillation generated by the high-pressure fluid injection; the event camera is extremely sensitive to the sub-millisecond grayscale changes at the edge of the flame; the dual-band camera maintains imaging quality under high thermal radiation background through two sets of optical paths: visible light texture and mid-infrared radiation.

[0026] The Brillouin scattering frequency shift has a linear relationship with the medium temperature and axial strain. After injecting a pulse at the fiber end, the system measures the center frequency of the echo gain spectrum and uses an interpolation look-up table algorithm to convert the tank wall temperature and local stress in real time. The radar end adopts a frequency-modulated continuous wave system. The transmitted and received signals are mixed to obtain a beat frequency signal, and then the fast Fourier transform is performed to separate the distances of multiple targets. The pitch angle of the point cloud is inverted from the phase difference of the antenna array, and the temperature sensitivity of the radar hardware gate drift is compensated by a phase-locked loop. The acoustic crystal sensor body is a high-quality factor optical microcavity. The refractive index change caused by acoustic strain is converted into a slight shift of the transmission spectrum, and then the short-time Fourier transform is used to output the acoustic spectrum tensor. The event camera directly records the sudden change of pixel grayscale, and the data volume is much lower than that of frame-by-frame imaging. Denoising based on the histogram distribution can be completed within the edge FPGA. The dual-band camera uses a confocal lens group, and the visible light and mid-infrared are imaged on the same optical axis by using a beam splitter prism to reduce the registration error.

[0027] When the six-channel data arrives at the FPGA, it first enters the multi-scale phase convolution alignment module. Taking the sampling clock of the fiber channel as a reference, the local oscillator phase signal is convolved with three-level Morlet wavelets respectively, and the position with the minimum sum of squared residuals is the cross-channel time difference. This method maintains sub-microsecond alignment accuracy in a simulation of one hundred thousand frames of random drift. The tensors of each aligned channel are stitched together into a unified tensor. Gated sparse strategy is used for tensor fusion: A weight tensor of the same dimension is set. Through end-side gradient descent training and adding L1 norm regularization to keep the sparsity rate at 15%. The core fusion calculation formula is:

[0028] After training, the dimension of the fused feature tensor is reduced from more than one thousand two hundred dimensions to two hundred and fifty-six dimensions, and the average information fidelity is maintained above 90%.

[0029] The attitude matrix is generated using the fast iterative closest point algorithm. Fifteen groups of corner points are extracted from the point cloud and the visible light image respectively. The rotation matrix and translation vector are obtained through least squares optimization and combined into a four-by-four homogeneous coordinate transformation matrix, which is directly used as the benchmark for the robot path planning and the deployment angle of the thermal shield. The actual verification in the tank area shows that the root mean square error of the registration residual is less than three centimeters, so that the deviation between the path of the robot on the narrow valve group platform and the valve center does not exceed five centimeters.

[0030] To verify the contribution of the perception fusion unit to the interlock response time, the prototype system conducts a high-pressure gasoline spray ignition test on a one-to-one steel tank platform. The scheme relying solely on infrared images reaches the interlock threshold 200 milliseconds after the fireball appears; the scheme of the present invention triggers the precursor path of the prediction unit when the fiber optic temperature rises by one degree Celsius, the radar echo intensity decreases by 5%, and the gray mutation of the event camera covers 3% of the tank opening, completing the calculation window of the interlock action about one second earlier than the image scheme. This time difference allows the quantum annealing solver to perform an additional minimax search based on a 500-microsecond annealing, further reducing the redundancy of the minimum action set by 30%.

[0031] Another group of experiments simulates gasoline pump leakage at the fueling island. The acoustic crystal sensor detects high-speed bubble phonons earlier than other channels, and obvious low-frequency peaks appear in the short-time Fourier spectrum; some point clusters are lost in the radar point cloud under spray occlusion; there is no significant increase in the fiber optic temperature. After multi-source fusion, the gating weight automatically increases the proportion of the acoustic spectrum and the point cloud dimension, enabling the prediction unit to regard leakage rather than combustion as the priority hazard source. Finally, the interlock system selects a low-action opening scheme, only closing the leaking pump and moving the robot carrying the dry powder module to the downwind side of the tank in advance, winning 30 seconds for subsequent explosion suppression layout time.

[0032] Preferably, when the perception fusion unit performs gated sparse tensor fusion, it sets a gating weight tensor. The element values of the gating weight tensor are between zero and one. The perception fusion unit performs weighted parallel multiplication and addition operations on the tensors of each perception channel according to the gating weight tensor to reduce the redundant feature dimension and improve the sparsity of feature representation.

[0033] The key to the perception fusion unit to complete tensor fusion lies in the adaptive learning of the gating weight tensor. First, the multi-source channel data aligned by timestamps are sequentially concatenated into a unified tensor . The system creates a weight register array inside the edge field programmable gate array. The size of the array is exactly the same as the tensor . Each storage unit in the register array corresponds to an element of the gating weight tensor . In the initialization stage, all storage units are written with 0.5, indicating that the feature contributions of each channel are the same. Subsequently, it enters the online training process: on the continuously collected new data stream, the system takes the disaster prediction error as the objective function and updates the weights through element-wise gradient descent. To ensure sparsity, an absolute value one-norm constraint is imposed on the gating weight tensor after each update. When the cumulative weight of a certain row or column is too low, it is directly set to zero, closing the data path of the invalid dimension at the hardware level.

[0034] The core formula is:

[0035] where represents element-wise multiplication; is the output fusion feature tensor; is the gating weight tensor, and the element value ranges from zero to one: is the aligned channel feature tensor.

[0036] During calculation, the edge field programmable gate array completes multiplication and accumulation in a pipelined manner, and a row of tensor results can be obtained in a single cycle. Since a large number of elements have been sparsely set to zero, the corresponding multiplier can be shut down, and the power consumption of the field programmable gate array is reduced by more than 25%.

[0037] The weight update strategy adopts a two-step method. First, the prediction residuals of the last three frames are accumulated in the field programmable gate array, and the channel contribution degree is inversely calculated through a look-up table, and then a gradient descent is performed on the fusion processor. The gradient update formula is:

[0038] where is the prediction loss function, is the learning rate, is the time weight value at. To prevent the weight from drifting to extreme values of zero or one, a clamping operation is performed on after updating. This not only maintains the sparse structure but also avoids information loss caused by permanent channel shielding.

[0039] The above mechanism directly improves the accuracy of SIS in the scenario of early warning signs of dangerous syndromes. Taking the ignition of hydrocarbon gas leakage in a crude oil tank area as an example: Before the formation of the flame, the acoustic crystal sensor first detects the high-frequency whistling sound of the shell microcrack, and the radar point cloud also shows obvious fluctuations in the refraction distortion caused by the leakage airflow, while the fiber optic temperature has not yet risen. After three-frame weight update, the gating weight tensor automatically increases the weight values of the sound spectrum and point cloud channels, reduces the weight values of the event camera and the dual-band camera, and the energy proportion of the output fusion feature tensor in the sound spectrum and geometric dimensions increases to 45%. The risk assessment unit immediately increases the pre-combustion danger entropy by two orders of magnitude, and the interlock control unit generates the minimum action set 300 milliseconds in advance, instructing the robot team to deploy inerting sprays on the downwind side. The entire process completes explosion isolation two seconds earlier than the traditional single-channel trigger strategy based on fiber optic temperature rise.

[0040] In another comparative experiment, the system artificially reduces the radar transmission power to simulate hardware failure. After the gating weight tensor monitors a sudden drop in the information entropy of the point cloud dimension, it reduces the relevant weight values within 100 milliseconds and increases the proportion of the event camera and infrared image dimensions. Finally, the overall information volume of the fusion feature tensor only decreases by 5%, ensuring that the spatio-temporal model can still output a stable flame spread path. This result shows that the weight tensor enables the perception fusion unit to have the ability to dynamically allocate computing power and bandwidth, can quickly transfer attention to effective channels when any channel degrades, and enhances the reliability of the large system of SIS interlock.

[0041] The hardware implementation of gated sparse tensor fusion combined with online weight training realizes the real-time compression of high-dimensional perception data and channel adaptive scheduling. In scenarios such as oil and petrochemical fires with high dust, high heat radiation, and easy sensor failure, this design significantly reduces data bus congestion, improves prediction accuracy, provides low-dimensional inputs with high credibility for subsequent quantum optimization and interlock decision-making, thereby shortening the overall closed-loop delay of the system and ensuring the safety and efficiency of multi-robot collaborative fire extinguishing.

[0042] As Figure 2 shown, a prediction and risk assessment unit is used to establish a spatio-temporal model based on the fused feature data to generate disaster prediction data and propagation potential energy data, calculate risk entropy data, and send the disaster prediction data, propagation potential energy data, and risk entropy data to the interlock control unit; The prediction and risk assessment unit plays the role of "foresight + quantification" in the SIS. It uses the fused feature data to restore the three-dimensional topology and thermal-mass coupling state of the tank farm, gives the disaster evolution trend several seconds in advance, and measures the overall uncertainty with a single scalar, providing a directly comparable input basis for the interlock control unit. The system first maps the fused feature data into a heterogeneous graph according to the physical positions of the sensors: the nodes correspond to storage tanks, pipe manifolds, valve islands, and robots, and the edges represent heat transfer, combustible diffusion, and shock wave coupling. Subsequently, a spatio-temporal model is run on the graph, with the core being a two-stage graph neural network. The first stage performs multi-head attention aggregation on the information at the current moment to extract the instantaneous coupling between nodes; the second stage uses a gated recurrent unit to concatenate the historical hidden state and the instantaneous coupling to obtain the first-order time derivative, thereby outputting the disaster prediction data, that is, the estimated values of the temperature, concentration, and shock pressure of each node at future moments. The propagation potential energy data is converted from the disaster prediction data by accumulating the temperature gradient and combustible concentration gradient of the node pairs on each edge. The edges with larger gradients have higher potential energy weights, which can intuitively represent the spreading tendency of flames or high-pressure steam.

[0043] To summarize the multi-dimensional potential energy distribution into a single-valued quantization index, the unit further calculates the risk entropy data. First, the propagation potential energy data is regularized into the probability of a dangerous chain event occurring for the node pair , and then use:

[0044] to define the risk entropy. In the formula represents the risk entropy, represents the node to node The probability of a dangerous event occurring between them. The more uniform the probability, the higher the entropy value, indicating that there are multiple possible paths in the danger chain; when the probability is concentrated on a few paths, the entropy value decreases, indicating that the position of the critical shortcoming has been identifiable. The interlock control unit determines the coverage breadth of the action set accordingly: when the risk entropy is higher than the preset threshold, the action set not only cuts off the leakage source but also arranges explosion suppression robots at multiple nodes; when the risk entropy is lower than the threshold, only local interlocks on the high-probability paths are implemented.

[0045] The prototype system was tested comparatively in a 9000-cubic-meter crude oil tank farm. The scheme using only visible light cameras triggered an alarm 200 milliseconds after the flame appeared, while the prediction and risk assessment unit of the present invention output disaster prediction data and generated high-gradient propagation potential energy data when the temperature rise of the optical fiber was 0.8 °C and the radar point cloud density decreased by 8%, and the risk entropy rose to the critical value, pushing the minimum action set to the interlock control unit one second in advance. Finally, the spraying device and the robot team intervened in advance before the flame formed, effectively limiting the spreading radius of the flame. In another test of leakage but without combustion, the acoustic sensor first detected the crack whistling sound, and the model automatically down-regulated the weight of the temperature rise and up-regulated the weight of the sound spectrum, keeping the risk entropy at a medium level; the interlock action only closed the leakage pump and arranged inerting sprays, without mis-triggering a full-station pump shutdown, reducing unnecessary losses.

[0046] Through graph structure modeling and risk entropy quantification, the prediction and risk assessment unit compresses the high-dimensional dynamic disaster field into three intuitive and computable outputs: disaster prediction data, propagation potential energy data, and risk entropy data. These outputs are respectively used for the decision-making criteria of action positioning, action range, and action redundancy, realizing the forward-looking control of complex disaster chains in petrochemical scenarios and significantly improving the response speed and interlock accuracy of SIS under extreme conditions.

[0047] Preferably, the prediction and risk assessment unit adopts a spatio-temporal model based on a graph neural network, maps the fused feature data into graph structure node features and edge features, uses a multi-head attention mechanism to propagate messages between nodes, and iteratively updates the node representation within a fixed number of time steps and outputs the disaster prediction data and the propagation potential energy data.

[0048] The prediction and risk assessment unit undertakes the function of "restoring the on-site transient observations to the disaster evolution picture in the next few seconds". To meet the requirements of SIS for a millisecond-level foresight window, this unit adopts a spatio-temporal model based on a graph neural network, transforms the fused feature data into iteratively updatable node representations and edge representations, and then uses multi-head attention to propagate information in the graph. This method can not only maintain the physical interpretability of the topological structure but also give a high-resolution prediction of the complex heat-mass coupling process.

[0049] The fused feature data output by the perception fusion unit is first mapped to a heterogeneous graph. The node set covers five categories: storage tanks, pipeline pumps, inlet and outlet manifolds, robots, and personnel; the edge set corresponds to four types of interactions: heat conduction, combustible gas diffusion, shock wave radiation, and personnel movement. Each node is attached with the current temperature, combustible gas concentration, pressure, and local three-dimensional pose, and each edge is attached with the Euclidean distance, damping coefficient, and relative orientation between node pairs. This graph is internally stored as a sparse adjacency matrix and a feature matrix for fast indexing in the graph neural network.

[0050] The spatio-temporal model of the graph neural network consists of two stacked segments. The first segment is a static topology encoder that uses the multi-head attention mechanism to consider both directional and category correlations among nodes. In one propagation, each node splits its own representation into several attention heads, then linearly combines and normalizes with the representations of adjacent nodes to obtain a new node representation. Since there is a fixed relationship between the storage tank and the valve island in the physical structure, the attention weights will explicitly reflect the dominant paths of heat and material flow after training. The second segment is a time updater that uses a gated recurrent unit to combine the current node representation with the hidden state at the previous time step and outputs a new hidden state, thereby generating a node evolution sequence within a fixed time step. The hidden state output can obtain disaster prediction data through a linear transformation, including predicted values of the temperature, concentration, and pressure of the corresponding nodes in several future time steps. The propagation potential energy data accumulates the temperature gradient and concentration gradient of node pairs on each edge and multiplies by the damping coefficient. Edges with high values indicate that the fire or shock wave is more likely to spread.

[0051] To compress the multi-dimensional potential energy distribution into a single quantization index, the present invention introduces risk entropy. First, the propagation potential energy data is normalized to obtain the probability of a dangerous chain reaction. If the distribution of dangerous propagation paths is relatively uniform, the risk entropy increases, indicating that the interlock control unit needs to prepare actions with a wider coverage; if the probability is concentrated on a few paths, the risk entropy decreases, and the interlock action can be locked on key nodes to achieve the minimum action principle. In this expression, the natural logarithm is selected for the logarithmic operation, and the entropy unit is dimensionless, which is easy to normalize with other indices.

[0052] During online operation, the prediction and risk assessment unit receives new fused feature data every 100 milliseconds for a node update, and then outputs the disaster prediction data and propagation potential energy data from the next second to the next three seconds through a sliding window. At the same time, the latest risk entropy is pushed to the interlock control unit together with the other two types of data. The interlock control unit directly adds the risk entropy to the objective function to penalize or reward the Boolean action vector output by the quantum annealing, so that the minimum action set not only satisfies safety redundancy but also avoids excessive pump shutdown and mis-spray of coolant.

[0053] Taking the leakage ignition of a 9,000-cubic-meter crude oil tank as an example. In the initial stage of the accident, the acoustic sensor detected the stress wave inside the thin-walled tank shell, a gas refraction area appeared at the edge of the radar point cloud, and the event camera captured the dense gray-scale events generated by the spray jet. After the model converged, the predicted node temperature continuously increased within 900 milliseconds, and the potential energy of the two edges connecting the tank body and the manifold increased rapidly. The risk entropy increased from the baseline value to 1.5 times, and the interlock control unit immediately generated an action set. First, it cut off the bypass pipeline, and then dispatched a robot to carry a dry powder module to spray at the bottom of the tank. When the flame appeared, the temperature of the tank wall was 20 degrees Celsius lower than that of the unprepared plan, effectively blocking the bottom heat radiation.

[0054] In another case of gas leakage but without combustion, the model regarded the increase in node pressure and concentration as the priority danger signal, and the weight of temperature change was automatically down-regulated by the multi-head attention. As a result, the propagation potential energy was concentrated on the edge from the leakage point to the personnel passage downstream of the wind direction, and the risk remained at a medium level. The interlock action only closed the leakage pump and arranged an inerting spray, without triggering a total station shutdown, avoiding economic losses to the normal loading area. This case shows that the spatio-temporal model of the graph neural network can adaptively adjust the contribution ratio of different node features to the risk assessment.

[0055] In summary, the prediction and risk assessment unit realizes the fine prediction of node local evolution through the spatio-temporal model of the graph neural network, and realizes the quantifiable assessment of the overall danger chain through the propagation potential energy and risk entropy. This design not only significantly shortens the warning delay of the SIS, but also provides a structured input that can be directly used for optimization and solution for the interlock control unit, so as to still maintain the unity of the minimum action principle and the global safety goal under extreme working conditions. The risk entropy formula is as follows:

[0056] In the formula represents the risk entropy, represents the node to node The probability of a dangerous event occurring between them.

[0057] If the distribution of the dangerous propagation path is relatively uniform, the risk entropy increases, indicating that the interlock control unit needs to prepare actions with a wider coverage; if the probability is concentrated on a few paths, the risk entropy decreases, and the interlock action can be locked on key nodes to achieve the minimum action principle. In this expression, the natural logarithm is selected for the logarithmic operation, and the entropy unit is dimensionless, which is easy to normalize with other indicators.

[0058] During online operation, the prediction and risk assessment unit receives new fused feature data every 100 milliseconds for node updates, and then outputs disaster prediction data and propagation potential energy data from the next second to the next three seconds through a sliding window. At the same time, the latest risk entropy is pushed to the interlock control unit together with the other two types of data. The interlock control unit directly adds the risk entropy to the objective function to penalize or reward the Boolean action vector output by the quantum annealing, so that the minimum action set can satisfy both safety redundancy and avoid excessive pump shutdown and mis-spraying of coolant.

[0059] Taking the leakage and ignition of a 9000-cubic-meter crude oil tank as an example. In the initial stage of the accident, the acoustic sensor detected the stress wave inside the thin-walled tank shell, a gas refraction area appeared at the edge of the radar point cloud, and the event camera captured the dense gray-scale events generated by the spray jet. After the model converged, the predicted node temperature continuously increased within 900 milliseconds, and the potential energy of the two edges connecting the tank body and the pipeline quickly increased. The risk entropy increased from the baseline value to 1.5 times, and the interlock control unit immediately generated an action set, first cutting off the bypass pipeline, and then dispatching a robot to carry a dry powder module to spray at the bottom of the tank. When the flame appeared, the temperature of the tank wall was 20 degrees Celsius lower than that of the unforeseen plan, effectively blocking the bottom heat radiation.

[0060] In another case of gas leakage but without combustion, the model regarded the increase in node pressure and concentration as the priority danger signal, and the weight of temperature change was automatically down-regulated by the multi-head attention. As a result, the propagation potential energy was concentrated on the edge from the leakage point to the personnel passage downstream of the wind direction, and the risk entropy remained at a medium level. The interlock action only closed the leakage pump and arranged an inerting spray, without triggering a total station shutdown, avoiding economic losses to the normal loading area. This case demonstrates that the spatio-temporal model of the graph neural network can adaptively adjust the contribution ratio of different node features to the risk assessment.

[0061] In summary, the prediction and risk assessment unit realizes the fine prediction of node local evolution through the spatio-temporal model of the graph neural network, and realizes the quantifiable assessment of the overall danger chain through the propagation potential energy and risk entropy. This design not only significantly shortens the warning delay of the SIS, but also provides a structured input that can be directly used for optimization and solution to the interlock control unit, so as to still maintain the unity of the minimum action principle and the global safety goal under extreme working conditions.

[0062] Preferably, the prediction and risk assessment unit uses the generative adversarial correction method to generate a perturbation tensor, superimposes the perturbation tensor on the disaster prediction data and inputs it into the discriminant network. After the discriminant network outputs the confidence level, the parameters of the generative network are updated. The prediction and risk assessment unit calculates the risk entropy data based on the corrected disaster prediction data, and the risk entropy data measures the system danger uncertainty through the logarithmic probability summation method.

[0063] The prediction and risk assessment unit in the SIS is responsible for converting the fused feature data into a credible prediction of the disaster evolution in the next few seconds, and at the same time quantifying the uncertainty of the prediction results. Although the disaster prediction data output by the spatio-temporal model has considered multi-source information, there may still be deviations in the oil and petrochemical field due to sensor distortion, air turbulence or occlusion. To avoid relying solely on a single path for interlock actions, the present invention introduces a generative adversarial correction method, actively constructs a perturbation tensor subject to physical constraints, injects the worst-case scenario into the disaster prediction data, then uses a discriminative network to verify the feasibility of the perturbation, and dynamically adjusts the generative network according to the discriminative results to make the risk assessment more robust.

[0064] The core framework consists of a generative network and a discriminative network. The generative network outputs a perturbation tensor after inputting random noise, and the perturbation tensor is added element-wise to the disaster prediction data to obtain a correction candidate; the discriminative network receives the original prediction data and the correction candidate and outputs a binary classification confidence. The goal of the generative network is to maximize the misjudgment probability of the discriminative network within the physically feasible range, and the goal of the discriminative network is to accurately identify the true prediction and the correction candidate. The two are alternately trained, so that the generative network gradually captures potential scenarios that cause prediction failures, such as the concentration peak of local gas clouds and the instantaneous blockage of the tank breather valve.

[0065] To ensure that the perturbation tensor conforms to the heat and mass conservation constraints, the system sets an energy upper limit on the output of the generative network, that is, the temperature increment and concentration increment of the perturbation tensor at each node must be kept within the range of the on-site sensor, and the overall heat increment must not exceed the initial latent heat budget. If the output of the generative network exceeds the constraint, it is directly scaled to the upper limit. This strategy not only prevents the model from diverging, but also allows the discriminative network to learn the truly reachable dangerous states.

[0066] The discriminative network structure is a double-layer convolutional kernel plus a fully connected layer. The first layer extracts local spatial gradient features, and the second layer focuses on overall connectivity. The cross-entropy loss of the discrimination result is used to update the parameters of the generative network. In the inference stage, the network is no longer updated, only a perturbation tensor is generated once and overlaid on the disaster prediction data to obtain the corrected prediction. Subsequently, the propagation probability matrix is calculated, the propagation potential energy of each pair of nodes after correction is normalized to the interlock event probability, and then the risk entropy is calculated. The higher this entropy value represents, the more dispersed the distribution of dangerous paths is, and the interlock control unit needs to prepare actions with a wider coverage; the decrease in the entropy value indicates that the danger tends to a single link, and local actions can be used to suppress it.

[0067] Illustrate the leakage scenario of the outlet flange of a high-pressure light oil pump by way of example. On-site sensors captured a slight increase in the surrounding temperature and sparsification of the radar point cloud. The spatio-temporal model predicted that the gas cloud would spread towards the loading station within two seconds; the generative network output a perturbation tensor to further increase the concentration in the densely populated area. The discriminative network determined that the perturbation met the flammable concentration range. After correction, the propagation probability in the direction of the loading station doubled, and the risk entropy rose above the threshold. Based on this, the interlock control unit increased the operation of the ventilation fans in the enclosed loading island and dispatched robots to pre-deploy dry powder around the loading station. If no adversarial correction was performed, the original model only predicted local hazards in the tank farm, which might lead to insufficient protection for the downwind population.

[0068] Next, look at the scenario where the breather valve at the top of a liquefied petroleum gas spherical tank freezes and becomes blocked. The original prediction data already showed an increase in the pressure at the top of the spherical tank. After the generative network randomly perturbed it, it wanted to further increase the pressure, but the physical constraints restricted the coupling of temperature and pressure. The discriminative network quickly identified that this perturbation was not feasible, and the confidence output was lower than the threshold. The generative network reduced the perturbation amplitude to the allowable range according to the loss. Finally, the change in the propagation potential energy after correction was not significant, and the risk entropy remained at a medium level. The interlock actions focused on opening the top safety valve and remote spraying, without the need for large-scale evacuation of personnel, improving the disposal efficiency.

[0069] Compared with the traditional Monte Carlo method, the generative adversarial correction of the present invention can obtain the most influential feasible perturbation in one iteration, avoiding a large number of sample tests. The local safety factor is dynamically compensated by the correction, enabling the SIS to still have the ability to predict in the face of unknown or low-frequency extreme conditions. System tests showed that the average error of the risk entropy was less than 5% under more than two thousand different working conditions, the redundancy rate of the interlock actions was reduced by about 30%, and the response time was shortened by 20%. The generative adversarial correction method provides a perspective closer to the true worst-case scenario for the evaluation unit, significantly improving the reliability and flexibility of the SIS interlock.

[0070] An interlock control unit, configured to construct an optimization model based on the fused feature data, propagation potential energy data, and risk entropy data, obtain the minimum action set data through an optimization solver, write it into a programmable logic array, and then output an interlock instruction stream to trigger the SIS interlock action; The task of the interlock control unit is to give the minimum action set that meets the requirements of the functional safety level within the millisecond level, enabling the SIS to complete isolation, explosion suppression, and fire extinguishing with the most economical actions and the shortest path. The unit inputs three types of data: a fused feature tensor, a propagation potential energy matrix, and a risk entropy scalar. The fused feature tensor records the current comprehensive state of each node; the propagation potential energy matrix depicts the spreading ability of the hazard along the edges; the risk entropy scalar reflects the concentration of the hazard path distribution. The interlock control unit first maps the above inputs to a weighted directed graph: the nodes inherit the features such as temperature, pressure, and concentration in the tensor, and the edge weights are equal to the propagation potential energy values. Subsequently, a binary optimization model is constructed, and each candidate action is encoded as a Boolean variable , where the value of one indicates the execution of an action, and the value of zero indicates no execution of an action. The total number of variables is . The action types include five categories: cutting off the fuel transfer pump, shutting off the solenoid valve, robot placement, injection medium triggering, and thermal shield deployment.

[0071] The objective function consists of two parts: the number of actions and the residual risk:

[0072] In the formula is the action cost coefficient, is the risk potential energy coefficient, represents the node to node of the propagation potential energy value. The first term encourages reducing the number of actions, and the second term punishes the situation where the high-potential edges are not covered. The model constraints include the interlock dependence between the pump group and the valve group, the upper limit of the number of robot placements in the same area, the lower limit of the remaining inventory of the fire extinguishing agent, etc. The interlock control unit first uses the parser to transform the objective function and constraints into a binary unconstrained optimization matrix, and then sends it to the quantum annealing solver. Quantum annealing can search the exponential-scale state space simultaneously in microseconds, so it can output a high-quality Boolean vector within the strict response time limit.

[0073] After the solver returns the Boolean vector, the unit introduces a zero-sum game correction mechanism. The two players in the game represent the action set and the risk potential energy respectively, and the payoff function is selected as the difference between the increment of the risk potential energy and the action execution cost. Through three rounds of minimax search, the system makes marginal adjustments to the quantum solution, eliminates the isolated actions that may be generated by quantum noise, and at the same time ensures that the high-potential paths are effectively covered. The data of the minimum action set after correction is immediately written into the memristive programmable logic array. The memristive array represents the action bit one and zero with high and low levels respectively, and the writing time is on the order of nanoseconds, ensuring that the subsequent signal chain will not miss the interlock window due to configuration delay.

[0074] After the programmable logic array change is completed, an interlock instruction stream is generated. The instruction stream is encoded in four segments: the pump group, the valve group, the robot, and the injection device. Each segment contains the action bit, the execution priority, and the timeout threshold. After receiving the instruction, the on-site SIS triggers the hardwired circuit and the programmable safety controller in the order of priority, so that the core actions can still be completed in extreme situations such as power failure and bus congestion.

[0075] The examples show that in the scenario of crude oil tank wall leakage and ignition, the traditional interlocking logic based on fixed rules needs to execute twelve actions, and it takes one hundred and fifty milliseconds to complete all of them. The interlocking control unit of the present invention only outputs seven necessary actions, and the action sequence is completed within one hundred milliseconds, and the residual propagation potential energy of the tank area is kept below the safety threshold. In another set of liquefied petroleum gas ball tank top pressure rise scenarios, the initial value of the risk entropy is low. This unit can eliminate the danger by outputting four local actions, avoiding the economic losses caused by the shutdown of the entire station. According to statistics of two thousand simulations of different working conditions, the combination of quantum annealing and game correction can reduce the number of actions by an average of 30%, and shorten the interlocking response time by more than 25%.

[0076] By combining quantum global search, local game correction and instant writing of memristive logic, the interlocking control unit achieves a dynamic balance between the minimum action principle and functional safety redundancy, significantly improving the SIS's ability to make rapid decisions and reliable execution in high-risk scenarios in the petroleum and petrochemical industry.

[0077] Preferably, the interlocking control unit constructs a binary unconstrained optimization model based on the fused feature data, propagation potential energy data and risk entropy data, wherein the objective function of the optimization model is composed of a linear combination of minimizing the number of actions and minimizing the hazard potential energy, and the interlocking control unit maps the Boolean variables in the optimization model into a binary unconstrained optimization matrix and inputs it into a quantum annealing solver.

[0078] The design goal of the interlocking control unit is to block the disaster chain with as few actions as possible and maintain the interpretability of the system under the premise of meeting the functional safety level. To this end, the unit maps the three types of inputs from the prediction and risk assessment unit - fusion feature data, propagation potential data, and risk entropy data - to the binary unconstrained optimization model. The core idea is to abstract each possible action into a Boolean variable, let one represent execution, and if the variable is zero, it means no execution; all variables constitute a Boolean vector. In order for the quantum annealing solver to be able to process directly, the objective function and constraints must all be written in quadratic form for Boolean variables, that is, the binary unconstrained optimization matrix.

[0079] The action pool is divided into four groups according to physical categories: "cut-off", "explosion suppression", "injection" and "path". The cut-off category covers the main pump, unloading pump and key valve positions; the explosion suppression category refers to the placement of the robot carrying dry powder or inert agent; the injection category refers to the pulse injection of two-phase supercritical medium at the specified valve group; the path category is the robot's weighted inspection of high potential energy nodes. Each action is assigned a unique index, forming a length of Boolean vector of The objective function is a linear combination: one measures the total number of actions, and the other measures the residual hazard potential after passive coverage. It can be formalized as:

[0080] in is the action cost weight, is the dangerous potential energy weight; is a column vector of all ones; is a symmetric matrix, and the element is jointly derived from the propagation potential energy matrix and the risk entropy: when the propagation potential energy between node pairs is high and the risk entropy is prominent, the corresponding element is large, to encourage the selection of actions covering this path.

[0081] For the hard constraints in the oil and petrochemical scenarios, such as the mutual exclusion between the main pump and the bypass valve in the same loop, the maximum number of robot deployment points, the lower limit of the fire extinguishing agent inventory, etc., they are uniformly written into the penalty function. After multiplying the penalty function by a large coefficient, it is superimposed on the objective function, so that any Boolean vector violating the constraints is in a high-energy valley in the annealing energy diagram and will be automatically excluded during the solution process.

[0082] At the implementation level, the interlock control unit first uses the processor to calculate the matrix and the coefficient based on the real-time input, and then expands the objective function into three parts: the constant term, the first-order term, and the second-order term and writes them into the quantum processor interface configuration file. The external quantum annealing chip has thousands of qubits and can complete an optimization in dozens of microseconds. The Boolean vector output by the quantum annealing is the candidate minimum action set.

[0083] To offset the random jitter that may be brought by the quantum annealing, the present invention adds a minimax game correction once. The profit function is defined as "the decrease in the dangerous potential energy after executing the action minus the number of actions multiplied by the unit cost". The algorithm conducts three rounds of search on the local neighborhood of the quantum solution. If the profit increases after removing some actions, these actions will be removed in the next round; if adding a small number of actions can significantly reduce the dangerous potential energy, they will also be added. This can not only ensure the global optimal approximation but also filter out isolated and redundant actions.

[0084] After the minimum action set is determined, it is written into the programmable logic array. The memristive crossbar array can be written in one step and does not require the multi-stage download of the traditional FPGA, and can shorten the configuration time to the order of nanoseconds. The array outputs the interlock instruction stream, and the format is encoded in sequence according to the pump valve, robot, and spraying device. Each action bit has an independent timeout threshold, so that the SIS can still execute the core actions according to the hardwired loop in case of communication anomalies.

[0085] Example 1: In the scenario of leakage and fire at the bottom of a 9000-cubic-meter crude oil tank, the beta coefficient is set to five, making the weight of "minimum danger potential energy" slightly higher than the action cost. Quantum annealing gives a 13-bit action vector, which is reduced to 9 bits after game correction, including closing the leakage pump, starting the annular spray, and dispatching two robotic guard valve islands. The whole process consumes 0.2 milliseconds of annealing plus 0.4 milliseconds of correction, and the total response time is 7 milliseconds, reducing the actions by 40% compared to the traditional PLC rule table and shortening the interlock delay by one-third.

[0086] Example 2: The breather valve of a liquefied petroleum gas spherical tank is over-pressurized due to low-temperature frosting. The risk entropy is at a low level due to the single propagation path. The interlock control unit assigns a higher weight to the number of actions, and quantum annealing directly outputs four actions: starting the top safety valve, turning on the proximal exhaust fan, dispatching a single robot to arrange a quick-release spray, and issuing a personnel limit warning. As a result, the number of operation instructions is reduced by more than 70 compared to the conventional emergency pump shutdown plan, avoiding a full-station shutdown.

[0087] By combining the binary unconstrained optimization model with quantum annealing, the interlock control unit can find a high-quality and low-redundancy action set in the millisecond level while strictly satisfying the constraints. For high-risk sites in the petroleum and petrochemical industries, this "minimum action principle" means lower mis-shutdown costs and higher personnel safety margins, reflecting the balance advantage of the present invention between functional safety and resource economy.

[0088] Preferably, after the quantum annealing solver outputs a Boolean vector, the interlock control unit introduces a minimax game strategy to perform three rounds of strategy correction on the Boolean vector. Each round of strategy correction uses the difference in danger potential energy as the payoff function, and the interlock control unit determines the minimum action set data after completing the strategy correction.

[0089] After the interlock control unit obtains the Boolean vector returned by the quantum annealing solver, it does not immediately use this vector as the final action set. Instead, it introduces a minimax game strategy to perform three rounds of strategy correction, aiming to further compress redundant actions and improve the coverage of critical danger chains without increasing the calculation delay. The Boolean vector output by the quantum annealing solver is often close to the global optimum, but due to the random fluctuations of quantum annealing itself and the topological constraints of the hardware embedded graph, it may still contain "isolated switches" or miss low-energy but highly influential actions. The minimax game places the quantum solution and the danger potential energy matrix in an adversarial perspective, reallocating the payoffs for the two through a finite number of rounds, and finally obtaining more robust minimum action set data.

[0090] The two players in the game are named the action agent and the potential agent respectively. The strategy space of the action agent is the switch selection of each bit in the Boolean vector; the strategy space of the potential agent is to dynamically adjust the weights in the propagation potential energy matrix to highlight the high-risk edges that have not been covered by actions. The payoff function is designed as the difference between the reduction in danger potential energy and the new cost of actions. Mathematically expressed, when the Boolean vector passes through the After round correction, the profit function can be written as:

[0091] where represents the node after the round, from node to the dangerous potential energy of node represents a newly added action bit in this round; is the action cost weight constant. The profit function The larger it is, the more significant the decrease in dangerous potential energy brought by this round of correction and the lower the cost. This formula is only given in the core innovation link, and the remaining conventional summation and threshold judgment processes are only described in words.

[0092] The three-round game correction follows the order of "filling gaps, merging, and fine-tuning". In the first round of filling gaps: the potential energy agent scans the propagation matrix, marks the edges with risk entropy higher than the average and not covered by actions as the edges of concern, and the action agent selects several action bits with the largest contribution from the candidate set of nodes connected by these edges and sets them to one. In the second round of merging: for the actions with the total number of switches ranking in the last 20% and marginal contribution, the action agent tries to set them to zero. If the total dangerous potential energy does not increase by more than the preset threshold, it is confirmed to be deleted, so as to eliminate isolated actions. In the third round of fine-tuning: the potential energy agent reallocates weights according to the remaining high-weight edges, and the action agent makes a try of flipping the local bit to refine the remaining action set. After three rounds, if the overall dangerous potential energy is still higher than the critical value, the action bit with the largest profit in the previous round is re-added, and finally the minimum action set data is output.

[0093] The entire game runs on the edge accelerator. The action agent logic is implemented by parallel Boolean operations; the potential energy agent logic uses a sparse matrix multiply-add processor, and the total time for three rounds does not exceed one millisecond. At the hardware level, floating-point operations are avoided, and all weights and profits are completed in the sixteen-bit fixed-point domain, ensuring a match with the output rhythm of quantum annealing at the level of five hundred microseconds and not slowing down the system interlock response.

[0094] Example 1: In the scenario of a methanol vapor cloud fire occurring in a 50,000-cubic-meter floating roof tank, quantum annealing initially gives twelve actions, including three independent injection valve positions. In the first round of the game, it is found that the high-potential energy edge on the north side of the wind direction is not covered, and a new action of robot dry powder distribution point is added. In the second round, it is determined that the spraying coverage areas of the two valve positions overlap highly, and one of them is deleted. In the third round of fine-tuning, the spraying duration of the injection valve is shortened by half and nitrogen inerting is added at the adjacent valve position. Finally, the number of actions is reduced to ten, the dangerous potential energy is reduced by 35%, and the total response delay increases by 0.7 milliseconds, still meeting the functional safety time limit requirements.

[0095] Example 2: The low-temperature expansion of liquefied petroleum gas causes the breather valve to freeze. Quantum annealing outputs five actions, including stopping the pumps across the station. In the first round of the game, the top node of the breather valve is weighted, and a new manual discharge action replaces the pump stop across the station; in the second round, the bypass valve switch that is mutually exclusive with this action is removed; in the third round, only the robot path is slightly adjusted. Finally, there are three actions in the action set, and the dangerous potential energy is equivalent to the pump stop plan, but the impact on production is significantly reduced.

[0096] Through the minimax game correction, the interlock control unit can perform local game search based on the approximately optimal solution given by quantum annealing, remove redundant actions, and fill in the key actions that may be missed by the quantum solution. This not only improves the safety margin of the minimum action set but also avoids the misoperation cost caused by hardware noise or quantum embedding defects. This "quantum global + game local" double-layer optimization structure enables the SIS to achieve fast, accurate, and interpretable interlock responses in complex and multi-path petrochemical fire chains.

[0097] Preferably, the interlock control unit writes the minimum action set data into the memristive programmable logic array. The cross-wire voltage of the memristive programmable logic array is set by the interlock control unit to a first high level and a second low level. The first high level is used to represent that the action bit is one, and the second low level is used to represent that the action bit is zero.

[0098] After determining the minimum action set data, the interlock control unit needs to reliably, quickly, and low-power solidify each bit of the action instruction to the hardwired layer to ensure that the SIS can still execute the core interlock actions even when the main controller loses power, the field bus is interfered, or the traditional electrically erasable memory fails due to high temperature. The present invention uses a memristive programmable logic array as the hardware carrier of the interlock instruction. Its core advantages are that the writing speed is in nanoseconds, the conductance state remains unchanged after power-off, and the unit density is much higher than that of traditional static random access memories or lookup table arrays.

[0099] The memristive programmable logic array adopts a cross-wire structure, and a resistive variable oxide thin film is deposited at the intersection of the upper wire and the lower wire. Under the action of a nanosecond-level pulse voltage, the valence bonds of this thin film change, and the conductance jumps from a low state to a high state or vice versa. For ease of on-site measurement, the system stipulates the first high level for writing the thin film into the low-resistance state, and the corresponding action bit is set to one; the second low level writes the thin film into the high-resistance state, and the corresponding action bit is set to zero. The writing process is completed by a dedicated drive module of the interlock control unit. First, it parses the minimum action set data, maps Boolean one to + , and maps Boolean zero to + . Subsequently, write pulses are sequentially applied to the cross nodes according to the Cartesian coordinates of the row select line and the column select line. The pulse width is 30 nanoseconds, and the amplitude is accurately output by a digital programmable voltage controller.

[0100] To prevent adjacent intersections from being parasitically written, a half-selection protection strategy is adopted for the write pulse: when a certain intersection needs to be written to a high level, its row line is applied with , and its column line is applied with ; the unselected row lines and column lines are simultaneously applied with the inverted level. This ensures that the voltage difference across the target intersection is , and the voltage difference across non-target intersections does not exceed half of the thin-film triggering threshold, effectively suppressing miswriting. A similar principle is used for low-level writing. After the array writing is completed, the interlock control unit immediately starts the verification mode, scans the intersection conductance row by row. If the detected resistance deviation exceeds 10% of the tolerance, it will be automatically rewritten once, and the intersection number will be recorded in the system log.

[0101] In terms of low power consumption, there is still a sub-milliampere-level leakage current when the memristive thin film is in the high-conductance state. In the present invention, the action array is divided into four sub-regions through row-column segmented address decoding, and only the sub-region that needs to perform actions is powered on, reducing the static power consumption by 60%. At the same time, in order to prevent the wires from degrading due to high temperature, the cross-wire material is selected as copper-aluminum composite wiring, which has a low surface resistivity and good heat diffusion ability. After cyclic aging tests from 50 degrees Celsius to 180 degrees Celsius, the array resistance drift is less than 5%.

[0102] Two typical scenarios are selected for effect verification. The first is a high-pressure fire pipeline bursting and instantaneous fire. The prediction and risk assessment unit outputs a high-propagation potential energy matrix, and the interlock control unit generates a fifteen-bit minimum action set data, which includes cutting off the main pump, opening the bypass spray, deploying two robots, and unfolding the heat shield film. Writing a fifteen-bit full-length Boolean vector to the memristive programmable logic array takes 450 nanoseconds; after the array outputs the interlock instruction stream, the hard-wired circuit has completed the action within 3 milliseconds. Compared with the traditional static random access memory-based programmable gate array, the overall response time is shortened by about 30%, and the wire state remains unchanged after re-powering, without the need to re-download the configuration.

[0103] The second scenario is the condensation and swelling of liquefied petroleum gas tanks. The risk entropy is relatively low, and the minimum action set data has only eight bits. The writing takes less than 300 nanoseconds. Because the action bit density is low, segmented decoding only powers on a single sub-region, and the static power consumption is less than 10 milliwatts, which is suitable for long-term standby. After manual review afterwards, it is confirmed that all interlock actions have been executed, and only the top safety valve and a local inerting spray are triggered on-site, avoiding a full-site shutdown.

[0104] Through half-selection protection, line-by-line verification, and segmented decoding, the present invention solidifies the minimum action set generated by quantum annealing and game correction into a physical conductance state at the sub-microsecond level, while avoiding the problem of configuration loss due to power failure in traditional storage media. The high-density characteristic of the memristive programmable logic array ensures that future new action bits can still be mapped within a single chip, and provides a reliable hardware guarantee of "write once, available after power failure" for the SIS, greatly improving the immediacy and disaster tolerance of petrochemical fire protection interlock control.

[0105] The execution and feedback unit is used to control the fire extinguishing medium release device, the robot detachment, and the thermal shielding device according to the interlock instruction stream, perform positioning and path planning in combination with the attitude matrix data, collect the execution status to form feedback data, and return it to the prediction and risk assessment unit and the interlock control unit to complete closed-loop self-correction.

[0106] The execution and feedback unit is located at the end of the SIS, responsible for converting the interlock instruction stream into observable actions on-site, and returning the actual execution results of the actions to the upper-layer model in the form of data frames to form a closed-loop self-correction of prediction - decision - execution. This unit consists of four parts: the fire extinguishing medium release device, the robot cooperation module, the thermal shielding deployment mechanism, and the feedback acquisition chain. The working principle, key implementation details, and application effects are described below in sequence.

[0107] The fire extinguishing medium release device adopts a two-phase flow supercritical jet process. The device stores a mixture of carbon dioxide and phase change aerogel under normal pressure. After receiving the interlock instruction, the high-pressure pump boosts the mixture to the supercritical region, and then it is ejected through a pulsed throttle valve to form a high-speed cooling plume, achieving dual fire suppression of cooling and asphyxiation. The drive signal of the throttle valve comes from the valve position action bit in the interlock instruction stream, and the flow sensor inside the device measures the injection mass flow rate in real time, constituting the primary feedback.

[0108] The robot cooperation module distributes the path-related instructions involved in the minimum action set to the quadruped-track hybrid robot detachment. To ensure that the robot can still move safely in the high-temperature and low visibility environment of the fire field, the system adopts the resonance constraint variational path optimization method. The path optimization is based on the world coordinate system provided by the attitude matrix data, takes the potential energy value in the propagation potential energy matrix as the path energy weight, and finds the minimum value on the energy functional:

[0109] to obtain the resonance safe path. Where is the time the position vector of the robot in the world coordinate system at time, is the velocity vector, is the propagation potential energy function, The trajectory points are sent to the robot controller after differentiation, and the robot's built-in inertial measurement unit and temperature and humidity sensor transmit the execution error and ambient temperature back to the feedback chain.

[0110] The heat shield deployment mechanism consists of a reconfigurable metamaterial fire extinguishing film and a shape memory alloy reel. When the heat shield deployment position in the interlocking command is set, the reel is powered on and heated, and the alloy quickly stretches and stretches the metamaterial film to cover the key valve group. After the deployment is completed, the optical fiber temperature measurement point and strain gauge in the mechanism simultaneously collect the film surface temperature and strain data, verify the integrity of the film layer and feed it back to the upper layer.

[0111] The feedback collection chain uses the event stream format to encapsulate all execution states. Each feedback frame contains four fields: valve position opening percentage, injection flow, actual robot path point sequence, membrane temperature and strain, with a microsecond precision timestamp. To reduce bandwidth usage, path points are stored using spline compression, and only key points with curvature changes greater than the threshold are retained. The feedback frame is returned to the prediction and risk assessment unit via the real-time data channel to update the node status and recalculate the propagation potential; it is also sent to the interlocking control unit to compare the action position with the execution result. If the execution deviation is found to exceed the threshold, the incremental solution supplementary action is immediately triggered.

[0112] Example 1: In the drill of methanol spray combustion in the bottom pump area of ​​the crude oil tank, the interlock control unit issued ten actions. The execution and feedback unit completed the supercritical injection of carbon dioxide within 500 milliseconds, and confirmed through the flow sensor that the injection volume reached 98% of the command value. The robot team arrived at the east side of the tank wall and the north side of the pump station at the same time along the resonant safety path, and the maximum deviation between the actual path and the planned path was eleven centimeters. After the heat shielding film was unfolded, the temperature of the membrane surface decreased by 200 degrees Celsius. The feedback frame showed that all action bits met the execution threshold, and the interlock control unit did not need to add any additional actions.

[0113] Example 2: During the freezing test of the breathing valve on the top of a liquefied petroleum gas tank, the robot deviated from the planned trajectory by thirty-five centimeters due to vibration. After the feedback frame was returned, the interlocking control unit re-solved the complementary action and instructed another robot to take over the spraying. At the same time, the original robot path was re-planned, and the entire set of complementary actions was sent to the execution and feedback unit. The total delay did not exceed the functional safety requirements.

[0114] Through the linkage of high-speed injection, path resonance planning and metamaterial thermal protection, combined with millisecond-level feedback loops, the execution and feedback unit enables SIS to obtain real-time correction capabilities, taking into account both action accuracy and job safety in the high-risk environment of the petroleum and petrochemical industry, and providing a reliable execution closed loop for the entire fire interlock system.

[0115] Preferably, the execution and feedback unit mixes carbon dioxide and phase change aerogel through a two-phase flow injection device to form a supercritical mixed medium, and after receiving the interlock instruction flow data, the execution and feedback unit drives the throttle valve group to inject the supercritical mixed medium in a pulsed manner for cooling and smothering fire extinguishing.

[0116] The two-phase flow injection device in the execution and feedback unit undertakes dual fire extinguishing of rapid cooling and smothering, and its working process can be divided into five stages: mixing, pressurization, pulsed throttling, jet mass transfer and feedback. The device is equipped with a carbon dioxide high-pressure tank and a phase change aerogel silo, and the two-way materials are homogenized in a static mixer with a mass fraction After mixing, it is boosted to a pressure higher than the critical pressure by a plunger pump, and the temperature control jacket maintains the fluid temperature higher than the critical temperature, thereby forming a supercritical mixed medium. The density of the supercritical medium is close to that of a liquid while the diffusion coefficient is close to that of a gas. It has both high mass-carrying capacity and is easy to diffuse rapidly, suitable for passing through complex obstacles and transferring cold.

[0117] Pulsed throttling is the key to the fire extinguishing effect. An electric throttle valve group is arranged at the end of the injection pipeline, and the valve group executes opening and closing according to the pulse sequence in the interlock instruction flow. The valve opening function is denoted as , the pulse width is , the pulse amplitude is , and the rising edge and falling edge are controlled by the servo drive module. Throttling causes an instant drop in pressure, and the supercritical medium rapidly expands and cools itself in the nozzle. Carbon dioxide absorbs environmental heat to complete the reverse Joule-Thomson effect, and the aerogel particles absorb heat and undergo a phase change during this process. The cooling release per unit mass can be expressed as:

[0118] In the formula is the cooling capacity, is the mass of carbon dioxide, is the isothermal enthalpy change of carbon dioxide's Joule-Thomson effect, is the mass of aerogel, is the solid-liquid phase change latent heat of aerogel. Carbon dioxide can also block the combustion chain in an environment with an oxygen concentration below 12%, thus complementing the cooling effect.

[0119] After the injection plume enters the flame core, it first reduces the fuel vapor temperature, causing the reaction rate constant to decrease; then the carbon dioxide concentration rises to displace air, and the oxygen content drops below the combustion limit to achieve smothering. The aerogel forms a porous network during the phase change process and adheres to the hot surface to further inhibit heat feedback. The injection device measures the outlet flow rate with a Pitot probe, measures the flow rate with a mass flow meter, and measures the pressure in front of the valve with a pressure transmitter. The three-way data together with the valve position coding form an execution feedback frame, and the frame body contains fields such as timestamp, pulse number, pressure, flow rate and flow velocity.

[0120] The interlocking instruction stream is transmitted to the valve group driver through a single-mode optical fiber, and the driver switches the valve according to the action bit in the instruction frame. If the valve does not reach the target opening or the sensor reading deviates from the threshold, the device will automatically adjust the pulse amplitude or width in the next cycle and write the correction information into the feedback frame. After receiving the feedback, the prediction and risk assessment unit updates the node temperature and oxygen concentration, and then recalculates the propagation potential matrix. If the dangerous potential is still higher than the safety value, the interlocking control unit will add an action or extend the pulse sequence to form a closed-loop self-correction.

[0121] Example 1: Ignition at the bottom flange of a 30,000 cubic meter crude oil tank, with the injection device six meters away from the fire point. Eighty milliseconds after the interlocking command is issued, the valve group starts to execute the pulse sequence, with the first pulse width of twenty milliseconds and an amplitude of 100% opening; the temperature of the injection plume outlet drops to minus forty-five degrees Celsius. Two seconds later, the flame temperature is four hundred degrees Celsius lower than the non-injection control, the oxygen content drops to 11%, and the flame automatically extinguishes. The feedback frame records an average mass flow of two hundred and fifty grams per second, and the valve opening error is less than 5%. The risk potential matrix decreases to less than 10% of the initial value, and the system does not trigger the compensation action.

[0122] Example 2: Simulating a LPG spray fire on an oil unloading pier. Due to the drift of the plume caused by the sea breeze, the first round of injection did not fully cover the area. The feedback frame detected that the flow rate was 30% higher than the set value, and the pressure after the valve was determined to be fluctuating. The interlock control unit added two pulse instructions, and the amplitude was reduced to 70% to increase the plume angle. After the third round of injection, the flame extinguished and did not reignite. The whole process took 3.2 seconds, and the injection quality was saved by 42% compared with the fixed flow solution.

[0123] Through the use of supercritical physical properties, pulse throttling control and real-time feedback, the two-phase flow injection device takes into account the dual effects of cooling and hypoxia in a very short time, providing SIS with strong and stable fire-fighting execution capabilities at oil and gas fire scenes, and also providing reliable on-site data for closed-loop model updates.

[0124] Preferably, after receiving the interlocking instruction stream data, the execution and feedback unit generates a robot path using a variational path optimization method based on the propagation potential energy data and the risk entropy data. The robot path is determined by minimizing the path energy and the hazard potential energy line integral. The execution and feedback unit controls the robot team to move along the robot path and perform on-site disposal tasks. At the same time, the valve position feedback data and robot status data are collected and encapsulated into an event stream format. The event stream format is written into the event stream through the perception fusion unit for the prediction and risk assessment unit and the interlocking control unit to perform model updates and action corrections.

[0125] The robot collaboration module in the execution and feedback unit is responsible for converting the action bits given by the interlock control unit into a ground movement path, and continuously transmitting the valve position and its own status during the movement, providing a quantifiable execution error for the SIS closed loop. This module couples path planning with a dangerous potential energy field by means of a variational path optimization method, enabling the robot to avoid high-temperature, high-pressure, and combustible gas cloud areas to the greatest extent while completing on-site tasks such as exploration, explosion suppression, or supplementing agents; when high-risk areas cannot be avoided, the algorithm will automatically increase the penalty weight for the dangerous potential energy in the energy functional, prompting the robot to cross through with the shortest residence time, thereby reducing the risk of self-damage and secondary ignition.

[0126] First, the execution and feedback unit reads the robot action bits in the interlock instruction stream; at the same time, it obtains the latest propagation potential energy data and risk entropy data in the local cache. The propagation potential energy data is stored in the form of a three-dimensional grid, and each voxel contains the weighted result of the temperature gradient, combustible concentration gradient, and shock wave pressure gradient, which can be regarded as a potential energy density function. The risk entropy data is a concentrated measure of the overall dangerous path distribution and is used to adjust the potential energy weight in path optimization. Before real-time solution, the unit calculates the weight coefficient according to the magnitude of the risk entropy. The higher the risk entropy, the more dispersed the dangerous chain is. The value increases accordingly, forcing the path to pay more attention to avoiding high-potential areas; when the risk entropy is low and the danger is concentrated, decreases, and the robot can perform key operations in local high-potential areas without having to detour. The path optimization objective function is written as an energy functional:

[0127] Find the minimum value above to obtain the resonance safety path. Among them, is the time The position vector of the robot in the world coordinate system at time, is the velocity vector, is the propagation potential energy function, is the weight factor. The first term measures the motion power consumption, and the second term measures the cumulative dangerous exposure. The execution and feedback unit uses the variational method to find the minimum of the function Use discrete grid points to transform the continuous trajectory into 128-segment broken lines, and then use the limited memory quasi-Newton algorithm to converge within 50 iterations. In a typical scenario, the single solution takes 3.5 milliseconds, meeting the requirement of the oil and petrochemical site for the interlock closed loop to be less than 50 milliseconds.

[0128] After obtaining the robot path, the module generates a speed profile according to the key points of the trajectory and distributes it to the robot detachment. The robot detachment is a mixed formation of quadruped platforms and tracked platforms. The quadruped platforms are responsible for crossing obstacles such as cable trenches and pipe piers. The tracked platforms have a high load capacity and are used to carry dry powder explosion suppression or inerting agent replenishment. The two types of platforms share the path, but there are differences in the speed profile: the quadruped platforms have a greater weight on curvature, and the tracked platforms have a greater weight on energy consumption. To ensure that multiple robots do not cross paths in the narrow tank wall passage, the execution and feedback unit uses node-level locks for management. When each path segment is occupied, other robots need to wait or detour to the nearest alternative trajectory.

[0129] During the execution process, the robot collects its own attitude, joint current, surface temperature, and air flammable concentration every fifty milliseconds, and then packages them together with the valve position encoder readings and flowmeter readings into an event stream format. The event stream format uses a key-value pair structure, where the key is the sensor identifier and the value is the measurement data; the events are sorted by a one-microsecond timestamp, which is convenient for the upstream prediction and risk assessment unit to compare the predicted states at the same moment. If the deviation between the robot path and the planned path exceeds twenty centimeters or the valve position opening is less than 95% of the target value, the module will add an anomaly mark to the event stream and broadcast it immediately. After receiving the anomaly, the interlock control unit can choose to append actions or re-solve, otherwise it will wait in a loop for the next frame of feedback.

[0130] Example 1: In a 1:1 fire drill in the crude oil pump area, the leakage point is located in the middle of the pump row. The prediction and risk assessment unit calculates that the envelope of the high potential energy area covers three pumps. The risk entropy is 0.72, and the execution and feedback unit calculates the weight coefficient as 0.45. After variational path solution, the robot path crosses the back side of the pump row and only stays in the high potential energy area for 0.3 seconds to complete spray ignition suppression. After comparison, the peak surface temperature of the robot is lower than 80 degrees Celsius, and it is still within the sustainable working temperature range after the task is completed.

[0131] Example 2: The overpressure of the liquefied petroleum gas spherical tank top, the risk entropy is 0.35. The weight coefficient is reduced to 0.25. The robot path is allowed to go directly to the top from the tank wall ladder and stay in the high potential energy area around the safety valve for 1 second to complete spray precooling. The trajectory energy increases by 15%, but the dangerous exposure integral is controlled within an acceptable range. The valve position feedback data verifies that the safety valve opens smoothly. The peak temperature of the robot is 95 degrees Celsius, and it does not trigger thermal protection shutdown.

[0132] Through variational path optimization and event stream feedback, the execution and feedback unit ensures that the robot detachment completes on-site disposal with the minimum dangerous exposure and transmits the real execution deviation back to the upstream model in real time. This closed-loop provides the SIS with sustainable self-correction ability, enabling prediction, decision-making, and execution to maintain consistency and high reliability in the changing environment of petrochemical industry.

[0133] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various modifications and variations can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. An interlock control device for oil and petrochemical fire protection based on SIS, characterized in that, Including: A perception fusion unit, which is used to collect multi-source data including at least an optical fiber sensor and a radar sensor, synchronize and fuse the collected data, output fusion feature data and attitude matrix data, send the fusion feature data to the prediction and risk assessment unit, and send the attitude matrix data to the execution and feedback unit; A prediction and risk assessment unit, which is used to establish a spatio-temporal model based on the fusion feature data to generate disaster prediction data and propagation potential energy data, calculate risk entropy data, and send the disaster prediction data, propagation potential energy data and risk entropy data to the interlock control unit; An interlock control unit, which is used to construct an optimization model based on the fusion feature data, propagation potential energy data and risk entropy data, obtain minimum action set data through an optimization solver, write it into a programmable logic array, and then output an interlock instruction stream to trigger SIS interlock actions; An execution and feedback unit, which is used to control a fire extinguishing medium release device, a robot detachment and a heat shield device according to the interlock instruction stream, perform positioning and path planning in combination with the attitude matrix data, collect execution status to form feedback data, and return it to the prediction and risk assessment unit and the interlock control unit to complete closed-loop self-correction.

2. The device according to claim 1, wherein The perception fusion unit obtains Brillouin scattering frequency shift through a distributed optical fiber sensor and demodulates the Brillouin scattering frequency shift into temperature information and strain information. It emits a frequency-modulated continuous wave through a millimeter-wave radar sensor and performs a fast Fourier transform on the echo to obtain point cloud information. It converts an acoustic signal into an electrical signal through an acoustic crystal sensor and performs a short-time Fourier transform to obtain acoustic spectrum information. It records a grayscale change event stream through an event camera and outputs event stream information. It synchronously obtains visible light image information and infrared image information through a dual-band camera. After aligning the timestamps of the above temperature information, strain information, point cloud information, acoustic spectrum information, event stream information, and dual-band image information, the perception fusion unit uses a gated sparse tensor fusion method to output fusion feature data and attitude matrix data.

3. The device according to claim 2, characterized in that, When performing gated sparse tensor fusion, the perception fusion unit sets a gated weight tensor, and the element values of the gated weight tensor are between zero and one. The perception fusion unit performs weighted parallel multiplication and addition operations on the tensors of each perception channel according to the gated weight tensor to reduce the redundant feature dimension and improve the sparsity of feature representation.

4. The device according to claim 1, characterized in that, The prediction and risk assessment unit adopts a spatio-temporal model based on a graph neural network, maps the fusion feature data into graph structure node features and edge features, uses a multi-head attention mechanism to propagate messages between nodes, and iteratively updates the node representation within a fixed number of time steps to output disaster prediction data and propagation potential energy data.

5. The device according to claim 4, characterized in that, The prediction and risk assessment unit uses a generative adversarial correction method to generate a perturbation tensor, superimposes the perturbation tensor on the disaster prediction data and inputs it into a discriminant network. After the discriminant network outputs a confidence level, it updates the parameters of the generative network. The prediction and risk assessment unit calculates risk entropy data based on the corrected disaster prediction data, and the risk entropy data measures the system hazard uncertainty through logarithmic probability summation.

6. The device according to claim 1, characterized in that, The interlock control unit constructs a binary unconstrained optimization model based on the fusion feature data, propagation potential energy data, and risk entropy data. The objective function of the optimization model consists of a linear combination of minimizing the number of actions and minimizing the dangerous potential energy. The interlock control unit maps the Boolean variables in the optimization model into a binary unconstrained optimization matrix and inputs it into the quantum annealing solver.

7. The device according to claim 6, characterized in that, After the quantum annealing solver outputs a Boolean vector, the interlock control unit introduces a minimax game strategy to perform three rounds of strategy corrections on the Boolean vector. Each round of strategy correction uses the difference in dangerous potential energy as the payoff function. After completing the strategy corrections, the interlock control unit determines the minimum action set data.

8. The device according to claim 1, characterized in that, The interlock control unit writes the minimum action set data into the memristive programmable logic array. The cross-wire voltage of the memristive programmable logic array is set by the interlock control unit to a first high level and a second low level. The first high level is used to indicate that the action bit is one, and the second low level is used to indicate that the action bit is zero.

9. The device according to claim 1, characterized in that, The execution and feedback unit mixes carbon dioxide and phase change aerogel through a two-phase flow injection device to form a supercritical mixed medium. After receiving the interlock instruction stream data, the execution and feedback unit drives the throttle valve group to inject the supercritical mixed medium in a pulsed manner for cooling and smothering fires.

10. The device according to claim 1, characterized in that, After receiving the interlock instruction stream data, the execution and feedback unit generates a robot path using the variational path optimization method based on the propagation potential energy data and risk entropy data. The robot path is determined by minimizing the path energy and the line integral of the dangerous potential energy. The execution and feedback unit controls the robot detachment to move along the robot path and perform on-site disposal tasks. At the same time, it collects valve position feedback data and robot status data and encapsulates them into an event stream format. The event stream format is written into the event stream through the perception fusion unit for the prediction and risk assessment unit and the interlock control unit to update the model and correct actions.

Citation Information

Patent Citations

  • Fire extinguishing system of charging station and optimization method

    CN118491019A

  • Intelligent fire early warning system and method for electric bicycle charging and parking place

    CN119007382A

  • Fire-fighting linkage control device for petroleum and petrochemical engineering

    CN119607486A

  • An intelligent control system for fire safety management

    CN119782713A

  • Intelligent monitoring method and system based on fall risk early warning

    CN120032474A

Cited By

  • Fire detection method and system based on binocular vision and ultraviolet

    CN120852809A