Anomaly detection method and device of power grid system, computer equipment, readable storage medium and program product
By extracting multi-time scale sequence data and multi-modal features of the power grid system, and combining multi-scale and multi-modal data for abnormal detection, the problem of difficulty in analyzing different time scales and multi-modal data fusion is solved, and the accuracy and reliability of abnormal detection of power grid system are improved.
Patent Information
- Application Number
- CN202510349197.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-27
AI Technical Summary
The abnormality detection method of traditional power grid systems is difficult to analyze abnormalities on different time scales at the same time, and it is difficult to achieve efficient fusion of multimodal data, affecting the accuracy and reliability of abnormality detection in power grid systems.
By obtaining multimodal data of the power grid system, the statistical features and frequency band features of multi-time scale sequence data are extracted, and inputting them into the abnormality detection model corresponding to each time scale, combining multi-scale and multi-modal data for abnormality detection, and finally calculating the abnormality score based on the reconstruction error to determine whether an abnormal alarm is issued.
It realizes the identification of abnormalities in the power grid system on different time scales, improves the accuracy and reliability of abnormal detection of the power grid system, makes full use of multimodal data for abnormal detection and analysis, and reduces the possibility of missed and false alarms.
Smart Images

Figure CN120217243A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of power systems, and particularly to an abnormal detection method, device, computer device, computer-readable storage medium, and computer program product for a power grid system. Background Art
[0002] With the expansion of the scale of the power grid and the increase in power demand, the power grid system has become increasingly complex. Abnormal fluctuations in the power grid system may be caused by equipment aging, environmental changes, load fluctuations, or other external factors. If not detected and processed in a timely manner, it may lead to serious power outages and affect the safety and stability of the power grid system. Therefore, the abnormal detection of the power grid system has become particularly important.
[0003] Most traditional abnormal detection methods for power grid systems perform abnormal detection on single data sources or single-time scale data, making it difficult to analyze abnormalities on different time scales simultaneously, such as short-term sudden fluctuations and long-term trend changes. Therefore, certain types of abnormalities may be missed or misreported. In addition, the data involved in the operation of the power grid system is diverse, including both electrical signal data and environmental data. Traditional abnormal detection methods for power grid systems are difficult to achieve efficient fusion of multi-modal data, thus unable to fully utilize multi-modal data for abnormal detection analysis, affecting the accuracy and reliability of abnormal detection of the power grid system. Summary of the Invention
[0004] Based on this, it is necessary to provide an abnormal detection method, device, computer device, computer-readable storage medium, and computer program product for a power grid system to address the above technical problems.
[0005] In a first aspect, the present application provides an abnormal detection method for a power grid system, including:
[0006] Obtaining multi-time scale sequence data corresponding to multi-time scale abnormal change indicators of the power grid system according to multi-modal data of the power grid system;
[0007] Performing feature extraction on the multi-time scale sequence data to obtain statistical features and frequency band features of the multi-time scale sequence data;
[0008] Inputting the statistical features and frequency band features of the multi-time scale sequence data into the abnormal detection models corresponding to each time scale in sequence to obtain single-scale abnormal detection results corresponding to each time scale;
[0009] Obtaining a multi-scale abnormal detection result of the power grid system according to the single-time scale abnormal detection results corresponding to each time scale and the weights corresponding to the abnormal detection models corresponding to each time scale;
[0010] Determine multimodal abnormal data according to the multi-scale anomaly detection results;
[0011] Obtain an anomaly score based on the reconstruction error of the multimodal abnormal data to determine whether to issue an anomaly alarm.
[0012] In one embodiment, before obtaining the multi-time scale sequence data corresponding to the multi-time scale anomaly indicators of the power grid system according to the multimodal data of the power grid system, the method further includes:
[0013] Obtain the multimodal initial data of the power grid system;
[0014] Use the wavelet decomposition method to decompose the multimodal initial data to obtain multimodal high-frequency data and multimodal low-frequency data;
[0015] Filter and denoise the multimodal high-frequency data to obtain the filtered multimodal high-frequency data;
[0016] Perform missing value filling, normalization, and standardization processing on the filtered multimodal high-frequency data and multimodal low-frequency data to obtain the multimodal data of the power grid system.
[0017] In one embodiment, the extracting the statistical features and frequency band features of the multi-time scale sequence data from the multi-time scale sequence data includes:
[0018] Extract the mean, variance, skewness, and kurtosis of the multi-time scale sequence data as the statistical features of the multi-time scale sequence data;
[0019] Decompose the multi-time scale sequence data into features of different frequency bands through wavelet decomposition to obtain the frequency band features of the multi-time scale sequence data.
[0020] In one embodiment, the obtaining an anomaly score based on the reconstruction error of the multimodal abnormal data to determine whether to issue an anomaly alarm includes:
[0021] Calculate the attention scores of the abnormal data of each modality according to the self-attention mechanism to perform dynamic weight allocation on the abnormal data of each modality, and obtain the weights corresponding to the abnormal data of each modality;
[0022] Obtain the modality fusion data according to the abnormal data of each modality and the weights corresponding to the abnormal data of each modality;
[0023] Reconstruct the modality fusion data through an autoencoder to obtain the reconstruction error of the multimodal abnormal data;
[0024] Obtain an anomaly score according to the reconstruction error of the multimodal abnormal data;
[0025] When the abnormal score exceeds a preset threshold, an abnormal alarm is issued.
[0026] In one embodiment, after the abnormal alarm is issued, the method further includes:
[0027] Obtaining the current corresponding relationship between the level of the abnormal score and the response strategy;
[0028] Determining a response strategy according to the level of the abnormal score and the current corresponding relationship between the level of the abnormal score and the response strategy.
[0029] In one embodiment, the obtaining the current corresponding relationship between the level of the abnormal score and the response strategy includes:
[0030] Obtaining the previous corresponding relationship between the level of the abnormal score and the response strategy;
[0031] Obtaining the actual execution situation of the previous response strategy;
[0032] Optimizing the corresponding relationship between the level of the abnormal score and the response strategy according to the actual execution situation of the previous response strategy and the deep Q-network model, to obtain the current corresponding relationship between the level of the abnormal score and the response strategy.
[0033] In a second aspect, the present application further provides an abnormal detection device for a power grid system, including:
[0034] A sequence data acquisition module, configured to obtain multi-time scale sequence data corresponding to multi-time scale abnormal change indicators of the power grid system according to multi-modal data of the power grid system;
[0035] A feature extraction module, configured to perform feature extraction on the multi-time scale sequence data to obtain statistical features and frequency band features of the multi-time scale sequence data;
[0036] A single-scale result acquisition module, configured to sequentially input the statistical features and frequency band features of the multi-time scale sequence data into abnormal detection models corresponding to each time scale, to obtain single-scale abnormal detection results corresponding to each time scale;
[0037] A multi-scale abnormal detection result acquisition module, configured to obtain a multi-scale abnormal detection result of the power grid system according to the single-time scale abnormal detection results corresponding to each time scale and the weights corresponding to the abnormal detection models corresponding to each time scale;
[0038] A multi-modal abnormal data determination module, configured to determine multi-modal abnormal data according to the multi-scale abnormal detection result;
[0039] An abnormal alarm issuing judgment module, configured to obtain an abnormality score according to the reconstruction error of the multi-modal abnormal data, so as to judge whether to issue an abnormal alarm.
[0040] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and the processor executes the above method.
[0041] In a fourth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, and the computer program is executed by a processor to execute the above method.
[0042] In a fifth aspect, the present application further provides a computer program product. The computer program product includes a computer program, and the computer program is executed by a processor to execute the above method.
[0043] For the above abnormal detection method, device, computer device, computer-readable storage medium and computer program product of the power grid system, multi-time scale sequence data corresponding to multi-time scale abnormal indexes of the power grid system are obtained according to the multi-modal data of the power grid system; feature extraction is performed on the multi-time scale sequence data to obtain statistical features and frequency band features of the multi-time scale sequence data; the statistical features and frequency band features of the multi-time scale sequence data are sequentially input into the abnormal detection models corresponding to each time scale to obtain single-scale abnormal detection results corresponding to each time scale; according to the single-time scale abnormal detection results corresponding to each time scale and the weights corresponding to the abnormal detection models corresponding to each time scale, a multi-scale abnormal detection result of the power grid system is obtained; multi-modal abnormal data is determined according to the multi-scale abnormal detection result; an abnormality score is obtained according to the reconstruction error of the multi-modal abnormal data, so as to judge whether to issue an abnormal alarm. According to the multi-time scale sequence data and the abnormal detection models corresponding to each time scale, the present application obtains a multi-scale abnormal detection result, which can identify abnormalities in the power grid system at different time scales, improving the accuracy and reliability of abnormal detection in the power grid system; on the basis of the multi-scale abnormal detection result, multi-modal abnormal data is determined; an abnormality score is obtained according to the reconstruction error of the multi-modal abnormal data, so as to judge whether to issue an abnormal alarm, making full use of multi-modal data for abnormal detection analysis, reducing the possibility of missed alarms and false alarms, and further improving the accuracy and reliability of abnormal detection in the power grid system. Description of the Drawings
[0044] To more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the accompanying drawings required for the description in the embodiments of the present application or the related art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related accompanying drawings can be obtained based on these drawings.
[0045] Figure 1 It is an application environment diagram of an abnormal detection method for a power grid system in an embodiment;
[0046] Figure 2 It is a schematic flowchart of an abnormal detection method for a power grid system in an embodiment;
[0047] Figure 3 It is a schematic flowchart of determining whether to issue an abnormal alarm in an embodiment;
[0048] Figure 4 It is a structural block diagram of an abnormal detection device for a power grid system in an embodiment;
[0049] Figure 5 It is an internal structure diagram of a computer device in an embodiment. Specific embodiments
[0050] In order to make the purpose, technical solutions and advantages of the present application more clear, the following further details the present application in combination with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0051] The embodiments of the present application provide an abnormal detection method for a power grid system. This embodiment can be executed by a computer device. As Figure 1 shown, the computer device can obtain multi-modal data of the power grid system, and then detect whether the power grid system is abnormal. It can be understood that the computer device can be implemented through a server, or through a terminal, or through an interaction system between the terminal and the server. In this embodiment, the method includes Figure 2 the steps shown:
[0052] Step S201, obtaining multi-time scale sequence data corresponding to multi-time scale abnormal movement indicators of the power grid system according to the multi-modal data of the power grid system.
[0053] The multi-modal data of the power grid system may include the voltage, current, power and environmental data of the power grid system.
[0054] According to the actual situation, a multi-time scale anomaly index system of the power grid system can be constructed to capture the short-term, medium-term and long-term dynamic characteristics of the power grid system. For example, a multi-time scale anomaly index system at the second level, minute level and daily level can be constructed. The multi-time scale anomaly index can include the instantaneous current peak index at the second level, the load volatility index at the minute level, and the power consumption trend index at the daily level.
[0055] Based on the multi-modal data of the power grid system, the multi-time scale sequence data corresponding to the multi-time scale anomaly index of the power grid system can be obtained.
[0056] Exemplarily, based on the multi-modal data of the power grid system, the time scale sequence data corresponding to the instantaneous current peak index of the power grid system, the time scale sequence data corresponding to the load volatility index, and the time scale sequence data corresponding to the power consumption trend index can be obtained.
[0057] Step S202: Extract features from the multi-time scale sequence data to obtain the statistical features and frequency band features of the multi-time scale sequence data.
[0058] Features can be extracted from the multi-time scale sequence data to obtain the statistical features and frequency band features of the multi-time scale sequence data, so as to identify the main distribution characteristics of the multi-time scale sequence data and adapt to the feature analysis requirements of different time scales.
[0059] Step S203: Input the statistical features and frequency band features of the multi-time scale sequence data into the anomaly detection models corresponding to each time scale in turn to obtain the single-scale anomaly detection results corresponding to each time scale.
[0060] The statistical features and frequency band features of the multi-time scale sequence data can be input into the anomaly detection models corresponding to each time scale in turn to obtain the single-scale anomaly detection results of the anomaly detection models corresponding to the same time scale for the statistical features and frequency band features of the time scale sequence data.
[0061] Exemplarily, the time scales can include the second level, minute level and daily level. The anomaly detection models corresponding to each time scale are the long short-term memory (LSTM) model at the second level, the gated recurrent unit (GRU) model at the minute level, and the transformer model at the daily level.
[0062] The time scale sequence data corresponding to the instantaneous current peak index can be input into the long short-term memory network model at the second level, the gated recurrent unit model at the minute level, and the transformer model at the daily level in turn to obtain the single-scale anomaly detection results corresponding to the second level, the single-scale anomaly detection results corresponding to the minute level, and the single-scale anomaly detection results corresponding to the daily level.
[0063] Specifically, the second-level long short-term memory network model is used to capture short-term fluctuations in the power grid system and detect sudden anomalies. In the second-level long short-term memory network model, the input time-scale sequence data obtains the hidden state and the memory state through the following several calculation steps:
[0064]
[0065] where f t is the forget gate, is the input gate, is the output gate; , , and are weight matrices, , , and are bias terms; represents the sigmoid activation function, represents the element-wise product; the output of this second-level long short-term memory network model is regarded as the single-scale anomaly detection result corresponding to the second level.
[0066] The minute-level gated recurrent unit model is used to detect the load changes and medium-term anomalies of power grid equipment in the power grid system. The calculation process is as follows:
[0067]
[0068]
[0069]
[0070] where is the update gate, which is used to control the influence of the previous moment state on the current state; is the reset gate, which is used to control the influence of the current input on the current state; , and are weight matrices, , , are bias terms. Through the minute-level gated recurrent unit model, the short-term fluctuation characteristics of the power grid load can be better identified.
[0071] The daily-level converter model analyzes the long-term trends of the power grid system through the self-attention mechanism and detects long-term anomalies. The self-attention mechanism in the daily-level converter model is calculated by the following formula:
[0072]
[0073] In the formula, is the query matrix, is the key matrix, is the value matrix; is the dimension of the key vector, which is used to scale the dot product to prevent the numerical value from being too large; is used to normalize the calculation of the attention weight.
[0074] Through the self-attention mechanism, the daily-level converter model can capture the long-term dependencies between different time steps, so as to identify the long-term trends and anomalies in the power grid system.
[0075] Step S204: Obtain the multi-scale anomaly detection result of the power grid system according to the single-scale anomaly detection results corresponding to each time scale and the weights corresponding to the anomaly detection models corresponding to each time scale.
[0076] The weights corresponding to the anomaly detection models corresponding to each time scale can be obtained based on the detection accuracy, time scale characteristics or set initial weight values of the anomaly detection models corresponding to each time scale.
[0077] Based on the adaptive weight allocation mechanism, the weights corresponding to the anomaly detection models corresponding to each time scale can be dynamically adjusted according to the real-time state of the power grid system, the anomaly scores of the anomaly detection models corresponding to each time scale or the time series change trend.
[0078] The multi-scale anomaly detection result of the power grid system can be obtained according to the sum of the products of the single-scale anomaly detection results corresponding to each time scale and the weights corresponding to the anomaly detection models corresponding to each time scale.
[0079] Step S205: Determine the multi-modal anomaly data according to the multi-scale anomaly detection result.
[0080] When the multi-scale anomaly detection result indicates that there is an anomaly in the power grid system, determine the multi-modal data of the power grid system used to obtain the multi-scale anomaly detection result as the multi-modal anomaly data.
[0081] Step S206: Obtain the anomaly score according to the reconstruction error of the multi-modal anomaly data to judge whether to issue an anomaly alarm.
[0082] Multimodal anomaly data can be used to obtain modality fusion data; the modality fusion data can be compressed and encoded by an autoencoder to obtain the reconstructed data of the modality fusion data, and the reconstruction error of the multimodal anomaly data can be obtained based on the error between the modality fusion data and the reconstructed data of the modality fusion data. An anomaly score can be obtained based on the reconstruction error of the multimodal anomaly data. When the anomaly score exceeds a preset threshold, an anomaly alarm is issued; when the anomaly score does not exceed the preset threshold, no anomaly alarm is issued.
[0083] In the above-mentioned anomaly detection method for the power grid system, based on the multi-time scale sequence data and the anomaly detection models corresponding to each time scale, multi-scale anomaly detection results can be obtained, enabling the identification of anomalies in the power grid system at different time scales, thereby improving the accuracy and reliability of anomaly detection in the power grid system. Based on the multi-scale anomaly detection results, multimodal anomaly data is determined; an anomaly score is obtained based on the reconstruction error of the multimodal anomaly data to determine whether to issue an anomaly alarm, making full use of multimodal data for anomaly detection analysis, reducing the possibility of missed alarms and false alarms, and further improving the accuracy and reliability of anomaly detection in the power grid system.
[0084] In one embodiment, before obtaining the multi-time scale sequence data corresponding to the multi-time scale anomaly indicators of the power grid system based on the multimodal data of the power grid system, the method provided in this application further includes: acquiring the multimodal initial data of the power grid system; using the wavelet decomposition method to decompose the multimodal initial data to obtain multimodal high-frequency data and multimodal low-frequency data; filtering and denoising the multimodal high-frequency data to obtain the filtered multimodal high-frequency data; performing missing value filling, normalization, and standardization processing on the filtered multimodal high-frequency data and multimodal low-frequency data to obtain the multimodal data of the power grid system.
[0085] The wavelet decomposition method can be used to decompose the multimodal initial data to obtain multimodal high-frequency data and multimodal low-frequency data; the multimodal high-frequency data can be filtered and denoised to obtain the filtered multimodal high-frequency data, and the main information of the multimodal high-frequency data can be retained.
[0086] The missing values of the filtered multimodal high-frequency data and multimodal low-frequency data can be filled by interpolation methods or deep learning methods based on gated recurrent units to improve the integrity of the multimodal data.
[0087] The filtered multimodal high-frequency data and multimodal low-frequency data can be normalized and standardized to ensure the scale consistency of the multimodal data and the comparability of features.
[0088] In this embodiment, the multi-modal initial data is decomposed to obtain multi-modal high-frequency data and multi-modal low-frequency data; the multi-modal high-frequency data is filtered and denoised to obtain the filtered multi-modal high-frequency data; the filtered multi-modal high-frequency data and the multi-modal low-frequency data are subjected to missing value filling, normalization, and standardization processing to obtain the multi-modal data of the power grid system, which can ensure the integrity, scale consistency, and feature comparability of the multi-modal data.
[0089] In one embodiment, feature extraction is performed on the multi-time scale sequence data to obtain the statistical features and frequency band features of the multi-time scale sequence data. The specific steps are as follows: the mean, variance, skewness, and kurtosis of the multi-time scale sequence data are extracted as the statistical features of the multi-time scale sequence data; through wavelet decomposition, the multi-time scale sequence data is decomposed into features of different frequency bands to obtain the frequency band features of the multi-time scale sequence data.
[0090] The multi-time scale sequence data represents multiple time scale sequence data. For example, the multi-time scale sequence data may include second-level time scale sequence data, minute-level time scale sequence data, and daily-level time scale sequence data.
[0091] Exemplarily, the mean, variance, skewness, and kurtosis of the second-level time scale sequence data, minute-level time scale sequence data, and daily-level time scale sequence data can be extracted as the statistical features of the second-level time scale sequence data, minute-level time scale sequence data, and daily-level time scale sequence data. Through wavelet decomposition, the second-level time scale sequence data, minute-level time scale sequence data, and daily-level time scale sequence data can be decomposed into features of different frequency bands to obtain the frequency band features of the second-level time scale sequence data, minute-level time scale sequence data, and daily-level time scale sequence data.
[0092] In this embodiment, the mean, variance, skewness, and kurtosis of the multi-time scale sequence data are extracted as the statistical features of the multi-time scale sequence data, which can identify the main distribution characteristics of the multi-time scale sequence data; through wavelet decomposition, the multi-time scale sequence data is decomposed into features of different frequency bands to obtain the frequency band features of the multi-time scale sequence data, which can adapt to the feature analysis requirements of different time scales and make the subsequent anomaly detection more accurate and reliable.
[0093] In one embodiment, according to the reconstruction error of the multi-modal anomaly data, an anomaly score is obtained to determine whether to issue an anomaly alarm. The specific steps are as Figure 3Shown as follows: Step S301, calculate the attention scores of each modality's abnormal data according to the self-attention mechanism to perform dynamic weight allocation for each modality's abnormal data, and obtain the weights corresponding to each modality's abnormal data; Step S302, obtain the modality fusion data according to each modality's abnormal data and the weights corresponding to each modality's abnormal data; Step S303, reconstruct the modality fusion data through an autoencoder to obtain the reconstruction error of the multi-modal abnormal data; Step S304, obtain the abnormal score according to the reconstruction error of the multi-modal abnormal data; Step S305, when the abnormal score exceeds the preset threshold, issue an abnormal alarm.
[0094] The attention scores of each modality's abnormal data can be calculated according to the self-attention mechanism to perform dynamic weight allocation for each modality's abnormal data, obtain the weights corresponding to each modality's abnormal data, and fuse each modality's abnormal data according to importance, which can enhance the influence of key modality's abnormal data, thereby enhancing the flexibility and adaptability of the abnormal detection method for the power grid system provided by this application in different environments.
[0095] The modality fusion data can be obtained according to each modality's abnormal data and the weights corresponding to each modality's abnormal data, which can achieve efficient fusion of multi-modal data.
[0096] Reconstruct the modality fusion data through an autoencoder to obtain the reconstruction error of the multi-modal abnormal data. Specifically, reconstruct the modality fusion data through an autoencoder, and calculate the error between the modality fusion data and the reconstructed data of the modality fusion data as the reconstruction error of the multi-modal abnormal data.
[0097] Among them, the autoencoder can map the modality fusion data to a shared feature space to achieve cross-modal feature compression and extraction. The autoencoder can not only extract the main features of the modality fusion data, but also reduce the redundant information of the modality fusion data. It can ensure the efficient expression of features by minimizing the reconstruction error, thereby mapping the modality fusion data to a shared feature space to achieve cross-modal feature compression and extraction, and thus obtaining a unified representation of the features of the modality fusion data.
[0098] On this basis, a spatio-temporal feature extraction mechanism can be adopted to capture the spatial and temporal dynamic characteristics in the modality fusion data. Among them, the spatial features can be extracted through a convolutional neural network, and the temporal features can be modeled through the self-attention mechanism in the Transformer model to capture the long-range dependencies and trend changes of the modality fusion data in the time dimension. The convolution operation of the convolutional neural network is expressed by the following formula:
[0099]
[0100] In the formula, is the weight of the convolution kernel, is a local area of the input data, is the bias term. The convolution operation extracts local features of different regions of the power grid system, such as the status information of devices at different positions. The extracted spatial features are then fused with the temporal features, and the temporal dependence relationship is further modeled through the transformer model.
[0101] Adopting a spatio-temporal feature extraction mechanism to capture the spatial and temporal dynamic characteristics in the modal fusion data can effectively obtain the local state information of different regions of the power grid system, and can improve the sensitivity and accuracy in the anomaly detection of multi-time scale sequence data.
[0102] The preset threshold can be set according to the actual situation. The anomaly score can be obtained based on the reconstruction error of the multi-modal anomaly data; the larger the reconstruction error, the higher the anomaly score. Without label data, the preset threshold can be adaptively adjusted to adapt to different data distributions. When the anomaly score exceeds the preset threshold, an anomaly alarm is issued.
[0103] In this embodiment, according to the self-attention mechanism, the attention scores of each modal anomaly data are calculated to perform dynamic weight allocation for each modal anomaly data, and the weights corresponding to each modal anomaly data are obtained to obtain the modal fusion data; the modal fusion data is reconstructed through an autoencoder to obtain the reconstruction error of the multi-modal anomaly data to obtain the anomaly score; when the anomaly score exceeds the preset threshold, an anomaly alarm is issued, which can effectively identify the anomalies in the power grid system and provide a basis for the selection of subsequent response strategies.
[0104] In one of the embodiments, after the anomaly alarm is issued, the method provided by this application further includes: obtaining the current correspondence between the level of the anomaly score and the response strategy; determining the response strategy according to the level of the anomaly score and the current correspondence between the level of the anomaly score and the response strategy.
[0105] The level of the anomaly score can be determined according to the anomaly score. The response strategy can be determined according to the level of the anomaly score and the current correspondence between the level of the anomaly score and the response strategy.
[0106] Exemplarily, the current correspondence between the level of the anomaly score and the response strategy is as follows: record logs and continuously monitor for low-level anomalies; notify the operation and maintenance team for preventive inspections for medium-level anomalies; issue a high anomaly alarm and perform emergency shutdown or load switching operations for high-level anomalies. The above method of determining the response strategy can be called a multi-level response mechanism.
[0107] In this embodiment, different response strategies can be determined and executed according to the level of the anomaly score, and corresponding measures can be taken according to the severity of the anomaly to ensure the timely and accurate response to the anomaly event.
[0108] In addition to adopting different response strategies according to the level of anomaly scores, comprehensive closed-loop management can be achieved by combining real-time monitoring and visual display, which can dynamically display the grid status, anomaly detection situation, and response situation, enabling operation and maintenance personnel to quickly identify and adjust the grid system status. This collaborative method of multi-level response and real-time monitoring ensures the flexibility and timeliness of the grid system operation, and improves the management efficiency and security guarantee of the grid system.
[0109] In one embodiment, the specific steps to obtain the current corresponding relationship between the level of anomaly scores and response strategies are as follows: obtain the previous corresponding relationship between the level of anomaly scores and response strategies; obtain the actual execution situation of the previous response strategy; optimize the corresponding relationship between the level of anomaly scores and response strategies according to the actual execution situation of the previous response strategy and the deep Q-network model to obtain the current corresponding relationship between the level of anomaly scores and response strategies.
[0110] The corresponding relationship between the level of anomaly scores and response strategies can be optimized according to the actual execution situation of the previous response strategy and the deep Q-network model (deep reinforcement learning model) to obtain the current corresponding relationship between the level of anomaly scores and response strategies. Among them, the corresponding relationship between the level of anomaly scores and response strategies can be called the decision-making strategy.
[0111] The deep Q-network model can optimize the corresponding relationship between the level of anomaly scores and response strategies based on the principle of maximizing cumulative rewards. The update formula for Q value is:
[0112]
[0113] In the formula, is the learning rate, is the discount factor, is the immediate reward.
[0114] In this embodiment, the deep Q-network model performs reinforcement learning optimization based on anomaly scores, and continuously improves the decision-making strategy based on the actual execution situation of historical response strategies. Thus, the best response strategy can be selected in various abnormal situations, that is, the corresponding relationship between the level of anomaly scores and response strategies can be continuously optimized according to the actual execution situation of the previous response strategy and the deep Q-network model, and the most suitable response strategy can be selected to maximize the long-term cumulative reward and achieve intelligent response to grid system anomalies. It can realize the automatic response of response strategies in abnormal situations, cope with emergencies without manual intervention, and greatly improve the safety and stability of grid operation.
[0115] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this document, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0116] Based on the same inventive concept, an embodiment of the present application further provides an abnormal detection device for a power grid system for implementing the abnormal detection method for the power grid system described above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the abnormal detection device for the power grid system provided below can refer to the limitations on the abnormal detection method for the power grid system in the above text, and will not be repeated here.
[0117] In an exemplary embodiment, as Figure 4 shown, an abnormal detection device for a power grid system is provided, where:
[0118] The sequence data acquisition module 401 is configured to obtain multi-time scale sequence data corresponding to multi-time scale abnormal change indicators of the power grid system according to multi-modal data of the power grid system;
[0119] The feature extraction module 402 is configured to extract features from the multi-time scale sequence data to obtain statistical features and frequency band features of the multi-time scale sequence data;
[0120] The single-scale result acquisition module 403 is configured to sequentially input the statistical features and frequency band features of the multi-time scale sequence data into the abnormal detection models corresponding to each time scale to obtain single-scale abnormal detection results corresponding to each time scale;
[0121] The multi-scale result acquisition module 404 for multi-scale abnormal detection results is configured to obtain multi-scale abnormal detection results of the power grid system according to the single-time scale abnormal detection results corresponding to each time scale and the weights corresponding to the abnormal detection models corresponding to each time scale;
[0122] The multi-modal abnormal data determination module 405 is configured to determine multi-modal abnormal data according to the multi-scale abnormal detection results;
[0123] Anomaly alarm emission judgment module 406 is used to obtain an anomaly score based on the reconstruction error of the multimodal anomaly data to judge whether to emit an anomaly alarm.
[0124] In one embodiment, the device further includes a multimodal data acquisition module, which is used to: acquire the multimodal initial data of the power grid system; decompose the multimodal initial data by using the wavelet decomposition method to obtain multimodal high-frequency data and multimodal low-frequency data; filter and denoise the multimodal high-frequency data to obtain the filtered multimodal high-frequency data; perform missing value filling, normalization, and standardization processing on the filtered multimodal high-frequency data and multimodal low-frequency data to obtain the multimodal data of the power grid system.
[0125] In one embodiment, the feature extraction module 402 is further used to: extract the mean, variance, skewness, and kurtosis of the multi-time scale sequence data as the statistical features of the multi-time scale sequence data; decompose the multi-time scale sequence data into features in different frequency bands through wavelet decomposition to obtain the frequency band features of the multi-time scale sequence data.
[0126] In one embodiment, the anomaly alarm emission judgment module 406 is further used to: calculate the attention scores of each modal anomaly data according to the self-attention mechanism to perform dynamic weight allocation on each modal anomaly data to obtain the weights corresponding to each modal anomaly data; obtain the modal fusion data according to each modal anomaly data and the weights corresponding to each modal anomaly data; reconstruct the modal fusion data through an autoencoder to obtain the reconstruction error of the multimodal anomaly data; obtain an anomaly score according to the reconstruction error of the multimodal anomaly data; and emit an anomaly alarm when the anomaly score exceeds a preset threshold.
[0127] In one embodiment, the device further includes a response strategy determination module, which is used to: obtain the current correspondence between the level of the anomaly score and the response strategy; and determine the response strategy according to the level of the anomaly score and the current correspondence between the level of the anomaly score and the response strategy.
[0128] In one embodiment, the device further includes a correspondence optimization module, which is used to: obtain the previous correspondence between the level of the anomaly score and the response strategy; obtain the actual execution situation of the previous response strategy; and optimize the correspondence between the level of the anomaly score and the response strategy according to the actual execution situation of the previous response strategy and the deep Q network model to obtain the current correspondence between the level of the anomaly score and the response strategy.
[0129] Each module in the above abnormal detection device of the power grid system can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0130] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 5 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the data of the embodiments of the abnormal detection method of the power grid system. The input / output interface of the computer device is used for the processor to exchange information with external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements an abnormal detection method for a power grid system.
[0131] Those skilled in the art can understand that Figure 5 the structure shown in
[0132] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0133] In an embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0134] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0135] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0136] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0137] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.
[0138] The above-described embodiments merely represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the appended claims.
Claims
1. A method for detecting anomalies in a power grid system, characterized in that: The method comprises: According to the multi-modal data of the power grid system, multi-time scale series data corresponding to the multi-time scale abnormal index of the power grid system is obtained; Performing feature extraction on the multi-time scale series data to obtain statistical features and frequency band features of the multi-time scale series data; Inputting the statistical features and frequency band features of the multi-time scale series data into the anomaly detection model corresponding to each time scale in turn to obtain the single-scale anomaly detection result corresponding to each time scale; According to the single-time-scale anomaly detection results corresponding to each time scale and the weights corresponding to the anomaly detection models corresponding to each time scale, a multi-scale anomaly detection result of the power grid system is obtained; Determining multimodal abnormal data according to the multi-scale abnormality detection result; An abnormality score is obtained according to the reconstruction error of the multimodal abnormal data to determine whether to issue an abnormality alarm.
2. The method according to claim 1, characterized in that Before obtaining the multi-time scale series data corresponding to the multi-time scale abnormal index of the power grid system according to the multi-modal data of the power grid system, the method further includes: Acquire multi-modal initial data of the power grid system; Decomposing the multimodal initial data by using a wavelet decomposition method to obtain multimodal high-frequency data and multimodal low-frequency data; Filtering and denoising the multimodal high-frequency data to obtain filtered multimodal high-frequency data; The filtered multimodal high-frequency data and multimodal low-frequency data are subjected to missing value filling, normalization and standardization processing to obtain multimodal data of the power grid system.
3. The method according to claim 1, characterized in that The extracting features of the multi-time scale sequence data to obtain statistical features and frequency band features of the multi-time scale sequence data includes: Extracting the mean, variance, skewness and kurtosis of the multi-time scale series data as statistical features of the multi-time scale series data; The multi-time-scale sequence data is decomposed into features of different frequency bands by wavelet decomposition to obtain the frequency band features of the multi-time-scale sequence data.
4. The method according to claim 1, characterized in that: Obtaining an abnormality score according to the reconstruction error of the multimodal abnormal data to determine whether to issue an abnormality alarm includes: The attention score of each modal abnormal data is calculated according to the self-attention mechanism to dynamically assign weights to each modal abnormal data and obtain the weights corresponding to each modal abnormal data; According to the abnormal data of each modality and the weight corresponding to each abnormal data of each modality, the modal fusion data is obtained; Reconstructing the modal fusion data through an autoencoder to obtain a reconstruction error of the multimodal abnormal data; Obtaining an anomaly score according to a reconstruction error of the multimodal anomaly data; When the abnormality score exceeds a preset threshold, an abnormality alarm is issued.
5. The method according to claim 4, characterized in that After issuing an abnormality alarm, the method further includes: Obtaining the corresponding relationship between the level of anomaly score and the response strategy; A response strategy is determined according to the level of the anomaly score and the current correspondence between the level of the anomaly score and the response strategy.
6. The method according to claim 5, characterized in that The current correspondence between the abnormality score level and the response strategy includes: Obtain the last correspondence between the level of anomaly score and the response strategy; Get the actual execution status of the last response strategy; According to the actual execution of the last response strategy and the deep Q network model, the correspondence between the level of the anomaly score and the response strategy is optimized to obtain the current correspondence between the level of the anomaly score and the response strategy.
7. An abnormality detection device for a power grid system, characterized in that: The device comprises: A sequence data acquisition module, used to obtain multi-time scale sequence data corresponding to multi-time scale abnormal indicators of the power grid system according to the multi-modal data of the power grid system; A feature extraction module, used to extract features from the multi-time scale series data to obtain statistical features and frequency band features of the multi-time scale series data; A single-scale result acquisition module is used to input the statistical characteristics and frequency band characteristics of the multi-time-scale series data into the anomaly detection model corresponding to each time scale in turn to obtain the single-scale anomaly detection result corresponding to each time scale; A multi-scale anomaly detection result acquisition module is used to obtain a multi-scale anomaly detection result of the power grid system according to the single-time-scale anomaly detection results corresponding to each time scale and the weights corresponding to the anomaly detection models corresponding to each time scale; A multimodal abnormal data determination module, used to determine multimodal abnormal data according to the multi-scale abnormality detection result; The abnormal alarm issuance judgment module is used to obtain an abnormality score according to the reconstruction error of the multimodal abnormal data to determine whether to issue an abnormal alarm.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Cited By
Electricity carbon data anomaly detection method and device, medium and equipment
CN122241546A