Power grid operation anomaly detection method based on deep learning algorithm

Through deep learning algorithms combined with sliding windows and timing graph convolution networks, the complex interaction problem of timing data and topological structure is solved, the deep integration of the power grid system is achieved, and the accuracy and reliability of abnormal detection are improved.

CN120579095APending Publication Date: 2025-09-02FOSHAN POWER SUPPLY BUREAU GUANGDONG POWER GRID
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510449371.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

The existing grid anomaly detection methods are difficult to fully capture the complex interaction between timing data and topological structure, resulting in the model being unable to fully understand the dynamic behavior of the grid system, affecting the accuracy and reliability of anomaly detection.

Method used

The power grid operation abnormality detection method based on deep learning algorithm is adopted, and the timing data is preprocessed through sliding window technology, combined with topological structure information, node features are calculated using adjacency matrix and degree-centricity, and feature fusion is used for timing graph convolution network to achieve deep fusion of timing features and topological features.

Benefits of technology

It improves the accuracy and reliability of grid abnormality detection, can understand the dynamic behavior of the grid system more comprehensively, enhances the multi-dimensional and multi-scale understanding of the grid system, and improves the performance of abnormality detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120579095A_ABST
    Figure CN120579095A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of electric power, and relates to a power grid operation anomaly detection method based on a deep learning algorithm, which preprocesses time series data through a sliding window technology and keeps the time continuity of the data. Secondly, multi-dimensional characteristics of time series data are comprehensively captured by calculating statistical characteristics, trend characteristics and periodic characteristics; meanwhile, an adjacent matrix is used for representing a topological structure, degree centrality is calculated to serve as an initial node feature, and network structure information is effectively coded. The key lies in that a time sequence diagram convolutional network is adopted, the network architecture can process time sequence and diagram structure data at the same time, and deep fusion of time sequence features and topological features is achieved; therefore, the accuracy and reliability of anomaly detection are improved. Through the multi-dimensional and multi-scale data fusion and processing method, more comprehensive and deeper understanding of the power grid system is realized, and the performance of anomaly detection is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of electric power technology, and more specifically, relates to a method for detecting abnormal operation of a power grid based on a deep learning algorithm. Background Art

[0002] As a vital infrastructure in modern society, power grids undertake the critical tasks of electricity generation, transmission, and distribution. With the development of smart grid technology, power grid systems have become increasingly complex, encompassing a vast array of power generation equipment, transmission lines, substations, and various intelligent terminal devices. While this complexity improves grid efficiency and flexibility, it also increases operational uncertainty and potential risks.

[0003] To ensure the safe and stable operation of the power grid, timely detection and handling of various abnormal conditions is crucial. Grid anomalies may include equipment failures, changes in network topology, and unusual load fluctuations. If these anomalies are not detected and addressed promptly, they can lead to localized or widespread power outages, resulting in severe economic losses and social impacts. Therefore, detecting grid anomalies has become a key issue in smart grid management.

[0004] Traditional power grid anomaly detection methods rely primarily on threshold settings and expert experience. These methods are effective for simple anomalies, but often struggle with the diverse anomalies found in modern, complex power grid systems. With the advancement of machine learning and deep learning technologies, data-driven anomaly detection methods are gaining widespread application. These methods can automatically learn complex patterns in data, improving the accuracy and efficiency of anomaly detection.

[0005] However, existing machine learning-based anomaly detection methods still face several challenges. One key issue is how to effectively integrate and utilize the multi-source, heterogeneous data in power grid systems. Power grid systems contain two key types of information: time-series measurement data from SCADA systems, which reflects the operational status of each system node over time; and grid topology data, which describes the physical connections between system components. These two types of information have distinct properties and structures, yet both are crucial for anomaly detection.

[0006] Existing methods typically treat these two types of data separately or fuse them using simple feature splicing. This approach fails to fully capture the complex interactions between time series data and topology, resulting in an inability to fully understand the dynamic behavior of power grid systems, thus affecting the accuracy and reliability of anomaly detection. Summary of the Invention

[0007] The present invention provides a method for detecting power grid operation anomalies based on a deep learning algorithm, which aims to solve the technical problem that it is currently difficult to fully capture the complex interactions between time series data and topological structures, resulting in the model's inability to fully understand the dynamic operation of the power grid system, thereby affecting the accuracy and reliability of anomaly detection.

[0008] The power grid operation anomaly detection method based on deep learning algorithm includes the following steps:

[0009] Step 1: Obtain grid raw data from the SCADA system and grid management system to obtain time series measurement data and topology data;

[0010] Step 2: Perform outlier detection on the time series measurement data, remove the detected outliers, fill in the missing values ​​using linear interpolation, and finally normalize; use a 60-minute sliding window to split the normalized data with a step size of 5 minutes to obtain the processed time series data matrix Where N represents the number of nodes; T w represents the number of time steps in each window; F represents the number of features; N windows Indicates the number of windows;

[0011] Step 3: Generate the adjacency matrix A∈R based on the node connection relationship in the topological structure data (N×N) ; And calculate the degree centrality of each node as the initial node feature, and obtain the initial node feature matrix F′;

[0012] Step 4: Based on the time series data matrix, calculate the mean, standard deviation, maximum, minimum, and median within the sliding window to form a statistical feature matrix, and calculate the linear regression slope within the sliding window to obtain a trend feature matrix; extract periodic features based on the time series data matrix to obtain a periodic feature matrix, and concatenate the statistical feature matrix, trend feature matrix, and periodic feature matrix in the feature dimension to obtain an enhanced time series feature matrix X′;

[0013] Step 5: Based on the adjacency matrix, the initial node feature matrix, and the enhanced time series feature matrix as the input of the time series graph convolutional network, the anomaly score of each time step is obtained based on the time series graph convolutional network.

[0014] The present invention effectively solves the technical problem of the difficulty in capturing the complex interactions between time series measurement data and topological structure information by innovatively fusing them. First, the time series data is preprocessed by sliding window technology to retain the temporal continuity of the data. Secondly, by calculating statistical features, trend features and periodic features, the multidimensional characteristics of the time series data are fully captured. At the same time, the adjacency matrix is ​​used to represent the topological structure, and the degree centrality is calculated as the initial node feature to effectively encode the network structure information. The key lies in the use of a time series graph convolutional network, which can process time series and graph structure data at the same time, and realizes the deep fusion of time series features and topological features. This fusion enables the model to fully understand the dynamic behavior of the power grid system and take into account the mutual influence between nodes, thereby improving the accuracy and reliability of anomaly detection. Through this multi-dimensional, multi-scale data fusion and processing method, the present invention achieves a more comprehensive and in-depth understanding of the power grid system and effectively improves the performance of anomaly detection.

[0015] Preferably, the specific steps of the sliding window are as follows:

[0016] The parameters of the sliding window are set as follows: the time window size is 60 minutes, the step size is 5 minutes, and the data sampling interval is 1 minute;

[0017] Count the number of time steps each window contains:

[0018]

[0019] Where: W represents the size of the time window; Δt represents the data sampling interval;

[0020] Calculate the number of time steps corresponding to the step size:

[0021]

[0022] Where: S t Indicates the number of time steps corresponding to the step size; S indicates the step size;

[0023] Calculate the number of windows:

[0024]

[0025] Where: L represents the total time length of the data; Indicates rounding down;

[0026] Construct the time series data matrix X:

[0027] For each node n and each feature f: extract the data of each window from the normalized time series data. Each window consists of a continuous time period with a time step of T. w , and there are S between adjacent windows t overlap;

[0028] Calculate the data for each window and put it into a new matrix X:

[0029] X[n,i,t,f]=D[n,i,S t +t,f];

[0030] Where: n∈[0,N-1], represents the node index; i∈[0,N windows -1] represents the window index; t∈[0,T w -1] represents the time step index within the window; f∈[0,F-1] represents the feature index;

[0031] The final output time series data matrix:

[0032] Preferably, the specific steps of generating the adjacency matrix are as follows:

[0033] Based on the topological structure data, an adjacency matrix A is constructed to represent the connection relationship between nodes in the topological graph of the topological structure data:

[0034]

[0035] Each element A[i,j] of the adjacency matrix A indicates whether nodes i and j are directly connected, 1 indicates connected, and 0 indicates not connected;

[0036] The adjacency weight W[i,j] is introduced into the adjacency matrix A to represent the connection weight between node i and node j:

[0037]

[0038] Where: d[i,j] represents the relationship strength between node i and node j; σ represents the scaling factor, which is used to control the influence of relationship strength on weight.

[0039] Preferably, the initial node feature matrix is ​​obtained by the following steps:

[0040] Multi-scale feature extraction:

[0041] A k =A*A*…*A;

[0042] Among them: A k represents the k-step relationship between node i and node j;

[0043] Degree Centrality:

[0044]

[0045] Where: the degree of node i is equal to the number of connections it has with all other nodes; DC[i] represents the degree centrality of node i;

[0046] Eigenvector centrality:

[0047] A·v=λv;

[0048] Where: v represents the eigenvector; λ represents the maximum eigenvalue; A represents the adjacency matrix; solving the above equations yields the eigenvector v, and the eigenvector v[o] of each node represents the centrality of node i;

[0049] PageRank Centrality:

[0050]

[0051] Where: PR[j] represents the PageRank value of node j, indicating the relative importance of the node; PR[i] represents the PageRank value of node i; α represents the damping factor; N represents the total number of nodes in the network; In(i) represents the set of all nodes pointing to node i; L[j] represents the out-degree of node j, that is, the number of other nodes pointed to by node j;

[0052] Construction of node feature matrix F′: The feature vector of each node i includes degree centrality, feature vector centrality and PageRank centrality:

[0053]

[0054] Where: N represents the number of nodes.

[0055] Preferably, the trend feature is extracted as follows:

[0056]

[0057] Where: β i,t represents the linear regression slope of node i at time step t; represents the mean of time step t; X i,w,t represents the feature value of node i in window w at time t;

[0058]

[0059] Where: X i,w represents the feature mean of node i in window w;

[0060] The trend feature matrix is ​​obtained based on the linear regression slope of each node.

[0061] Preferably, the periodic feature extraction is as follows:

[0062] Extract the periodic component of the signal through Fourier transform and calculate the periodic amplitude:

[0063]

[0064] Where: A i,t represents the periodic amplitude of node i at time step t; f k Represents a leather girl, inferred based on the periodicity of the signal; X i,t,k represents the measurement value of node i at time step k;

[0065] A periodic characteristic matrix is ​​obtained based on the periodic amplitude of each node.

[0066] Preferably, the step 5 comprises the following steps:

[0067] In the temporal graph convolutional network, for each time step t, a temporal convolution layer is applied to capture the temporal relationship, and for each node’s feature F′ (t) Perform convolution operation on it with the adjacency matrix A and the features of the previous time step to obtain the time series features of node i at the current time step;

[0068] Set the window size of the temporal convolution and consider multiple time steps in the sliding window so that the model can capture the temporal trend of node features:

[0069] H t =σ(AH t-1 W t +F′ t W f );

[0070] Where: H t Represents the node features of the current time step; A represents the adjacency matrix; W t Represents the weight matrix of temporal convolution; W f represents the feature weight matrix; σ represents the activation function;

[0071] Multiple temporal convolutional layers are stacked, and the output of each layer contains multi-level modeling of time step t and adjacency relationships;

[0072] After passing through multiple layers of temporal convolutional layers, the temporal features of each node are mapped to a new representation space. At each time step t, the output features of all nodes are further processed to calculate the anomaly score:

[0073] Calculating node-level anomaly scores: Perform anomaly detection on the output features of each node to obtain a node-level anomaly score. Anomaly detection is performed by calculating the difference between the node features and the historical state, or the difference between the node features and the features of neighboring nodes.

[0074] Global anomaly score calculation: The anomaly scores of the nodes are aggregated and the global anomaly score is obtained by weighted average.

[0075] The beneficial effects of the present invention include:

[0076] The present invention effectively solves the technical problem of the difficulty in capturing the complex interactions between time series measurement data and topological structure information by innovatively fusing them. First, the time series data is preprocessed by sliding window technology to retain the temporal continuity of the data. Secondly, by calculating statistical features, trend features and periodic features, the multidimensional characteristics of the time series data are fully captured. At the same time, the adjacency matrix is ​​used to represent the topological structure, and the degree centrality is calculated as the initial node feature to effectively encode the network structure information. The key lies in the use of a time series graph convolutional network, which can process time series and graph structure data at the same time, and realizes the deep fusion of time series features and topological features. This fusion enables the model to fully understand the dynamic behavior of the power grid system and take into account the mutual influence between nodes, thereby improving the accuracy and reliability of anomaly detection. Through this multi-dimensional, multi-scale data fusion and processing method, the present invention achieves a more comprehensive and in-depth understanding of the power grid system and effectively improves the performance of anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0078] Figure 1 This is a flowchart of the overall steps provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0079] In order to make the technical problems, technical solutions and beneficial effects to be solved by this application more clearly understood, this application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0080] See also Figure 1 As shown, the preferred embodiment of the present invention is further described;

[0081] The power grid operation anomaly detection method based on deep learning algorithm includes the following steps:

[0082] Step 1: Obtain raw grid data from the SCADA system and grid management system to obtain time series measurement data and topology data; the time series measurement data includes voltage, current, power, etc.; the topology data is the grid topology diagram;

[0083] Step 2: Perform outlier detection on the time series measurement data, remove the detected outliers, fill in the missing values ​​using linear interpolation, and finally normalize; use a 60-minute sliding window to split the normalized data with a step size of 5 minutes to obtain the processed time series data matrix Where N represents the number of nodes; T w represents the number of time steps in each window; F represents the number of features; N windows Indicates the number of windows;

[0084] The specific steps of the sliding window are as follows:

[0085] The parameters of the sliding window are set as follows: the time window size is 60 minutes, the step size is 5 minutes, and the data sampling interval is 1 minute;

[0086] Count the number of time steps each window contains:

[0087]

[0088] Where: W represents the size of the time window; Δt represents the data sampling interval;

[0089] Calculate the number of time steps corresponding to the step size:

[0090]

[0091] Where: S t Indicates the number of time steps corresponding to the step size; S indicates the step size;

[0092] Calculate the number of windows:

[0093]

[0094] Where: L represents the total time length of the data; Indicates rounding down;

[0095] Construct the time series data matrix X:

[0096] For each node n and each feature f: extract the data of each window from the normalized time series data. Each window consists of a continuous time period with a time step of T. w , and there are S between adjacent windows t overlap;

[0097] Calculate the data for each window and put it into a new matrix X:

[0098] X[n,i,t,f]=D[n,i,S t +t,f];

[0099] Where: n∈[0,N-1], represents the node index; i∈[0,N windows -1] represents the window index; t∈[0,T w -1] represents the time step index within the window; f∈[0,F-1] represents the feature index;

[0100] The final output time series data matrix:

[0101] In this example, sliding window segmentation not only helps the model focus on data within a local time window, but also, by stacking multiple windows, allows the model to capture grid operational trends over a wider time span. Furthermore, by adjusting the number of windows, the model can capture grid operation over longer periods of time, thereby enhancing the model's temporal awareness and global understanding.

[0102] In this embodiment,

[0103] Step 3: Generate the adjacency matrix A∈R based on the node connection relationship in the topological structure data (N×N) ; And calculate the degree centrality of each node as the initial node feature, and obtain the initial node feature matrix F′;

[0104] The specific steps of generating the adjacency matrix are as follows:

[0105] Based on the topological structure data, an adjacency matrix A is constructed to represent the connection relationship between nodes in the topological graph of the topological structure data:

[0106]

[0107] Each element A[i,j] of the adjacency matrix A indicates whether nodes i and j are directly connected, 1 indicates connected, and 0 indicates not connected;

[0108] The adjacency weight W[i,j] is introduced into the adjacency matrix A to represent the connection weight between node i and node j:

[0109]

[0110] Where: d[i,j] represents the relationship strength between node i and node j; σ represents the scaling factor, which is used to control the influence of relationship strength on weight.

[0111] Preferably, the initial node feature matrix is ​​obtained by the following steps:

[0112] Multi-scale feature extraction:

[0113] A k =A*A*…*A;

[0114] Among them: A k represents the k-step relationship between node i and node j;

[0115] Degree Centrality:

[0116]

[0117] Where: the degree of node i is equal to the number of connections it has with all other nodes; DC[i] represents the degree centrality of node i;

[0118] Eigenvector centrality:

[0119] A·v=λv;

[0120] Where: v represents the eigenvector; λ represents the maximum eigenvalue; A represents the adjacency matrix; solving the above equations yields the eigenvector v, and the eigenvector v[i] of each node represents the centrality of node i;

[0121] PageRank Centrality:

[0122]

[0123] Where: PR[j] represents the PageRank value of node j, indicating the relative importance of the node; PR[i] represents the PageRank value of node i; α represents the damping factor; N represents the total number of nodes in the network; In(i) represents the set of all nodes pointing to node i; L[j] represents the out-degree of node j, that is, the number of other nodes pointed to by node j;

[0124] Construction of node feature matrix F′: The feature vector of each node i includes degree centrality, feature vector centrality and PageRank centrality:

[0125]

[0126] Where: N represents the number of nodes.

[0127] In this example, degree centrality is an important metric in graph theory that indicates the number of connections a node has. Nodes with higher degree centrality typically play a more important role in the graph. For example, in a power grid, nodes with higher degree centrality may be key nodes for power transmission or backbone nodes of the system. Using degree centrality as an initial node feature can provide the model with information about the importance of each node in the power grid, helping the model distinguish the characteristics and roles of different nodes.

[0128] Step 4: Based on the time series data matrix, calculate the mean, standard deviation, maximum, minimum, and median within the sliding window to form a statistical feature matrix, and calculate the linear regression slope within the sliding window to obtain a trend feature matrix; extract periodic features based on the time series data matrix to obtain a periodic feature matrix, and concatenate the statistical feature matrix, trend feature matrix, and periodic feature matrix in the feature dimension to obtain an enhanced time series feature matrix C′;

[0129] The trend features are extracted as follows:

[0130]

[0131] Where: β i,t represents the linear regression slope of node i at time step t; represents the mean of time step t; X i,w,t represents the feature value of node i in window w at time t;

[0132]

[0133] Where: X i,w represents the feature mean of node i in window w;

[0134] The trend feature matrix is ​​obtained based on the linear regression slope of each node.

[0135] Preferably, the periodic feature extraction is as follows:

[0136] Extract the periodic component of the signal through Fourier transform and calculate the periodic amplitude:

[0137]

[0138] Where: A i,t represents the periodic amplitude of node i at time step t; f k Represents a leather girl, inferred based on the periodicity of the signal; X i,t,k represents the measurement value of node i at time step k;

[0139] A periodic characteristic matrix is ​​obtained based on the periodic amplitude of each node.

[0140] In this example, by extracting statistical, trend, and cyclical features and combining them, a multi-dimensional, more informative time series feature matrix is ​​formed. This provides more comprehensive input data for the model, enabling it to capture the complex spatiotemporal variations in the power grid.

[0141] Step 5: Based on the adjacency matrix, the initial node feature matrix, and the enhanced time series feature matrix as the input of the time series graph convolutional network, the anomaly score of each time step is obtained based on the time series graph convolutional network.

[0142] The step 5 comprises the following steps:

[0143] In the temporal graph convolutional network, for each time step t, a temporal convolution layer is applied to capture the temporal relationship, and for each node’s feature F′ (t) Perform convolution operation on it with the adjacency matrix A and the features of the previous time step to obtain the time series features of node i at the current time step;

[0144] Set the window size of the temporal convolution and consider multiple time steps in the sliding window so that the model can capture the temporal trend of node features:

[0145] H t =σ(AH t-1 W t +F′ t W f );

[0146] Where: H t Represents the node features of the current time step; A represents the adjacency matrix; W t Represents the weight matrix of temporal convolution; W f represents the feature weight matrix; σ represents the activation function;

[0147] Multiple temporal convolutional layers are stacked, and the output of each layer contains multi-level modeling of time step t and adjacency relationships;

[0148] After passing through multiple layers of temporal convolutional layers, the temporal features of each node are mapped to a new representation space. At each time step t, the output features of all nodes are further processed to calculate the anomaly score:

[0149] Calculating node-level anomaly scores: Perform anomaly detection on the output features of each node to obtain a node-level anomaly score. Anomaly detection is performed by calculating the difference between the node features and the historical state, or the difference between the node features and the features of neighboring nodes.

[0150] Global anomaly score calculation: The anomaly scores of the nodes are aggregated and the global anomaly score is obtained by weighted average.

[0151] In this embodiment, the T-GCN (temporal graph convolutional network) model analyzes the temporal dependency and topological structure of the power grid time series data and outputs the anomaly score S for each time step. t , which represents the degree of abnormality at each time point. A higher score indicates a higher degree of abnormality at that moment.

[0152] Calculate the EWMA (exponentially weighted moving average) statistic:

[0153] Z t=λS t +(1-λ)Z t-1 ;

[0154] Where: Z t Represents the smoothed abnormal statistics at the current time point; S t represents the anomaly score output by the T-GCN model; λ represents the smoothing factor, which is 0.3; Z t-1 Indicates the abnormal statistics at the previous time point;

[0155] Dynamic update control limitations:

[0156] UCL t =μ t +kσ t ;

[0157] LCL t =μ t -kσ t ;

[0158] The control limit is calculated by calculating the mean μ of the smoothed statistic t and standard deviation σ t To dynamically determine, the control limits (UCL and LCL) define the boundaries of the anomaly. When the statistic exceeds this range, it is judged as an anomaly.

[0159] UCL t and LCL t are the upper and lower control limits, respectively; k represents the control parameter and is set to 3;

[0160] Abnormal judgment: If the current smooth abnormal statistic Z t Exceeding the upper limit UCL t , or below the lower limit LCL t If abnormal, the abnormal flag is output, 0 means normal, 1 means abnormal;

[0161] The results of adaptive anomaly detection are used as the final anomaly detection results, and further processing can be performed as needed, such as alarm, alarm classification, abnormal event analysis, etc.

[0162] Since the T-GCN model obtains anomaly scores for each time step, we are able to identify which time points have a high degree of anomaly in the model. However, relying solely on the output of T-GCN for direct judgment may face the following problems:

[0163] Volatility of time series data:

[0164] Time series data from systems like power grids often exhibit high natural volatility, so even normal changes can lead to large fluctuations in anomaly scores. If we rely solely on the output of the T-GCN model to directly identify anomalies, we may mistakenly identify these natural fluctuations as anomalies.

[0165] Dynamically changing control limits:

[0166] Using static thresholds for anomaly detection can be difficult to adapt to rapidly changing data. Adaptive anomaly detection calculates dynamic control limits (UCL and LCL) to flexibly adjust thresholds as time series data changes, adapting to natural data fluctuations and avoiding oversensitivity.

[0167] Smoothing to avoid over-response:

[0168] Smoothing the anomaly score with EWMA can avoid overreacting to transient abnormal fluctuations. By weighted averaging historical data, potential long-term trends and abnormal patterns can be more accurately captured rather than short-term noise.

[0169] Distinguishing between noise and anomaly scores:

[0170] The T-GCN model may react strongly to certain noise or data fluctuations, resulting in high anomaly scores. Adaptive anomaly detection helps distinguish normal fluctuations from actual anomalies through dynamically updated control limits, reducing false positives.

[0171] The present invention effectively solves the technical problem of the difficulty in capturing the complex interactions between time series measurement data and topological structure information by innovatively fusing them. First, the time series data is preprocessed by sliding window technology to retain the temporal continuity of the data. Secondly, by calculating statistical features, trend features and periodic features, the multidimensional characteristics of the time series data are fully captured. At the same time, the adjacency matrix is ​​used to represent the topological structure, and the degree centrality is calculated as the initial node feature to effectively encode the network structure information. The key lies in the use of a time series graph convolutional network, which can process time series and graph structure data at the same time, and realizes the deep fusion of time series features and topological features. This fusion enables the model to fully understand the dynamic behavior of the power grid system and take into account the mutual influence between nodes, thereby improving the accuracy and reliability of anomaly detection. Through this multi-dimensional, multi-scale data fusion and processing method, the present invention achieves a more comprehensive and in-depth understanding of the power grid system and effectively improves the performance of anomaly detection.

[0172] The above are only preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present application should be included in the scope of protection of the present application.

Claims

1. A method for detecting abnormal operation of a power grid based on a deep learning algorithm, characterized in that: The following steps are involved: Step 1: Obtain grid raw data from the SCADA system and grid management system to obtain time series measurement data and topology data; Step 2: Perform outlier detection on the time series measurement data, remove the detected outliers, fill in the missing values ​​using linear interpolation, and finally normalize; use a 60-minute sliding window to split the normalized data with a step size of 5 minutes to obtain the processed time series data matrix Where N represents the number of nodes; T w represents the number of time steps in each window; F represents the number of features; N windows Indicates the number of windows; Step 3: Generate the adjacency matrix A∈R based on the node connection relationship in the topological structure data (N×N) ; And calculate the degree centrality of each node as the initial node feature, and obtain the initial node feature matrix F′; Step 4: Calculate the mean, standard deviation, maximum, minimum, and median within the sliding window based on the time series data matrix to form a statistical feature matrix, and calculate the linear regression slope within the sliding window to obtain a trend feature matrix; Based on the time series data matrix, periodic feature extraction is performed to obtain a periodic feature matrix, and the statistical feature matrix, trend feature matrix and periodic feature matrix are spliced ​​in the feature dimension to obtain an enhanced time series feature matrix X′; Step 5: Based on the adjacency matrix, the initial node feature matrix, and the enhanced time series feature matrix as the input of the time series graph convolutional network, the anomaly score of each time step is obtained based on the time series graph convolutional network.

2. The method for detecting abnormal operation of a power grid based on a deep learning algorithm according to claim 1, characterized in that: The specific steps of the sliding window are as follows: The parameters of the sliding window are set as follows: the time window size is 60 minutes, the step size is 5 minutes, and the data sampling interval is 1 minute; Count the number of time steps each window contains: Where: W represents the size of the time window; Δt represents the data sampling interval; Calculate the number of time steps corresponding to the step size: Where: S t Indicates the number of time steps corresponding to the step size; S indicates the step size; Calculate the number of windows: Where: L represents the total time length of the data; Indicates rounding down; Construct the time series data matrix X: For each node n and each feature f: extract the data of each window from the normalized time series data. Each window consists of a continuous time period with a time step of T. w , and there are S between adjacent windows t overlap; Calculate the data for each window and put it into a new matrix X: X[n,i,t,f]=D[n,i,S t +t,f]; Where: n∈[0,N-1], represents the node index; i∈[0,N windows -1] indicates the window index; t∈[0,T w -1] represents the time step index within the window; f∈[0,F-1] represents the feature index; The final output time series data matrix:

3. The method for detecting abnormal operation of a power grid based on a deep learning algorithm according to claim 1, characterized in that: The specific steps of generating the adjacency matrix are as follows: Based on the topological structure data, an adjacency matrix A is constructed to represent the connection relationship between nodes in the topological graph of the topological structure data: Each element A[i,j] of the adjacency matrix A indicates whether nodes i and j are directly connected, 1 indicates connected, and 0 indicates not connected; The adjacency weight W[i,j] is introduced into the adjacency matrix A to represent the connection weight between node i and node j: Where: d[i,j] represents the relationship strength between node i and node j; σ represents the scaling factor, which is used to control the influence of relationship strength on weight.

4. The method for detecting abnormal operation of a power grid based on a deep learning algorithm according to claim 1, characterized in that: The initial node feature matrix is ​​obtained by the following steps: Multi-scale feature extraction: A k =A*A*…*A; Among them: A k represents the k-step relationship between node i and node j; Degree Centrality: Where: the degree of node i is equal to the number of connections it has with all other nodes; DC[i] represents the degree centrality of node i; Eigenvector centrality: A·v=λv; Where: v represents the eigenvector; λ represents the maximum eigenvalue; A represents the adjacency matrix; solving the above equations yields the eigenvector v, and the eigenvector v[i] of each node represents the centrality of node i; PageRank Centrality: Where: PR[j] represents the PageRank value of node j, indicating the relative importance of the node; PR[i] represents the PageRank value of node i; α represents the damping factor; N represents the total number of nodes in the network; In(i) represents the set of all nodes pointing to node i; L[j] represents the out-degree of node j, that is, the number of other nodes pointed to by node j; Construction of node feature matrix F′: The feature vector of each node i includes degree centrality, feature vector centrality and PageRank centrality: Where: N represents the number of nodes.

5. The method for detecting abnormal operation of a power grid based on a deep learning algorithm according to claim 1, characterized in that: The trend features are extracted as follows: Where: β i,t represents the linear regression slope of node i at time step t; represents the mean of time step t; X i,w,t represents the feature value of node i in window w at time t; Where: X i,w represents the feature mean of node i in window w; The trend feature matrix is ​​obtained based on the linear regression slope of each node.

6. The method for detecting abnormal operation of a power grid based on a deep learning algorithm according to claim 1, characterized in that: The periodic feature extraction is as follows: Extract the periodic component of the signal through Fourier transform and calculate the periodic amplitude: Where: A i,t represents the periodic amplitude of node i at time step t; f k Represents a leather girl, inferred based on the periodicity of the signal; X i,t,k represents the measurement value of node i at time step k; A periodic characteristic matrix is ​​obtained based on the periodic amplitude of each node.

7. The method for detecting abnormal operation of a power grid based on a deep learning algorithm according to claim 1, characterized in that: The step 5 comprises the following steps: In the temporal graph convolutional network, for each time step t, a temporal convolution layer is applied to capture the temporal relationship, and for each node’s feature F′ (t) Perform convolution operation on it with the adjacency matrix A and the features of the previous time step to obtain the time series features of node i at the current time step; Set the window size of the temporal convolution and consider multiple time steps in the sliding window so that the model can capture the temporal trend of node features: H t =σ(AH t-1 W t +F′ t W f ); Where: H t Represents the node features of the current time step; A represents the adjacency matrix; W t Represents the weight matrix of temporal convolution; W f represents the feature weight matrix; σ represents the activation function; Multiple temporal convolutional layers are stacked, and the output of each layer contains multi-level modeling of time step t and adjacency relationships; After passing through multiple layers of temporal convolutional layers, the temporal features of each node are mapped to a new representation space. At each time step t, the output features of all nodes are further processed to calculate the anomaly score: Calculating node-level anomaly scores: Perform anomaly detection on the output features of each node to obtain a node-level anomaly score. Anomaly detection is performed by calculating the difference between the node features and the historical state, or the difference between the node features and the features of neighboring nodes. Global anomaly score calculation: The anomaly scores of the nodes are aggregated and the global anomaly score is obtained by weighted average.