Automatic control code generation for industrial assets
By combining an automatic code generator with simulation environment verification, control codes are automatically generated and verified, solving the time-consuming and labor-intensive problem of control code generation in existing technologies. This enables efficient and reliable control code generation and verification, and improves the debugging efficiency and economy of industrial plants.
Patent Information
- Application Number
- CN202510263345.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-03-11
- Filing Date
- 2025-03-06
- Publication Date
- 2025-09-12
AI Technical Summary
In industrial factories, the generation and verification process of control codes requires a lot of manual effort and cannot be used out of the box in the factory, resulting in increased time and cost in the engineering phase.
An automatic code generator is used to generate candidate control codes, and their execution capabilities are verified through code verification and simulation environments. The Langchain framework and its tools are used for static analysis and symbolic execution, combined with generative AI and simulation environments to automate the control code generation process.
It reduces the time and manual effort of control code generation and verification, improves the efficiency and economy of commissioning industrial plant assets, and ensures that the generated control code can reliably perform the given task.
Smart Images

Figure CN120631320A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to creating control codes for industrial assets in an industrial plant during an engineering phase of the industrial plant. Background Art
[0002] Industrial assets in industrial plants are often not designed to perform their assigned tasks right out of the box. Instead, these assets are controlled by embedded systems or other computers. These computers require the appropriate control code to enable the assets to perform their assigned tasks.
[0003] Today, during the engineering phase of automation systems for industrial processes, control code is primarily created manually by control engineers. This process requires a thorough understanding of control theory, production processes, programming, verification, and simulation. Furthermore, before the control code can be deployed, it must be thoroughly verified and tested, and adapted to achieve the desired functionality. Consequently, the engineering phase of automation systems requires significant manual effort from control engineers. Summary of the Invention
[0004] It is therefore an object of the present invention to provide a method for at least partially automating the generation of control code, thereby reducing time and effort in the engineering phase of an industrial plant.
[0005] This object is achieved by a computer implemented method according to the independent claim. Further advantageous embodiments are specified in the dependent claims.
[0006] The present invention provides a computer-implemented method for generating control code for actuating assets in an industrial plant to perform a given task.
[0007] During the method, candidate control codes are obtained from an automatic code generator based at least in part on a given task. That is, the code generator can be of any type as long as its output is controlled in at least some way by the given task.
[0008] Code verification is then performed on the candidate control code. The code verification is configured to determine whether the candidate control code can be executed and / or whether it can be compiled for execution. If this is not the case (i.e., code verification is unsuccessful), code generation can be repeated.
[0009] In particular, code verification can verify various aspects of the generated control code, including compilation, static code analysis, and symbolic execution. This code verification is possible through the Langchain framework and its tool integration capabilities.
[0010] If code verification succeeds, a determination is made as to whether execution of the candidate control code is capable of actuating the asset to perform a given task. To this end, the candidate control code is executed in a simulation environment. If the candidate control code is written in an interpreter language, it can be executed directly using an appropriate interpreter. If the candidate control code is written in a compiled language, it can be compiled into target code by a compiler, which can then be executed on the hardware platform. The distinction between interpreter and compiler languages is immaterial; hereinafter, reference will be made to executing the candidate control code, regardless of whether it needs to be compiled first.
[0011] If this determination is positive (i.e., the code is capable of actuating the asset to perform the given task), the candidate control code is determined to be the sought control code. That is, the candidate control code is determined to function properly and achieve the given task, such that it can be used as a control code during normal operation of the industrial plant after the engineering phase. If the determination is negative (i.e., the code is not yet capable of actuating the asset to fully perform the given task), code generation can be repeated.
[0012] In this way, control code can be automatically generated using only any form of automatic code generator, a device for performing code verification, and a device for executing candidate control code in a simulation environment, which was previously a largely manual and arduous task. Depending on how complex the automatic code generator is, the first candidate control code generated may be the most feasible to run, with only a few minor issues left to resolve. Once these issues are resolved, the execution of the candidate control code can reveal that it has already achieved the goal of the desired task to some extent. This can be further improved by repeating the code generation several times.
[0013] In principle, however, any intelligence in the automatic code generator, and any prior knowledge therein, is optional. In the extreme case, the automatic code generator can simply output all possible candidate control codes, and an automated pipeline of code verification and code execution in a simulation environment can then select the best candidate control code as the control code to be used during normal operation of the industrial asset.
[0014] This is in some sense similar to participating in the "big and small coding" competition in the demo scene without a lot of manual effort. If the task is, for example, to write code that is only 16 bytes (or even only 8 bytes) in size, but still results in some attractive visual effects output to the screen, then all one needs is an environment for automatically executing all possible candidates and ranking the corresponding results output to the screen. Then, the code can be "screened" (in the case of 8 bytes) by an automatic pipeline that determines the code with the best results. 64 A surplus of possibilities.
[0015] The end result is that the entire process of commissioning assets in an industrial plant becomes faster and more economical. This entire process begins with obtaining the required assets and ends with ensuring that all assets are fully functional. During this process, there is the mandatory operation of obtaining the required control codes. Therefore, obtaining the control codes according to the proposed method is not considered to be just data processing or programming. Instead, it is an equally important part of the entire commissioning process, in addition to the physical installation of the assets within the plant and the connection of cables to the assets. Without the control codes, the assets will not function as intended.
[0016] In a particularly advantageous embodiment, if code verification determines that a candidate control code cannot be executed and / or compiled, a new candidate control code is obtained from an automatic code generator based at least in part on the results of the code verification as feedback. In this way, the generation of the new candidate control code can be targeted at accurately improving the current error and preventing the previous candidate control code from being compiled.
[0017] Likewise, if executing the candidate control code reveals that the candidate control code is incapable of actuating the asset to perform the given task, a new candidate control code is obtained from the automatic code generator based at least in part on the results of the code execution as feedback. In this manner, the generation of the new candidate control code can be targeted at improving any problems currently existing on the path to achieving the given task.
[0018] As discussed earlier, if a sufficiently sophisticated automatic code generator is used, even the first generated candidate control code can be expected to be at least somewhat compilable / executable and likely to be able to achieve the given task. That is, this first generated candidate control code will already be better than a completely random control code. This is something that can be built upon in future iterations. To use a simple analogy, when playing golf, the first stroke of the club against the ball will not carry the ball all the way from the tee to the hole. However, the ball will have covered most of the distance and cleared at least some obstacles along the way, and with future strokes, the ball will continue to travel toward the hole.
[0019] In particular, the results of code verification can include error messages from the compiler used to compile the candidate control code into executable object code. Often, such an error message will point to a location in the code that needs to be modified. For example, if a variable is used without being declared, the declaration needs to be inserted.
[0020] Similarly, the results of executing the candidate control code in the simulation environment include the output produced by the candidate control code when executed. If this execution occurs under known conditions and with known inputs, this output can be compared with the expected output. Any differences revealed by this comparison can then be used as feedback for improving the next iteration of the candidate control code.
[0021] Specifically, during the code verification and code execution process, the system interprets error messages and other messages generated from the runtime environment during the code verification and code execution phases. If necessary, the system will also consult and interact with human users to clarify requirements. Various types of information and feedback will be combined to regenerate the code. Modifications can include functional corrections, performance improvements, syntactic improvements, refactoring, or alternative algorithms. The four steps of generation, verification, execution, and modification can be performed iteratively until the code verification and code execution are successful.
[0022] Throughout the workflow, the generated code and any intermediate results (e.g., execution results and attempts to modify the generated code) can be presented to the user in a human-friendly manner. In this way, the user (e.g., a control engineer) can be given the opportunity to discover unusual constellations and feed such findings back to the automatic code generator.
[0023] In another particularly advantageous embodiment, the automatic code generator includes a large language model (LLM) that is configured to take a text prompt as input and repeatedly predict portions of the text. The LLM is a machine learning model that has been trained on a large collection of diverse text inputs. Therefore, it can understand many types of text input. For example, the LLM can understand an initial text prompt of the type, "Write an IEC-61131-compliant program that sets the temperature setpoint on the ABC T-25 controller to 120°C." However, it can also understand feedback of the type, for example, "This version of the code fails to compile with the error message Variable XYZ is undeclared. Please write code that will compile." or "This version of the code outputs the value 0, where the value 10 is expected. Please write code that will output the correct result." This feedback can be mixed with any type of human feedback from the control engineer. For example, the control engineer may observe that the candidate control code generated by the LLM gradually slows down, and one possible cause of this behavior is the depletion of memory or other resources that are not properly released after use.
[0024] In another advantageous embodiment, the automatic code generator can be configured to reassemble fragments of existing control codes to form new candidate control codes. In this way, existing knowledge of the forms of existing control codes can be used. This is similar in some sense to the behavior of a human programmer, who learns a new programming language by assembling bytes and fragments from example programs until the resulting control code performs the operation it is supposed to perform.
[0025] In another particularly advantageous embodiment, code generation includes replacing constant values in candidate control code with symbolic placeholders. In this way, the control code, when executed, compiles or delivers the expected result, and is found to be valid for more cases than can be represented by the constant values alone. That is, the use of symbolic placeholders covers any possible constant value, while a test for one specific constant value might, for example, miss the candidate control code execution at runtime with a "divide by zero" error for a different constant value.
[0026] In another advantageous embodiment, executing the candidate control code in the simulation environment includes:
[0027] Enter one or more test scenarios into the candidate control code, and
[0028] • Comparing one or more outputs produced by the candidate control code with the expected outputs.
[0029] In this way, testing can focus on coverage of scenarios that are likely to occur during subsequent normal operation of the asset.
[0030] In particular, a control runtime environment can be used that executes the generated control code in a loop according to predetermined inputs. If necessary, the system can also configure a simulation environment suitable for executing the generated control code. Configuring the runtime environment can mean including other situations, loops, or combinations for testing, which can be created by (1) manually or automatically combining using a prescribed prior art algorithm, or (2) generated by generative AI.
[0031] In another particularly advantageous embodiment, determining whether execution of the candidate control code is capable of actuating the asset includes determining whether execution of the candidate control code is capable of achieving a given control objective involving the asset without triggering alarms associated with the control objective and / or the asset. For example, such a control objective may include maintaining a variable, such as a state variable of the asset or an entire industrial process, near a given setpoint value through some action. For example, to change the temperature in a reaction vessel, a heater may be turned on, or materials of varying temperatures may be allowed to enter the vessel.
[0032] For example, the method can begin with an AI-powered module (code generation) that can understand the intent of input provided by a human user in natural language (e.g., "Write a control algorithm for controlling a distillation column") and generate control code accordingly. Static analysis tools can then be applied to check the generated code for syntactic and semantic errors. Another AI-powered module (feedback processing) can process error messages (e.g., "variable x is not defined") and other information to determine whether and how the code needs to be corrected. After the static verification step, the syntactically correct code can be compiled or interpreted and then executed in a simulation environment to see if it can achieve a given control objective (e.g., if the generated code can be used to stabilize a distillation column without triggering alarms). Again, if any errors occur during the execution phase, the code generation module can attempt to autonomously adapt the generated code. This can be facilitated by including error messages in the code generation prompts or by querying the internet for possible code adaptations. Incidentally, the method can report all intermediate results from verification and execution to the user, along with a summary of attempts to correct, modify, and regenerate the code and the corresponding reasons. Any feedback from the user (e.g., “In addition to increasing the product flow rate of the column, the code should also ensure that the impurity rate is below 1%”) can be processed by the feedback processing module. Once the generated code succeeds in the execution phase and the user is satisfied, it can be exported for deployment as part of the automation system.
[0033] That is to say, the solution can utilize generative AI and combine it with code compilation and symbolic execution tools and simulation environments for program analysis to automate the entire code generation workflow. The solution can first generate control code based on the requirements specified by the text from a human user, then verify the generated code, and if applicable, execute it in a (further configured) simulation runtime environment. The errors and problems identified in the process are solved by the solution, and the code can be suitable for trying to solve them. The solution can provide the user with intermediate results of code verification and execution and attempts to modify the code. In such a setting, manpower is reduced to providing requirements and feedback in natural language, checking intermediate results, and finally approving the generated code. By automating the workflow, the manual effort of control programming can be reduced while ensuring the reliability and functionality of the generated code.
[0034] Therefore, in another particularly advantageous embodiment, the automatic code generator is configured to prompt the control engineer about at least one decision of the creation of a candidate control code and / or at least one contribution to the candidate control code. Even if the control engineer is prompted from time to time in this way, compared with the previous situation where the creation of the control code is a completely manual process, the currently proposed method still provides huge relief. In this respect, each decision about the control code that can be made automatically is counted. Therefore, prompting the control engineer within a limited number of times is more economical than attempting to eliminate the need for such prompting with even more complex automatic code generators.
[0035] In another particularly advantageous embodiment, one or more instances of candidate control code deemed capable of actuating an asset to perform a given task after execution in a simulation environment are presented to a controls engineer for approval. If approval is given, the instance of the candidate control code is determined to be the desired control code. If approval is not given, a new candidate control code is obtained from an automatic code generator based at least in part on the controls engineer's feedback on the candidate control code. In this way, feedback from the controls engineer can be utilized to generate new control code for any remaining desired issues, which can then be used for their intended purpose.
[0036] An exemplary reason for disapproval by the controls engineer might be that when the candidate control code 3a accomplishes its primary task of causing the asset 2 to perform a given task 4, it is too slow, requires too much memory or other resources, or has a resource leak because resources are not properly released after use, such that repeated execution of the candidate control code 3a will gradually overwhelm all available resources.
[0037] In particular, the actuation of an asset may involve reading the value of a variable from the asset that characterizes the operating state of the asset and / or an industrial process in which the asset is involved. For example, this action may be performed by a distributed control system (DCS) of an industrial plant in order to monitor the industrial plant and control it according to given objectives. Another action that is often required is to instruct the asset to change its operating state and / or to exert a physical influence on the industrial process in which the asset is involved. This is done, for example, by the DCS as a result of one or more control loops to modify the behavior of a single asset or an entire industrial plant according to one or more control objectives.
[0038] Examples of industrial assets for which control code can be generated according to the proposed method include controllers, valves, pumps, mixers, pressure gauges, thermometers, fill level gauges, or any other field device that interacts with an industrial process executed on an industrial plant. In particular, the control code can be executed on an embedded controller of a field device.
[0039] Therefore, in another particularly advantageous embodiment, the determined control code is executed on a hardware platform connected to the asset in order to cause the asset to perform a given task. The results of performing the given task are fed back to the operator of the industrial plant and / or the distributed control system DCS. In this way, starting with a given asset and a given task, the given task can be performed with minimal effort required on the part of the control engineer and / or operator. While the final control code itself can be the permanent work result of the given task, which the control engineer then uses for the commissioning of the plant, it is also possible that the control engineer or operator is only interested in the fed-back results of performing the task. That is, the generation of the control code can occur silently in the background, and the control engineer or operator may not even be aware that the control code is being generated to perform the initially assigned task. As a result, the control engineer or operator can communicate with the asset in natural language, where previously the control code had to be manually written first.
[0040] In another preferred embodiment, the method further includes collecting intermediate results from code validation and execution of the candidate control code, and optionally also collecting a summary of attempts to correct, modify, and regenerate the code, and the corresponding reasons, in a monitoring summary for the industrial plant user. In this way, the user can provide feedback that can be processed by the feedback processing module and further improved in the next round of code generation. For example, user feedback could include, "In addition to increasing the product flow rate of the distillation column, the code should also ensure that the impurity rate is below 1%."
[0041] Because it is computer-implemented, the method can be implemented in the form of software. Therefore, the present invention also relates to a computer program having machine-readable instructions, which, when executed by one or more computers and / or computing instances, cause the one or more computers and / or computing instances to perform the above-described method. Examples of computing instances include virtual machines, containers, or serverless execution environments in the cloud. The present invention also relates to a machine-readable data carrier and / or a download product having the computer program. A download product is a digital product having a computer program that can be sold, for example, in an online store for immediate implementation and downloading to one or more computers. The present invention also relates to one or more computing instances having the computer program and / or having a machine-readable data carrier and / or a download product. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In the following, the present invention is explained using the accompanying drawings without intending to limit the scope of the invention. The accompanying drawings show:
[0043] Figure 1 : An exemplary embodiment of a method 100 for generating a control code 3 for actuating an asset 2 in an industrial plant 1 to perform a given task 4;
[0044] Figure 2 : Schematic diagram of the workflow from a given task 4 to the finalized control code 3;
[0045] Figure 3 : Schematic illustration of the difference between code verification 120 and determining 130 whether a candidate control code 3a can perform a given task 4. DETAILED DESCRIPTION
[0046] Figure 1 is a schematic flow chart of an exemplary embodiment of a method 100 for generating control code 3 for actuating an asset 2 in an industrial plant 1 to perform a given task 4. The input of the method is an industrial plant 1 having one or more assets 2 and a given task 4.
[0047] According to block 105, actuation of asset 2 may include:
[0048] reading from asset 2 the value of a variable characterizing the operating state of asset 2 and / or an industrial process in which asset 2 is involved; and / or
[0049] Instructing Asset 2 to change its operational state, and / or exert a physical influence on an industrial process in which Asset 2 is involved.
[0050] According to box 106 , the asset 2 may include one or more of the following: a controller, a valve, a pump, a mixer, a pressure gauge, a thermometer, a fill level gauge, or any other field device that interacts with an industrial process executed at the industrial plant 1 .
[0051] In step 110 , candidate control codes 3 a are obtained from an automatic code generator 5 based at least in part on a given task 4 .
[0052] According to block 111, the automatic code generator 5 may include a large language model LLM configured to take a text prompt as input and repeatedly predict portions of the text. As previously described, the LLM is capable of processing the initial given task 4 and any feedback obtained on the candidate control code 3a in natural language.
[0053] According to block 112 , the automatic code generator 5 may be configured to reassemble fragments of the existing control code 3 to form a new candidate control code 3 a so as to reuse already acquired knowledge contained in the existing control code 3 rather than starting from scratch.
[0054] According to block 113 , code generation 110 may include replacing constant values in the candidate control code 3 a with symbolic placeholders.
[0055] According to block 114 , the automatic code generator 5 may prompt the controls engineer 7 for at least one decision regarding the creation of the candidate control code 3 a and / or at least one contribution to the candidate control code 3 a .
[0056] In step 120, code verification is performed on the candidate control code 3a. The code verification is configured to determine whether the candidate control code 3a can be executed and / or whether it can be compiled for execution.
[0057] If the code verification is unsuccessful (the truth value 0 at diamond 120), then in step 150, a new candidate control code 3a# may be obtained from the automatic code generator 5 based at least in part on the result 120a of the code verification 120 as feedback. Specifically, according to block 151, the result 120a may include an error message from a compiler used to compile the candidate control code 3a into executable target code.
[0058] If the code verification is successful (a truth value of 1 at diamond 120), then in step 130, it is determined whether the execution of the candidate control code 3a is capable of actuating the asset 2 to perform the given task 4 by executing the candidate control code 3a in the simulation environment 6. That is, a truth value of 1 cannot be confused with a statement that the candidate control code 3a is being executed on the actual industrial plant 1. For safety reasons, the simulation environment 6 in a different computer and / or software platform is used.
[0059] To this end, one or more test scenarios 3b may be input to the candidate control code 3a according to block 131. According to block 132, one or more outputs 3c produced by the candidate control code 3a may then be compared with expected outputs 3d.
[0060] According to block 133 , determining whether execution of the candidate control code 3a is capable of actuating the asset may include determining whether execution of the candidate control code 3a is capable of achieving a given control objective involving the asset 2 without triggering alarms associated with the control objective and / or the asset 2 .
[0061] If it is determined by executing the candidate control code 3a in the simulation environment 6 that the candidate control code 3a is unable to actuate the asset to perform the given task 4 (true value 0 in step 130), new candidate control code 3a# may be obtained from the automatic code generator 5 based at least in part on the results 130a of the code execution 130 as feedback. In particular, according to block 161, these results 130a may include outputs generated by the candidate control code 3a when executed.
[0062] If the candidate control code 3 a is found to be able to actuate the asset to perform the given task 4 (true value 1 in step 130 ), then in step 140 , the candidate control code 3 a is determined to be the sought control code 3 .
[0063] Optionally, another barrier may be present for the candidate control code 3a before it is determined to be the sought control code 3. According to block 141, one or more instances of the candidate control code 3a deemed capable of actuating the asset 2 to perform the given task 4 after execution in the simulation environment 6 may be presented to the control engineer 7 for approval. If such approval is given (a truth value of 1 at diamond 141), then according to block 142, the instance of the candidate control code 3a may be determined to be the sought control code 3. If no approval is given (a truth value of 0 at diamond 141), then according to block 143, a new candidate control code 3a# may be obtained from the automatic code generator 5 based, at least in part, on the control engineer 7's feedback 141a on the candidate control code 3a. Again, a truth value of 1 is not to be confused with a statement that something is directly executed on the actual plant 1.
[0064] exist Figure 1 In the example shown, at step 170, the determined control code 3 is executed on the hardware platform 2a connected to the asset 2 to cause the asset 2 to perform a given task 4. At step 180, the result 4a of performing the given task 4 is fed back to the operator 8 and / or the distributed control system DCS 9 of the industrial plant 1.
[0065] Figure 2 It is a schematic diagram of the workflow from a given task 4 to the finalized control code 3.
[0066] Initially, the control engineer 7 formulates a given task 4 as a prompt to the automatic code generator 5, here: the Large Language Model (LLM). In step 110 of method 100, the automatic code generator 5 generates a candidate control code 3a. This candidate control code 3a is verified in step 120 of method 100. If the candidate control code 3a passes this verification, then, according to step 130 of method 100, the verification is executed in a simulation environment 6 configured according to input 6a from the control engineer 7. If this execution 130 reveals that the candidate control code 3a is capable of enabling the asset 2 to perform the given task 4, the candidate control code 3a is presented to the control engineer 7 for approval. If the control engineer 7 approves (true value 1), the candidate control code 3a is adopted as the final control code 3a for the asset 2.
[0067] If the code validation in step 120 fails, the detailed results 120a can be passed as feedback. Similarly, if the candidate control code 3a does not solve the given task 4, the results 130a of the code execution 130 can be passed as feedback. Feedback 141a can also come from the control engineer 7 who disapproves of the final candidate control code 3a (true value 0 at diamond 141). All such feedback can be processed according to block 143 and steps 150 and 160 of method 100 to request a new candidate control code 3a# from the automatic code generator 5.
[0068] The candidate control code 3 a , as well as the results 120 a of the code verification 120 and the results 130 a of the code execution 130 , may be clustered in a monitoring summary 10 that is presented to a control engineer 7 monitoring the commissioning of the asset 2 .
[0069] Figure 3 The difference between code verification 120 and code execution 130 is illustrated by a simple analogy. Initially, the automatic code generator 5 generates a first candidate control code 3a. This candidate control code 3a cannot run (here: fly) because a small but important part (the tail) is missing. Therefore, in the code verification step 120, it flies into the trash. The feedback 120a to the automatic code generator 5 is that the code needs the tail to fly, and it is missing.
[0070] Based on this feedback, the automatic code generator 5 generates a new candidate control code 3a#. When the code verification step 120 is repeated with this new candidate control code 3a#, it is proven that this code is complete and can therefore be executed. A check is then performed at step 130 to see whether this execution results in the given task 4 being solved by the asset 2. If so, the new candidate control code 3a# can become the final control code 3 used on the asset 2.
[0071] List of reference numerals:
[0072] 1 Industrial Factory
[0073] 2 Assets in Industrial Plant 1
[0074] 2a Hardware platform connected to asset 2
[0075] 3 Control code of asset 3
[0076] 3a Candidate Control Code
[0077] 3a# New candidate control code
[0078] 3b Test scenario for candidate control code 3a
[0079] 3c Actual output of candidate control code 3a
[0080] 3d Expected output of candidate control code 3a 4d Result of executing task 4 for a given task 44a to be completed using asset 2 and control code 3
[0081] 5 Automatic Code Generator
[0082] 6 Simulation Environment
[0083] 7 Control Engineer at Industrial Plant 1
[0084] 8 Operator of Industrial Plant 1 9 Distributed Control System DCS of Industrial Plant 1
[0085] 10 Monitoring Summary
[0086] 100 Method for determining control code 3
[0087] 105 Select a specific action for activating asset 2 106 Select a specific asset 2
[0088] 110 Obtain candidate control code 3a from generator 5
[0089] 111 Select LLM as generator 5
[0090] 112 Select the generator that reassembles the code snippet 5
[0091] 113 Replacing Constant Values with Symbolic Placeholders 114 Tips for Control Engineers 7
[0092] 120 Perform code verification 120a on candidate control code 3a Result 130 of code verification 120 Determine whether candidate control code 3a solves task 4
[0093] 130a Result of code execution 130 131 Input test scenario 3b to candidate control code 3a 132 Compare actual output 3c with expected output 3d 133 Determine whether a given control objective can be satisfied 140 Determine candidate control code 3a as final control code 31 41 Present candidate control code 3a for approval 141a Feedback with disapproval of candidate control code 142 Use candidate control code 3a as final control code 31 43 Request new candidate control code 3a with feedback 141a 150 Request new candidate control code 3a with feedback 120a 151 Use error message as feedback 120a
[0094] 160 Request new candidate control code 3a using feedback 130a #161 Use the output of the code as feedback 130a
[0095] 170 Execute the determined control code 3180 on the hardware platform 2a Feedback result 4a of executing task 4
Claims
1. A computer-implemented method (100) for generating control code (3) for actuating an asset (2) in an industrial plant (1) to perform a given task (4), the method comprising the steps of: Obtaining (110) a candidate control code (3a) from an automatic code generator (5) based at least in part on the given task (4); performing (120) code verification on the candidate control code (3a), the code verification being configured to determine whether the candidate control code (3a) is executable and / or can be compiled for execution; After successful code verification, determining (130) whether execution of the candidate control code (3a) is capable of actuating the asset (2) to perform the given task (4) by executing the candidate control code (3a) in a simulation environment (6); and If the determination is positive, the candidate control code (3a) is determined (140) as the sought control code (3).
2. The method (100) according to claim 1, further comprising: If the code verification (120) determines that the candidate control code (3a) cannot be executed and / or compiled, obtaining (150) a new candidate control code (3a#) from the automatic code generator (5) based at least in part on the result (120a) of the code verification (120) as feedback; and / or If executing (130) the candidate control code (3a) indicates that the candidate control code (3a) is unable to actuate the asset to perform the given task (4), obtaining (160) a new candidate control code (3a#) from the automatic code generator (5) based at least in part on the result (130a) of executing (130) the code as feedback.
3. The method (100) according to claim 2, wherein the results (120a) of the code verification (120) include (151) error messages from a compiler used to compile the candidate control code (3a) into executable object code, and / or • The results (130a) from the execution (130) of the candidate control code (3a) in the simulation environment (6) include (161) output produced by the candidate control code (3a) when executed.
4. The method (100) according to any one of claims 1 to 3, wherein the automatic code generator (5) comprises (111) a large language model (LLM) configured to take a text prompt as input and repeatedly predict parts of the text.
5. The method (100) according to any one of claims 1 to 4, wherein the automatic code generator (5) is configured (112) to reassemble fragments of an existing control code (3) to form a new candidate control code (3a).
6. The method according to any one of claims 1 to 5, wherein the code generation (110) comprises (113) replacing constant values in the candidate control code (3a) with symbolic placeholders.
7. The method (100) according to any one of claims 1 to 6, wherein executing the candidate control code (3a) in the simulation environment (6) comprises: inputting (131) one or more test scenarios (3b) to the candidate control code (3a), and • Comparing (132) one or more outputs (3c) produced by the candidate control code (3a) with expected outputs (3d).
8. A method (100) according to any one of claims 1 to 7, wherein determining (130) whether execution of the candidate control code (3a) is capable of actuating the asset includes determining (133) whether execution of the candidate control code (3a) is capable of achieving a given control objective involving the asset (2) without triggering an alarm associated with the control objective and / or the asset (2).
9. The method (100) according to any one of claims 1 to 8, wherein the automatic code generator (5) is configured to prompt (114) the control engineer (7) with at least one decision regarding the creation of a candidate control code (3a) and / or at least one contribution to the candidate control code (3a).
10. The method (100) according to any one of claims 1 to 9, wherein presenting (141) one or more instances of candidate control code (3a) deemed capable of actuating the asset (2) to perform the given task (4) after execution in the simulation environment (6) to a controls engineer (7) for approval; If said approval is given, determining (142) said instance of the candidate control code (3a) as said sought control code (3); and If the approval is not given, obtaining (143) a new candidate control code (3a#) from the automatic code generator (5) based at least in part on the feedback (141a) of the control engineer (7) on the candidate control code (3a).
11. The method (100) according to any one of claims 1 to 10, wherein the actuation of the asset (2) comprises (105): reading from the asset (2) the value of a variable characterizing the operating state of the asset (2) and / or an industrial process involving the asset (2); and / or • instructing the asset (2) to change the operational state of the asset, and / or to exert a physical influence on an industrial process involving the asset (2).
12. A method (100) according to any one of claims 1 to 11, wherein the assets (2) include (106) one or more of the following: a controller, a valve, a pump, a mixer, a pressure gauge, a thermometer, a fill level gauge or any other field device that interacts with an industrial process performed on the industrial plant (1).
13. The method (100) according to any one of claims 1 to 12, further comprising: executing (170) the determined control code (3) on a hardware platform (2a) coupled to the asset (2) so as to cause the asset (2) to perform the given task (4); and Feeding back (180) the result (4a) of performing the given task (4) to an operator (8) and / or a distributed control system DCS (9) of the industrial plant (1).
14. The method (100) according to any one of claims 1 to 13, further comprising: Collecting intermediate results of the code verification (120) and execution (130) of the candidate control code (3a), and optionally also collecting a summary of attempts to correct, modify and regenerate the code and the corresponding reasons in a monitoring summary (10) of a user of the industrial plant (1).
15. A computer program comprising machine-readable instructions which, when executed by one or more computers and / or computing instances, cause the one or more computers and / or computing instances to perform the method (100) according to any one of claims 1 to 14.
16. A non-transitory machine-readable data carrier and / or download product having a computer program according to claim 15.
17. One or more computers and / or computing instances having a computer program according to claim 15 and / or having a machine-readable data carrier and / or a download product according to claim 16.