Power system regulation and control operation behavior analysis method and system

By collecting multi-source data in the power system, building a grid status label-driven behavior pattern library, and dynamically adjusting feature weights, the technical problems existing in the existing technology are solved, and the flexibility and practicality of the power system are achieved. Through technical means, the accuracy and real-time response capability of the power system control operation behavior analysis are improved, and the risk prevention and control capabilities are enhanced.

CN120670730APending Publication Date: 2025-09-19NORTH CHINA BRANCH OF STATE GRID CORPORATION OF CHINA +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510790595.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

The existing power system control and operational behavior analysis methods lack dynamic control mechanisms, insufficient multi-source heterogeneous data fusion and in-depth analysis, and imperfect personalized feedback and abnormal management mechanisms, resulting in a lack of flexibility and practicality in operational behavior analysis.

Method used

Collect multi-source control data, extract behavioral features such as operation sequence matching scores and compliance scores, construct operation behavior records based on grid status labels, build a behavior pattern library based on k-means++ clustering, dynamically adjust feature weights when the grid status changes, update cluster centers and pattern library in real time, and perform anomaly classification by calculating the similarity between operation behavior and pattern clusters.

Benefits of technology

It improves the accuracy and real-time response capability of power system control and operation behavior analysis, enhances risk prevention and control capabilities and adaptive evolution capabilities, and supports closed-loop optimization of dispatching behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120670730A_ABST
    Figure CN120670730A_ABST
Patent Text Reader

Abstract

The invention discloses a power system regulation and control operation behavior analysis method and system. Collecting multi-source regulation and control data, and extracting behavior characteristics such as an operation sequence matching score and a compliance score based on an operation process and a regulation and control rule; constructing an operation behavior record as a clustering model input in combination with a power grid state label; k-means + + clustering operation is executed based on the power grid state and the response speed, a behavior pattern library is constructed, and typical cluster features are extracted. When the operation state of the power grid changes, dynamically adjusting the feature weight according to the state label, executing local clustering updating on the incremental sample, and updating the cluster center point and the behavior pattern library in real time; and finally, by calculating the similarity between the real-time operation behavior and each behavior pattern cluster, realizing the abnormal classification of the regulation and control behavior. According to the method, through fusion processing and feature extraction of the multi-source regulation and control data, multi-dimensional modeling and behavior pattern analysis are carried out on scheduling operation behaviors, and the method has good real-time performance, flexibility and interpretability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power system dispatching and operation, and specifically relates to a method and system for analyzing power system control operation behavior. Background Art

[0002] As power systems continue to expand in scale and become increasingly complex, the safety and reliability of power control operations are facing unprecedentedly stringent requirements. As the core decision-makers for the safe and stable operation of power systems, the actions of control operators directly determine the operational status of the power grid. With the deep integration of the Industrial Internet and digital technologies, power system control and management is undergoing a revolutionary breakthrough in intelligent transformation. Leveraging cutting-edge technologies, the development of more objective and accurate analysis and evaluation paradigms has become an industry consensus.

[0003] The patent application with publication number CN119962861A constructs a keyword set of power dispatching business names, extracts and establishes standardized operating steps for the corresponding business, and forms a set of power dispatching business operation specifications as a unified operating standard. The similarity between the actual power dispatching business operation steps and the said specifications is calculated step by step to achieve an accurate assessment of the consistency between the actual operation and the standard specifications, so as to timely identify and correct non-compliant operating behaviors and improve the standardization and safety of dispatching operations. The patent application with publication number CN111144747A proposes a computer device for evaluating the entire process of power dispatching. By collecting relevant data of the on-duty dispatcher from the dispatching telephone system, OCS system, frequency modulation system, DICP system and OMS system, the dispatcher's control behavior is quantitatively evaluated from four dimensions: telephone communication, power generation control, accident defect handling, and transmission and transformation operation, and the performance score of the dispatcher is comprehensively calculated in combination with job information.

[0004] The shortcomings of existing technologies are: (1) Lack of dynamic control mechanism; existing methods do not adjust the evaluation logic and feature weights in real time according to the operating status of the power grid, resulting in a lack of flexibility and practicality in the analysis of operational behavior. (2) Insufficient fusion and in-depth analysis of multi-source heterogeneous data; existing methods lack unified fusion and in-depth pattern recognition of data from SCADA, operation tickets, logs and other systems, which limits the comprehensive understanding and intelligent evaluation of operational behavior. (3) Imperfect personalized feedback and abnormal management mechanism; existing methods lack personalized feedback based on operating modes, abnormal pattern library construction and dynamic early warning linkage mechanism, making it difficult to support closed-loop optimization of dispatching behavior. Summary of the Invention

[0005] To address the deficiencies in the prior art, the present invention provides a method and system for analyzing the control and operation behavior of a power system. Multi-source control data is collected, and based on the operation process and control procedures, behavioral features such as operation sequence matching scores and compliance scores are extracted; operation behavior records are constructed in combination with grid status labels as input to a clustering model; k-means++ clustering operations are performed based on grid status and response speed to build a behavior pattern library and extract typical cluster features. When the grid operating state changes, the feature weights are dynamically adjusted according to the state labels, local clustering updates are performed on incremental samples, and cluster centers and behavior pattern libraries are updated in real time; finally, abnormal classification of control behavior is achieved by calculating the similarity between real-time operation behavior and each behavior pattern cluster.

[0006] The first aspect of the present application discloses a method for analyzing power system control operation behavior, which adopts the following technical solution:

[0007] Acquire multi-source control data from the power system and pre-process it; extract operational behavior features from the pre-processed multi-source control data;

[0008] Matching the operation behavior to the corresponding grid status label according to the start time, and constructing the operation behavior record based on the operation behavior characteristics as the input of the clustering operation;

[0009] Based on the operation behavior records, the initial centroid is selected according to the grid status label and response speed; clustering operations are performed to obtain multiple operation behavior pattern clusters, and cluster features are extracted to design the behavior pattern library structure;

[0010] Collecting real-time multi-source control data, dynamically adjusting feature weights in the clustering operation based on real-time grid status tags, performing local clustering updates, and updating cluster features in the pattern library;

[0011] Calculate the pattern scores of real-time operation behaviors and updated pattern libraries, and classify real-time operation behaviors as abnormal.

[0012] Furthermore, the operation behavior characteristics include an operation sequence matching score and a compliance score;

[0013] The operation sequence matching score is calculated by comparing the execution process of the operation behavior with the control standard process. The matching score is equal to 1-(number of wrong operation sequence steps / total number of steps).

[0014] The execution process of the operation behavior is compared with the preset rules to calculate the compliance score, which is equal to 1-(number of violation steps / total number of steps).

[0015] Furthermore, the construction process of the operation behavior record includes:

[0016] Based on the multi-source control data, a state identification rule is used to obtain a power grid state label;

[0017] Based on the multi-source control data at the start of the operation behavior, the operation behavior is matched with the corresponding grid status label;

[0018] The operation behavior features corresponding to the operation behavior are combined with the matching power grid state labels to construct an operation behavior record, which is used to input into the clustering model.

[0019] Furthermore, the step of selecting the initial centroid includes:

[0020] The time difference between the time when the operation instruction is issued and the time when the operation is completed is recorded as the response time through the timestamp, and the initial samples whose response time meets the threshold range are selected according to the grid status label;

[0021] Set the weights of compliance score and response speed in the initial sample score, calculate the sample weighted score for the initial sample; select the initial sample with the highest score as the initial centroid;

[0022] For the initial samples other than the selected initial centroid, calculate the square of the minimum Euclidean distance to the selected initial centroid and construct a probability distribution; select the next centroid according to the probability distribution until k initial centroids are selected.

[0023] Furthermore, the behavior pattern library structure includes:

[0024] Cluster characteristics, grid status labels, weight mapping rules, and pattern scoring thresholds;

[0025] The cluster features include the feature center point, feature distribution, and category mapping label of each behavior pattern cluster; wherein the category mapping label is encoded by the semantic association between the business scenario and the operation behavior feature, and each label corresponds to an integer.

[0026] Furthermore, the dynamically adjusting the feature weights in the clustering operation according to the real-time grid status tags includes:

[0027] When the grid status tag is updated, the weight update process is triggered; the updated compliance score and response speed weight are obtained through the weight mapping rules;

[0028] Extract and filter samples that match the current grid status label from the incremental data collected in real time. Recalculate the weighted scores of the filtered samples based on the new weights.

[0029] Perform local clustering updates and write the updated cluster features into the behavior pattern library.

[0030] Furthermore, the process of classifying the real-time operation behavior as abnormal includes:

[0031] Calculate the distance between the feature vector of the real-time operation behavior and the center point of each cluster and normalize it to similarity as the pattern score;

[0032] Select the cluster corresponding to the maximum pattern score, and classify the real-time operation behavior into abnormal behavior according to the pattern score division threshold;

[0033] If the classification result is normal behavior, the feature vector of the real-time operation behavior is added to the cluster sample pool;

[0034] If the classification result is abnormal behavior, an early warning of the power system is triggered; if the abnormal behavior is a new abnormal pattern, the feature vector of the real-time operation behavior is added to the existing abnormal pattern library and the cluster center point is expanded.

[0035] A second aspect of the present application provides a power system regulation and operation behavior analysis system, which runs the regulation and operation behavior analysis method described in the first aspect, and the system includes:

[0036] Data acquisition module; acquires multi-source control data from the power system and performs preprocessing; extracts operational behavior features from the preprocessed multi-source control data;

[0037] Feature extraction module: matching the operation behavior with the corresponding grid status label according to the start time, and constructing the operation behavior record based on the operation behavior characteristics as the input of the clustering operation;

[0038] Cluster analysis module: Based on the operation behavior records, the initial centroid is selected according to the grid status label and response speed; clustering operations are performed to obtain multiple operation behavior pattern clusters, and cluster features are extracted to design the behavior pattern library structure;

[0039] Real-time analysis module; collects real-time multi-source control data, dynamically adjusts the feature weights in the clustering operation according to the real-time power grid status tags, performs local clustering updates, and updates the cluster features in the pattern library;

[0040] Abnormal evaluation module: calculates the pattern scores of real-time operation behavior and updated pattern library, and classifies real-time operation behavior into abnormal behavior.

[0041] The present application also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is loaded into the processor, the method for analyzing the control operation behavior described in the first aspect of the present application is implemented.

[0042] The present application also provides a computer-readable storage medium, which stores a computer program, and is characterized in that when the computer program is executed by a processor, it implements the control operation behavior analysis method described in the first aspect of the present application.

[0043] The beneficial effect of the present invention is that, compared with the prior art,

[0044] 1. This application extracts behavioral features from multi-source control data, such as operation frequency, response time, sequence matching score, and compliance score. It also matches the current grid operation state (e.g., "normal operation," "high-load operation," "fault emergency") based on the operation start time. This fusion of grid state labels and behavioral features creates a context-aware operational behavior record. This helps distinguish behavioral differences under different states, improving the accuracy of cluster analysis and the ability to interpret actual business semantics.

[0045] 2. When the power grid state changes, this application dynamically adjusts the importance weights in the control behavior characteristics based on the preset weight mapping rules, and applies the new weight configuration to the real-time weighted processing of the feature vector. Only local clustering updates are performed on sample data and cluster clusters related to the current state, and the center points and distribution structures of the corresponding clusters are optimized, rather than full retraining. This mechanism reduces the model update frequency and computing resource consumption, enabling the model to quickly adapt to changes in behavioral characteristics under different power grid states, and improving the real-time response capability and operating efficiency of the recognition system.

[0046] 3. After constructing a behavioral model, the present invention generates a behavioral pattern score by obtaining the feature vector of the real-time operational behavior and calculating its weighted similarity with the center points of each cluster. The behavior is then judged to be normal based on the score and a preset threshold. If the score is below the threshold, it is automatically determined to be abnormal behavior, triggering a system alarm. Abnormal behaviors that do not belong to any known clusters are written into the abnormal pattern library as new abnormal patterns, and the cluster centers are updated to achieve model self-evolution. This mechanism supports regulatory behavior identification, risk discovery, and knowledge updating, enhancing the system's risk prevention and control capabilities and adaptive evolution capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is a flow chart of the power system control operation behavior analysis method;

[0048] Figure 2 System structure diagram for power system control operation behavior analysis. DETAILED DESCRIPTION

[0049] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. The embodiments described in this application are only part of the embodiments of the present invention, not all of them. Based on the spirit of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0050] Example 1

[0051] This embodiment provides a specific implementation method of a power system control operation behavior analysis method. Figure 1 , Figure 1 The following is a flow chart of the power system control operation behavior analysis method. This method includes the following steps:

[0052] S1: Collect various data during the power system control operation process through multiple systems such as the power system automation monitoring system, dispatching automation system, and operation ticket system, and perform pre-processing. Specifically including:

[0053] Obtain operating parameters such as voltage, current, frequency, and equipment status from the SCADA system; obtain the command content and execution process of the control operation from the operation ticket system; and obtain metadata such as operation time, personnel identity, and execution results from the event log system.

[0054] Preprocess the acquired multi-source regulatory data, including:

[0055] Data cleaning: Remove noise and abnormal data, such as incorrect timestamps, duplicate data records, and obviously unreasonable operation data.

[0056] Data conversion: Process data from different sources into a unified format, such as unifying the time format in different systems, standardizing device names and numbers, etc.

[0057] Data integration: Integrate the cleaned and converted data to form a standardized control operation data set to facilitate subsequent analysis and processing.

[0058] S2: Extract key operational behavior features from pre-processed multi-source control data, including:

[0059] Operation frequency: The number of operations within a period of time is collected through a time sliding window;

[0060] Operation duration: The duration of a single operation is obtained by taking the time difference between the start and end time of the operation;

[0061] Operation response time: Calculates the time difference between fault detection and operation execution;

[0062] Operation sequence matching score: Calculate the matching score between the execution process and the control standard process. The calculation method is matching score = 1-(number of incorrect operation sequence steps / total number of steps);

[0063] Operation type distribution: statistics on the proportion of each type of operation in the total number of operations;

[0064] Compliance Score: Based on a rule base, the system automatically assigns a score based on whether operational behavior adheres to operating procedures. The compliance score is defined as a quantitative indicator that measures whether operational behavior complies with pre-set rules, safety standards, or dispatch procedures, based on the standard operating procedure sequence defined in the Power Grid Dispatch Operating Procedures (e.g., "circuit breaker closing → transformer commissioning → load distribution"). A higher score indicates more standardized and safer operation.

[0065] Experts judge whether the operation complies with the preset rules. If the operation ticket steps are completely matched, the score is 1; if there are skipped steps or missed steps, points are deducted according to the number of violations; if safety regulations are violated, the score is 0. The calculation method is to train a scoring model based on historical data, and map the operation behavior to a compliance score, which is expressed as: Compliance score = 1-(number of illegal steps / total number of operation steps)

[0066] The extracted operational behavior features are processed uniformly using maximum and minimum normalization or Z-score standardization to obtain multi-source data features for input clustering.

[0067] S3: Based on the multi-source data features of S2, establish a mapping between operation behavior and grid status; specifically:

[0068] 3.1: Based on the multi-source control data collected by SCADA and other systems in S1, the grid status label is obtained by using the state recognition rules. Table 1 shows the labeling examples of operating parameters and grid status labels.

[0069] Table 1. Example of labeling of operating parameters and grid status labels

[0070]

[0071] 3.2: Based on the start time of the operation behavior, match the corresponding grid status label. For example, when the grid is in the "high load operation" state, if the "closing operation" is performed on circuit breaker A at time t, the grid status label corresponding to the closing operation at time t is "high load operation".

[0072] Combined with the operation behavior characteristics corresponding to S2's operation behavior, an example of the operation behavior record constructed in this step is as follows:

[0073] {Operation behavior: "Close";

[0074] Operation timestamp: "2025-06-05 11:13:41"

[0075] Device Type: "Circuit Breaker";

[0076] Grid status label: "High load operation";

[0077] Operation time: "8s";

[0078] Operation response time: "3.2s";

[0079] Operation order matching score: "0.92";

[0080] Operating frequency: "12";

[0081] Operation interval time: "56s";

[0082] Operation type distribution: "0.1";

[0083] Compliance score: "95%"}.

[0084] 3.3: Based on the operation behavior records constructed in 3.2, clustering is performed using the k-means++ clustering model; specifically:

[0085] The grid status label is encoded into a numerical form (e.g., "normal operation" = 0, "high load" = 1, "fault emergency" = 2, using manually defined label encoding) and added as an additional feature to the feature vector of the operation behavior record. The standardized feature vector of each operation behavior record is in the form of [x1, x2, ..., x n ,s], where x1 to x n is the operational behavior feature, n is the number of behavior features; s is the grid status label code.

[0086] 3.3.1: Select the initial centroid based on the grid status and response speed;

[0087] K-means++ clustering originally randomly selects a centroid as initialization. However, because the choice of centroid significantly affects the clustering effect of the k-means++ algorithm, improper initial centroid selection can cause the algorithm to fall into a local optimal solution, thereby affecting the quality of the clustering results. In power grid operation, response speed (the time it takes for dispatchers or on-site personnel to execute operating instructions) is a key factor affecting system stability and dispatch efficiency. In high-load or fault emergency scenarios, the power grid's response speed requirements for regulating resources (such as units, energy storage, and loads) are significantly increased, so response speed needs to be taken into consideration during clustering.

[0088] Therefore, this application adopts the centroid selection method driven by grid state optimization, that is, based on the current grid state label, the samples with fast response speed are selected as the centroid from the candidate samples. The selection process is as follows:

[0089] First, leveraging experience and historical data statistics, we set thresholds for response times corresponding to different grid status tags. Examples of threshold settings include: normal operation: response time ≤ 5s (average 3s, standard deviation 1.2s); high load: response time ≤ 3s (average 2.5s, standard deviation 0.8s); and fault emergency: response time ≤ 2s (average 1.8s, standard deviation 0.5s). The rationality of the thresholds was confirmed based on the typical response time distribution in a historical accident case database (e.g., the Power Grid Dispatch Operation Manual).

[0090] The weights of compliance score and response speed in the initial sample score are set; Table 2 gives some examples of weight mapping rules for power grid status labels.

[0091] Table 2 Some examples of weight mapping rules

[0092]

[0093] Then, the time difference between the time the instruction is issued and the time the operation is completed is recorded by timestamp, which is recorded as response time. Then, through standardization processing, the response time is normalized to the interval [0,1] and used in combination with the standardized feature vector.

[0094] For the standardized feature vector containing the grid status label code and response time, samples whose response time meets the threshold range set according to the grid status label are extracted; if the number of screened samples is insufficient (such as <10%), the threshold is relaxed (such as high load: response time ≤4s) and a log is recorded.

[0095] The weighted scores of the selected samples are calculated based on the comprehensive response speed and compliance scores:

[0096]

[0097] Among them, Score is the sample weighted score, ω r is the weight of response speed, ω c is the weight of compliance score, ω rf are the weights of other features; T res is the response time, Reflects response speed; Score compliance is the compliance score; RF is the remaining features in the normalized feature vector.

[0098] Sort the samples by weighted scores from high to low, and select the sample with the highest score as the initial centroid.

[0099] Taking the grid status of "high load" as an example, experts first confirm that the current load factor is >90%, which meets the definition of the "high load" label. Based on Table 2, the response time threshold is adjusted to ≤3s, the response speed weight is 0.6, the compliance score weight is 0.2, and the remaining feature weights are 0.2.

[0100] The weighted scoring formula is used to calculate samples A, B, and C respectively, and the weighted scores of the three samples are 0.404, 0.370, and 0.420. At this time, sample C is selected as the initial centroid.

[0101] 3.3.2: For the remaining samples except the selected centroid, calculate the square of the minimum Euclidean distance to the selected centroid D 2 (f), and construct the probability distribution:

[0102]

[0103] Among them, P(f i ) is the i-th sample f i The probability of being selected as the next centroid, D(f i ) is the sample f i The minimum distance to the selected centroid, is the D of all remaining samples except the selected centroid 2 (f i ), and m is the number of all samples screened out.

[0104] Then, the next centroid is selected according to this probability distribution, ensuring that samples far from the existing centroid are more likely to be selected. Repeat this step until k initial centroids are selected;

[0105] After completing the initial centroid selection, the k-means++ clustering operation is performed, and finally multiple typical operation behavior pattern clusters are obtained to characterize the distribution law of operation characteristics in scheduling behavior.

[0106] 3.4: The information of each type of pattern is formed into a structured behavior pattern library. Each behavior pattern library includes the feature center point, feature distribution, category label, etc. of each type. Specifically:

[0107] 3.4.1: Pattern feature extraction: Based on the cluster center points (Centroid) of multiple typical operation behavior pattern clusters output by the clustering model, extract the feature description of each cluster; including:

[0108] Feature center: records the mean of the feature vector of each cluster (such as the mean of operation frequency, mean of response time, mean of compliance score, etc.);

[0109] Feature distribution: Calculate the distribution range of each feature value in each cluster (such as the minimum, maximum, and standard deviation of the response time);

[0110] Category label mapping: Cluster numbers are mapped to business-understandable labels (such as "high-frequency and high-efficiency," "incorrect operation," and "inefficient regulation"). This is primarily determined by power dispatch experts and encoded based on the semantic relevance of business scenarios and operational behavior characteristics. Each label corresponds to an integer. Table 3 shows examples of cluster characteristics from the clustering output.

[0111] Table 3: Example table of cluster features output by clustering

[0112]

[0113] 3.4.2: Behavioral pattern library structure design and storage; use a structured database (relational database, DAMO in production environment, MySQL in debugging environment, etc.) to store pattern information, and the table contains the following fields: Pattern ID: unique identifier; Feature center point: stores the mean of each feature; Feature distribution: records the statistical range of the feature (minimum value, maximum value, standard deviation); Grid status label: the grid status corresponding to the pattern (such as "high load", "fault emergency"); Weight mapping rule: dynamic weight allocation of each feature under this pattern (such as response speed weight = 0.6); Pattern scoring threshold: matching threshold used for subsequent real-time evaluation (such as similarity ≥ 0.85 is normal, <0.7 is abnormal, mainly based on historical data and manual experience assignment).

[0114] The following is an example of table structure data:

[0115]

[0116] S4: Real-time operational behavior evaluation based on pattern library;

[0117] 4.1: Collect data from the automated monitoring system, dispatching automation system, and operation ticket system in real time, and extract real-time behavior feature vectors and real-time grid status labels.

[0118] 4.2: Dynamically adjust the weights of each feature in the clustering model based on the grid status label; specifically:

[0119] Deploy a grid status change listener (using Kafka message queues) to detect status tag changes in the SCADA system in real time;

[0120] Once the grid status tag is updated, the weight update process is triggered, including:

[0121] According to the current grid state, the feature weight corresponding to the new grid state label is obtained from the weight mapping table (Table 2).

[0122] For example, if the real-time grid status label is updated from "high load" to "fault emergency", the response speed weight and compliance score weight are extracted as 0.8 and 0.1 respectively.

[0123] 4.3: Call the S3 clustering model (k-means++ clustering model), update feature weights in real time and trigger local clustering updates; including:

[0124] (1) Push the dynamic weight configuration to the clustering model service through the preset model service interface (RESTful API is selected in this embodiment). The request parameters are as follows:

[0125]

[0126] Weight mapping rule table linkage: The model service queries the corresponding weight allocation rule from the preset weight mapping rule table based on the parameter grid_state and verifies the validity of the parameters (for example, whether the sum of the weights is 1). If the verification fails, the update is rejected and a log is recorded.

[0127] (2) Real-time update of feature weights

[0128] After receiving the weight update request, the model service dynamically weights the relevant operation behavior feature vectors, that is, updates the feature weights in real time according to the current grid status labels, and multiplies the dynamic weights by the feature vectors to form a weighted feature vector.

[0129] (3) Local cluster update and cluster center optimization

[0130] When the grid status label changes (such as switching from "high load" to "fault emergency"), the model service only performs local clustering updates on the new data and affected clusters (such as clusters sensitive to response speed) instead of fully retraining the model.

[0131] (4) Local clustering update step:

[0132] a. Data screening: Extract samples that match the current grid status label (such as operation behavior records in the "fault emergency" state) from the incremental data collected in real time.

[0133] b. Weighted score calculation: For the screened samples, the relevant operational behavior feature vectors are dynamically weighted. That is, the feature weights are updated in real time according to the current grid status labels, and the sample weighted scores are recalculated based on the new weights.

[0134] c. Local clustering execution: Execute the k-means++ clustering model only for the affected clusters (such as clusters significantly affected by the change in response speed weights) to perform local updates:

[0135] d. Cluster center point update record: The updated cluster center point is stored in the behavior pattern library (i.e., step 4) and marked with the update timestamp and grid status label.

[0136] (5) Exception handling and rollback mechanism: If an exception occurs in the model service during the weight update or local clustering process (such as network interruption, parameter error), it will roll back to the most recent valid weight configuration and cluster center point.

[0137] (6) Update the local cache of the clustering model (saved in the Redis database) to ensure that the latest weights are used in subsequent similarity calculations.

[0138] (7) Synchronously update the behavior pattern library, including updating the feature center points, distribution range, weight mapping rules, etc. in the pattern library.

[0139] 4.3: Calculate the similarity between the current operation behavior and the center of the behavior pattern; including:

[0140] Extract standardized behavioral feature vectors from real-time multi-source data (such as SCADA systems, operation ticket systems, and event logs); obtain cluster centers corresponding to the current power grid status labels from the behavioral pattern library;

[0141] Calculate the distance between the real-time behavior feature vector and the center point of each cluster and normalize it to similarity as the pattern score;

[0142] Select the cluster with the highest pattern score and record its cluster label;

[0143] Based on the pattern score, real-time operation behaviors are classified as abnormal behaviors: when the pattern score is ≥0.85, it is normal behavior; when the pattern score is in [0.7, 0.85), it is potential abnormal behavior, triggering manual review; when the pattern score is <0.7, it is abnormal behavior, triggering a system warning.

[0144] Update the pattern library based on the abnormal behavior classification; the update strategy is:

[0145] Normal behavior: its feature vector is added to the cluster sample pool and the cluster center is updated regularly;

[0146] Abnormal behavior: If it is confirmed to be a new abnormal pattern, its feature vector is added to the existing abnormal pattern library, and the cluster center point is expanded or a new cluster is added.

[0147] As an optional step of this embodiment, feedback linkage and adaptive update mechanism are also included; specifically:

[0148] 1. Feedback data collection, including:

[0149] (1) When real-time operation behavior is judged as "potential anomaly" or "abnormal behavior", the system automatically triggers the manual review process (notifying the dispatcher or expert). The review results (such as "false alarm", "needs correction", "new abnormal pattern") are transmitted back to the system through a dedicated interface (such as web form, API).

[0150] (2) Record the handling process of all warning events (such as warning time, response personnel, disposal measures, and result status) to evaluate the accuracy and effectiveness of the warning system.

[0151] (3) System operation log: including clustering model update records, pattern library change logs, feature weight adjustment records, etc., used to trace the historical trajectory of system dynamic adjustments.

[0152] (4) User operation feedback: The dispatcher or operation and maintenance personnel manually mark the system suggestions (operation compliance score, pattern matching results) through the visual interface (including "adopt", "ignore", "correct", etc.) as the basis for optimization.

[0153] 2. Feedback data classification and labeling

[0154] (1) Classification by type: Feedback data is divided into “mode correction type” (such as cluster center point update requirements), “parameter adjustment type” (such as weight mapping rule optimization requirements), “abnormal mode addition type” (such as newly discovered illegal operation modes) and “system optimization type” (such as interface interaction improvement requirements).

[0155] (2) Priority labeling: Feedback data is prioritized (e.g., “high,” “medium,” or “low”) based on its business impact. For example, the priority for abnormal mode correction related to power grid security is “high,” while the priority for interface interaction optimization is “low.”

[0156] As an optional step of this embodiment, a dynamic update mechanism of the pattern library is also included; specifically:

[0157] 1. Normal mode update process

[0158] (1) Incremental sample integration:

[0159] For normal behaviors with a similarity score ≥ 0.85, their feature vectors (such as operation frequency, response time, and compliance score) are automatically archived to the training sample pool of the corresponding cluster.

[0160] (2) Periodic cluster retraining, the system performs batch update tasks every morning:

[0161] a. Extract new data from the sample pool and rerun the k-means++ clustering algorithm based on historical data to generate new cluster centers.

[0162] b. Compare the differences between the new and old cluster centers (such as Euclidean distance changes, feature distribution shifts). If the difference exceeds a preset threshold (such as 5%), update the behavior pattern library.

[0163] 2. Abnormal mode update process

[0164] (1) Adding new modes after manual confirmation

[0165] When manual review confirms that a "potential abnormal" behavior is a new abnormal pattern, the system automatically adds its feature vector to the abnormal pattern library and assigns a unique pattern ID. For example:

[0166] {

[0167] "Mode ID":"C4",

[0168] "Feature Center Point":{"Operation Frequency":25,"Response Time":15.0,"Compliance Score":0.3},

[0169] "Feature Distribution":{"Response Time":{"min":12.0,"max":18.0,"std":2.5}},

[0170] "Grid status label": "Fault emergency",

[0171] "Category Label": {"Name":"Inefficient Regulation","Value":4}

[0172] }

[0173] (2) Exception pattern expansion and merging

[0174] If the features of multiple abnormal samples are highly similar (e.g., response time > 15s, compliance score < 0.4), the system prompts the expert whether to merge them into the same cluster.

[0175] (3) Archiving of historical abnormal patterns

[0176] For abnormal patterns that have not appeared for a long time (such as no matching records in the past 6 months), the system will mark them as "historical patterns" and archive them for future reference but they will no longer participate in real-time evaluation.

[0177] As an optional step of this embodiment, dynamic adjustment of system parameters is also included; specifically:

[0178] 1. Optimization of weight mapping rules

[0179] (1) Weight correction based on feedback:

[0180] Adjust the weight mapping rule table based on manual review results. For example:

[0181] If the response speed weight of a certain power grid state (such as "fault emergency") is frequently marked as "too low", its weight is increased to 0.9.

[0182] If the weight of a feature (such as "operation type distribution") is proven to contribute less to anomaly detection, its weight is reduced.

[0183] (2) Automatic learning rules: The system automatically generates weight adjustment suggestions for expert review by statistically analyzing the importance of features in the feedback data (e.g., the response time ratio in abnormal patterns is >80%).

[0184] 2. Dynamic calibration of threshold

[0185] (1) Similarity score threshold adjustment:

[0186] Dynamically adjust the similarity score threshold based on the warning accuracy. For example:

[0187] If the false positive rate of "potential anomaly" is >30%, the threshold is increased from 0.7 to 0.75.

[0188] If the "abnormal behavior" false negative rate is >10%, the threshold is lowered from 0.7 to 0.65.

[0189] (2) Response time threshold optimization:

[0190] Combined with the historical accident case library (such as the Power Grid Dispatch Operation Manual), regularly calibrate the response time thresholds under different power grid conditions. For example:

[0191] If the average actual response time under the "high load" state increases from 3s to 4s, the updated threshold is ≤4s.

[0192] Example 2

[0193] This embodiment describes the system structure and module functions of this application. Figure 2 The system structure of this application can be divided into four layers, from bottom to top: data acquisition layer, processing and analysis layer, feedback layer and access layer. Among them:

[0194] 1. Data Collection Layer: This layer is the foundational support layer for the system and is responsible for collecting heterogeneous data from multiple sources. Specific functions include: Multi-source data access: connecting to the SCADA system, operation ticket system, event log system, dispatch automation system, and fault emergency system to collect grid operating parameters (voltage, current, frequency), operation command content, metadata (operation time, personnel identity, execution results), and accident handling records.

[0195] 2. Processing and Analysis Layer: This layer is the core business logic layer of the entire system and consists of data preprocessing, feature extraction, cluster analysis, real-time evaluation modules, and a pattern library. Specific functions include:

[0196] (1) Data preprocessing: Receive the raw data from the data acquisition layer and form a structured control operation data set through steps such as cleaning, conversion, and integration, laying a good foundation for extraction and analysis.

[0197] (2) Feature extraction: Extract normalized feature vectors based on standardized data sets to provide input for cluster analysis.

[0198] (3) Cluster analysis: The k-means++ algorithm is used to dynamically adjust the initial centroid selection and feature weights in combination with the grid status labels to generate typical operation behavior pattern clusters and build a structured behavior pattern library.

[0199] (4) Real-time evaluation: Dynamically adjust the feature weight according to the grid status label, calculate the similarity between the real-time operation behavior and the center point of the pattern library cluster, and classify the behavior according to the scoring threshold.

[0200] (5) Pattern library: stores structured clustering results and dynamically updated clustering information, and supports query and expansion of pattern features.

[0201] 3. Feedback layer: The feedback layer realizes the closed loop of business processes and improves the accuracy of power system control operation behavior analysis through mechanisms such as manual review, early warning response and adaptive update. Specifically including:

[0202] (1) Manual review function: Trigger the review process for abnormal behavior, receive feedback from dispatchers or business experts, and send the corrected data back to the model database.

[0203] (2) Early warning response module: records the processing process of early warning events (such as response time and disposal measures) to evaluate system performance and optimize early warning strategies.

[0204] (3) Adaptive update module: dynamically update the pattern library, archive the normal behavior feature vectors to the corresponding sample pool, and regularly retrain the clustering model; expand the corresponding pattern library data after abnormal behavior is manually confirmed; optimize the weight mapping rules based on feedback data, calibrate the similarity score threshold and response time threshold.

[0205] 4. Access layer: User access interaction layer, which provides a visual interface and can be accessed through a computer browser on the information intranet. It includes functions or pages such as real-time display of power grid status labels, abnormal warning information display, operation behavior pattern scoring, pattern library query, clustering result query, etc.

[0206] As an optional implementation, modules implement data transmission and interaction through message queues, interfaces, and internal data channels. The data acquisition layer transmits raw data to the processing and analysis layer; the processing and analysis layer preprocesses the raw data, extracts features, performs cluster analysis, and saves the data, transmitting the results to the access layer for display. The feedback layer transmits the data back and reversely updates the pattern library, forming a closed-loop business process.

[0207] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A method for analyzing power system control operation behavior, characterized in that: include: Acquire multi-source control data from the power system and perform pre-processing; Extracting operational behavior features from pre-processed multi-source regulatory data; Matching the operation behavior to the corresponding grid status label according to the start time, and constructing the operation behavior record based on the operation behavior characteristics as the input of the clustering operation; Based on the operation behavior records, the initial centroid is selected according to the grid status label and response speed; Perform clustering operations to obtain multiple operation behavior pattern clusters, extract cluster features, and design the behavior pattern library structure; Collecting real-time multi-source control data, dynamically adjusting feature weights in the clustering operation based on real-time grid status tags, performing local clustering updates, and updating cluster features in the pattern library; Calculate the pattern scores of real-time operation behaviors and updated pattern libraries, and classify real-time operation behaviors as abnormal.

2. A method for analyzing power system control operation behavior according to claim 1, characterized in that: The operation behavior characteristics include an operation sequence matching score and a compliance score; The operation sequence matching score is calculated by comparing the execution process of the operation behavior with the control standard process. The matching score is equal to 1-(number of wrong operation sequence steps / total number of steps). The execution process of the operation behavior is compared with the preset rules to calculate the compliance score, which is equal to 1-(number of violation steps / total number of steps).

3. The method for analyzing power system control operation behavior according to claim 1, characterized in that: The construction process of the operation behavior record includes: Based on the multi-source control data, a state identification rule is used to obtain a power grid state label; Based on the multi-source control data at the start of the operation behavior, the operation behavior is matched with the corresponding grid status label; The operation behavior features corresponding to the operation behavior are combined with the matching power grid state labels to construct an operation behavior record, which is used to input into the clustering model.

4. The method for analyzing power system control operation behavior according to claim 1, characterized in that: The steps of selecting the initial centroid include: The time difference between the time when the operation instruction is issued and the time when the operation is completed is recorded as the response time through the timestamp, and the initial samples whose response time meets the threshold range are selected according to the grid status label; Set the weights of compliance score and response speed in the initial sample score, calculate the sample weighted score for the initial sample; select the initial sample with the highest score as the initial centroid; For the initial samples other than the selected initial centroid, calculate the square of the minimum Euclidean distance to the selected initial centroid and construct a probability distribution; select the next centroid according to the probability distribution until k initial centroids are selected.

5. The method for analyzing power system control operation behavior according to claim 1, characterized in that: The behavior pattern library structure includes: Cluster characteristics, grid status labels, weight mapping rules, and pattern scoring thresholds; The cluster features include the feature center point, feature distribution, and category mapping label of each behavior pattern cluster; wherein the category mapping label is encoded by the semantic association between the business scenario and the operation behavior feature, and each label corresponds to an integer.

6. The method for analyzing power system control operation behavior according to claim 1, characterized in that: The dynamically adjusting the feature weights in the clustering operation according to the real-time grid status tag includes: When the grid status tag is updated, the weight update process is triggered; the updated compliance score and response speed weight are obtained through the weight mapping rules; Extract and filter samples that match the current grid status label from the incremental data collected in real time. Recalculate the weighted scores of the filtered samples based on the new weights. Perform local clustering updates and write the updated cluster features into the behavior pattern library.

7. The method for analyzing power system control operation behavior according to claim 1, characterized in that: The process of classifying abnormal behavior of real-time operation behavior includes: Calculate the distance between the feature vector of the real-time operation behavior and the center point of each cluster and normalize it to similarity as the pattern score; Select the cluster corresponding to the maximum pattern score, and classify the real-time operation behavior into abnormal behavior according to the pattern score division threshold; If the classification result is normal behavior, the feature vector of the real-time operation behavior is added to the cluster sample pool; If the classification result is abnormal behavior, an early warning of the power system is triggered; if the abnormal behavior is a new abnormal pattern, the feature vector of the real-time operation behavior is added to the existing abnormal pattern library and the cluster center point is expanded.

8. A power system control operation behavior analysis system, running the control operation behavior analysis method according to any one of claims 1 to 7, the system comprising: Data acquisition module; Acquire multi-source control data from the power system and perform pre-processing; Extracting operational behavior features from pre-processed multi-source regulatory data; Feature extraction module; Matching the operation behavior to the corresponding grid status label according to the start time, and constructing the operation behavior record based on the operation behavior characteristics as the input of the clustering operation; Cluster analysis module; Based on the operation behavior records, the initial centroid is selected according to the grid status label and response speed; Perform clustering operations to obtain multiple operation behavior pattern clusters, extract cluster features, and design the behavior pattern library structure; Real-time analysis module; Collecting real-time multi-source control data, dynamically adjusting feature weights in the clustering operation based on real-time grid status tags, performing local clustering updates, and updating cluster features in the pattern library; Abnormal evaluation module: calculates the pattern scores of real-time operation behavior and updated pattern library, and classifies real-time operation behavior into abnormal behavior.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the computer program is loaded into a processor, the control operation behavior analysis method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the control operation behavior analysis method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Power dispatching whole process evaluation computer device, method and equipment

    CN111144747A

  • Power grid dispatching business operation normalization evaluation system and method

    CN119962861A