Intelligent monitoring method and system based on dual-mode communication
By constructing a spectral feature library and cross-modal support, and establishing a time-link matrix for multi-level detection, the problem of insufficient utilization of signal correlation and complementarity in dual-mode communication is solved, and noise interference can be quickly identified and accurately distinguished, thereby improving the accuracy and response speed of communication monitoring.
Patent Information
- Application Number
- CN202511050927.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-07-29
Smart Images

Figure CN120692171A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of dual-mode communication, and in particular to an intelligent monitoring method and system based on dual-mode communication. Background Art
[0002] In power line communication, due to the presence of power line environmental noise, its characteristics are similar to real signal attenuation, which leads to misjudgment in communication quality monitoring and affects the stable operation of the power network.
[0003] Current dual-mode communication technologies, such as the fusion of HPLC (high-speed broadband power line carrier communication) and HRF (micropower radio communication), have improved communication reliability and flexibility to a certain extent. However, these technologies often focus on monitoring and switching within a single mode, overlooking the potential correlations and complementarities between different signals. In particular, when fusing different communication modes, existing methods fail to fully account for the dynamic correlations between signals in time and space, as well as cross-modal complementarities. This limits the accuracy and responsiveness of communication quality monitoring, making it difficult to meet the high real-time and accuracy requirements of smart grids. Summary of the Invention
[0004] This application solves the problem that the existing technology fails to fully consider the dynamic correlation of signals in time and space dimensions and the complementarity across modalities by providing an intelligent monitoring method and system based on dual-mode communication, and achieves the technical effect of improving the accuracy of communication monitoring based on the correlation and complementarity between different communication modes.
[0005] This application provides an intelligent monitoring method based on dual-mode communication, including:
[0006] S1: Obtain basic data information, extract multi-dimensional signal features to build a spectrum feature library, and calculate real-time noise similarity; if the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly; if the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained;
[0007] S2: Calculate the cross-modal support between the two signals based on the multi-dimensional signal characteristics. If the cross-modal support is greater than 0.7, establish a time-link matrix and set up a multi-level detection mechanism to detect abnormal signals; the multi-level detection mechanism includes instantaneous anomaly capture, spatiotemporal propagation analysis, and composite anomaly index;
[0008] S3: Mark the detected abnormal signals as propagation source nodes, extract signal feature fingerprints, mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation characteristics of all nodes in the second range, and generate a secondary abnormal propagation graph;
[0009] S4: Analyze causal characteristics based on the secondary anomaly propagation graph, determine the causal path, identify risk indicators to obtain the risk index, and predict the threat level.
[0010] Furthermore, the method further comprises:
[0011] S5: Generate cross-layer policies based on threat levels, including signal layer, device layer, and network layer; detect cross-layer conflicts and set execution priorities for hierarchical execution;
[0012] S6: Obtain causal characteristics and causal paths to group the system according to constraints; construct a causal map within the group and evaluate the risk status within the group in real time, and set the intra-group collaboration strategy; evaluate the global risk status and dynamically choose whether to trigger the cross-group collaboration strategy; the constraints are to maximize the strength of the causal relationship within the group and minimize the causal interaction between groups.
[0013] Furthermore, the cross-modal support is a quantitative indicator used to measure the feature complementarity of two different communication modes in different dimensions, and its range is [0, 1]; the cross-modal support includes a time domain complementarity coefficient and a spatial domain synergy index, the time domain complementarity coefficient is the comprehensive coefficient minus the absolute value of the difference between HPLC time domain stability and HRF time domain stability, and the comprehensive coefficient is 1; the spatial domain synergy index is the covariance of HPLC node correlation and HRF spatial gradient; the cross-modal support is the sum of the time domain complementarity coefficient and the spatial domain synergy index.
[0014] Furthermore, the spatiotemporal propagation analysis obtains the spatiotemporal propagation state based on the time-link matrix, obtains the propagation characteristics of the nodes within the first range, and constructs a main anomaly propagation graph, including: monitoring the signal characteristics of each node within the first range, finding the node where the anomaly characteristics first appear as the starting position of the anomaly; continuously monitoring the changes in the signal characteristics of each node within the first range at subsequent time points, recording the order and direction of the propagation of the anomaly from one node to the adjacent nodes; measuring the time required for the anomaly to propagate from one node to the adjacent nodes, and calculating the propagation speed; forming the main anomaly propagation graph based on the node where the anomaly first appears, the propagation path, and the diffusion speed;
[0015] The first range is centered on an abnormal signal node, and includes nodes directly connected to it and an area covered by one or two levels of relay nodes; the first range is smaller than the second range.
[0016] Furthermore, the second range is centered on the propagation source node, identifies the diffusion influence of each node, pre-sets a minimum influence threshold, and is the area covered by nodes whose diffusion influence is greater than the minimum influence threshold;
[0017] Calculating the diffusion influence of each node involves simulating independent activation behavior between nodes and the cumulative effect of the influence of neighbors on a node. Independent activation refers to the probability that a node will independently trigger propagation through its own direct connections, based on the number of direct connections between nodes. The cumulative effect refers to the probability that a node will trigger propagation through the indirect influence of multi-hop neighbors. A weighted average of the independent activation behavior and the cumulative effect is taken as the final propagation probability.
[0018] Obtain all path distances between any two nodes to obtain the average path distance, and determine the corresponding path influence propagation degree based on the average path distance as the path influence value, which ranges from [0, 1];
[0019] The final propagation probability, exponential decay function, and path influence value are normalized and then weighted summed to obtain the diffusion influence degree of each node.
[0020] Furthermore, the causal characteristics include temporal causality, spatial causality, and intensity correlation; temporal causality is the order of abnormal events in the temporal dimension, spatial causality is the diffusion path of abnormal events in the spatial dimension, and intensity correlation is the intensity change of abnormal signals during the propagation process;
[0021] The risk indicators are used to quantify the risk level of abnormal propagation, and the risk indicators include propagation speed, root cause overlap, and potential impact.
[0022] An intelligent monitoring system based on dual-mode communication, the system comprising:
[0023] The data collection and initial screening module is used to obtain basic data information and calculate the real-time noise similarity. If the real-time noise similarity is greater than the similarity threshold, the first anomaly is output. If the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained.
[0024] The dual-mode time-link module is used to calculate the cross-modal support between the two signals based on the multi-dimensional signal characteristics. If the cross-modal support is greater than 0.7, a time-link matrix is established and a multi-level detection mechanism is set up to detect abnormal signals.
[0025] The abnormal propagation image generation module is used to obtain the spatiotemporal propagation state based on the time-link matrix, obtain the propagation characteristics of the nodes within the first range, and construct the main abnormal propagation map; mark the detected abnormal signals as the propagation source nodes, extract the signal feature fingerprint, and mark the first diffusion node, mutation node, and intersection node; obtain the propagation characteristics of all nodes in the second range and generate the secondary abnormal propagation map;
[0026] The causal analysis module is used to analyze causal characteristics based on the secondary anomaly propagation graph, determine the causal path, identify risk indicators to obtain the risk index, and predict the threat level;
[0027] The grouping module is used to obtain causal features and causal paths to group the system according to the constraints;
[0028] The strategy generation module is used to generate cross-level strategies according to the threat level, detect cross-level conflicts, and set execution priorities for hierarchical execution; build a cause-and-effect diagram within the group and evaluate the risk status within the group in real time, set the collaboration strategy within the group; evaluate the global risk status and dynamically choose whether to trigger the cross-group collaboration strategy.
[0029] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0030] By collecting multi-dimensional signal features and building a spectrum feature library, we can quickly identify noise interference, effectively distinguish between communication problems and noise interference, and improve noise identification accuracy. We can quantify the time domain complementarity and spatial domain synergy of HPLC and HRF modes, generate new feature vectors based on cross-modal support, fuse dual-mode signal features, eliminate single-mode perception blind spots, dynamically adjust feature fusion strategies, accurately identify the correlation and complementarity between different modes, and improve monitoring accuracy. We can also construct a communication network topology diagram, combine it with the node spatial coordinate database, set association rules to obtain a time-link matrix, and locate the source of the anomaly through a multi-level detection mechanism. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 Schematic diagram of a flow chart of an intelligent monitoring method based on dual-mode communication in an embodiment of the present invention;
[0032] Figure 2 This is an architecture diagram of an intelligent monitoring system based on dual-mode communication in an embodiment of the present invention. DETAILED DESCRIPTION
[0033] To facilitate understanding of the present invention, the present application will be described more comprehensively below with reference to the relevant drawings; the drawings show preferred embodiments of the present invention, but the present invention can be implemented in many different forms and is not limited to the embodiments described herein; on the contrary, the purpose of providing these embodiments is to enable a more thorough and comprehensive understanding of the disclosed content of the present invention.
[0034] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this invention pertains; the terms used herein in the specification of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention; the term "and / or" used herein includes any and all combinations of one or more of the associated listed items.
[0035] Example 1: Figure 1As shown, an intelligent monitoring method based on dual-mode communication, the method includes:
[0036] S1: Obtain basic data information, extract multi-dimensional signal features to build a spectrum feature library, and calculate the real-time noise similarity; if the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly; if the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained.
[0037] In this embodiment, basic data information is obtained from the target node (such as a smart meter, concentrator or transformer terminal) by active polling (such as periodically sending query instructions) or passive reception (such as monitoring data uploaded by the node). The basic data information includes the device information, communication mode and basic signal information of the target node; the device information includes the node number (the unique identifier of the device in the communication network, used to locate the device in the network), signal timing information (recording the time series and path information of signal transmission, used to track the source and flow of the signal), device type (distinguishing different devices such as smart meters, concentrators, transformer terminals, etc., to adapt the feature analysis strategy) and device status flag (indicating whether the device is in normal, standby or fault state); the communication mode marks the HPLC or HRF mode currently used by the device; the basic signal information refers to the carrier signal, modulation signal and noise signal. This embodiment uses dual-channel parallel acquisition, that is, the main communication frequency band and the environmental noise frequency band are collected at the same time, and a timestamp and frequency mark are added to each signal sample; the main communication frequency band collects the carrier signal (the continuous wave signal of the main frequency band) and the modulation signal (the actual data signal of the modulated signal); the environmental noise frequency band collects the noise signal (environmental interference signal, such as industrial inverter noise).
[0038] The multi-dimensional signal characteristics are used to quantify signal quality, and the multi-dimensional signal characteristics include but are not limited to frequency distribution, harmonic content, signal-to-noise ratio (SNR), bit error rate (BER) and fluctuation index; the frequency distribution refers to the energy distribution of the carrier signal in different frequency bands, reflecting the frequency domain characteristics of the signal; the harmonic content is expressed as total harmonic distortion (THD), which is used to measure the degree of signal distortion (a high value indicates that the signal is distorted by environmental interference); the signal-to-noise ratio is used to indicate signal quality, and a high value indicates a clear signal; the bit error rate is obtained by decoding a standard test frame (the test frame is sent by the system), reflecting the reliability of data transmission (a low value indicates accurate transmission); the fluctuation index is used to measure the severity of the change in signal amplitude, and is calculated by analyzing the carrier signal envelope (amplitude change) (a high value indicates an unstable signal), and the range is [0, 1).
[0039] In some embodiments, multidimensional signal features are extracted based on basic data information. This includes applying an FFT (Fast Fourier Transform) or wavelet transform to the carrier signal to convert the time domain signal into the frequency domain, calculating the energy distribution of each frequency band, and generating frequency distribution features. The sub-band division is based on the characteristics of the communication frequency band (for example, 2-30 MHz is divided into 10 sub-bands). The fundamental (main frequency) energy and harmonic (integer multiple frequency) energy are extracted from the carrier signal, and the harmonic content is calculated using frequency domain integration. The fundamental frequency is determined by the communication standard (for example, the 12 MHz fundamental in HPLC). The SNR is extracted by separating the signal power (the average power of the carrier signal) and the noise power (the average power in the ambient noise band), calculating the ratio using power spectral density, and converting it to dB units. The BER is calculated by sending a predefined test frame (for example, a 256-bit pseudo-random sequence). The receiving end decodes and compares the difference between the transmitted and received data to count the number of error bits. The fluctuation index is calculated by performing envelope detection on the carrier signal (using a Hilbert transform or peak detection), calculating the standard deviation and mean of the envelope signal, and obtaining the fluctuation index. The above feature extraction techniques are common and are not specifically limited in this embodiment.
[0040] In some embodiments, a spectral feature library is constructed to store a database of typical noise spectral features for noise identification. Environmental noise templates (such as inverter noise and motor interference) are pre-collected or learned. Each template includes the noise type, spectral feature vector (primarily based on frequency distribution), and statistical attributes (historical mean, standard deviation). Specifically, before system deployment or during low-load periods, noise signals (only in the ambient noise frequency band of 0-500kHz) are collected under various typical noise scenarios. Examples include industrial inverter noise (characteristic: 150Hz harmonic peak), residential household appliance interference (characteristic: broadband white noise), and natural interference (such as lightning pulses). At least 100 samples are collected for each noise type. Frequency domain analysis is performed on each noise sample to extract a spectral feature vector. Key elements include the main peak frequency, bandwidth, and harmonic distribution. The noise feature vector, noise type label (such as "inverter harmonics"), and historical statistics (mean, standard deviation) are stored in a database. The noise type label is generated by manual labeling or automatic clustering. During normal operation, when the system detects a new noise pattern (with a similarity lower than the pre-defined similarity threshold, which is dynamically set based on historical data), it automatically adds a new template and calculates historical parameters for each template: mean noise power, mean harmonic content, etc.
[0041] In some embodiments, the real-time noise similarity is a scalar value between 0 and 1, indicating the degree of similarity between the real-time noise spectrum and a noise template in a spectral signature library. Higher values (closer to 1) indicate a close match between the noise and the template (e.g., 0.95 indicates 95% similarity), useful for identifying known interference sources. The parameter deviation indicates the degree to which current signal parameters (e.g., SNR, BER) deviate from their historical baseline values. The historical baseline is derived from the average parameters under normal conditions (stored in the past 24 hours of historical data).
[0042] Based on historical experimental data and specific needs, a noise similarity threshold (for example, 95%) is pre-set. If the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly. That is, if the real-time noise similarity is greater than 95%, it is marked as the first anomaly, that is, the corresponding anomaly is determined to be a noise anomaly, and the abnormality of the communication mode is excluded. Only the abnormality of the device noise needs to be processed; if the real-time noise similarity is not greater than 95%, the abnormality of the communication mode cannot be excluded, and the parameter deviation is calculated to obtain the initial anomaly value, and the abnormality of the communication mode is further judged based on the initial anomaly value.
[0043] In some embodiments, the parameter deviation refers to the SNR deviation rate, BER growth rate and harmonic distortion rate deviation. The above deviation indices are obtained by comparing the real-time data with the mean of historical data to obtain the corresponding deviation data, and the acquired data is normalized, the corresponding weight coefficient is pre-set, and the weighted sum is performed to obtain the initial outlier value.
[0044]
[0045] Where R is the initial outlier value; They are SNR deviation rate, BER growth rate and harmonic distortion rate deviation; are the corresponding weight coefficients respectively.
[0046] In some embodiments, the normal range of the initial abnormal value is adaptively based on historical data and dynamically adjusted according to actual conditions. The first threshold and the second threshold are pre-set according to historical data or experimental records. For example, the first threshold is set to 0.6 and the second threshold is set to 0.3. Then, normal: initial abnormal value <0.3 (parameter deviation is less than the threshold); warning: 0.3≤initial abnormal value <0.6 (potential abnormality, reverse test is performed, and the treatment plan is further determined based on the reverse test results); abnormal: initial abnormal value ≥0.6 (confirmed abnormality).
[0047] In some embodiments, the anomaly type is preliminarily determined based on the initial anomaly value and pre-set first and second thresholds. These anomaly types include environmental noise interference, line attenuation, and device failure. If the anomaly type is "line attenuation failure" and the reverse test result consistency rate is greater than 90% (the reverse test compares the consistency of the original signal with the retransmitted signal), the communication mode is immediately switched (for example, from HPLC to HRF). Reason: A sustained decrease in SNR indicates physical line attenuation; HRF mode (radio) can bypass line issues. If the anomaly type is "device hardware failure" and the reverse test result consistency rate is greater than 90%, the communication mode is switched and the failure is reported. Reason: An increased BER indicates an internal device error; switching to a backup mode ensures communication continuity. If the anomaly is environmental noise interference (Type 1), the mode is not switched (only power is increased); noise is not mode-dependent. If the reverse test result consistency rate is less than 90%, reassessment (supplemental testing) is required to avoid mis-switching. Mode switching is only initiated when physical layer or device issues are confirmed to ensure resource efficiency. Mode switching commands are sent over a reliable channel, and the connection status is verified in the new mode.
[0048] If the initial outlier value is greater than a preset first threshold, execute step S2: calculate the cross-modal support between the two signals based on the multidimensional signal characteristics. If the cross-modal support is greater than 0.7, establish a time-link matrix and set a multi-level detection mechanism to detect abnormal signals; the multi-level detection mechanism includes instantaneous anomaly capture, spatiotemporal propagation analysis, and composite anomaly index.
[0049] In some embodiments, the cross-modal support is a quantitative indicator used to measure the feature complementarity of two different communication modes in different dimensions, and its range is [0, 1]. A spatiotemporal synchronous acquisition system is constructed, and a functional high-precision clock module is used to ensure the time alignment of HPLC and HRF signal acquisition. A node spatial coordinate database is established to record the physical location of each node in the power distribution network. Multidimensional signal features are classified into types, including time domain features, frequency domain features, and spatial domain features, and the HPLC feature set and HRF feature set are obtained respectively. The time domain features in the HPLC feature set include: signal intensity fluctuation rate, envelope mutation count; frequency domain features include: harmonic distortion spectrum, signal-to-noise ratio distribution; spatial domain features include: adjacent node signal correlation matrix; the time domain features in the HRF feature set include: signal attenuation slope, packet loss rate; frequency domain features include: spectrum flatness, frequency deviation index; and spatial domain features include: spatial propagation attenuation gradient.
[0050] In some embodiments, cross-modal support is calculated based on multidimensional signal features, including a time-domain complementarity coefficient and a spatial-domain synergy index. The time-domain complementarity coefficient is the comprehensive coefficient minus the absolute value of the difference between the HPLC time-domain stability and the HRF time-domain stability, and the comprehensive coefficient is 1. The spatial-domain synergy index is the covariance between the HPLC node correlation and the HRF spatial gradient. The cross-modal support is the sum of the time-domain complementarity coefficient and the spatial-domain synergy index. HPLC time-domain stability is used to quantify power line signal amplitude fluctuations (1-fluctuation index), reflecting sudden changes in grid impedance; HRF time-domain stability is used to quantify wireless transmission continuity (1-packet loss rate), reflecting spatial channel quality. HPLC time-domain stability and HRF time-domain stability provide input for the cross-modal time-domain complementarity coefficient, dynamically guiding the feature fusion strategy, avoiding dual-mode mutual drag under a single fault mode, and improving the system's robustness in complex interference environments.
[0051] In this embodiment, the signal features extracted from the HPLC and HRF communication modes are mathematically combined based on cross-modal support to generate a more comprehensive and robust new feature vector, thereby solving the perception blind spots of a single communication mode and enhancing the accuracy of anomaly detection.
[0052] In some embodiments, establishing a time-link matrix includes: constructing a communication network topology map, obtaining a node spatial coordinate database, including physical locations and connection relationships; setting association rules, such as: direct proximity (i.e., power lines A and B are directly connected), weighting 1; distance by one node, weighting 0.6; distance by multiple nodes, weighting 0.3; and locations under the same transformer, weighting 1.3. Outputting an N*N-dimensional spatial association matrix (N is the number of nodes); adding a physical attenuation factor to each communication path, where the factor is the inverse of the square root of the product of the physical distance and the dielectric attenuation coefficient. A three-tiered temporal hierarchy is employed in the temporal dimension, including minute, hour, and historical levels. The historical level is generated from historical time data and used for comparison with the current fault status, thereby enabling accurate dynamic prediction. The spatial association matrix is partitioned according to the temporal dimension to generate a time-link matrix. In terms of spatial characteristics, given the tree-like / mesh-like connectivity of distribution network nodes, faults propagate along electrical pathways. In terms of temporal characteristics, interference often propagates in a burst-like, sustained decay, and baseline recovery pattern.
[0053] In this embodiment, spatial correlation is used to set spatial weights based on connection relationships and distances to quantify the probability of fault transmission between nodes. For example, when node A is abnormal, the risk of its impact on other nodes can be calculated, enabling early warning of high-risk nodes. A fault propagation dynamics model is established through temporal correlation, enabling a hierarchical response to the same abnormal event. This captures the time nodes and sources of welder failures, identifies persistent trends, and matches historical patterns. Propagation analysis based on both temporal and spatial correlations reduces missed reports and positioning errors, improves fault classification accuracy, accelerates response efficiency, and achieves instantaneous capture. Power communication faults are highly correlated, making traditional single-point-of-fault analysis incapable of global status monitoring.
[0054] In some embodiments, the multi-level detection mechanism includes instantaneous anomaly capture, spatiotemporal propagation analysis, and composite anomaly index. By performing sudden anomaly detection on abnormally complex situations, and through detection means at three different levels, a comprehensive and in-depth analysis and judgment of abnormal situations are performed from multiple angles to improve the accuracy and reliability of anomaly detection, ensuring that serious sudden failures can be discovered and accurately determined in a timely manner.
[0055] Transient anomaly detection focuses on sudden changes in data over time. By presetting a mutation threshold based on historical data and experimental results, potential anomalies can be quickly captured. Cross-modal verification is then used to further verify the authenticity of anomalies and avoid misjudgments. Specifically, during data collection, the mutation threshold is continuously monitored for feature differences between adjacent sampling points. Based on the fluctuation range of historical data, a threshold is set. When the feature difference between adjacent sampling points exceeds three times the historical fluctuation range, a transient anomaly alert is triggered. For example, when monitoring device temperature data, if the historical temperature fluctuation range is within ±5 degrees, a temperature difference between two adjacent sampling points exceeding 15 degrees is considered a possible transient anomaly. To ensure that detected transient anomalies are genuine disturbances rather than accidental data fluctuations or false alarms, dual-mode detection is employed. This involves simultaneously monitoring the same object using two different data collection methods or sensors. Only when both modalities detect a sudden change is it considered a true disturbance. For example, when monitoring traffic flow, ground-sensing loops are used to detect vehicle traffic, while cameras are used for image recognition and counting. A true anomaly is only determined when both detect a sudden change in traffic flow.
[0056] If both modes detect a sudden change in the transient anomaly capture result, the presence of a true transient disturbance is confirmed. This result provides the basis for subsequent spatiotemporal propagation analysis and calculation of the composite anomaly index, pinpointing the anomaly's starting point. If only one mode detects a sudden change, or if the feature differences between adjacent sampling points do not exceed the set sudden change threshold, it is considered a false alarm or a non-anomalous condition, and the system continues normal data monitoring.
[0057] The spatiotemporal propagation analysis obtains the spatiotemporal propagation state based on the time-link matrix, obtains the propagation characteristics of the nodes within the first range, and constructs the main abnormal propagation graph. The first range is centered on an abnormal signal node, and includes the nodes directly connected to it and the area covered by one or two levels of relay nodes. The first range is smaller than the second range. It can be set based on the topology of the communication network, the importance of the node, the size of the power grid, and the historical fault propagation range. For core nodes (such as important transformer terminals), the first range can be appropriately expanded due to the large number of connected nodes and the large impact range; for edge nodes, the first range is relatively small.
[0058] Within the first range, by monitoring the signal characteristics of each node, find the node that first displays abnormal characteristics and use this as the starting point of the anomaly. Continuously monitor changes in the signal characteristics of each node within the first range at subsequent time points, and record the order and direction in which the anomaly propagates from one node to adjacent nodes. For example, by analyzing changes in communication links and signal strength between nodes, determine how the anomaly spreads between nodes. Measure the time required for the anomaly to propagate from one node to an adjacent node to determine the anomaly's diffusion speed. For example, record the time difference between the occurrence of the anomaly at two adjacent nodes and, combined with the distance between the nodes, calculate the propagation speed.
[0059] Based on the node where the anomaly first occurred, the propagation path, and the diffusion speed, a primary anomaly propagation map is generated, visually illustrating the anomaly's propagation within the first range. This first range allows for a preliminary determination of the anomaly's localized spread, quickly locating key nodes that may be directly affected. Within this range, the initial spread of an anomaly can be promptly identified. For example, in a power communication network, the first range can help quickly determine whether smart meters or concentrators directly connected to the anomaly node are affected. This further distinguishes the correlation and mutual influence between communication patterns and device failures.
[0060] Using the interference source location formula, we can assist in locating possible interference sources from the perspective of time and space correlation. Specifically, based on the location formula of time and space correlation, we use the time information of each node anomaly occurrence and the spatial distance between nodes to calculate their correlation coefficients. For example, let the anomaly occurrence time of node i and node j be and , the spatial distance is, then the correlation coefficient The calculation formula is expressed as:
[0061]
[0062] Where n is the total number of sampling points in the time window used for calculation, and are the average abnormal occurrence time of node i and node j in the time window, and are the duration of the anomaly at sampling point K. By analyzing the size and distribution of the correlation coefficient, it can be seen that for pairs of nodes with large correlation coefficients, there is a strong correlation between the anomaly occurrence time and spatial distance. Therefore, the specific locations pointed by these nodes are likely to be interference sources.
[0063] Once a transient anomaly is confirmed, the system begins recording relevant information about the anomaly and constructing an anomaly propagation map. First, the node where the anomaly first occurred—that is, the starting location of the anomaly—is identified. The propagation path of the anomaly at subsequent time points is then tracked, recording the order and direction in which the anomaly spreads to other nodes. Simultaneously, the anomaly's diffusion rate is calculated, for example, by measuring the time it takes for the anomaly to propagate from one node to adjacent nodes. Using the time information of each node's anomaly occurrence and the spatial distance between nodes, their correlation coefficient is calculated. The correlation coefficient reflects the degree of correlation between the anomaly occurrence time and spatial distance. By analyzing the size and distribution of the correlation coefficient, possible interference sources can be located. For example, if the anomaly occurrence time of certain nodes shows a strong correlation with their spatial distance to a specific location, then that specific location is likely the interference source.
[0064] The anomaly propagation map generated by the spatiotemporal propagation analysis intuitively illustrates the propagation of an anomaly over time and space, helping to understand its development and impact. For example, in network fault detection, the anomaly propagation map can clearly show the node where the fault originated, how it spread to other nodes, and the speed of spread. The correlation coefficient calculated using the interference source location formula provides important clues for locating possible interference sources. Based on these clues, targeted inspections and troubleshooting of relevant areas or equipment can be carried out, improving troubleshooting efficiency.
[0065] The composite anomaly index combines multiple key factors, including the intensity of the transient anomaly, its propagation speed, and its impact range. Through weighted calculation, a comprehensive index is generated, serving as a criterion for determining severe sudden faults, making fault determination more scientific and comprehensive. Specifically, a weighted calculation is performed based on the transient anomaly intensity, propagation speed, and impact range obtained previously, using given weights. The formula for calculating the sudden fault index is: sudden fault index = transient intensity × 0.5 + propagation speed × 0.3 + impact range × 0.2. The transient intensity can be measured by the degree of mutation determined during the transient anomaly capture phase; the propagation speed is obtained during the spatiotemporal propagation analysis phase; and the impact range can be determined based on the number of nodes or region size involved in the anomaly propagation graph. The calculated sudden fault index is then compared with a preset threshold of 0.65. When the sudden fault index exceeds 0.65, it is determined to be a severe sudden fault, and the system triggers the corresponding alarm mechanism, notifying relevant personnel for action.
[0066] The composite anomaly index results indicate a severe sudden failure. A sudden failure index greater than 0.65 is considered severe. Emergency measures are taken to prevent further escalation and minimize the impact on the system or business. If the sudden failure index is less than or equal to 0.65, the anomaly is not yet considered severe, but requires continued attention. The system will continue to monitor and analyze the anomaly to prevent it from escalating.
[0067] In some embodiments, dynamic analysis is performed based on a time-link matrix and a multi-level detection mechanism is set up, which solves the problem of one-sided analysis caused by independent detection of a single node in the existing technology, as well as the problem of ignoring fault propagation and being unable to adapt to dynamic changes in complex environments. It realizes the quantification of the influence relationship between nodes through spatial topology, the recording of the abnormal diffusion path and speed, and the dynamic association of historical scenarios and real-time fluctuations.
[0068] S3: Mark the detected abnormal signals as propagation source nodes, extract the signal feature fingerprint, mark the first diffusion node, mutation node and intersection node; obtain the propagation characteristics of all nodes in the second range, and generate a secondary abnormal propagation graph.
[0069] In some embodiments, the second range is centered on the propagation source node, identifies the diffusion influence of each node, pre-sets a minimum influence threshold, counts the node diffusion influence in historical data within a period of time (e.g., 24 hours), and calculates the average value as the minimum influence threshold; the area covered by the nodes whose diffusion influence is greater than the minimum influence threshold. Specifically, the detected several abnormal signals are marked as propagation source nodes. There are several propagation source nodes. With one propagation source node as the center, identify the diffusion influence of each node (propagation source node, first diffusion node, mutation node, and intersection node). For overlapping influence areas, randomly select one. Combining the node structure characteristics and the propagation dynamic characteristics, calculate the diffusion influence of each node. First, determine the propagation probability of the node, simulate the independent activation behavior between nodes, and the cumulative effect of the node being affected by neighbors. The independent activation behavior is based on the number of direct connections between the nodes, which refers to the probability that the node independently triggers propagation through its own direct connection (i.e., one-hop neighbor), reflecting the basic propagation capability of the node. Its core assumption is that the occurrence of the propagation event depends only on the direct relationship between the source node and the target node, and is not affected by other intermediate nodes. For example, if node A has three neighbors B, C, and D, and , then the probability that A independently activates at least one neighbor is 1−(1−0.3)*(1−0.2)*(1−0.1)=0.496.
[0070] The cumulative effect is the probability of a node triggering propagation through the indirect influence of multi-hop neighbors, reflecting the deep propagation potential of the node. Its core assumption is that the occurrence of propagation events depends on the core position of the node in the propagation network or the superposition of the influence of its neighbors. It is necessary to calculate the influence of a single node and the corresponding weight value. For example, if the influence of node A's neighbors B and C are I (B) = 0.6 and I (C) = 0.4 respectively, and the weight , then the cumulative effect is min(1, 0.7×0.6+0.3×0.4)=0.54.
[0071] For each node, the probability of activating neighboring nodes through independent activation and cumulative effects is calculated simultaneously. Based on the independent activation behavior and cumulative effects, a weighted average is taken as the final propagation probability. Dynamic characteristics are then identified: information propagation decays over time, calculated using an exponential decay function. The diversity of propagation paths and the shortest path from a node to another node reflect propagation redundancy. The path influence value reflects the redundancy and efficiency of propagation paths between nodes. Shorter paths and lower redundancy indicate higher propagation efficiency. The average path distance is obtained from all paths between any two nodes. Based on this average path distance, the corresponding path influence propagation degree (calculated using the path distance and exponential decay function described above) is determined as the path influence value, which ranges from 0 to 1. The final propagation probability, exponential decay function, and path influence value are normalized and then weighted summed to obtain the diffusion influence degree of each node.
[0072] In some embodiments, the minimum influence threshold may be pre-set by fitting an influence distribution curve based on actual influence data of nodes in historical propagation events, and calculating a standard deviation as the minimum influence threshold.
[0073] In some embodiments, the second range is further expanded or adjusted based on the first range, covering a wider range of node connections. In this embodiment, the second range is defined by comparing the diffusion impact of each node with a minimum impact threshold, with the area covered by nodes whose diffusion impact exceeds the minimum impact threshold being defined as the second range. The division of the second range can also be adjusted based on actual circumstances, for example, to include nodes that are indirectly connected to nodes in the first range (via multi-level relays), or based on the overall network layout and potential paths along which the fault may spread. For example, if the first range primarily covers a small area where the abnormal node is located, the second range can be expanded to include several similar adjacent areas to comprehensively monitor the propagation of the abnormality.
[0074] The second scope focuses on comprehensively monitoring the propagation of anomalies across the entire network, identifying potential spread paths and broader impact areas. This second scope analysis helps determine whether anomalies span different regions or subnets, allowing for more comprehensive response measures. For example, after an anomaly is initially contained within the first scope, the second scope analysis can determine whether it will spread to other regions.
[0075] Several detected anomaly signals are marked as propagation source nodes. These nodes are key nodes in the propagation of the primary anomaly or newly emerged anomaly nodes within the secondary range. The signals of the propagation source nodes are analyzed in detail to extract their unique signal characteristics, forming a signal characteristic fingerprint. Signal characteristic changes of nodes adjacent to the propagation source node within the secondary range are monitored, and the propagation of the anomaly on these nodes is recorded. Based on the propagation characteristics of the propagation source node and adjacent nodes, as well as the signal characteristic fingerprint, a secondary anomaly propagation graph is generated. The graph also marks the first diffusion node (the node to which the anomaly first spreads from the propagation source node), mutation nodes (nodes where the signal characteristics change significantly), and intersection nodes (nodes where multiple anomaly propagation paths intersect), comprehensively displaying the propagation of the anomaly within the secondary range.
[0076] The signal feature fingerprint is an abstract representation of the unique characteristics of a signal. It contains the key feature information of the signal in multiple dimensions and can uniquely identify a signal or distinguish signals from different sources. For example, in power communication signals, the signal feature fingerprint may include the frequency distribution characteristics of the signal, the harmonic content pattern, the specific modulation method, etc. The signal feature fingerprint can accurately describe the unique characteristics of the signal and improve the accuracy and reliability of signal identification. Even in a complex signal environment, different signal sources can be distinguished by the signal feature fingerprint. In anomaly detection, it is used to identify the source and characteristics of abnormal signals and help determine the type and cause of the anomaly. For example, by comparing the feature fingerprints of normal signals and abnormal signals, it can be determined whether the abnormal signal is caused by equipment failure, environmental interference or other reasons. This application is based on real-time monitoring of dual-mode communication, and the analysis and identification of abnormal signals realizes monitoring of the entire system.
[0077] Propagation characteristics refer to the various features exhibited by a signal during propagation, including signal strength variations, propagation path, and propagation time. They reflect the propagation behavior and characteristics of a signal within a network. Signal strength monitoring devices are installed at each node in the network to monitor signal strength variations in real time. For example, in a power communication network, signal monitoring modules on smart meters or concentrators record signal strength at different locations. Using the network topology and communication protocols, information about the path a signal takes from one node to another is recorded. For example, by analyzing the communication links and data flows between nodes, the signal propagation path can be determined. Recording the propagation time of a signal between different nodes can be achieved by adding timestamps to the signal. For example, the transmission time is recorded when the signal is sent, and the reception time is recorded at the receiving node. The difference between the two is the propagation time.
[0078] By identifying and analyzing propagation characteristics in this embodiment, the behavior and characteristics of the signal during propagation can be comprehensively and accurately described, providing an important basis for fault analysis and anomaly detection. In spatiotemporal propagation analysis, propagation characteristics are used to construct anomaly propagation maps, showing the propagation process and impact range of the anomaly. By analyzing propagation characteristics, the propagation path and diffusion speed of the anomaly can be determined, assisting in locating the source of interference. For example, if a sudden drop in signal strength is detected in a certain area, analyzing the propagation characteristics can determine whether it is caused by a line fault or a device failure.
[0079] The technical solutions in the above embodiments of the present application have at least the following technical effects or advantages:
[0080] This application collects multi-dimensional signal features and constructs a spectrum feature library to quickly identify noise interference, effectively distinguish between communication problems and noise interference, and improve noise identification accuracy;
[0081] Quantify the temporal complementarity and spatial synergy of HPLC and HRF modes, generate new feature vectors based on cross-modal support, fuse dual-mode signal features, eliminate single-mode perception blind spots, dynamically adjust feature fusion strategies, accurately identify the correlation and complementarity between different modes, and improve monitoring accuracy;
[0082] Construct a communication network topology map, combine it with the node spatial coordinate database, set association rules to obtain the time-link matrix, and locate the source of the anomaly through a multi-level detection mechanism.
[0083] Example 2: Continue to refer to Figure 1 , the method further includes: S4: analyzing causal characteristics according to the secondary anomaly propagation graph, determining the causal path, identifying risk indicators to obtain a risk index, and predicting the threat level.
[0084] In some embodiments, the causal features include temporal causality, spatial causality, and intensity correlation. Temporal causality is the temporal order of abnormal events, reflecting the dynamic process of propagation. Nodes in the secondary anomaly propagation graph are sorted by the time of anomaly occurrence to construct a time series chain. The time intervals between adjacent nodes are calculated to identify key time nodes (e.g., mutation points). For example, if node A is abnormal at t=10s and node B is abnormal at t=15s, and A and B are directly connected, then A→B constitutes a temporal causal chain. Spatial causality is the spatial diffusion path of an abnormal event, reflecting the influence of network topology. Based on the propagation paths in the secondary anomaly propagation graph, the spatial distance between nodes (e.g., physical distance or number of hops) is calculated to identify high-frequency propagation paths (e.g., paths shared by multiple anomaly chains). For example, if an anomaly spreads from a transformer terminal to three adjacent smart meters, the transformer terminal is the source of the spatial causality. Intensity correlation is the change in the intensity of the abnormal signal during propagation, reflecting the attenuation or enhancement effects of propagation. For nodes along the propagation path, calculate the rate of change of signal strength (such as SNR) and identify strength mutation points (such as sudden drops or increases in SNR). For example, if the signal propagates from node A (SNR = 20dB) to node B (SNR = 15dB), the strength attenuation rate is 25%.
[0085] In some embodiments, risk indicators are identified based on causal characteristics, and the risk indicators are used to quantify the risk level of abnormal propagation. The risk indicators include propagation speed, root source overlap, and potential impact. The propagation speed is the number of nodes or area range to which the abnormality spreads per unit time. The root source overlap is the degree of similarity between the current abnormality and the historical abnormality root source. The propagation source characteristics of the current abnormality (such as equipment type and location) are extracted, matched with the historical abnormality root source library, and the J similarity coefficient is calculated. For example: if the current abnormality source overlaps with the source characteristics of three inverter interference events in history by 0.8, then the root source overlap is 0.8. The potential impact refers to the number of edge nodes or the proportion of key equipment that the abnormality may affect. Based on the network topology, the number of nodes that the abnormality may spread to is calculated, key equipment (such as transformer terminals) is identified, and the probability of its being affected is calculated. For example: if the abnormality may affect 10 nodes, 2 of which are key equipment, then the potential impact is (N is the total number of nodes, H is the number of critical devices). The acquired risk indicator data is normalized to a value between [0, 1] and then weighted summed (propagation speed set to 0.4, root cause overlap set to 0.4, and potential impact set to 0.2) to obtain the risk index. The threat level (level 1, 2, or 3) is determined based on the risk index and pre-set matching rules. For example, a risk index of 0.4 or higher corresponds to a level 1 threat, a risk index greater than 0.4 and less than 0.6 corresponds to a level 2 threat, and a risk index of 0.6 or higher corresponds to a level 3 threat. This level needs to be dynamically adjusted based on the propagation of the risk path and the number of nodes involved.
[0086] S5: Generate cross-layer strategies based on threat levels, including signal layer, device layer, and network layer; detect cross-layer conflicts and set execution priorities for hierarchical execution.
[0087] In some embodiments, cross-layer strategies are selected based on the threat level, including the signal layer, device layer, and network layer. A third-level threat requires processing strategies involving all three layers. Specifically, a layered response strategy is generated and cross-layer conflicts are resolved. Signal layer strategies include adjusting the communication mode (e.g., switching from HPLC to HRF), increasing signal power, or switching frequency bands. Device layer strategies include isolating faulty devices (e.g., disconnecting abnormal smart meters) and activating backup devices (e.g., switching to backup transformer terminals). Network layer strategies include rerouting traffic (e.g., bypassing abnormal areas) and limiting communication bandwidth in abnormal areas.
[0088] Detect and identify conflict types, including resource conflicts (e.g., signal layer power boost and device layer isolation simultaneously require communication resources); and target conflicts (e.g., network layer rerouting that may cause service delays). Prioritization rules are set: policies with higher threat levels are prioritized, policies involving critical devices are prioritized, and policies with the least system impact are selected. For example, if signal layer power boost (priority 2) conflicts with device layer isolation (priority 1), the device layer policy takes precedence.
[0089] This embodiment traces the "cause" of anomaly propagation from its "result" to reveal its evolutionary patterns. Existing technologies typically focus only on the spatial and temporal distribution of anomalies (e.g., which nodes are anomaly and when), but fail to explain how anomalies propagate (e.g., whether an anomaly at node A causes an anomaly at node B). This embodiment employs causal features to identify temporal causality (the order of anomalies), spatial causality (network topology dependent on propagation paths), and intensity correlation (signal attenuation or enhancement patterns). This allows for a logical chain of anomaly propagation, achieving technical benefits difficult to achieve with simple statistical correlation. In dual-mode communication (HPLC+HRF), causal features can distinguish between noise interference (without a clear causal chain) and equipment failure (with a clear propagation path), determining the true propagation direction and avoiding misjudgment. Combined with causal features (e.g., inverter interference causing power line noise, which in turn causes smart meter bit errors), threat levels can be linked to specific root causes (e.g., inverter model and location), supporting targeted remediation.
[0090] In this embodiment, the limitations of a single-layer strategy are addressed, and end-to-end anomaly management is achieved through coordinated responses at the signal layer, device layer, and network layer. Signal layer: Directly adjusting communication parameters (such as switching frequency bands and increasing power) can quickly suppress interference, but cannot resolve equipment failures. Device layer: Isolating faulty equipment (such as disconnecting smart meters) can block propagation, but may cause local business interruptions. Network layer: Rerouting traffic (such as bypassing abnormal areas) can maintain communication, but may increase latency. Combining the advantages of a three-layer strategy (such as signal layer power enhancement + device layer fault isolation + network layer rerouting), the dual indicators of rapid recovery and minimal impact can be balanced. Setting up detection of cross-layer conflicts and priority grading to implement multi-layer strategies in parallel solves cross-layer conflict problems.
[0091] The technical solutions in the above embodiments of the present application have at least the following technical effects or advantages:
[0092] This application analyzes the temporal causality, spatial causality and intensity correlation from the secondary anomaly propagation graph, identifies risk indicators such as propagation speed, root source overlap, potential impact based on causal characteristics, and obtains a risk index by normalizing and weighting the sum, and determines the threat level based on the risk index and preset rules; constructs an anomaly propagation logic chain, distinguishes noise interference from equipment failure, determines the true propagation direction, and further improves the accuracy of communication monitoring; generates cross-level strategies for the signal layer, device layer, and network layer according to the threat level, detects cross-level conflicts and sets execution priority and hierarchical execution, identifies specific anomaly roots, and realizes cross-level rapid anomaly handling.
[0093] Example 3: Continue to refer to Figure 1 The method further includes: S6: obtaining causal characteristics and causal paths to group the system according to constraints, wherein the grouping includes propagation-type grouping, diffusion-type grouping, and mixed-type grouping; constructing an intra-group causal graph and evaluating the intra-group risk status in real time, and setting an intra-group collaboration strategy; evaluating the global risk status, and dynamically selecting whether to trigger a cross-group collaboration strategy; the constraints are to maximize the intra-group causal relationship strength and minimize the causal interaction between groups.
[0094] In some embodiments, all nodes are considered to be in an ungrouped state, and the node with the highest causal relationship strength is selected as the grouping seed (e.g., the node with a strong causal relationship with the most nodes). For each seed node, ungrouped nodes whose causal relationship strength is greater than a strength threshold (e.g., 0.6) are iteratively added. The strength threshold is a pre-set value used to measure the strength of the causal relationship and needs to be set based on historical experimental data. For example, all abnormal devices in the historical data are determined, and the abnormal source devices are determined based on the corresponding device causal chain. The number of abnormal devices caused by the abnormal source devices through the causal chain is screened out, and the strength threshold is set based on the number percentage and the degree of abnormality. For example, the number of abnormal devices caused by the causal chain is 40, the total number of abnormal devices is 80, and the number percentage is 50%, that is, 0.5; among the 40 abnormal devices, the proportion of high-level abnormal devices is 30%, that is, 0.3; the proportion of medium-level abnormal devices is 40%; and the proportion of low-level abnormal devices is 30%; therefore, the strength threshold is set to 1-(1-0.5)(1-0.3) = 0.65, and the strength threshold can be initially set to 0.65. The above is just an example of briefly setting the strength threshold. It needs to be dynamically set according to actual experimental data and needs, and this application does not impose specific restrictions. Set the stopping condition as follows: the number of nodes in the group reaches the upper limit (such as 20) or no new nodes can be added. Assign the remaining ungrouped nodes to the nearest neighbor group (based on spatial distance or causal relationship strength), and finally form an initial group list (including group ID, member nodes, group type). Define the grouping type, which includes propagation grouping, diffusion grouping and hybrid grouping. For example: propagation grouping: with high-frequency time causal chain as the core (such as inverter interference → power line noise → smart meter error); diffusion grouping: with high-frequency spatial causal path as the core (such as transformer terminal → adjacent 3 concentrators); hybrid grouping: contains strong time and space causal relationships at the same time.
[0095] In some embodiments, constructing an intra-group causal graph involves obtaining basic signal characteristics (SNR, BER) and propagation characteristics (propagation path, diffusion speed) of nodes within the group, modeling a temporal causal chain: constructing a directed acyclic graph (DAG) with edge weights representing temporal causal strength (e.g., frequency of propagation from A to B divided by total frequency); spatial causal path modeling: calculating the inverse of the spatial distance between nodes as the spatial causal weight; and intensity correlation modeling: mapping the SNR decay rate to intensity correlation weights (e.g., a 20% SNR decay corresponds to a weight of 0.8). Outputting an intra-group causal graph (nodes represent devices, edges represent causal weights). Risk assessment is performed on the group, and the intra-group risk status is determined based on the abnormal conditions of the nodes within the group (e.g., risk propagation speed, anomaly impact). Intra-group coordination strategies are still dynamically configured at three levels: the signal layer: adjusting intra-group communication parameters (e.g., increasing power, switching frequency bands); the device layer: isolating faulty devices within the group (e.g., disconnecting an abnormal smart meter); and the network layer: limiting intra-group communication bandwidth or rerouting traffic.
[0096] In some embodiments, key causal information is shared through standardized interfaces, a global anomaly view is maintained, causal relationship transmission and global perception between groups are realized, the global risk status is evaluated (the standard deviation of all risk statuses within the group is obtained or the mode is taken), and it is dynamically selected whether to trigger the cross-group collaboration strategy; for example, if the global risk index is greater than 0.6 or the number of cross-group causal chains exceeds a threshold (such as 5), real-time cross-group collaboration strategies are implemented, such as: global switching of communication modes (such as HPLC→HRF), isolation of key faulty equipment across groups, and rerouting of global traffic (such as bypassing high-risk groups).
[0097] In this embodiment, grouping structure and inference parameters are optimized based on real-time causal feedback to improve adaptability and achieve dynamic grouping optimization and adaptive adjustment. Specifically, adjustment rules are set. For example, group merging: If the number of cross-group causal chains between two groups is greater than 3 and the spatial distance is less than 50 meters, they are merged into a new group. Group splitting: If the number of causal chains within a group is greater than 20 (excessive complexity), it is split into two sub-groups based on spatial distance. Trigger conditions: Adjustment is triggered every 10 minutes or when the global risk index changes by more than 0.2. Causal relationship weights are adjusted based on historical data (for example, if the prediction accuracy of a causal chain is less than 70%, its weight is reduced). If anomalies are not alleviated after the execution of the intra-group strategy (for example, the signal-to-noise ratio (SNR) does not improve), causal relationships are re-inferred. Evaluation metrics are set as follows: intra-group inference time: target < 100ms; cross-group communication overhead: target < 10% of the total bandwidth; global anomaly detection accuracy: target > 95%. Set iteration rules. For example, if the inference time within a group is greater than 200ms, split the group. If the cross-group communication overhead is greater than 15%, optimize the interface data volume.
[0098] In this embodiment, causal characteristics and causal paths are obtained based on the contents of the above embodiments to perform grouping division, achieve low-complexity causal reasoning and fast response within the group, and reduce the global computing load. For the first time, time / space / intensity causal characteristics are converted into the basis for grouping division, solving the problem of weak correlation in traditional grouping. Millisecond-level response is achieved through the causal graph within the group, avoiding global computing delays and realizing local autonomous reasoning within the group. A lightweight interface is designed to maintain a global anomaly view while reducing communication overhead, and optimize the efficiency of cross-group causal relationship transmission. The grouping structure is adjusted according to real-time causal feedback to adapt to the dynamically changing network environment and realize dynamic grouping adaptive optimization.
[0099] Example 4: This embodiment also provides an intelligent monitoring system based on dual-mode communication according to the above method, such as Figure 2 As shown, the system includes: a data acquisition and initial screening module, which is used to obtain basic data information and calculate the real-time noise similarity; if the real-time noise similarity is greater than the similarity threshold, the first abnormality is output; if the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial abnormality value is obtained.
[0100] The dual-mode time-link module is used to calculate the cross-modal support between the dual signals based on the multi-dimensional signal characteristics. If the cross-modal support is greater than 0.7, a time-link matrix is established and a multi-level detection mechanism is set up to detect abnormal signals.
[0101] The abnormal propagation image generation module is used to obtain the spatiotemporal propagation state based on the time-link matrix, obtain the propagation characteristics of the nodes within the first range, and construct the main abnormal propagation map; mark the detected several abnormal signals as propagation source nodes, extract the signal feature fingerprint, mark the first diffusion node, mutation node and intersection node; obtain the propagation characteristics of all nodes in the second range, and generate the secondary abnormal propagation map.
[0102] The causal analysis module is used to analyze causal characteristics based on the secondary anomaly propagation graph, determine the causal path, identify risk indicators to obtain the risk index, and predict the threat level.
[0103] The grouping module is used to obtain causal features and causal paths to group the system according to the constraints.
[0104] The strategy generation module is used to generate cross-level strategies according to the threat level, detect cross-level conflicts, and set execution priorities for hierarchical execution; build a cause-and-effect diagram within the group and evaluate the risk status within the group in real time, set the collaboration strategy within the group; evaluate the global risk status and dynamically choose whether to trigger the cross-group collaboration strategy.
[0105] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Various modifications and variations are readily apparent to those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. An intelligent monitoring method based on dual-mode communication, characterized in that: include: S1: Obtain basic data information, extract multi-dimensional signal features to build a spectrum feature library, and calculate real-time noise similarity; If the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly; If the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial outlier value is obtained; S2: Calculate the cross-modal support between the two signals based on the multi-dimensional signal characteristics. If the cross-modal support is greater than 0.7, establish a time-link matrix and set up a multi-level detection mechanism to detect abnormal signals; the multi-level detection mechanism includes instantaneous anomaly capture, spatiotemporal propagation analysis, and composite anomaly index; S3: Mark the detected abnormal signals as propagation source nodes, extract signal feature fingerprints, mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation characteristics of all nodes in the second range, and generate a secondary abnormal propagation graph; S4: Analyze causal characteristics based on the secondary anomaly propagation graph, determine the causal path, identify risk indicators to obtain the risk index, and predict the threat level.
2. The intelligent monitoring method based on dual-mode communication according to claim 1, characterized in that: The method further comprises: S5: Generate cross-layer policies based on threat levels, including signal layer, device layer, and network layer; detect cross-layer conflicts and set execution priorities for hierarchical execution; S6: Obtain causal characteristics and causal paths to group the system according to constraints; construct a causal map within the group and evaluate the risk status within the group in real time, and set the intra-group collaboration strategy; evaluate the global risk status and dynamically choose whether to trigger the cross-group collaboration strategy; the constraints are to maximize the strength of the causal relationship within the group and minimize the causal interaction between groups.
3. The intelligent monitoring method based on dual-mode communication according to claim 1, characterized in that: The basic data information includes device information, communication mode and basic signal information of the target node; The multidimensional signal characteristics are used to quantify signal quality, and the multidimensional signal characteristics include frequency distribution, harmonic content, signal-to-noise ratio, bit error rate and fluctuation index; The real-time noise similarity is a scalar value in [0, 1], which represents the similarity between the real-time noise spectrum and the noise template in the spectrum feature library; The parameter deviation indicates the degree of deviation of the current signal parameter from its historical reference value.
4. The intelligent monitoring method based on dual-mode communication according to claim 1, characterized in that: The cross-modal support is a quantitative indicator used to measure the feature complementarity of two different communication modes in different dimensions, and its range is [0, 1]. The cross-modal support includes a time domain complementarity coefficient and a spatial domain synergy index. The time domain complementarity coefficient is the comprehensive coefficient minus the absolute value of the difference between the HPLC time domain stability and the HRF time domain stability, and the comprehensive coefficient is 1. The spatial domain synergy index is the covariance of the HPLC node correlation and the HRF spatial gradient. The cross-modal support is the sum of the time domain complementarity coefficient and the spatial domain synergy index.
5. The intelligent monitoring method based on dual-mode communication according to claim 1, characterized in that: Establishing the time-link matrix includes: constructing a communication network topology diagram, obtaining a node spatial coordinate database, including physical locations and connection relationships; setting association rules and belonging weights, and outputting an N*N-dimensional spatial association matrix, where N is the number of nodes; and dividing the spatial association matrix according to the time dimension to obtain a time-link matrix.
6. The intelligent monitoring method based on dual-mode communication according to claim 1, characterized in that: The spatiotemporal propagation analysis obtains the spatiotemporal propagation state based on the time-link matrix, obtains the propagation characteristics of the nodes within the first range, and constructs a main anomaly propagation graph, including: monitoring the signal characteristics of each node within the first range, finding the node where the anomaly characteristics first appear as the starting location of the anomaly; continuously monitoring the changes in the signal characteristics of each node within the first range at subsequent time points, recording the order and direction of the anomaly propagating from one node to adjacent nodes; measuring the time required for the anomaly to propagate from one node to adjacent nodes, and calculating the propagation speed; and forming the main anomaly propagation graph based on the node where the anomaly first appears, the propagation path, and the diffusion speed. The first range is centered on an abnormal signal node, and includes nodes directly connected to it and an area covered by one or two levels of relay nodes; the first range is smaller than the second range.
7. The intelligent monitoring method based on dual-mode communication according to claim 1, characterized in that: The second range is centered on the source node, identifies the diffusion influence of each node, pre-sets a minimum influence threshold, and defines the area covered by nodes whose diffusion influence is greater than the minimum influence threshold; Calculating the diffusion influence of each node involves simulating independent activation behavior between nodes and the cumulative effect of the influence of neighbors on a node. Independent activation refers to the probability that a node will independently trigger propagation through its own direct connections, based on the number of direct connections between nodes. The cumulative effect refers to the probability that a node will trigger propagation through the indirect influence of multi-hop neighbors. A weighted average of the independent activation behavior and the cumulative effect is taken as the final propagation probability. Obtain all path distances between any two nodes to obtain the average path distance, and determine the corresponding path influence propagation degree based on the average path distance as the path influence value, which ranges from [0, 1]; The final propagation probability, exponential decay function, and path influence value are normalized and then weighted summed to obtain the diffusion influence degree of each node.
8. The intelligent monitoring method based on dual-mode communication according to claim 1, characterized in that: The causal characteristics include temporal causality, spatial causality, and intensity correlation; temporal causality is the order of abnormal events in the temporal dimension, spatial causality is the diffusion path of abnormal events in the spatial dimension, and intensity correlation is the intensity change of abnormal signals during the propagation process; The risk indicators are used to quantify the risk level of abnormal propagation, and the risk indicators include propagation speed, root cause overlap, and potential impact.
9. The intelligent monitoring method based on dual-mode communication according to claim 2, characterized in that: The grouping includes: treating all nodes as ungrouped, selecting the node with the highest causal relationship strength as a grouping seed, and iteratively adding ungrouped nodes with causal relationship strength greater than a strength threshold to each seed node; The preset stop conditions are: the number of nodes in the group reaches the upper limit or no new nodes can be added; Assign the remaining ungrouped nodes to the nearest neighbor groups, and finally form the initial grouping list; defining a grouping type, wherein the grouping type includes a propagation grouping, a diffusion grouping, and a mixed grouping; Constructing the intra-group causal graph includes: obtaining the basic signal characteristics and propagation characteristics of the nodes within the group, performing time causal chain modeling, spatial causal path modeling and intensity correlation modeling; outputting the intra-group causal graph, where the nodes are devices and the edges are causal relationship weights.
10. An intelligent monitoring system based on dual-mode communication, applied to an intelligent monitoring method based on dual-mode communication according to any one of claims 1 to 9, characterized in that: The system comprises: The data collection and initial screening module is used to obtain basic data information and calculate the real-time noise similarity. If the real-time noise similarity is greater than the similarity threshold, the first anomaly is output. If the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained. The dual-mode time-link module is used to calculate the cross-modal support between the two signals based on the multi-dimensional signal characteristics. If the cross-modal support is greater than 0.7, a time-link matrix is established and a multi-level detection mechanism is set up to detect abnormal signals. The abnormal propagation image generation module is used to obtain the spatiotemporal propagation state based on the time-link matrix, obtain the propagation characteristics of the nodes within the first range, and construct the main abnormal propagation map; mark the detected abnormal signals as the propagation source nodes, extract the signal feature fingerprint, and mark the first diffusion node, mutation node, and intersection node; obtain the propagation characteristics of all nodes in the second range and generate the secondary abnormal propagation map; The causal analysis module is used to analyze causal characteristics based on the secondary anomaly propagation graph, determine the causal path, identify risk indicators to obtain the risk index, and predict the threat level; The grouping module is used to obtain causal features and causal paths to group the system according to the constraints; The strategy generation module is used to generate cross-level strategies according to the threat level, detect cross-level conflicts, and set execution priorities for hierarchical execution; build a cause-and-effect diagram within the group and evaluate the risk status within the group in real time, set the collaboration strategy within the group; evaluate the global risk status and dynamically choose whether to trigger the cross-group collaboration strategy.
Citation Information
Patent Citations
Electric quantity accounting management system based on artificial intelligence
CN120013360A
Metering and monitoring method and system based on pipeline multiphase flow
CN120063415A
Method and device for testing communication performance of HPLC (High Performance Liquid Chromatography) dual-mode communication module
CN120165787A
Dual-mode carrier communication aggregation interference identification system and device based on graph neural network
CN120301570A
Intelligent monitor temperature drift correction method and system based on temperature compensation algorithm
CN120369024A
Cited By
HPLC and HRF dual-mode communication method and system for smart power grid
CN121463040A
A method and system for HPLC and HRF dual-mode communication of smart grid
CN121463040B
Real-time deviation correction control method and system for static pressure pile construction based on edge computing
CN122613860A