Intelligent monitoring method and system based on dual-mode communication
By constructing a spectral feature library and cross-modal support, a time-linked matrix is established for multi-level detection to identify abnormal signals. This solves the problem that the correlation and complementarity of signals are not fully utilized in existing technologies, and improves the monitoring accuracy and response speed of dual-mode communication.
Patent Information
- Application Number
- CN202511050927.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-07-29
AI Technical Summary
Existing dual-mode communication technology fails to fully consider the dynamic correlation of signals in time and space dimensions as well as the complementarity across modes, resulting in insufficient accuracy and response speed in communication quality monitoring, making it difficult to meet the real-time and accuracy requirements of smart grids.
By acquiring multi-dimensional signal features, constructing a spectral feature library, calculating real-time noise similarity and cross-modal support, establishing a time-linked matrix, performing multi-level detection, identifying abnormal signals, constructing anomaly propagation diagrams, analyzing causal characteristics and risk indicators, and generating cross-level strategies to improve monitoring accuracy.
It enables rapid identification of noise interference, distinguishes communication problems from noise interference, eliminates blind spots in single-mode perception, dynamically adjusts feature fusion strategies, accurately identifies the correlation and complementarity between different modes, and improves the accuracy and response speed of communication monitoring.
Smart Images

Figure CN120692171B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of dual-mode communication technology, and in particular to an intelligent monitoring method and system based on dual-mode communication. Background Technology
[0002] In power line communication, the presence of environmental noise along power lines has characteristics similar to real signal attenuation, which can easily lead to misjudgments during communication quality monitoring and affect the stable operation of the power network.
[0003] Current dual-mode communication technologies, such as the fusion of HPLC (High-Speed Broadband Power Line Carrier) and HRF (Hard Power Radio), have improved communication reliability and flexibility to some extent. However, existing technologies largely focus on monitoring and switching between single modes, neglecting the potential correlations and complementarities between different signals. Particularly when fusing different communication modes, existing methods fail to fully consider the dynamic correlations of signals in time and space, as well as cross-modal complementarity. This limits the accuracy and response speed of communication quality monitoring, making it difficult to meet the high real-time and accuracy requirements of smart grids. Summary of the Invention
[0004] This application provides an intelligent monitoring method and system based on dual-mode communication, which solves the problem that the prior art fails to fully consider the dynamic correlation of signals in the time and space dimensions and the complementarity across modes, and achieves the technical effect of improving the accuracy of communication monitoring based on the correlation and complementarity between different communication modes.
[0005] This application provides an intelligent monitoring method based on dual-mode communication, including:
[0006] S1: Obtain basic data information, extract multi-dimensional signal features to construct a spectrum feature library, and calculate real-time noise similarity; if the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly; if the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained.
[0007] S2: Calculate the cross-modal support between the two signals based on the multi-dimensional signal characteristics. If the cross-modal support is greater than 0.7, establish a time-linked matrix and set a multi-level detection mechanism to detect abnormal signals. The multi-level detection mechanism includes instantaneous anomaly capture, spatiotemporal propagation analysis, and composite anomaly index.
[0008] S3: Mark the detected abnormal signals as propagation source nodes, extract signal feature fingerprints, and mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation features of all nodes in the second range and generate a sub-anomaly propagation map;
[0009] S4: Analyze causal characteristics based on the sub-anomaly propagation diagram, determine the causal path, identify risk indicators to obtain the risk index, and predict the threat level.
[0010] Furthermore, the method also includes:
[0011] S5: Generates cross-layer policies based on threat levels, including signal layer, device layer, and network layer; detects cross-layer conflicts and sets execution priorities for hierarchical execution;
[0012] S6: Obtain causal features and causal paths, and group the system according to constraints; construct intra-group causal graphs and evaluate intra-group risk status in real time, and set intra-group collaboration strategies; evaluate global risk status and dynamically select whether to trigger cross-group collaboration strategies; the constraints are to maximize the strength of causal relationships within a group and minimize causal interactions between groups.
[0013] Furthermore, the cross-modal support is a quantitative indicator used to measure the feature complementarity of two different communication modes in different dimensions, and its range is [0, 1]. The cross-modal support includes a temporal complementarity coefficient and a spatial synergy index. The temporal complementarity coefficient is the comprehensive coefficient minus the absolute value of the difference between the temporal stability of HPLC and the temporal stability of HRF, and the comprehensive coefficient is 1. The spatial synergy index is the covariance of HPLC node correlation and HRF spatial gradient. The cross-modal support is the sum of the temporal complementarity coefficient and the spatial synergy index.
[0014] Furthermore, the spatiotemporal propagation analysis obtains the spatiotemporal propagation state based on the time-linked matrix, acquires the propagation characteristics of nodes within a first range, and constructs a main anomaly propagation map, including: within the first range, monitoring the signal characteristics of each node, identifying the node with the earliest abnormal characteristics as the starting position of the anomaly; continuously monitoring the changes in signal characteristics of each node within the first range at subsequent time points, recording the order and direction of the anomaly propagating from one node to adjacent nodes; measuring the time required for the anomaly to propagate from one node to adjacent nodes, and calculating the propagation speed; and forming a main anomaly propagation map based on the node where the anomaly first appears, the propagation path, and the propagation speed.
[0015] The first range is centered on an abnormal signal node, including nodes directly connected to it and areas covered by one or two relay nodes; the first range is smaller than the second range.
[0016] Furthermore, the second range is the area covered by nodes whose diffusion impact is greater than the minimum impact threshold, centered on the propagation source node and identified by the degree of diffusion impact of each node.
[0017] The calculation of the diffusion impact of each node includes: simulating independent activation behavior between nodes and the cumulative effect of a node being influenced by its neighbors; the independent activation behavior is based on the number of direct connections between nodes, referring to the probability that a node independently triggers propagation through its own direct connections; the cumulative effect is the probability that a node cumulatively triggers propagation through the indirect influence of multi-hop neighbors; based on the independent activation behavior and the cumulative effect, a weighted average is taken as the final propagation probability.
[0018] The average path distance is obtained by acquiring all path distances between any two nodes. The path influence propagation degree is determined based on the average path distance and used as the path influence value, which ranges from [0, 1].
[0019] The final propagation probability, exponential decay function, and path influence value are normalized and then weighted and summed to obtain the diffusion influence of each node.
[0020] Furthermore, the causal features include temporal causality, spatial causality, and intensity correlation; temporal causality is the chronological order of anomalous events in the time dimension, spatial causality is the propagation path of anomalous events in the spatial dimension, and intensity correlation is the intensity change of anomalous signals during propagation.
[0021] The risk indicators are used to quantify the degree of risk of abnormal propagation, and the risk indicators include propagation speed, root cause overlap, and potential impact.
[0022] An intelligent monitoring system based on dual-mode communication, the system comprising:
[0023] The data acquisition and initial screening module is used to acquire basic data information and calculate real-time noise similarity. If the real-time noise similarity is greater than the similarity threshold, the first anomaly is output. If the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained.
[0024] The dual-mode time-connection module is used to calculate the cross-mode support between two signals based on multi-dimensional signal characteristics. If the cross-mode support is greater than 0.7, a time-connection matrix is established and a multi-level detection mechanism is set to detect abnormal signals.
[0025] The anomaly propagation image generation module is used to obtain the spatiotemporal propagation state based on the time-linked matrix, obtain the propagation characteristics of nodes in the first range, and construct the main anomaly propagation map; mark the detected several anomaly signals as propagation source nodes, extract signal feature fingerprints, and mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation characteristics of all nodes in the second range and generate the sub-anomaly propagation map;
[0026] The causal analysis module is used to analyze causal characteristics based on the secondary anomaly propagation graph, determine causal paths, identify risk indicators to obtain risk indices, and predict threat levels.
[0027] The grouping module is used to acquire causal characteristics and causal paths and group the system according to constraints.
[0028] The strategy generation module is used to generate cross-level strategies based on threat levels, detect cross-level conflicts, and set execution priorities for hierarchical execution; construct intra-group causal graphs and assess intra-group risk status in real time, and set intra-group collaborative strategies; assess global risk status and dynamically select whether to trigger cross-group collaborative strategies.
[0029] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0030] By collecting multi-dimensional signal features and constructing a spectral feature library, noise interference can be quickly identified, effectively distinguishing between communication problems and noise interference, thus improving the accuracy of noise identification. The temporal complementarity and spatial synergy of HPLC and HRF modes are quantified, and new feature vectors are generated based on cross-modal support. Dual-mode signal features are fused to eliminate blind spots in single-mode perception. The feature fusion strategy is dynamically adjusted to accurately identify the correlation and complementarity between different modes, improving monitoring accuracy. A communication network topology map is constructed, and combined with a node spatial coordinate database, association rules are set to obtain a temporal linkage matrix. A multi-level detection mechanism is then used to locate the source of anomalies. Attached Figure Description
[0031] Figure 1 This is a schematic diagram of a smart monitoring method based on dual-mode communication in an embodiment of the present invention;
[0032] Figure 2 This is an architecture diagram of an intelligent monitoring system based on dual-mode communication in an embodiment of the present invention. Detailed Implementation
[0033] To facilitate understanding of the present invention, a more complete description of this application will be given below with reference to the accompanying drawings, which illustrate preferred embodiments of the invention. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to enable a more thorough and complete understanding of the disclosure of the present invention.
[0034] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to limit the invention; the term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0035] Example 1: As Figure 1As shown, an intelligent monitoring method based on dual-mode communication is described, the method comprising:
[0036] S1: Obtain basic data information, extract multi-dimensional signal features to construct a spectrum feature library, and calculate real-time noise similarity; if the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly; if the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained.
[0037] In this embodiment, basic data information is obtained from the target node (such as a smart meter, concentrator, or transformer terminal) through active polling (e.g., sending query commands periodically) or passive reception (e.g., listening to data uploaded by the node). The basic data information includes the target node's device information, communication mode, and basic signal information. The device information includes a node number (a unique identifier for the device in the communication network, used to locate the device within the network), signal timing information (recording the time sequence and path information of signal transmission, used to track the signal source and flow), device type (distinguishing between different devices such as smart meters, concentrators, and transformer terminals to adapt to feature analysis strategies), and device status flags (indicating whether the device is in a normal, standby, or faulty state). The communication mode indicates whether the device is currently using the HPLC or HRF mode. The basic signal information refers to carrier signals, modulation signals, and noise signals. This embodiment uses dual-channel parallel acquisition, simultaneously acquiring the main communication frequency band and the environmental noise frequency band, and adding a timestamp and frequency marker to each signal sample. The main communication frequency band acquires carrier signals (continuous wave signals of the main frequency band) and modulation signals (modulated actual data signals); the environmental noise frequency band acquires noise signals (environmental interference signals, such as noise from industrial frequency converters).
[0038] The multidimensional signal features are used to quantify signal quality. These features include, but are not limited to, frequency distribution, harmonic content, signal-to-noise ratio (SNR), bit error rate (BER), and fluctuation index. Frequency distribution refers to the energy distribution of the carrier signal in different frequency bands, reflecting the signal's frequency domain characteristics. Harmonic content is expressed as total harmonic distortion (THD), used to measure the degree of signal distortion (high values indicate signal distortion due to environmental interference). The signal-to-noise ratio indicates signal quality, with high values indicating clear signals. The bit error rate is obtained by decoding standard test frames (sent by the system), reflecting data transmission reliability (low values indicate accurate transmission). The fluctuation index measures the drastic change in signal amplitude, calculated by analyzing the carrier signal envelope (amplitude variation) (high values indicate signal instability), and ranges from [0, 1].
[0039] In some embodiments, multidimensional signal features are extracted based on basic data information. Specifically, this includes applying FFT (Fast Fourier Transform) or wavelet transform to the carrier signal to convert the time-domain signal to the frequency domain, calculating the energy distribution of each frequency band, generating frequency distribution features, and dividing sub-bands based on communication frequency band characteristics (e.g., 2-30MHz divided into 10 sub-bands); extracting fundamental (main frequency) energy and harmonic (integer multiples of frequency) energy from the carrier signal, calculating harmonic content using frequency domain integration, with the fundamental frequency determined by the communication standard (e.g., 12MHz fundamental for HPLC); extracting SNR: separating signal power (average power of the carrier signal) and noise power (average power of the ambient noise band), calculating the ratio using power spectral density, and converting it to dB units; calculating BER: the system sends a predefined test frame (e.g., a 256-bit pseudo-random sequence), decodes and compares the differences between the transmitted and received data at the receiving end, and counts the number of error bits; calculating the fluctuation index: performing envelope detection on the carrier signal (using Hilbert transform or peak detection), calculating the standard deviation and mean of the envelope signal, and obtaining the fluctuation index. The above feature extraction techniques are commonly used, and this embodiment does not impose specific limitations.
[0040] In some embodiments, a spectral feature library is constructed to store a database of typical noise spectral features for noise identification; environmental noise templates (such as inverter noise, motor interference, etc.) are pre-collected or learned, each template including noise type, spectral feature vector (primarily frequency distribution), and statistical attributes (historical mean, standard deviation). Specifically, this includes: collecting noise signals (ambient noise frequency band 0-500kHz only) under various typical noise scenarios before system deployment or during low-load periods. For example: inverter noise in industrial areas (feature: 150Hz harmonic peak), household appliance interference in residential areas (feature: broadband white noise), and natural interference (such as lightning pulses), with at least 100 samples collected for each noise type; performing frequency domain analysis on each noise sample to extract the spectral feature vector, with key elements including the main peak frequency, bandwidth, and harmonic distribution; storing the noise feature vector, noise type label (e.g., "inverter harmonics"), and historical statistics (mean, standard deviation) in the database, with the noise type label being manually labeled or automatically generated by clustering. During normal operation, when the system detects a new noise pattern (with a similarity lower than the pre-set similarity threshold, which is dynamically set based on historical data), it automatically adds a new template and calculates historical parameters for each template, such as the average noise power and the average harmonic content.
[0041] In some embodiments, the real-time noise similarity is a scalar value in the range [0, 1], representing the degree of similarity between the real-time noise spectrum and a noise template in a spectral feature library. A higher value (closer to 1) indicates a high degree of match between the noise and the template (e.g., 0.95 represents 95% similarity), which is used to identify known interference sources. The parameter deviation represents the degree of deviation of the current signal parameters (e.g., SNR, BER) from their historical baseline values. The historical baseline is derived from the average parameters under normal conditions (stored in historical records over the past 24 hours).
[0042] Based on historical experimental data and specific needs, a noise similarity threshold (e.g., 95%) is pre-set. If the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly. That is, if the real-time noise similarity is greater than 95%, it is marked as the first anomaly, which means that the corresponding anomaly is determined to be a noise anomaly. The anomaly of the communication mode is excluded, and only the device noise anomaly needs to be processed. If the real-time noise similarity is not greater than 95%, the anomaly of the communication mode cannot be excluded. In this case, the parameter deviation is calculated and an initial anomaly value is obtained. The anomaly of the communication mode is further judged based on the initial anomaly value.
[0043] In some embodiments, the parameter deviation refers to the deviation of SNR deviation rate, BER growth rate and harmonic distortion rate. The above deviation indices are obtained by comparing the mean of real-time data with the mean of historical data, and the obtained data is normalized, the corresponding weight coefficients are preset, and the weighted sum is performed to obtain the initial outlier value.
[0044]
[0045] Where R is the initial outlier; These are the SNR deviation rate, BER growth rate, and harmonic distortion rate deviation, respectively. These are the corresponding weighting coefficients.
[0046] In some embodiments, the normal range of initial outliers is adaptively based on historical data and dynamically adjusted according to actual conditions. A first threshold and a second threshold are preset based on historical data or experimental records. For example, if the first threshold is set to 0.6 and the second threshold is set to 0.3, then: Normal: initial outlier < 0.3 (parameter deviation is less than the threshold); Warning: 0.3 ≤ initial outlier < 0.6 (potential outlier, reverse testing is performed, and the handling plan is further determined based on the reverse testing results); Outlier: initial outlier ≥ 0.6 (confirmed outlier).
[0047] In some embodiments, the anomaly type is initially determined based on an initial anomaly value and a pre-set first and second threshold. The anomaly types include environmental noise interference, line attenuation, and equipment failure. When the anomaly category is "line attenuation failure" and the reverse test result consistency rate is >90% (the reverse test compares the consistency between the original signal and the retransmitted signal), the communication mode is immediately switched (e.g., from HPLC to HRF). Reason: A continuous decrease in SNR indicates physical line attenuation; HRF mode (radio) can bypass line problems. When the anomaly category is "equipment hardware failure" and the reverse test result consistency rate is >90%, the communication mode is switched and the fault is reported. Reason: An increase in BER indicates an internal equipment error; switching to a backup mode ensures communication continuity. If it is environmental noise interference (Type 1), even if the anomaly index is high, the mode is not switched (only power is increased); noise is not mode-dependent. If the reverse test result consistency rate is <90%, a reassessment (supplementary testing) is required to avoid accidental switching. Mode switching is only initiated when a physical layer or equipment problem is confirmed to ensure resource efficiency. The mode switching command is sent through a reliable channel, and the connection status is verified in the new mode.
[0048] If the initial outlier value is greater than the preset first threshold, proceed to step S2: calculate the cross-modal support between the two signals based on the multidimensional signal characteristics. If the cross-modal support is greater than 0.7, establish a time-linked matrix and set a multi-level detection mechanism to detect the outlier signal. The multi-level detection mechanism includes instantaneous outlier capture, spatiotemporal propagation analysis, and composite outlier index.
[0049] In some embodiments, the cross-modal support is a quantitative indicator used to measure the feature complementarity of two different communication modes in different dimensions, and its range is [0, 1]. A spatiotemporal synchronous acquisition system is constructed, and a high-precision clock module is used to ensure the time alignment of HPLC and HRF signal acquisition. A node spatial coordinate database is established to record the physical location of each node in the power distribution network. The multidimensional signal features are classified into time-domain features, frequency-domain features, and spatial-domain features, corresponding to HPLC feature sets and HRF feature sets, respectively. The HPLC feature set includes the following features: time-domain features: signal intensity fluctuation rate, envelope mutation count; frequency-domain features: harmonic distortion spectrum, signal-to-noise ratio distribution; spatial-domain features: adjacent node signal correlation matrix. The HRF feature set includes the following features: time-domain features: signal attenuation slope, packet loss rate; frequency-domain features: spectral flatness, frequency offset index; spatial-domain features: spatial propagation attenuation gradient.
[0050] In some embodiments, cross-modal support is calculated based on multi-dimensional signal characteristics, including a temporal complementarity coefficient and a spatial coordination index. The temporal complementarity coefficient is the absolute value of the difference between HPLC temporal stability and HRF temporal stability minus the comprehensive coefficient, with a comprehensive coefficient of 1. The spatial coordination index is the covariance of HPLC node correlation and HRF spatial gradient. The cross-modal support is the sum of the temporal complementarity coefficient and the spatial coordination index. HPLC temporal stability is used to quantify the amplitude fluctuation of the power line signal (1 - fluctuation index), reflecting abrupt changes in grid impedance; HRF temporal stability is used to quantify the continuity of wireless transmission (1 - packet loss rate), reflecting spatial channel quality. HPLC temporal stability and HRF temporal stability provide inputs for the cross-modal temporal complementarity coefficient, dynamically guiding the feature fusion strategy, avoiding mutual dragging down of dual modes under a single fault mode, and improving the robustness of the system in complex interference environments.
[0051] In this embodiment, the signal features extracted by HPLC and HRF communication modes are mathematically combined based on cross-modal support to generate a more comprehensive and robust new feature vector, thereby solving the perception blind spot of a single communication mode and enhancing the accuracy of anomaly detection.
[0052] In some embodiments, establishing a time-linked matrix includes: constructing a communication network topology map, obtaining a node spatial coordinate database, including physical locations and connection relationships; setting association rules, such as direct adjacency (A and B are directly connected by power lines, weight set to 1); spacing between one node, weight set to 0.6; spacing between multiple nodes, weight set to 0.3; and location under the same transformer, weight set to 1.3. An N*N dimensional spatial association matrix is output (N is the number of nodes); a physical attenuation factor is added to each communication path, the physical attenuation factor being the reciprocal of the square root of the product of physical spatial distance and dielectric attenuation coefficient. A three-layer time-level architecture is adopted in the time dimension, including minute-level, hour-level, and historical-level. The historical-level is generated from historical time data and used to compare with the current fault state, thereby achieving accurate dynamic prediction. The spatial association matrix is divided according to the time dimension to obtain the time-linked matrix. In terms of spatial characteristics, based on the tree / mesh connection of distribution network nodes, faults will spread along electrical paths; in terms of temporal characteristics, interference often propagates in a pattern of sudden onset, continuous attenuation, and baseline recovery.
[0053] This embodiment quantifies the probability of fault propagation between nodes by spatial correlation and setting spatial weights based on connection relationships and distances. For example, when node A is abnormal, the risk of its impact on other nodes can be calculated, enabling early warning of high-risk nodes. A fault propagation dynamic model is established through temporal correlation, enabling tiered responses to the same abnormal event, capturing the sudden time node and fault source of the welding machine; discovering continuous changing trends; and matching historical patterns. Propagation analysis is performed based on both temporal and spatial correlation steps, reducing the false negative rate and location error rate, improving fault classification accuracy, accelerating response efficiency, and achieving instantaneous capture. Power communication faults are highly correlated, and traditional single-fault-point analysis cannot achieve global status monitoring.
[0054] In some embodiments, the multi-level detection mechanism includes instantaneous anomaly capture, spatiotemporal propagation analysis, and composite anomaly index. By detecting sudden anomalies in complex abnormal states, the mechanism uses three different levels of detection methods to conduct comprehensive and in-depth analysis and judgment of abnormal situations from multiple perspectives, thereby improving the accuracy and reliability of anomaly detection and ensuring that serious sudden faults can be detected and accurately determined in a timely manner.
[0055] The instantaneous anomaly detection primarily focuses on sudden changes in data over time. By pre-setting a mutation threshold based on historical data and experimental results, potential anomalies are quickly identified, and cross-modal verification is used to further confirm the authenticity of the anomalies, avoiding misjudgments. Specifically, a mutation threshold is set: during data acquisition, the characteristic differences between adjacent sampling points are continuously monitored. Based on the fluctuation range of historical data, a threshold is set. When the characteristic difference between adjacent sampling points exceeds three times the historical fluctuation range, an instantaneous anomaly alarm is triggered. For example, when monitoring the temperature data of an equipment, if the historical temperature fluctuation range is within ±5 degrees, a temperature difference exceeding 15 degrees between two adjacent sampling points is considered a possible instantaneous anomaly. To ensure that the detected instantaneous anomalies are real interferences rather than accidental data fluctuations or false alarms, a dual-modal detection method is adopted. That is, two different types of data acquisition methods or sensors are used simultaneously to monitor the same object. Only when both modalities detect a sudden change is it confirmed as a real interference. For example, when monitoring traffic flow, both inductive loop detectors are used to detect vehicle passage, and cameras are used for image recognition and counting. Only when both detect a sudden change in traffic flow is it determined to be a real anomaly.
[0056] If both modes detect a sudden change in the transient anomaly capture result, the existence of a real transient disturbance is successfully confirmed. This result provides a basis for subsequent spatiotemporal propagation analysis and composite anomaly index calculation, clarifying the starting point of the anomaly. If only one mode detects a sudden change, or if the characteristic difference between adjacent sampling points does not exceed the set sudden change threshold, it is determined to be a false alarm or a non-anomaly, and the system continues normal data monitoring.
[0057] The spatiotemporal propagation analysis obtains the spatiotemporal propagation state based on the time-linkage matrix, acquires the propagation characteristics of nodes within a first range, and constructs a main anomaly propagation map. The first range is centered on an anomalous signal node, encompassing directly connected nodes and the area covered by one or two relay nodes. The first range is smaller than the second range. It can be set according to the communication network topology, the importance of nodes, the size of the power grid, and the historical fault propagation range. For core nodes (such as important transformer terminals), due to their numerous connected nodes and large impact range, the first range can be appropriately expanded; while for edge nodes, the first range is relatively smaller.
[0058] Within the first range, by monitoring the signal characteristics of each node, the node where the earliest abnormal characteristics appear is identified as the starting point of the anomaly. The signal characteristic changes of each node within the first range are continuously monitored at subsequent time points, recording the order and direction of the anomaly's propagation from one node to adjacent nodes. For example, by analyzing communication links and signal strength changes between nodes, the propagation method of the anomaly is determined. The time required for the anomaly to propagate from one node to an adjacent node is measured to determine the propagation speed. For example, the propagation speed is calculated by recording the time difference between the occurrence of the anomaly at two adjacent nodes and combining this with the distance between the nodes.
[0059] A master anomaly propagation map is created based on the node where the anomaly first appears, the propagation path, and the spread speed, visually presenting the anomaly's propagation process within a first-range area. Based on this first range, the local propagation of the anomaly is preliminarily determined, quickly locating key nodes that may be directly affected. Within this range, the initial spread trend of the anomaly can be detected in a timely manner. For example, in power communication networks, the first range can help quickly determine whether smart meters or concentrators directly connected to the anomaly node are affected. Further differentiation is made regarding the correlation and mutual influence between communication modes and equipment failures.
[0060] Using interference source localization formulas, potential interference sources can be located from the perspective of temporal and spatial correlation. Specifically, the localization formula based on temporal and spatial correlation calculates the correlation coefficient using the time information of anomalies occurring at each node and the spatial distance between nodes. For example, let the anomaly occurrence times of nodes i and j be... and If the spatial distance is , then the correlation coefficient is... The calculation formula is expressed as:
[0061]
[0062] Where n is the total number of sampling points within the time window used for calculation. and These are the average anomaly occurrence times for nodes i and j within this time window, respectively. and These represent the duration of the anomaly at sampling point K. By analyzing the magnitude and distribution of the correlation coefficients, it was found that the node pairs with larger correlation coefficients exhibit a strong correlation between the anomaly occurrence time and spatial distance. Therefore, the specific locations pointed to by these nodes are likely to be the source of interference.
[0063] Once a transient anomaly is confirmed, the system begins recording relevant information and constructing an anomaly propagation graph. First, the node where the anomaly first appears is identified, i.e., the starting point of the anomaly. Then, the propagation path of the anomaly is tracked at subsequent time points, recording the order and direction of its spread to other nodes. Simultaneously, the propagation speed of the anomaly is calculated, for example, by measuring the time required for the anomaly to propagate from one node to an adjacent node. Using the time information of the anomaly occurrence at each node and the spatial distance between nodes, their correlation coefficients are calculated. The correlation coefficient reflects the degree of association between the anomaly occurrence time and spatial distance. By analyzing the magnitude and distribution of the correlation coefficient, potential sources of interference can be located. For example, if the anomaly occurrence time of some nodes shows a strong correlation with their spatial distance to a specific location, then that specific location is likely the source of interference.
[0064] The spatiotemporal propagation analysis results generate an anomaly propagation map that visually illustrates the propagation process of an anomaly in time and space, helping to understand its development trend and scope of impact. For example, in network fault detection, the anomaly propagation map can clearly show which node the fault originated from, how it spread to other nodes, and the speed of propagation. The correlation coefficient calculated using the interference source localization formula provides important clues for locating potential interference sources. Based on these clues, targeted inspections and troubleshooting of relevant areas or equipment can be conducted, improving the efficiency of fault handling.
[0065] The composite anomaly index integrates multiple key factors such as the intensity of the instantaneous anomaly, its propagation speed, and its impact range. A weighted calculation yields a comprehensive index, which serves as the standard for determining severe sudden faults, making fault assessment more scientific and comprehensive. Specifically, based on the instantaneous anomaly intensity, propagation speed, and impact range information obtained from previous detections, a weighted calculation is performed according to given weights. The formula for calculating the suddenness index is: Suddenness Index = Instantaneous Intensity × 0.5 + Propagation Speed × 0.3 + Impact Range × 0.2. Here, instantaneous intensity can be measured by the degree of abrupt change determined during the instantaneous anomaly capture phase; propagation speed is obtained from the spatiotemporal propagation analysis phase; and impact range can be determined based on the number of nodes or the size of the region involved in the anomaly propagation graph. The calculated suddenness index is compared with a preset threshold of 0.65. When the suddenness index is greater than 0.65, it is determined to be a severe sudden fault, and the system will trigger a corresponding alarm mechanism to notify relevant personnel for handling.
[0066] The composite anomaly index is used to determine a severe sudden failure. A sudden failure index greater than 0.65 is considered a severe sudden failure. Emergency measures are taken to prevent the failure from escalating further and to reduce the impact on the system or business operations. If the sudden failure index is less than or equal to 0.65, the anomaly is considered not yet severe, but continued monitoring is still required. The system will continue to monitor and analyze the anomaly to prevent it from worsening.
[0067] In some embodiments, dynamic analysis based on the time-linked matrix and setting up a multi-level detection mechanism solves the problem of one-sided analysis caused by independent detection of a single node in the prior art, as well as the problems of ignoring fault propagation and being unable to adapt to dynamic changes in complex environments. It realizes the quantification of the influence relationship between nodes through spatial topology, recording the path and speed of abnormal diffusion, and dynamically associating historical scenes and real-time fluctuations.
[0068] S3: Mark the detected abnormal signals as propagation source nodes, extract signal feature fingerprints, and mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation features of all nodes in the second range and generate a sub-abnormal propagation map.
[0069] In some embodiments, the second range is centered on the source node, identifying the diffusion influence of each node, pre-setting a minimum influence threshold, statistically analyzing the diffusion influence of nodes in historical data over a period of time (e.g., 24 hours), and calculating the average value as the minimum influence threshold; the area covered by nodes whose diffusion influence exceeds the minimum influence threshold. Specifically, several detected abnormal signals are marked as propagation source nodes. Given several source nodes, the diffusion influence of each node (source node, initial diffusion node, mutation node, and intersection node) is identified centered on one source node. For overlapping influence areas, one can be randomly selected. Combining node structural characteristics and propagation dynamic characteristics, the diffusion influence of each node is calculated. First, the propagation probability of the node is determined, simulating independent activation behavior between nodes and the cumulative effect of a node being influenced by its neighbors. The independent activation behavior is based on the number of direct connections between nodes, referring to the probability that a node independently triggers propagation through its own direct connections (i.e., one-hop neighbors), reflecting the node's basic propagation capability. Its core assumption is that the occurrence of a propagation event depends only on the direct relationship between the source node and the target node, and is not affected by other intermediate nodes. For example, if node A has 3 neighbors B, C, and D, and... The probability that A independently activates at least one neighbor is 1−(1−0.3)*(1−0.2)*(1−0.1)=0.496.
[0070] The cumulative effect refers to the probability that a node triggers propagation through the indirect influence of its multi-hop neighbors, reflecting the node's deep propagation potential. Its core assumption is that the occurrence of a propagation event depends on the node's core position in the propagation network or the cumulative influence of its neighbors. This requires calculating the influence of a single node and its corresponding weight value. For example, if the influence of node A's neighbors B and C are I(B) = 0.6 and I(C) = 0.4 respectively, and the weights are... The cumulative effect is min(1, 0.7×0.6+0.3×0.4)=0.54.
[0071] For each node, the probability of activating neighboring nodes through independent activation and cumulative effects is calculated simultaneously. A weighted average of these probabilities is taken as the final propagation probability. Dynamic features are then identified, including information decay over time (calculated using an exponential decay function) and the diversity of propagation paths. The shortest path from a node to other nodes reflects propagation redundancy, and the path influence value reflects the redundancy and efficiency of propagation paths between nodes; shorter paths and lower redundancy indicate higher propagation efficiency. The average path distance is obtained by acquiring all path distances between any two nodes. The corresponding path influence propagation degree is determined based on the average path distance (calculated using the path distance and exponential decay function mentioned above), and is used as the path influence value, ranging from [0, 1]. The final propagation probability, exponential decay function, and path influence value are normalized and then weighted and summed to obtain the diffusion influence degree of each node.
[0072] In some embodiments, a minimum impact threshold can be preset by fitting an influence distribution curve based on the actual influence data of nodes in historical propagation events, and calculating the standard deviation as the minimum impact threshold. This embodiment does not impose specific limitations.
[0073] In some embodiments, the second range is obtained by further expanding or adjusting the first range, involving a wider range of node connections. In this embodiment, the second range is defined by comparing the diffusion impact degree of each node with a minimum impact threshold, and defining the area covered by nodes whose diffusion impact degree is greater than the minimum impact threshold. Specifically, the division of the second range can be adjusted according to actual circumstances, for example, including nodes that are indirectly connected to nodes within the first range (through multi-level relays), or determined based on the overall network layout and potential paths for fault propagation. For example, if the first range mainly covers a small area where the abnormal node is located, the second range can be extended to several adjacent similar areas to comprehensively monitor the propagation of the anomaly.
[0074] The second scope focuses on comprehensively monitoring the propagation of anomalies throughout the network, identifying potential spread paths and a wider range of impact. Analysis within the second scope helps determine whether anomalies will cross different regions or subnets, allowing for more comprehensive responses. For example, after an anomaly is initially contained within the first scope, analysis within the second scope can assess whether it will re-spread to other areas.
[0075] Several detected anomalous signals are labeled as propagation source nodes. These nodes are either key nodes in the main anomaly propagation process or newly emerging anomalous nodes within the second range. The signals of the propagation source nodes are analyzed in detail to extract their unique signal characteristics, forming signal feature fingerprints. Changes in the signal characteristics of nodes adjacent to the propagation source nodes within the second range are monitored, and the propagation of the anomaly at these nodes is recorded. Based on the propagation characteristics of the propagation source nodes, adjacent nodes, and signal feature fingerprints, a secondary anomaly propagation map is generated, and initial diffusion nodes (nodes where the anomaly first spreads from the propagation source node), mutation nodes (nodes where signal characteristics change significantly), and intersection nodes (nodes where multiple anomaly propagation paths intersect) are labeled, comprehensively demonstrating the propagation of the anomaly within the second range.
[0076] Signal fingerprints are abstract representations of the unique characteristics of a signal. They contain key feature information of the signal across multiple dimensions, uniquely identifying a signal or distinguishing signals from different sources. For example, in power communication signals, signal fingerprints can include frequency distribution characteristics, harmonic content patterns, and specific modulation methods. Signal fingerprints accurately describe the unique characteristics of a signal, improving the accuracy and reliability of signal identification. Even in complex signal environments, different signal sources can be distinguished using signal fingerprints. In anomaly detection, they are used to identify the source and characteristics of abnormal signals, helping to determine the type and cause of the anomaly. For example, by comparing the feature fingerprints of normal and abnormal signals, it can be determined whether the abnormal signal is caused by equipment failure, environmental interference, or other reasons. This application utilizes real-time monitoring based on dual-mode communication to analyze and identify abnormal signals, enabling monitoring of the entire system.
[0077] Propagation characteristics refer to the various features exhibited by a signal during propagation, including signal strength changes, propagation path, and propagation time. It reflects the propagation behavior and characteristics of a signal within a network. Signal strength monitoring devices are installed at each node in the network to monitor signal strength changes in real time. For example, in power communication networks, signal monitoring modules on smart meters or concentrators record signal strength at different locations. The path information of a signal propagating from one node to another is recorded using the network topology and communication protocols. For example, the propagation path is determined by analyzing the communication links and data flow between nodes. Recording the propagation time of a signal between different nodes can be achieved by adding timestamps to the signal. For example, the transmission time is recorded at the sending node, and the reception time is recorded at the receiving node; the difference between the two is the propagation time.
[0078] This embodiment, by identifying and analyzing propagation characteristics, can comprehensively and accurately describe the behavior and characteristics of signals during propagation, providing important basis for fault analysis and anomaly detection. In spatiotemporal propagation analysis, propagation characteristics are used to construct anomaly propagation maps, showing the propagation process and impact range of anomalies. By analyzing propagation characteristics, the propagation path and diffusion speed of anomalies can be determined, assisting in locating the interference source. For example, when a sudden drop in signal strength is detected in a certain area, analyzing propagation characteristics can determine whether it is caused by a line fault or an equipment fault.
[0079] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages:
[0080] This application rapidly identifies noise interference by collecting multi-dimensional signal features and constructing a spectrum feature library, effectively distinguishing between communication problems and noise interference, and improving the accuracy of noise identification.
[0081] The temporal complementarity and spatial synergy of quantification HPLC and HRF modes are used to generate new feature vectors based on cross-modal support, fuse dual-mode signal features, eliminate the blind spot of single-mode perception, dynamically adjust feature fusion strategy, accurately identify the correlation and complementarity between different modes, and improve monitoring accuracy.
[0082] A communication network topology map is constructed, and a node spatial coordinate database is combined with association rules to obtain a time-linked matrix. An anomaly source is located through a multi-level detection mechanism.
[0083] Example 2: Continue to refer to Figure 1 The method further includes: S4: Analyzing causal characteristics based on the sub-anomaly propagation graph, determining causal paths, identifying risk indicators to obtain risk indices, and predicting threat levels.
[0084] In some embodiments, the causal features include temporal causality, spatial causality, and intensity correlation. Temporal causality refers to the chronological order of anomalous events in the time dimension, reflecting the dynamic process of propagation. Nodes in the sub-anomaly propagation graph are sorted according to the time of anomaly occurrence to construct a time sequence chain. The time interval between adjacent nodes is calculated to identify key time nodes (such as mutation points). For example, if node A becomes anomalous at t=10s and node B becomes anomalous at t=15s, and A and B are directly connected, then A→B is a temporal causal chain. Spatial causality is the diffusion path of anomalous events in the spatial dimension, reflecting the influence of network topology. Based on the propagation path in the sub-anomaly propagation graph, the spatial distance between nodes (such as physical distance or hop count) is calculated to identify high-frequency propagation paths (such as paths shared by multiple anomaly chains). For example, if an anomaly spreads from the transformer terminal to three adjacent smart meters, then the transformer terminal is the spatial causal source. Intensity correlation is the intensity change of the anomalous signal during propagation, reflecting the attenuation or enhancement effect of propagation. For nodes along the propagation path, calculate the rate of change of signal strength (such as SNR) and identify points of abrupt changes in strength (such as a sudden drop or rise in SNR). For example, if a signal propagates from node A (SNR=20dB) to node B (SNR=15dB), the strength attenuation rate is 25%.
[0085] In some embodiments, risk indicators are identified based on causal features. These risk indicators quantify the degree of risk in anomaly propagation and include propagation speed, root cause overlap, and potential impact. Propagation speed is the number of nodes or the geographical area affected by the anomaly per unit time. Root cause overlap is the similarity between the current anomaly and the root causes of historical anomalies. The propagation source features of the current anomaly (such as equipment type and location) are extracted and matched with a historical anomaly root cause database to calculate the J-similarity coefficient. For example, if the current anomaly source has a 0.8 overlap with the source features of three historical inverter interference events, then the root cause overlap is 0.8. Potential impact refers to the number of edge nodes or the proportion of critical equipment that the anomaly may affect. Based on the network topology, the number of nodes that the anomaly may spread to is calculated, critical equipment (such as transformer terminals) is identified, and the probability of being affected is calculated. For example, if the anomaly may affect 10 nodes, of which 2 are critical equipment, then the potential impact is... (N is the total number of nodes, H is the number of critical devices). The acquired risk indicator data is normalized to a range of [0, 1], and then weighted and summed (propagation speed is set to 0.4, root cause overlap to 0.4, and potential impact to 0.2) to obtain the risk index. Based on the magnitude of the risk index and pre-set corresponding rules, the threat level (Level 1, Level 2, Level 3) is determined. For example, a risk index of not less than 0.4 corresponds to Level 1 threat, a risk index greater than 0.4 and less than 0.6 corresponds to Level 2 threat, and a risk index of not less than 0.6 corresponds to Level 3 threat. Specific adjustments need to be made dynamically based on the propagation degree of the risk path and the number of nodes involved.
[0086] S5: Generates cross-layer policies based on threat levels, including signal layer, device layer, and network layer; detects cross-layer conflicts and sets execution priorities for hierarchical execution.
[0087] In some embodiments, corresponding cross-layer strategies are selected based on the threat level, including the signal layer, device layer, and network layer. Facing a level 3 threat requires handling strategies across all three layers. Specifically, layered response strategies are generated, and cross-layer conflicts are resolved. Signal layer strategies include: adjusting communication modes (e.g., switching from HPLC to HRF), increasing signal power, or switching frequency bands. Device layer strategies include: isolating faulty devices (e.g., disconnecting malfunctioning smart meters) and activating backup devices (e.g., switching to a backup transformer terminal). Network layer strategies include: rerouting traffic (e.g., bypassing abnormal areas) and limiting communication bandwidth in abnormal areas.
[0088] Detect and determine the type of conflict, including resource conflicts (e.g., signal layer boosting power and device layer isolation devices simultaneously require communication resources) and target conflicts (e.g., network layer rerouting may cause service delays). Set priority rules: policies with high threat levels are executed first, policies involving critical devices are executed first, and policies with the least impact on the system are selected. For example, if signal layer boosting power (priority 2) conflicts with device layer isolation devices (priority 1), then the device layer policy is executed first.
[0089] In this embodiment, the "cause" is traced from the "result" of anomaly propagation to reveal the evolutionary pattern of the anomaly. Existing technologies typically only focus on the spatial-temporal distribution of anomalies (e.g., which nodes are anomalous and when), but cannot explain how anomalies propagate (e.g., whether anomaly at node A leads to anomaly at node B). This embodiment sets up causal features, and by identifying temporal causality (the order of anomalies), spatial causality (network topology dependent on propagation paths), and intensity correlation (signal attenuation or enhancement patterns), a logical chain of anomaly propagation can be constructed, achieving technical effects that are difficult to achieve with simple statistical correlation. In dual-mode communication (HPLC+HRF), causal features can distinguish between noise interference (no clear causal chain) and equipment failure (with a clear propagation path), determine the true propagation direction, and avoid misjudgment. Combining causal features (e.g., inverter interference causing power line noise, which in turn causes smart meter errors), the threat level can be associated with a specific root cause (e.g., inverter model and location), supporting targeted remediation.
[0090] This embodiment addresses the limitations of single-layer strategies by achieving end-to-end anomaly management through coordinated responses at the signal, device, and network layers. Signal layer: Directly adjusting communication parameters (such as switching frequency bands or increasing power) can quickly suppress interference, but cannot resolve device faults. Device layer: Isolating faulty devices (such as disconnecting smart meters) can block propagation, but may cause localized service interruptions. Network layer: Rerouting traffic (such as bypassing abnormal areas) can maintain communication, but may increase latency. Combining the advantages of a three-layer strategy (such as signal layer power enhancement + device layer fault isolation + network layer rerouting) balances the dual objectives of rapid recovery and minimal impact. Setting up cross-layer conflict detection and priority grading enables parallel implementation of multi-layer strategies, resolving cross-layer conflict issues.
[0091] The technical solutions described in the embodiments of this application have at least the following technical effects or advantages:
[0092] This application analyzes temporal causality, spatial causality, and intensity correlation from the sub-anomaly propagation graph. Based on causal characteristics, it identifies risk indicators such as propagation speed, root cause overlap, and potential impact, and obtains a risk index through normalized weighted summation. The threat level is determined based on the risk index and preset rules. An anomaly propagation logic chain is constructed to distinguish between noise interference and equipment failure, determine the true propagation direction, and further improve the accuracy of communication monitoring. Based on the threat level, cross-layer strategies are generated at the signal layer, device layer, and network layer. Cross-layer conflicts are detected, and execution priorities are set for hierarchical execution. Specific anomaly root causes are identified, enabling rapid cross-layer anomaly handling.
[0093] Example 3: Continue to refer to Figure 1 The method further includes: S6: acquiring causal features and causal paths, grouping the system according to constraints, the grouping including propagation grouping, diffusion grouping and hybrid grouping; constructing intra-group causal graphs and evaluating intra-group risk status in real time, setting intra-group collaboration strategies; evaluating global risk status and dynamically selecting whether to trigger cross-group collaboration strategies; the constraints are maximizing the strength of causal relationships within a group and minimizing causal interactions between groups.
[0094] In some embodiments, all nodes are considered to be in an ungrouped state. The node with the strongest causal relationship is selected as the grouping seed (e.g., the node with the strongest causal relationship with the most nodes). For each seed node, ungrouped nodes with a causal relationship strength greater than a strength threshold (e.g., 0.6) are iteratively added. The strength threshold is a pre-set value used to measure the strength of causal relationships and needs to be set based on historical experimental data. For example, all abnormal devices in the historical data are identified, and the abnormal source devices are determined according to the corresponding device causal chains. The number of devices that become abnormal due to the abnormal source devices passing through the causal chains is selected. The strength threshold is set according to the proportion of the number and the degree of abnormality. For example, if the number of devices that become abnormal due to the causal chains is 40, the total number of abnormal devices is 80, and the proportion of the number is 50%, i.e., 0.5; among the 40 abnormal devices, the proportion of high-level abnormal devices is 30%, i.e., 0.3; the proportion of medium-level abnormal devices is 40%; and the proportion of low-level abnormal devices is 30%; therefore, the strength threshold is set as 1-(1-0.5)(1-0.3)=0.65, and the strength threshold can be initially set to 0.65. The above is merely a brief example of setting the intensity threshold. Specific settings need to be dynamically adjusted based on actual experimental data and requirements; this application does not impose specific limitations. The stopping condition is set as follows: the number of nodes within a group reaches its maximum (e.g., 20) or no new nodes can be added. The remaining ungrouped nodes are assigned to nearest-neighbor groups (based on spatial distance or causal relationship strength), ultimately forming an initial group list (including group ID, member nodes, and group type). Group types are defined, including propagation-type grouping, diffusion-type grouping, and hybrid grouping. For example: propagation-type grouping: based on a high-frequency temporal causal chain (e.g., inverter interference → power line noise → smart meter error); diffusion-type grouping: based on a high-frequency spatial causal path (e.g., transformer terminal → 3 adjacent concentrators); hybrid grouping: simultaneously includes strong temporal and spatial causal relationships.
[0095] In some embodiments, constructing an intra-group causal graph includes: acquiring the basic signal characteristics (SNR, BER) and propagation characteristics (propagation path, diffusion speed) of nodes within the group; performing temporal causal chain modeling: constructing a directed acyclic graph (DAG) with edge weights representing temporal causal strength (e.g., propagation frequency of A→B / total frequency); spatial causal path modeling: calculating the reciprocal of the spatial distance between nodes as the spatial causal weight; strength correlation modeling: mapping the SNR attenuation rate to strength correlation weights (e.g., a weight of 0.8 corresponding to a 20% SNR attenuation); and outputting the intra-group causal graph (nodes are devices, edges are causal relationship weights). Risk assessment is performed on the group, and the intra-group risk status is obtained based on the abnormal conditions of nodes within the group (risk propagation speed, abnormal impact, etc.). Intra-group coordination strategies are still dynamically set based on three levels, such as: signal layer: adjusting intra-group communication parameters (e.g., increasing power, switching frequency bands); device layer: isolating faulty devices within the group (e.g., disconnecting faulty smart meters); and network layer: limiting intra-group communication bandwidth or rerouting traffic.
[0096] In some embodiments, key causal information is shared through a standardized interface to maintain a global anomaly view, realize the transmission of causal relationships between groups and global awareness, assess the global risk status (obtain the standard deviation of the risk status within all groups to obtain or take the mode), and dynamically select whether to trigger cross-group collaboration strategies; for example, if the global risk index is greater than 0.6 or the number of cross-group causal chains exceeds the number threshold (e.g., 5), real-time cross-group collaboration strategies are implemented, such as: global switching of communication mode (e.g., HPLC→HRF), isolation of critical faulty equipment across groups, and rerouting of global traffic (e.g., bypassing high-risk groups).
[0097] In this embodiment, the grouping structure and inference parameters are optimized based on real-time causal feedback to improve adaptability and achieve dynamic optimization and adaptive adjustment of the grouping. Specifically: adjustment rules are set, such as: merging groups: if the number of cross-group causal chains between two groups is >3 and the spatial distance is <50 meters, then they are merged into a new group. splitting groups: if the number of causal chains within a group is >20 (too complex), then it is split into two sub-groups based on spatial distance. Triggering conditions: adjustment is triggered every 10 minutes or when the global risk index changes by >0.2. Causal relationship weights are adjusted based on historical data (e.g., if the prediction accuracy of a causal chain is <70%, its weight is reduced). If the anomaly is not alleviated after the strategy is executed within the group (e.g., SNR does not improve), then the causal relationship is re-inferred. Evaluation indicators are set as follows: inference time within the group: target <100ms; cross-group communication overhead: target <10% of total bandwidth; global anomaly detection accuracy: target >95%. Set iteration rules, for example: if the inference time within a group is >200ms, then split the group; if the cross-group communication overhead is >15%, then optimize the interface data volume.
[0098] This embodiment uses causal features and causal paths obtained from the above embodiments to perform grouping, achieving low-complexity causal reasoning and fast response within each group, reducing global computational load. For the first time, temporal / spatial / intensity causal features are transformed into grouping criteria, solving the problem of weak correlation in traditional grouping. Millisecond-level response is achieved through causal graphs within groups, avoiding global computational delays and enabling local autonomous reasoning within groups. A lightweight interface is designed to maintain a global anomaly view while reducing communication overhead, optimizing the efficiency of cross-group causal relationship transmission. The grouping structure is adjusted based on real-time causal feedback to adapt to dynamically changing network environments, achieving dynamic adaptive grouping optimization.
[0099] Example 4: This example also provides an intelligent monitoring system based on dual-mode communication, such as... Figure 2 As shown, the system includes: a data acquisition and screening module, used to acquire basic data information and calculate real-time noise similarity; if the real-time noise similarity is greater than the similarity threshold, the first anomaly is output; if the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained.
[0100] The dual-mode time-linked module is used to calculate the cross-mode support between two signals based on multi-dimensional signal characteristics. If the cross-mode support is greater than 0.7, a time-linked matrix is established and a multi-level detection mechanism is set to detect abnormal signals.
[0101] The abnormal propagation image generation module is used to obtain the spatiotemporal propagation state based on the time-linked matrix, obtain the propagation characteristics of nodes in the first range, and construct the main abnormal propagation map; mark the detected abnormal signals as propagation source nodes, extract signal feature fingerprints, and mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation characteristics of all nodes in the second range and generate the secondary abnormal propagation map.
[0102] The causal analysis module is used to analyze causal characteristics based on the sub-anomaly propagation graph, determine causal paths, identify risk indicators to obtain risk indices, and predict threat levels.
[0103] The grouping module is used to acquire causal characteristics and causal paths and group the system according to constraints.
[0104] The strategy generation module is used to generate cross-level strategies based on threat levels, detect cross-level conflicts, and set execution priorities for hierarchical execution; construct intra-group causal graphs and assess intra-group risk status in real time, and set intra-group collaborative strategies; assess global risk status and dynamically select whether to trigger cross-group collaborative strategies.
[0105] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. An intelligent monitoring method based on dual-mode communication, characterized in that, include: S1: Obtain basic data information, extract multi-dimensional signal features to construct a spectrum feature library, and calculate real-time noise similarity; If the real-time noise similarity is greater than the similarity threshold, it is marked as the first anomaly; If the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial outlier value is obtained. The parameter deviation refers to the deviation of SNR deviation rate, BER growth rate and harmonic distortion rate. The parameter deviation is normalized, the corresponding weight coefficient is preset, and the initial outlier value is obtained by weighted summation. S2: If the initial outlier value is greater than the preset first threshold, calculate the cross-modal support between the two signals based on the multi-dimensional signal characteristics. If the cross-modal support is greater than 0.7, establish a time-linked matrix and set a multi-level detection mechanism to detect the outlier signal. The multi-level detection mechanism includes instantaneous outlier capture, spatiotemporal propagation analysis, and composite outlier index. The cross-modal support is a quantitative indicator used to measure the complementarity of features between two different communication modes in different dimensions, and its range is [0, 1]. The cross-modal support includes a temporal complementarity coefficient and a spatial synergy index. The temporal complementarity coefficient is the comprehensive coefficient minus the absolute value of the difference between the temporal stability of HPLC and the temporal stability of HRF, and the comprehensive coefficient is 1. The spatial synergy index is the covariance of HPLC node correlation and HRF spatial gradient. The cross-modal support is the sum of the temporal complementarity coefficient and the spatial synergy index. Establishing the temporal correlation matrix includes: constructing a communication network topology map, obtaining a database of node spatial coordinates, including physical locations and connection relationships; setting association rules and their respective weights, and outputting an N*N dimensional spatial correlation matrix, where N is the number of nodes; and dividing the spatial correlation matrix according to the time dimension to obtain the temporal correlation matrix. S3: Mark the detected abnormal signals as propagation source nodes, extract signal feature fingerprints, and mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation features of all nodes in the second range and generate a sub-anomaly propagation map; S4: Analyze causal characteristics based on the sub-anomaly propagation diagram, determine the causal path, identify risk indicators to obtain the risk index, and predict the threat level.
2. The intelligent monitoring method based on dual-mode communication as described in claim 1, characterized in that, The method further includes: S5: Generates cross-layer policies based on threat levels, including signal layer, device layer, and network layer; detects cross-layer conflicts and sets execution priorities for hierarchical execution; S6: Obtain causal features and causal paths, and group the system according to constraints; construct intra-group causal graphs and evaluate intra-group risk status in real time, and set intra-group collaboration strategies; evaluate global risk status and dynamically select whether to trigger cross-group collaboration strategies; the constraints are to maximize the strength of causal relationships within a group and minimize causal interactions between groups.
3. The intelligent monitoring method based on dual-mode communication as described in claim 1, characterized in that, The basic data information includes the target node's device information, communication mode, and basic signal information; The multidimensional signal features are used to quantify signal quality, and the multidimensional signal features include frequency distribution, harmonic content, signal-to-noise ratio, bit error rate, and fluctuation index. The real-time noise similarity is a scalar value located in [0, 1], representing the degree of similarity between the real-time noise spectrum and the noise template in the spectrum feature library; The parameter deviation represents the degree of deviation of the current signal parameter from its historical reference value.
4. The intelligent monitoring method based on dual-mode communication as described in claim 1, characterized in that, The spatiotemporal propagation analysis obtains the spatiotemporal propagation state based on the time-linked matrix, acquires the propagation characteristics of nodes within a first range, and constructs a main anomaly propagation map. This includes: within the first range, monitoring the signal characteristics of each node, identifying the node with the earliest abnormal characteristics as the starting position of the anomaly; continuously monitoring the changes in signal characteristics of each node within the first range at subsequent time points, recording the order and direction of the anomaly propagating from one node to adjacent nodes; measuring the time required for the anomaly to propagate from one node to adjacent nodes, and calculating the propagation speed; and forming a main anomaly propagation map based on the node where the anomaly first appears, the propagation path, and the propagation speed. The first range is centered on an abnormal signal node, including nodes directly connected to it and areas covered by one or two relay nodes; the first range is smaller than the second range.
5. The intelligent monitoring method based on dual-mode communication as described in claim 1, characterized in that, The second range is the area covered by nodes whose diffusion impact is greater than the minimum impact threshold, centered on the source node. The calculation of the diffusion impact of each node includes: simulating independent activation behavior between nodes and the cumulative effect of a node being influenced by its neighbors; the independent activation behavior is based on the number of direct connections between nodes, referring to the probability that a node independently triggers propagation through its own direct connections; the cumulative effect is the probability that a node cumulatively triggers propagation through the indirect influence of multi-hop neighbors; based on the independent activation behavior and the cumulative effect, a weighted average is taken as the final propagation probability. The average path distance is obtained by acquiring all path distances between any two nodes. The path influence propagation degree is determined based on the average path distance and used as the path influence value, which ranges from [0, 1]. The final propagation probability, exponential decay function, and path influence value are normalized and then weighted and summed to obtain the diffusion influence of each node.
6. The intelligent monitoring method based on dual-mode communication as described in claim 1, characterized in that, The causal features include temporal causality, spatial causality, and intensity correlation; temporal causality is the chronological order of anomalous events in the time dimension, spatial causality is the propagation path of anomalous events in the spatial dimension, and intensity correlation is the intensity change of anomalous signals during propagation. The risk indicators are used to quantify the degree of risk of abnormal propagation, and the risk indicators include propagation speed, root cause overlap, and potential impact.
7. The intelligent monitoring method based on dual-mode communication as described in claim 2, characterized in that, The grouping process includes: treating all nodes as ungrouped, selecting the node with the strongest causal relationship as the grouping seed, and iteratively adding ungrouped nodes whose causal relationship strength with the seed node is greater than the strength threshold. The pre-set stopping condition is: the number of nodes in the group reaches the upper limit or no new nodes can be added; The remaining ungrouped nodes are assigned to the nearest neighbor groups to form the initial group list. Define grouping types, including propagation grouping, diffusion grouping, and hybrid grouping; Constructing the intra-group causal graph includes: acquiring the basic signal characteristics and propagation characteristics of nodes within the group, performing temporal causal chain modeling, spatial causal path modeling, and intensity correlation modeling; and outputting the intra-group causal graph, where nodes are devices and edges are causal relationship weights.
8. An intelligent monitoring system based on dual-mode communication, applied to an intelligent monitoring method based on dual-mode communication as described in any one of claims 1 to 7, characterized in that, The system includes: The data acquisition and initial screening module is used to acquire basic data information and calculate real-time noise similarity. If the real-time noise similarity is greater than the similarity threshold, the first anomaly is output. If the real-time noise similarity is not greater than the similarity threshold, the parameter deviation is calculated and the initial anomaly value is obtained. The parameter deviation refers to the deviation of SNR, BER growth rate and harmonic distortion rate. The parameter deviation is normalized, the corresponding weight coefficient is preset, and the initial anomaly value is obtained by weighted summation. The dual-mode time-linked module calculates the cross-modal support between the two signals based on multi-dimensional signal characteristics if the initial outlier value is greater than a preset first threshold. If the cross-modal support is greater than 0.7, a time-linked matrix is established and a multi-level detection mechanism is set to detect outlier signals. The cross-modal support includes a temporal complementarity coefficient and a spatial synergy index. The temporal complementarity coefficient is the comprehensive coefficient minus the absolute value of the difference between the HPLC temporal stability and the HRF temporal stability, and the comprehensive coefficient is 1. The spatial synergy index is the covariance of the HPLC node correlation and the HRF spatial gradient. The cross-modal support is the sum of the temporal complementarity coefficient and the spatial synergy index. Establishing the temporal correlation matrix includes: constructing a communication network topology map, obtaining a database of node spatial coordinates, including physical locations and connection relationships; setting association rules and their respective weights, and outputting an N*N dimensional spatial correlation matrix, where N is the number of nodes; and dividing the spatial correlation matrix according to the time dimension to obtain the temporal correlation matrix. The anomaly propagation image generation module is used to obtain the spatiotemporal propagation state based on the time-linked matrix, obtain the propagation characteristics of nodes in the first range, and construct the main anomaly propagation map; mark the detected several anomaly signals as propagation source nodes, extract signal feature fingerprints, and mark the first diffusion nodes, mutation nodes, and intersection nodes; obtain the propagation characteristics of all nodes in the second range and generate the sub-anomaly propagation map; The causal analysis module is used to analyze causal characteristics based on the secondary anomaly propagation graph, determine causal paths, identify risk indicators to obtain risk indices, and predict threat levels. The grouping module is used to acquire causal characteristics and causal paths and group the system according to constraints. The strategy generation module is used to generate cross-level strategies based on threat levels, detect cross-level conflicts, and set execution priorities for hierarchical execution; construct intra-group causal graphs and assess intra-group risk status in real time, and set intra-group collaborative strategies; assess global risk status and dynamically select whether to trigger cross-group collaborative strategies.
Citation Information
Patent Citations
Metering and monitoring method and system based on pipeline multiphase flow
CN120063415A
Intelligent monitor temperature drift correction method and system based on temperature compensation algorithm
CN120369024A