A method and system for anomaly detection and adaptive optimization of indicators based on multi-model fusion

By employing a multi-model fusion-based anomaly detection method, which utilizes wavelet coherence analysis and a Bayesian-spatiotemporal graph causal network to dynamically adjust fusion weights, the method addresses the issues of poor adaptability and missing response loops in anomaly detection within power systems, thereby improving detection accuracy and response efficiency.

CN120724090BActive Publication Date: 2025-10-31NANJING HUADUN ELECTRIC POWER INFORMATION SAFETY EVALUATION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511135973.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-14
Publication Date
2025-10-31
Estimated Expiration
2045-08-14

AI Technical Summary

Technical Problem

Existing power system anomaly detection technologies have poor adaptability in complex business scenarios, weak correlation modeling, and lack of response closure, resulting in frequent false alarms and missed alarms, and failing to identify potential linkage anomalies or structural risks.

Method used

A multi-model fusion method for anomaly detection is adopted. A dynamic correlation matrix is ​​constructed through wavelet coherence analysis, combined with a causal network of Bayesian-spatiotemporal graph structure, edge weights are updated in real time, anomaly detection models are called in parallel, the fusion weights are dynamically adjusted, and a fusion anomaly score result is generated.

Benefits of technology

It improves the detection accuracy and response efficiency of power systems in scenarios with multiple anomalies, realizes spatiotemporal modeling and adaptive optimization of potential anomalies among multiple indicators, and enhances system resilience and response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120724090B_ABST
    Figure CN120724090B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for anomaly detection and adaptive optimization based on multi-model fusion, relating to the field of intelligent operation and maintenance technology for power systems. The method constructs a dynamic causal network graph based on operational data flow, integrates wavelet coherence analysis and Bayesian-spatiotemporal graph structures, updates edge weights in real time, and calculates propagation probabilities. It concurrently invokes multiple anomaly detection models, dynamically adjusts the fusion weights based on confidence scores and propagation risk coefficients, and generates a fused anomaly score result. For high-risk indicator segments, it extracts time-frequency features and topological features, inputs them into a lightweight model to generate a confidence correction factor, calculates the anomaly impact value, and drives adaptive allocation of monitoring resources. The method and system of this invention improve model adaptability, anomaly detection accuracy, and response efficiency in complex power scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent operation and maintenance technology for power systems, and in particular to a method and system for anomaly detection and adaptive optimization based on multi-model fusion. Background Technology

[0002] With the continuous improvement of the digitalization and automation level of power systems, massive amounts of time-series monitoring data and operation log information have been accumulated in power operation and maintenance scenarios. Anomaly detection technology based on indicator data has been widely used in many core aspects such as fault early warning, condition assessment, and equipment health management.

[0003] However, traditional methods often rely on fixed models to judge data from different scenarios, making it difficult to match the complex and ever-changing business structures and indicator patterns in power systems, leading to frequent false alarms and missed alarms. Most methods ignore the causal and topological relationships between indicators, fail to model the dynamic propagation and structural impact paths between multiple indicators, and cannot identify potential linked anomalies or structural risks. Anomaly detection results usually lack the ability to be re-verified and dynamically optimized, and cannot adjust fusion strategies and resource scheduling strategies based on the real-time severity or propagation trend of anomalies, resulting in insufficient sensitivity in operation and maintenance response.

[0004] Therefore, there is an urgent need for an indicator anomaly detection and intelligent operation and maintenance method with the ability to model the structure between indicators, the ability to integrate and adapt models, and the ability to optimize through self-feedback, so as to improve the detection accuracy and response efficiency of the power industry in multi-dimensional indicator anomaly scenarios. Summary of the Invention

[0005] To address the issues of poor adaptability, weak correlation modeling, and lack of response loop in existing power system anomaly detection technologies under complex business scenarios, this invention proposes an indicator anomaly detection and adaptive optimization method and system based on multi-model fusion. It integrates causal graph construction, propagation modeling, dynamic adjustment of fusion weights, and high-risk feedback mechanism to form an intelligent anomaly detection closed loop encompassing indicator profiling, multi-model fusion, risk-driven feedback, and resource self-adjustment.

[0006] The present invention achieves the above objectives through the following technical solutions:

[0007] A method for anomaly detection and adaptive optimization of indicators based on multi-model fusion, the method comprising:

[0008] Receive and store operational data streams and business rule logs from the power system;

[0009] Based on the running data stream, wavelet coherence analysis is used to calculate the dynamic correlation matrix between each indicator. Combined with the business rule log, a Bayesian-spatiotemporal graph causal network is constructed. Incremental graph convolution is used to update the edge weights of the causal network in real time, forming a dynamic causal network graph with propagation probability.

[0010] At least two anomaly detection models are invoked in parallel to determine anomalies in the target monitoring indicators, generating anomaly determination results and confidence scores for each anomaly detection model. Based on the confidence scores, the basic fusion weights for the anomaly determination results of each anomaly detection model are set.

[0011] Based on the propagation path information of the target monitoring indicators in the dynamic causal network graph, the propagation risk coefficient is calculated to dynamically adjust the basic fusion weights of each anomaly detection model, and a fusion anomaly score result is generated as the anomaly judgment result of the target monitoring indicators.

[0012] As a preferred embodiment of the present invention, the step of calculating the dynamic correlation matrix between various indicators using wavelet coherence analysis includes:

[0013] Sliding window segmentation is performed on the time series sequence of each indicator in the running data stream;

[0014] Extract the business scenario identifier from the business rule log and select the target frequency band of wavelet decomposition corresponding to the business scenario identifier in the preset frequency band feature library;

[0015] Wavelet decomposition is performed on the time series sequence of the index within each sliding window, and the wavelet coefficients of the target frequency band are extracted.

[0016] Based on the wavelet coefficients, the wavelet coherence coefficient between pairwise indices is calculated using the following formula:

[0017] ;

[0018] In the formula, As an indicator With indicators In frequency The wavelet coherence coefficients under the given conditions; Indicators With indicators In frequency Wavelet cross-power spectral density; , Indicators With indicators wavelet power spectral density;

[0019] Wavelet coherence coefficients corresponding to multiple frequency points within the target frequency band Perform a weighted average as an indicator Aggregate association values;

[0020] Construct a dynamic correlation matrix for the current time window using the aggregated correlation values ​​of all indicator pairs as elements;

[0021] An L1 norm sparsity constraint is applied to the dynamic correlation matrix to eliminate weakly correlated index pairs.

[0022] As a preferred embodiment of the present invention, the construction of the causal network with a Bayesian-spacetime graph structure includes:

[0023] Edges formed by aggregating association values ​​in the dynamic association matrix are defined as statistical association edges, and an edge set is constructed. The weight of each associated edge is the corresponding aggregate association value.

[0024] Map the business topology structure in the business rule logs to a set of vertices in a graph. This forms a directed graph structure. And attach the spatial location identifier and timestamp sequence of each indicator node in the running data stream to form the spatiotemporal status label of the indicator node;

[0025] The causal relationship adjustment events between indicators in the business rule log are analyzed to extract the causal sequence pairs and their corresponding confidence levels. The causal sequence pairs are added to the directed graph structure as rule injection edges, and the edge weights of the rule injection edges are specified as conditional probability values. The conditional probability values ​​are set according to the confidence level. The conditional probability values ​​corresponding to high, medium and low confidence levels are 1.0, 0.7 and 0.3, respectively.

[0026] A joint probabilistic graphical model is constructed and, under the condition of satisfying the causal inference assumption, is used to infer causal paths between indicators, thus forming a causal network with a Bayesian-spatiotemporal graphical structure that satisfies the joint probability expression:

[0027] ;

[0028] In the formula, The probability of all indicators occurring together; For vertex set The first in Individual indicator nodes; Indicator Node The set of parent nodes; For conditional probability;

[0029] When a new event in the business rule log is a topology change event, the vertex set and edge set of the directed graph structure are synchronously added or deleted according to the information of the added or invalid nodes recorded in the topology change event, so as to keep the Bayesian network structure consistent with the real-time business structure.

[0030] As a preferred embodiment of the present invention, the formation of a dynamic causal network graph with propagation probability includes:

[0031] Update the dynamic correlation matrix of the current window based on the time series sequence of indicators within the new sliding time window in the running data stream;

[0032] For all statistically related edges in the causal network, the edge weights are adjusted based on the difference in the corresponding aggregated correlation values ​​between the old and new windows, according to the following incremental update formula:

[0033] ;

[0034] In the formula, This represents the change in the aggregated correlation value; For smoothing coefficients; , These are the old edge weight and the new edge weight, respectively;

[0035] Inject all rules into the edges of the causal network, keeping the conditional probability values ​​as edge weights unchanged;

[0036] For any index node All incoming edges are normalized using the softmax function, and the edge propagation probability is calculated. :

[0037] ;

[0038] In the formula, For temperature coefficient, Indicates from indicator node Pointing to indicator nodes The edge weight; parent node point to The right of the border; Indicator Node All parent node indexes;

[0039] The edge propagation probability value is used as the edge weight of the dynamic causal network graph for subsequent path reasoning and propagation strength evaluation.

[0040] As a preferred embodiment of the present invention, at least two anomaly detection models are invoked in parallel to determine anomalies in the target monitoring indicators, and basic fusion weights are set for the anomaly determination results of each anomaly detection model, including:

[0041] For each target monitoring indicator, the indicator time series within the same sliding window is synchronously input into at least two different types of anomaly detection models, including a predictive model based on time series fitting and an isolated model based on statistical distribution.

[0042] Obtain the anomaly judgment result and confidence score of each anomaly detection model for the current window. The confidence score is calculated from the model output residual, the fitting error distribution, or the decision boundary distance.

[0043] Sensitivity factors are set based on the pre-classification attributes of each target monitoring indicator. And score the confidence of each anomaly detection model. Perform the correction to obtain the attribute-weighted confidence score. , ;

[0044] A dynamic reliability coefficient is constructed by combining the false alarm rate and false negative rate of each anomaly detection model within the sliding window history. Set the base fusion weights for each anomaly detection model, using the following formula:

[0045] ;

[0046] In the formula, Indicates the first The basic fusion weights of each anomaly detection model; The number of parallel anomaly detection models; , The first The attribute-weighted confidence and dynamic reliability coefficient of an anomaly detection model.

[0047] As a preferred embodiment of the present invention, the calculation of the propagation risk coefficient dynamically adjusts the basic fusion weights of each anomaly detection model to generate a fusion anomaly score result, including:

[0048] Based on all reachable paths from the target monitoring index in the dynamic causal network graph, identify the set of propagation paths whose propagation probability exceeds the threshold within the current sliding window;

[0049] For each propagation path, the propagation depth, the maximum propagation probability in the path, and the average fusion anomaly score of the path terminal node are determined. The above three parameters are multiplied together to obtain the propagation risk value of the propagation path. The propagation risk values ​​of all propagation paths are weighted and averaged to generate the original propagation risk coefficient of the target monitoring indicator.

[0050] Define the ratio of the number of paths containing the target monitoring indicator to the total number of paths as the path overlap factor of the target monitoring indicator in the propagation path set, and multiply it by the original propagation risk coefficient to obtain the modified propagation risk coefficient;

[0051] The risk sensitivity coefficient of each anomaly detection model is preset, and the basic fusion weight is adjusted up or down according to whether the confidence score of each anomaly detection model is higher than the average confidence score of all anomaly detection models. The adjustment range of the weight is determined by the product of the risk sensitivity coefficient and the modified propagation risk coefficient.

[0052] The anomaly determination results of all anomaly detection models are weighted and fused with the corresponding dynamically adjusted fusion weights to generate a fused anomaly score result, which serves as the final anomaly determination result for the target monitoring indicator.

[0053] As a preferred embodiment of the present invention, the method further includes:

[0054] When the modified propagation risk coefficient exceeds a preset threshold, high-risk indicator node sequence segments in the propagation path are identified based on the propagation depth and propagation probability of the propagation path.

[0055] Multi-scale sliding window partitioning is performed on the indicator data corresponding to the high-risk indicator node sequence segment. The main frequency features, frequency band energy ratio and spectral density of each scale window are extracted as time frequency features. At the same time, the in-edge weight distribution, out-edge propagation probability and path branching degree of the indicator nodes in the high-risk indicator node sequence segment in the dynamic causal network graph are extracted as topological features.

[0056] The time-frequency features and topological features are fused to construct a fused input vector, which is then input into a lightweight validation model to generate a confidence correction factor.

[0057] The abnormal impact value is calculated based on the propagation depth, criticality, and confidence correction factor of the indicator node. The monitoring resource allocation parameters are then dynamically adjusted according to the abnormal impact value to achieve adaptive allocation and processing of monitoring tasks.

[0058] As a preferred embodiment of the present invention, the generation of the confidence correction factor includes:

[0059] The fused input vector is normalized and encoded before being input into a lightweight verification model. The lightweight verification model includes at least one convolutional neural network feature extraction layer and one attention weighting module. The attention weighting module generates weight coefficients based on the historical distribution of the contribution of different feature dimensions to the model output. The model output is mapped through a fully connected layer to generate a confidence correction factor, which represents the confidence correction coefficient of the current high-risk indicator node sequence segment to the fused anomaly scoring result.

[0060] As a preferred embodiment of the present invention, the formula for calculating the abnormal influence value is as follows: ;

[0061] In the formula, Indicates the depth of dissemination; The criticality of a node is represented by the weighted sum of the number of outgoing edges and the probability of propagation of outgoing edges. This is a confidence level correction factor; , , The weighting coefficients preset by the system;

[0062] When the abnormal impact value exceeds the system threshold, the sampling frequency and alarm priority level of the indicator node corresponding to the abnormal impact value are automatically increased until the abnormal impact value falls back below the threshold.

[0063] A multi-model fusion-based index anomaly detection and adaptive optimization system, the system comprising:

[0064] The data access module is used to receive and store operational data streams and business rule logs from the power system;

[0065] The dynamic causal modeling module is used to calculate the dynamic correlation matrix between various indicators based on the running data stream using wavelet coherence analysis, construct a causal network with a Bayesian-spatiotemporal graph structure by combining the business rule logs, and update the edge weights of the causal network in real time using incremental graph convolution to form a dynamic causal network graph with propagation probability.

[0066] The multi-model judgment module is used to call at least two anomaly detection models in parallel to judge the anomalies of the target monitoring indicators, generate the anomaly judgment results and confidence scores of each anomaly detection model, and set the basic fusion weight of the anomaly judgment results of each anomaly detection model based on the confidence scores.

[0067] The weight adjustment and fusion module is used to dynamically adjust the basic fusion weights of each anomaly detection model based on the propagation path information of the target monitoring indicators in the dynamic causal network graph, calculate the propagation risk coefficient, and generate a fusion anomaly score result as the anomaly judgment result of the target monitoring indicators.

[0068] The beneficial effects of this invention are as follows: By constructing dynamic indicator profiles and using a multi-model confidence scoring mechanism, combined with a propagation risk coefficient, the fusion weights of each model are dynamically adjusted, effectively adapting to different indicator scenarios and reducing model selection bias. A dynamic correlation matrix based on wavelet coherence and a Bayesian-spatiotemporal graph structure are introduced to construct a dynamic causal network graph with propagation probability, supporting spatiotemporal modeling of potential abnormal links between multiple indicators. Based on the extraction of time frequency and structural features from high-risk indicator segments in the propagation path, a lightweight validation network generates a confidence correction factor for re-verifying and adjusting the confidence of the original detection results. An abnormal impact value model integrating propagation depth, criticality, and confidence correction factor is constructed to achieve adaptive adjustment of the sampling frequency, alarm priority, and resource consumption strategy of key monitoring indicators, enhancing system resilience and response efficiency. Attached Figure Description

[0069] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0070] Figure 1 This is a flowchart of the method of the present invention;

[0071] Figure 2 This is a schematic diagram of the modular structure of the system in an embodiment of the present invention. Detailed Implementation

[0072] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the described embodiments of the present invention are within the scope of protection of the present invention.

[0073] like Figure 1 As shown, this is an embodiment of the present invention, which provides a method for anomaly detection and adaptive optimization of indicators based on multi-model fusion, mainly including the following steps:

[0074] S1: Receive and store operation data streams and business rule logs from the power system;

[0075] Business rule logs are structured records of business events generated in real time or collected periodically during system operation, and mainly include the following fields:

[0076] SceneTag: Identifies the business operation context to which the current data belongs, such as "main transformer monitoring", "transmission line load", "power grid dispatching", etc.

[0077] Business topology (TopoStructure): Describes the physical or logical dependencies between monitored objects, including node ID, upstream and downstream connections, device ownership level, etc.

[0078] CausalAdjustEvent: Represents real-time changes in the understanding of logical relationships between metrics during business operations, such as equipment failure feedback, changes in associated paths, or manual rule corrections. Each event includes: adjustment type (add / remove / enhancement), metric pair (source node - target node), and adjustment confidence level (high / medium / low).

[0079] Through a structured and scenario-based business rule log injection mechanism, the system can introduce business knowledge and human experience into the fusion modeling process, thereby improving the dynamic adaptability and accuracy of indicator relationship modeling.

[0080] S2: Based on the running data stream, wavelet coherence analysis is used to calculate the dynamic correlation matrix between each indicator. A causal network with a Bayesian-spatiotemporal graph structure is constructed by combining business rule logs. Incremental graph convolution is used to update the edge weights of the causal network in real time, forming a dynamic causal network graph with propagation probability.

[0081] In this embodiment of the invention, to effectively model the anomaly transmission mechanism among monitoring indicators, a dynamic correlation matrix reflecting the relationship between each indicator is first constructed by running data streams. This matrix is ​​based on wavelet coherence among indicators within a sliding time window, and combines a business scenario-driven frequency band selection mechanism and sparsity control methods to ensure that the extracted correlation structure has real-time performance, adaptability, and interpretability. The specific implementation steps are as follows:

[0082] 1) Data preprocessing and sliding window partitioning

[0083] For each monitoring indicator in the received power system operation data stream, according to a fixed time window length and sliding step size Execution is segmented, forming multiple time windows. Each segment contains the original time-series sequence of all monitoring indicators within that time period.

[0084] 2) Frequency band selection driven by business scenarios

[0085] Extract the business scenario identifier (such as "equipment commissioning", "peak load", "abnormal weather", etc.) from the business rule logs accessed from the system maintenance side. This business scenario identifier is used to retrieve the target frequency bands of interest in the current time period from a predefined frequency band feature library. For example: normal operation scenarios correspond to the low and medium frequency band [0.1Hz, 1Hz]; fault warning scenarios correspond to the high frequency band [5Hz, 20Hz].

[0086] 3) Wavelet coherence calculation

[0087] For each time window, the indicators are paired Perform a continuous wavelet transform (CWT) to obtain the index's representation in the frequency domain: Indicators In frequency ,time Wavelet coefficients below; Similarly;

[0088] Based on the frequency domain representation, the wavelet coherence coefficient between pairwise indices is calculated using the following formula:

[0089] ;

[0090] In the formula, As an indicator With indicators In frequency The wavelet coherence coefficients, with values ​​ranging from [0,1], represent the frequency... The synchronization strength between the two indicators; Indicators With indicators In frequency Wavelet cross-power spectral density; , Indicators With indicators wavelet power spectral density;

[0091] 4) Coherence aggregation and correlation value extraction

[0092] In the target frequency band Internally, for each indicator... wavelet coherence coefficient Perform weighted averaging to obtain the aggregated correlation value of the frequency band. :

[0093] ;

[0094] In the formula, This is the frequency weighting coefficient (which can be set to equal weight or according to the scenario).

[0095] 5) Construction of dynamic association matrix

[0096] Aggregate related values Using elements, construct a dynamic correlation matrix for the current time window t. ,in Indicates the first The first indicator and the first The aggregated correlation value of each indicator.

[0097] 6) Application of sparsity constraints

[0098] To avoid introducing noise into the causal graph due to weak correlation indicators, L1 norm constraints are used to perform sparsity processing on the dynamic correlation matrix, removing correlation values ​​below a threshold. Elements or through optimization: ;

[0099] In the formula, The regularization coefficient is . This is the fitting error term (such as the prediction residual);

[0100] After processing, a sparse dynamic correlation matrix is ​​obtained. , which serves as the initial edge weight reference for the subsequent causal network structure.

[0101] To accurately express the causal dependencies between various indicators in the power system over time, this embodiment constructs a causal network with a Bayesian-spatiotemporal graph structure, possessing spatiotemporal attributes and conditional probability semantics, based on a dynamic correlation matrix and integrating business rule knowledge. The key lies in: constructing an initial edge set using statistical correlation, injecting causal constraint edges with expert experience, and introducing a joint probability model for subsequent inference. The specific construction process is as follows:

[0102] Based on the dynamic correlation matrix obtained in the previous embodiment Extract all monitoring metrics Aggregate association value Using these as the initial edge weights, construct an edge set. This is used to reflect the statistical correlation between indicators. The boundary weights between each pair of indicators... Initially set to .

[0103] Extract the current business topology from the business rule logs, and map it to a set of vertices in a directed graph based on the list of monitored objects and their connections. This forms a directed graph structure. .

[0104] For each indicator node Query its spatial location identifier in the running data stream. (such as substation code, equipment ID) and timestamp sequence Generate its spatiotemporal state labels This is used to support subsequent path propagation and node updates.

[0105] Analyze the causal relationship adjustment events between metrics recorded in the business rule logs, and extract the causal sequence pairs. And its corresponding confidence levels (high, medium, low).

[0106] Add causal order pairs as rules to the directed graph structure as edges. In this approach, the existing statistical edge set is expanded. Each rule-injected edge is appended with its corresponding conditional probability. This value is set according to the confidence level:

[0107] High confidence level → ;

[0108] Confidence level: Medium → ;

[0109] Low confidence level → .

[0110] Note: Rule-injected edges and statistical correlation edges can coexist. If the same indicator pair has both statistical correlation edges and rule-injected edges, a fusion mechanism or weight priority control strategy should be set. For example, the conditional probability of the rule edge can be used as the final edge weight.

[0111] After the graph structure is established, the conditional probabilities in the edge weights are combined to form a complete joint probabilistic graphical model. In this model, the joint probability of all index nodes can be expressed by the following Bayesian factor decomposition:

[0112] ;

[0113] in, The probability of all indicators occurring together; For vertex set The first in Individual indicator nodes; Indicator Node The set of parent nodes, i.e., all nodes pointing to The upstream causal node; This represents the conditional probability.

[0114] This joint distribution can be used for subsequent functions such as path inference, probability propagation, and anomaly node scoring.

[0115] When a new event is added to the business rule log as a topology change event, the system dynamically adjusts the graph structure based on the information of newly added or invalidated nodes recorded in the topology change event:

[0116] If a new indicator node is added, then... Add new vertices and set edges based on their relationships and confidence levels;

[0117] If the original node fails or the corresponding equipment is decommissioned, then from Remove the vertex and simultaneously remove all related edges.

[0118] This operation ensures the graph structure It maintains consistency with the actual business structure and supports the long-term evolution of causal networks.

[0119] To ensure that the constructed Bayesian-spatiotemporal graph structure of the causal network possesses dynamic response capabilities and quantifiable propagation strength assessment capabilities, this embodiment proposes a propagation probability calculation method based on incremental edge weight update and softmax normalization. The process includes four steps: edge weight update, rule injection and edge preservation, normalization processing, and propagation graph formation.

[0120] 1) Extraction and dynamic correlation update of indicator data within the sliding time window

[0121] After receiving the running data stream, the time series of each monitoring indicator is divided into sliding windows according to a fixed step size to obtain the indicator data in the latest window;

[0122] Using wavelet coherence analysis, the aggregated correlation values ​​of all monitoring indicator pairs within the current window are calculated, and a dynamic correlation matrix for the current window is generated accordingly. .

[0123] 2) Update of incremental edge weights for statistical edges

[0124] Dynamic association matrix for the previous window Dynamic association matrix with the current window The same indicator in China Calculate the difference between the aggregated correlation values. .

[0125] For each edge in the original edge set constructed based on statistical correlation in the causal network graph, its edge weight is corrected using the following incremental formula: ;

[0126] in, For the old edge weights, The new edge weight; This is a smoothing coefficient, and its value is dynamically set according to the stability of the business scenario: it is set to 0.9 when the scenario is stable and 0.6 during the switching phase.

[0127] This mechanism can suppress errors caused by short-term fluctuations and enhance the stability and traceability of causal relationship evolution.

[0128] 3) The edge weights remain unchanged under conditional probability.

[0129] For the causal injection edges injected by business rule logs in the causal network graph, their edge weights are set as conditional probabilities (such as 1.0, 0.7, 0.3). They are not updated in this step to maintain stability and ensure the validity of the reasoning of prior business knowledge.

[0130] 4) Softmax normalization generates a propagation probability graph

[0131] For each indicator node in the graph Enumerate all incoming edges, perform softmax normalization on each edge, and calculate the edge propagation probability. ,Right now:

[0132] ;

[0133] In the formula, Indicates from indicator node Pointing to indicator nodes The edge weight; express The set of parent nodes, i.e., all nodes pointing to Nodes; parent node point to The right of the border; It is a temperature coefficient used to control the degree of dispersion of the normalized distribution.

[0134] Normalization results That is, indicators For indicators The unit propagation intensity is used for subsequent propagation path reasoning, risk impact calculation, and resource allocation.

[0135] S3: Invoke at least two anomaly detection models in parallel to determine anomalies in the target monitoring indicators, generate anomaly determination results and confidence scores for each anomaly detection model, and set the basic fusion weights for the anomaly determination results of each anomaly detection model based on the confidence scores.

[0136] For step S3, in order to achieve the fusion and weighting of multi-model anomaly detection results of target monitoring indicators, this embodiment constructs a dynamic fusion mechanism that combines indicator attribute sensitivity and model historical reliability.

[0137] For the sequence data within the current sliding time window of each target monitoring indicator, at least two types of anomaly detection models are input in parallel, including:

[0138] Predictive models, such as Prophet and SARIMA models based on time series fitting;

[0139] Isolated models, such as Isolation Forest and LOF (Local Anomaly Factor) based on distribution anomaly detection.

[0140] Each model independently outputs the anomaly determination result (such as a boolean value indicating whether it is an anomaly) within the current window, and generates a confidence score based on the model's structural features.

[0141] For each anomaly detection model, calculate its raw confidence score within the current window. Its sources include, but are not limited to:

[0142] Predictive model: based on the standardized deviation of the fitted residuals at the current point;

[0143] Isolated model: based on the length of isolated paths or the distance to the density distribution boundary of samples in a high-dimensional feature space.

[0144] The scoring results are normalized to the interval [0,1] and used as the initial input for subsequent weight calculations.

[0145] The system retrieves preset sensitivity factors by looking up a table based on the indicator classification label (such as periodic, non-stationary, or abrupt change) of the target monitoring indicator. The confidence scores for each model are adjusted to obtain the attribute-weighted confidence scores. ;in This reflects the confidence stability of current anomaly detection models under such indicators. For example, predictive models set periodic indicators... Setting high-frequency volatility indicators .

[0146] The system statistics show that each anomaly detection model has recently... A sliding window (such as) False alarm rate in ) With the false negative rate Construct the dynamic reliability coefficient of the anomaly detection model: This coefficient is updated over time and measures the stability of the model's actual judgments in the short term.

[0147] Sensitivity-corrected confidence scores from all models With dynamic reliability The basic fusion weights for each anomaly detection model are set according to the following normalization formula:

[0148] ;

[0149] In the formula, Indicates the first The basic fusion weights of each anomaly detection model; The number of anomaly detection models participating in the decision-making process in parallel; , The first The attribute-weighted confidence and dynamic reliability coefficient of an anomaly detection model.

[0150] The judgment results of all models and their corresponding basic fusion weights are used as weighted inputs and then passed to the subsequent propagation risk coefficient adjustment module for secondary dynamic adjustment and final fusion anomaly score generation.

[0151] S4: Based on the propagation path information of the target monitoring indicators in the dynamic causal network graph, calculate the propagation risk coefficient and dynamically adjust the basic fusion weights of each anomaly detection model to generate a fusion anomaly score result, which serves as the anomaly judgment result for the target monitoring indicators.

[0152] This embodiment aims to dynamically adjust the basic fusion weights of each anomaly detection model by leveraging propagation path structure features and real-time risk levels, thereby generating more scenario-sensitive fusion anomaly scoring results. Specifically, it includes:

[0153] In a dynamic causal network diagram, monitoring metrics for each target are... Starting from this point, perform a path traversal of the directed graph to identify the set of all reachable paths. Each path Indicates possible propagation paths of the anomaly.

[0154] Filtering upstream and downstream nodes in the current window The occurrence of weak abnormal signals or the probability of side propagation ( The paths with a threshold value are used as the set of transmission risk paths. .

[0155] For each transmission path Calculate the following path characteristic indicators:

[0156] Dissemination depth Decrease the number of nodes in the path by one;

[0157] Maximum Propagation Probability The maximum probability of propagation for all edges in the path;

[0158] Path penetration The average aggregated anomaly score of terminal nodes along the path reflects the propagation capability of anomaly intensity along the path.

[0159] Based on this, the transmission risk value of the transmission path is calculated. Then, a weighted average of all transmission risk values ​​is taken to obtain the original transmission risk coefficient. .

[0160] Statistical target monitoring indicators exist Path overlap : ,express The degree of centrality in high-risk pathways generates a modified propagation risk coefficient. .

[0161] Preset the risk sensitivity coefficient for each anomaly detection model And obtain the current confidence score of each model. Calculate the mean confidence score for all models. Implement a confidence backoff mechanism to adjust the fusion weights of each model:

[0162] ;

[0163] The judgment results of all anomaly detection models With adjusted weights Weighted fusion is used to obtain the final fusion anomaly score. This is used to determine whether the target monitoring indicators within the current window are abnormal.

[0164] .

[0165] In one preferred embodiment, the method further includes: when the modified propagation risk coefficient exceeds a preset threshold, initiating a verification and adaptive processing flow for high-risk indicator node sequence segments in the propagation path. The specific steps are as follows:

[0166] Based on the propagation depth and probability of the propagation path, the propagation paths within the current window are traversed, and those with a propagation depth greater than a threshold are selected. And the cumulative propagation probability along the path is greater than the threshold. The path segments are used to extract the indicator nodes contained therein to form a high-risk indicator node sequence segment. ;

[0167] For each indicator node in the high-risk indicator node sequence segment Multi-scale sliding window partitioning (e.g., window widths of 3, 5, and 7) is performed on the corresponding time series data. Wavelet transform and FFT transform are performed on each scale to extract the main frequency features, frequency band energy ratio, and spectral density as time frequency features. At the same time, topological features such as the distribution of incoming edge weights, outgoing edge propagation probability, and path branching degree are extracted from the dynamic causal network graph.

[0168] A fusion input vector is constructed by fusing time-frequency features with topological structure features. Input the lightweight validation model to generate confidence correction factors The lightweight validation model comprises the following modules:

[0169] A single-layer one-dimensional convolutional neural network (1D-CNN) is used to extract local feature trends;

[0170] A single attention-weighted module assigns weights to each feature dimension. This enhances the response strength of propagation probability and dominant frequency characteristics;

[0171] A fully connected output layer is used to map the final corrected value.

[0172] , ;

[0173] In the formula, For attention weights, For training parameters, The number of feature dimensions; This is the Sigmoid function, used to map the confidence correction factor to the (0,1) interval.

[0174] Propagation depth based on indicator nodes Node criticality and confidence correction factor Calculate the impact value of anomalies The calculation formula is: ;

[0175] In the formula, Indicates the depth of dissemination; The criticality of a node is represented by the number of outgoing edges. Probability of outbound propagation The sum The weighted value; This is a confidence level correction factor; , , The weighting coefficients preset by the system;

[0176] The formula for calculating node criticality is: , ; for The set of downstream nodes; , These are weighting coefficients;

[0177] The monitoring resource allocation parameters are dynamically adjusted based on the impact value of anomalies to achieve adaptive allocation and processing of monitoring tasks. For example, when the impact value of anomalies exceeds the system threshold, the sampling frequency of the indicator node corresponding to the impact value is automatically increased to the upper limit frequency range, the alarm priority level is increased by one level, the reporting window period is shortened, and the alarm is given priority in the streaming analysis queue until the impact value of anomalies falls back below the threshold.

[0178] like Figure 2 As shown, another embodiment of the present invention provides a multi-model fusion-based index anomaly detection and adaptive optimization system, comprising:

[0179] The data access module is used to receive and store operational data streams and business rule logs from the power system;

[0180] The dynamic causal modeling module is used to calculate the dynamic correlation matrix between various indicators based on the running data flow and wavelet coherence analysis. It combines business rule logs to construct a causal network with a Bayesian-spatiotemporal graph structure and uses incremental graph convolution to update the edge weights of the causal network in real time, forming a dynamic causal network graph with propagation probability.

[0181] The multi-model judgment module is used to call at least two anomaly detection models in parallel to judge the anomalies of the target monitoring indicators, generate the anomaly judgment results and confidence scores of each anomaly detection model, and set the basic fusion weight of the anomaly judgment results of each anomaly detection model based on the confidence scores.

[0182] The weight adjustment and fusion module is used to calculate the propagation risk coefficient based on the propagation path information of the target monitoring indicators in the dynamic causal network graph, dynamically adjust the basic fusion weights of each anomaly detection model, and generate a fusion anomaly score result as the anomaly judgment result of the target monitoring indicators.

[0183] In summary, this invention improves the power index anomaly detection system in terms of intelligent model selection, interpretable anomaly paths, and adaptive resource scheduling by constructing a dynamic causal graph structure with propagation modeling capabilities and integrating multi-model confidence mechanisms and propagation risk feedback paths. It systematically solves the problems of poor adaptability, weak correlation modeling, and lack of response closure in existing anomaly detection technologies under complex business scenarios.

[0184] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any other combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product, which includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another.

[0185] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. This storage medium can be a read-only memory, a disk, or an optical disk, etc.

[0186] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various variations or substitutions within the technical scope disclosed in this application, and these should all be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for anomaly detection and adaptive optimization of indicators based on multi-model fusion, characterized in that, The method includes: Receive and store operational data streams and business rule logs from the power system; Based on the running data stream, wavelet coherence analysis is used to calculate the dynamic correlation matrix between each indicator. Combined with the business rule log, a Bayesian-spatiotemporal graph causal network is constructed. Incremental graph convolution is used to update the edge weights of the causal network in real time, forming a dynamic causal network graph with propagation probability. At least two anomaly detection models are invoked in parallel to determine anomalies in the target monitoring indicators, generating anomaly determination results and confidence scores for each anomaly detection model. Based on the confidence scores, the basic fusion weights for the anomaly determination results of each anomaly detection model are set. Based on the propagation path information of the target monitoring indicators in the dynamic causal network graph, the propagation risk coefficient is calculated and the basic fusion weights of each anomaly detection model are dynamically adjusted to generate a fusion anomaly score result, which serves as the anomaly judgment result of the target monitoring indicators. The calculation of the dynamic correlation matrix between various indicators using wavelet coherence analysis includes: Sliding window segmentation is performed on the time series sequence of each indicator in the running data stream; Extract the business scenario identifier from the business rule log and select the target frequency band of wavelet decomposition corresponding to the business scenario identifier in the preset frequency band feature library; Wavelet decomposition is performed on the time series sequence of the index within each sliding window, and the wavelet coefficients of the target frequency band are extracted. Based on the wavelet coefficients, the wavelet coherence coefficient between pairwise indices is calculated using the following formula: ; In the formula, As an indicator With indicators In frequency The wavelet coherence coefficients under the given conditions; Indicators With indicators In frequency Wavelet cross-power spectral density; , Indicators With indicators wavelet power spectral density; Wavelet coherence coefficients corresponding to multiple frequency points within the target frequency band Perform a weighted average as an indicator Aggregate association values; Construct a dynamic correlation matrix for the current time window using the aggregated correlation values ​​of all indicator pairs as elements; An L1 norm sparsity constraint is applied to the dynamic correlation matrix to eliminate weakly correlated index pairs; The causal network constructed using the Bayesian-space-time graph structure includes: Edges formed by aggregating association values ​​in the dynamic association matrix are defined as statistical association edges, and an edge set is constructed. The weight of each associated edge is the corresponding aggregate association value. Map the business topology structure in the business rule logs to a set of vertices in a graph. This forms a directed graph structure. And attach the spatial location identifier and timestamp sequence of each indicator node in the running data stream to form the spatiotemporal status label of the indicator node; The causal relationship adjustment events between indicators in the business rule log are analyzed to extract the causal sequence pairs and their corresponding confidence levels. The causal sequence pairs are added to the directed graph structure as rule injection edges, and the edge weights of the rule injection edges are specified as conditional probability values. The conditional probability values ​​are set according to the confidence level. The conditional probability values ​​corresponding to high, medium and low confidence levels are 1.0, 0.7 and 0.3, respectively. A joint probabilistic graphical model is constructed and, under the condition of satisfying the causal inference assumption, is used to infer causal paths between indicators, thus forming a causal network with a Bayesian-spatiotemporal graphical structure that satisfies the joint probability expression: ; In the formula, The probability of all indicators occurring together; For vertex set The first in Individual indicator nodes; Indicator Node The set of parent nodes; For conditional probability; When a new event in the business rule log is a topology change event, the vertex set and edge set of the directed graph structure are synchronously added or deleted according to the information of the added or invalid nodes recorded in the topology change event, so as to keep the Bayesian network structure consistent with the real-time business structure. The calculation of the propagation risk coefficient dynamically adjusts the basic fusion weights of each anomaly detection model to generate a fusion anomaly score, including: Based on all reachable paths from the target monitoring index in the dynamic causal network graph, identify the set of propagation paths whose propagation probability exceeds the threshold within the current sliding window; For each propagation path, the propagation depth, the maximum propagation probability in the path, and the average fusion anomaly score of the path terminal node are determined. The above three parameters are multiplied together to obtain the propagation risk value of the propagation path. The propagation risk values ​​of all propagation paths are weighted and averaged to generate the original propagation risk coefficient of the target monitoring indicator. Define the ratio of the number of paths containing the target monitoring indicator to the total number of paths as the path overlap factor of the target monitoring indicator in the propagation path set, and multiply it by the original propagation risk coefficient to obtain the modified propagation risk coefficient; The risk sensitivity coefficient of each anomaly detection model is preset, and the basic fusion weight is adjusted up or down according to whether the confidence score of each anomaly detection model is higher than the average confidence score of all anomaly detection models. The adjustment range of the weight is determined by the product of the risk sensitivity coefficient and the modified propagation risk coefficient. The anomaly determination results of all anomaly detection models are weighted and fused with the corresponding dynamically adjusted fusion weights to generate a fused anomaly score result, which serves as the final anomaly determination result for the target monitoring indicator.

2. The method for anomaly detection and adaptive optimization of indicators based on multi-model fusion according to claim 1, characterized in that, The formation of the dynamic causal network graph with propagation probability includes: Update the dynamic correlation matrix of the current window based on the time series sequence of indicators within the new sliding time window in the running data stream; For all statistically related edges in the causal network, the edge weights are adjusted based on the difference in the corresponding aggregated correlation values ​​between the old and new windows, according to the following incremental update formula: ; In the formula, This represents the change in aggregated related values; For smoothing coefficients; , These are the old edge weight and the new edge weight, respectively; Inject all rules into the edges of the causal network, keeping the conditional probability values ​​as edge weights unchanged; For any index node All incoming edges are normalized using the softmax function, and the edge propagation probability is calculated. : ; In the formula, For temperature coefficient, Indicates from indicator node Pointing to indicator nodes The edge weight; parent node point to The right of the border; Indicator Node All parent node indexes; The edge propagation probability value is used as the edge weight of the dynamic causal network graph for subsequent path reasoning and propagation strength evaluation.

3. The method for anomaly detection and adaptive optimization of indicators based on multi-model fusion according to claim 1, characterized in that, At least two anomaly detection models are invoked in parallel to determine anomalies in the target monitoring metrics. Basic fusion weights are set for the anomaly determination results of each anomaly detection model, including: For each target monitoring indicator, the indicator time series within the same sliding window is synchronously input into at least two different types of anomaly detection models, including a predictive model based on time series fitting and an isolated model based on statistical distribution. Obtain the anomaly judgment result and confidence score of each anomaly detection model for the current window. The confidence score is calculated from the model output residual, the fitting error distribution, or the decision boundary distance. Sensitivity factors are set based on the pre-classification attributes of each target monitoring indicator. And score the confidence of each anomaly detection model. Perform the correction to obtain the attribute-weighted confidence score. , ; A dynamic reliability coefficient is constructed by combining the false alarm rate and false negative rate of each anomaly detection model within the sliding window history. Set the base fusion weights for each anomaly detection model, using the following formula: ; In the formula, Indicates the first The basic fusion weights of each anomaly detection model; The number of parallel anomaly detection models; , The first The attribute-weighted confidence and dynamic reliability coefficient of an anomaly detection model.

4. The method for anomaly detection and adaptive optimization of indicators based on multi-model fusion according to claim 1, characterized in that, The method further includes: When the modified propagation risk coefficient exceeds a preset threshold, high-risk indicator node sequence segments in the propagation path are identified based on the propagation depth and propagation probability of the propagation path. Multi-scale sliding window partitioning is performed on the indicator data corresponding to the high-risk indicator node sequence segment. The main frequency features, frequency band energy ratio and spectral density of each scale window are extracted as time frequency features. At the same time, the in-edge weight distribution, out-edge propagation probability and path branching degree of the indicator nodes in the high-risk indicator node sequence segment in the dynamic causal network graph are extracted as topological features. The time-frequency features and topological features are fused to construct a fused input vector, which is then input into a lightweight validation model to generate a confidence correction factor. The abnormal impact value is calculated based on the propagation depth, criticality, and confidence correction factor of the indicator node. The monitoring resource allocation parameters are then dynamically adjusted according to the abnormal impact value to achieve adaptive allocation and processing of monitoring tasks.

5. The method for anomaly detection and adaptive optimization of indicators based on multi-model fusion according to claim 4, characterized in that, The generation of confidence correction factors includes: The fused input vector is normalized and encoded before being input into a lightweight verification model. The lightweight verification model includes at least one convolutional neural network feature extraction layer and one attention weighting module. The attention weighting module generates weight coefficients based on the historical distribution of the contribution of different feature dimensions to the model output. The model output is mapped through a fully connected layer to generate a confidence correction factor, which represents the confidence correction coefficient of the current high-risk indicator node sequence segment to the fused anomaly scoring result.

6. The method for anomaly detection and adaptive optimization of indicators based on multi-model fusion according to claim 4, characterized in that, The formula for calculating the abnormal impact value is: ; In the formula, Indicates the depth of dissemination; The criticality of a node is represented by the weighted sum of the number of outgoing edges and the probability of propagation of outgoing edges. This is a confidence level correction factor; , , The weighting coefficients preset by the system; When the abnormal impact value exceeds the system threshold, the sampling frequency and alarm priority level of the indicator node corresponding to the abnormal impact value are automatically increased until the abnormal impact value falls back below the threshold.

7. A multi-model fusion-based indicator anomaly detection and adaptive optimization system, applied to the multi-model fusion-based indicator anomaly detection and adaptive optimization method as described in any one of claims 1-6, characterized in that, The system includes: The data access module is used to receive and store operational data streams and business rule logs from the power system; The dynamic causal modeling module is used to calculate the dynamic correlation matrix between various indicators based on the running data stream using wavelet coherence analysis, construct a causal network with a Bayesian-spatiotemporal graph structure by combining the business rule logs, and update the edge weights of the causal network in real time using incremental graph convolution to form a dynamic causal network graph with propagation probability. The multi-model judgment module is used to call at least two anomaly detection models in parallel to judge the anomalies of the target monitoring indicators, generate the anomaly judgment results and confidence scores of each anomaly detection model, and set the basic fusion weight of the anomaly judgment results of each anomaly detection model based on the confidence scores. The weight adjustment and fusion module is used to dynamically adjust the basic fusion weights of each anomaly detection model based on the propagation path information of the target monitoring indicators in the dynamic causal network graph, calculate the propagation risk coefficient, and generate a fusion anomaly score result as the anomaly judgment result of the target monitoring indicators.

Citation Information

Patent Citations

  • Abnormity detection and response system and method for intelligent electric power heterogeneous data fusion

    CN119272115A

  • Digital twin system for power grid

    WO2025086085A1