Anomaly detection method and device of power grid system and electronic equipment
By deploying sub-gateways and edge gateways in the power grid system, using base data maps to process power equipment data, and generating global abnormality information, the problem of the existing technology being unable to detect overall abnormalities in the power grid system is solved, and timely and accurate detection of the power grid system is achieved.
Patent Information
- Application Number
- CN202510667233.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-09-30
AI Technical Summary
Existing technologies are unable to accurately detect overall abnormalities in the power grid system and can only detect abnormalities in individual power equipment, making it impossible to fully understand the overall operating status of the power grid system.
By deploying sub-gateways in the power grid system, the power data of the power equipment is obtained, processed using the base data map, and abnormal data is generated. The abnormal data of each sub-gateway is integrated through the edge gateway to determine the global abnormal information of the power grid system, and finally an alarm is issued at the sub-gateway.
It realizes timely and accurate detection of the overall abnormal conditions of the power grid system, and can integrate the information of each sub-gateway to obtain the global abnormal information of the power grid system, thereby improving the data processing efficiency of the power grid system and the accuracy of abnormality detection.
Smart Images

Figure CN120728845A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of power grid technology, and in particular to a method, device, and electronic device for detecting anomalies in a power grid system. Background Art
[0002] With the development of smart grid systems, sub-gateways can be used to connect to different power equipment under the grid system to achieve control of power equipment.
[0003] Existing technologies can detect the operating status of power equipment and identify any abnormalities in the equipment. However, these technologies can only detect abnormalities in individual power equipment and cannot determine the overall operating status of the power grid system, nor can they detect any abnormalities in the entire power grid system.
[0004] Therefore, there is an urgent need for a solution that can accurately detect the overall abnormal conditions of the power grid system. Summary of the Invention
[0005] The embodiments of the present application provide a method, device, and electronic device for detecting abnormalities in a power grid system, so as to accurately detect abnormalities in the overall power grid system.
[0006] In a first aspect, an embodiment of the present application provides a method for detecting anomalies in a power grid system, the method being applied to a sub-gateway in the power grid system, the power grid system including an edge gateway and multiple sub-gateways, the edge gateway being connected to the sub-gateway, and the sub-gateway being connected to at least one power device; the method comprising:
[0007] Obtaining power data of the power equipment connected to the sub-gateway; and processing the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway; wherein the base data map corresponding to the sub-gateway is obtained by processing the power data of the power equipment under the sub-gateway under normal operating conditions; and the abnormal data corresponding to the sub-gateway represents the abnormal condition of the power equipment under the sub-gateway;
[0008] Sending the abnormal data corresponding to the sub-gateway to the edge gateway; wherein the abnormal data of each sub-gateway is used to determine the global abnormal information of the power grid system, and the global abnormal information represents the abnormal situation of the overall operating state of the power grid system;
[0009] The global abnormality information sent by the edge gateway is received, and an alarm is issued to the power equipment corresponding to the sub-gateway based on the global abnormality information.
[0010] In a possible implementation, processing the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway includes:
[0011] Comparing the base data map corresponding to the sub-gateway and the power data according to a time series matching algorithm to obtain a deviation corresponding to the power data; wherein the deviation represents the degree of deviation between the power data and the base data map corresponding to the sub-gateway;
[0012] If the deviation corresponding to the power data is greater than or equal to a preset threshold, the power data is determined to be abnormal data.
[0013] In a possible implementation, a comparison process is performed on the base data map corresponding to the sub-gateway and the power data according to a time series matching algorithm to obtain a deviation corresponding to the power data, including:
[0014] Determining, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity, and a third similarity between the power data and the base data map corresponding to the sub-gateway; wherein the first similarity represents the similarity in time series length between the power data and the base data map corresponding to the sub-gateway; the second similarity represents the similarity in numerical value variation between the power data and the base data map corresponding to the sub-gateway; and the third similarity represents the similarity in numerical value between the power data and the base data map corresponding to the sub-gateway;
[0015] A weighted average calculation process is performed on the first similarity, the second similarity, and the third similarity to obtain a deviation corresponding to the power data.
[0016] In one possible implementation, determining, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity, and a third similarity between the power data and the base data map corresponding to the sub-gateway includes:
[0017] Performing a two-dimensional matrix conversion process on the base data map corresponding to the sub-gateway to obtain first two-dimensional matrix data, performing a two-dimensional matrix conversion process on the power data to obtain second two-dimensional matrix data; and determining a similarity between the first two-dimensional matrix data and the second two-dimensional matrix data as the first similarity;
[0018] Determine, based on a covariance matrix of the power data and a base data map corresponding to the sub-gateway, a Mahalanobis distance between the power data and the base data map corresponding to the sub-gateway, as the second similarity;
[0019] The cosine similarity between the power data and the base data map corresponding to the sub-gateway is determined as the third similarity.
[0020] In a possible implementation, before processing the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway, the method further includes:
[0021] performing data preprocessing on the power data;
[0022] The data preprocessing includes one or more of the following: data cleaning, data conversion, and data standardization.
[0023] In a possible implementation, the abnormal data corresponding to the sub-gateway indicates first abnormal association information, where the first abnormal association information represents the power devices under the same sub-gateway that are associated with an abnormal situation when the power device under the sub-gateway has an abnormal situation.
[0024] In a possible implementation, the edge gateway is configured to:
[0025] Performing data analysis and processing on the abnormal data of each sub-gateway to obtain second abnormality association information; wherein the second abnormality association information represents the power equipment under different sub-gateways associated with the abnormal situation when the power equipment under the sub-gateway has an abnormal situation;
[0026] Constructing a graph structure based on the first abnormality association information and the second abnormality association information corresponding to each sub-gateway; wherein the nodes of the graph structure are power devices under the power grid system, and the edges of the graph structure indicate the power devices associated with the abnormal situation;
[0027] The graph structure is identified and processed according to an anomaly detection model to obtain global anomaly information of the power grid system.
[0028] In a possible implementation, when the edge gateway is used to identify and process the graph structure according to the anomaly detection model to obtain global anomaly information of the power grid system, it is specifically used to:
[0029] Inputting the graph structure into the anomaly detection model for convolution processing to obtain a node feature matrix;
[0030] Based on the fully connected layer in the anomaly detection model, the node feature matrix is identified and processed to obtain global anomaly information of the power grid system.
[0031] In a second aspect, an embodiment of the present application provides an abnormality detection device for a power grid system, the device being applied to a sub-gateway in the power grid system, the power grid system including an edge gateway and multiple sub-gateways, the edge gateway being connected to the sub-gateway, and the sub-gateway being connected to at least one power device; the device comprising:
[0032] An acquisition module is configured to acquire power data of a power device connected to a sub-gateway; and process the power data based on a base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway; wherein the base data map corresponding to the sub-gateway is obtained by processing power data of the power device under the sub-gateway under normal operating conditions; and the abnormal data corresponding to the sub-gateway represents abnormal conditions of the power device under the sub-gateway;
[0033] a processing module, configured to send abnormal data corresponding to the sub-gateway to the edge gateway; wherein the abnormal data of each sub-gateway is used to determine global abnormal information of the power grid system, wherein the global abnormal information represents abnormal conditions of the overall operating state of the power grid system;
[0034] An alarm module is configured to receive the global abnormality information sent by the edge gateway and issue an alarm to the power equipment corresponding to the sub-gateway based on the global abnormality information.
[0035] In a possible implementation, the acquisition module includes:
[0036] a processing submodule, configured to compare the base data map corresponding to the sub-gateway and the power data according to a time series matching algorithm to obtain a deviation corresponding to the power data; wherein the deviation represents a degree of deviation between the power data and the base data map corresponding to the sub-gateway;
[0037] If the deviation corresponding to the power data is greater than or equal to a preset threshold, the power data is determined to be abnormal data.
[0038] In a possible implementation, the processing submodule includes:
[0039] a determination module, configured to determine, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity, and a third similarity between the power data and the base data map corresponding to the sub-gateway; wherein the first similarity represents the similarity between the power data and the base data map corresponding to the sub-gateway in terms of time series length; the second similarity represents the similarity between the power data and the base data map corresponding to the sub-gateway in terms of numerical variation; and the third similarity represents the similarity between the power data and the base data map corresponding to the sub-gateway in terms of numerical values;
[0040] A weighted average calculation process is performed on the first similarity, the second similarity, and the third similarity to obtain a deviation corresponding to the power data.
[0041] In a possible implementation, the determination module includes:
[0042] Performing a two-dimensional matrix conversion process on the base data map corresponding to the sub-gateway to obtain first two-dimensional matrix data, performing a two-dimensional matrix conversion process on the power data to obtain second two-dimensional matrix data; and determining a similarity between the first two-dimensional matrix data and the second two-dimensional matrix data as the first similarity;
[0043] Determine, based on a covariance matrix of the power data and a base data map corresponding to the sub-gateway, a Mahalanobis distance between the power data and the base data map corresponding to the sub-gateway, as the second similarity;
[0044] The cosine similarity between the power data and the base data map corresponding to the sub-gateway is determined as the third similarity.
[0045] In a possible implementation, before processing the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway, the method further includes:
[0046] performing data preprocessing on the power data;
[0047] The data preprocessing includes one or more of the following: data cleaning, data conversion, and data standardization.
[0048] In a possible implementation, the abnormal data corresponding to the sub-gateway indicates first abnormal association information, where the first abnormal association information represents the power devices under the same sub-gateway that are associated with an abnormal situation when the power device under the sub-gateway has an abnormal situation.
[0049] In a possible implementation, the edge gateway is configured to:
[0050] Performing data analysis and processing on the abnormal data of each sub-gateway to obtain second abnormality association information; wherein the second abnormality association information represents the power equipment under different sub-gateways associated with the abnormal situation when the power equipment under the sub-gateway has an abnormal situation;
[0051] Constructing a graph structure based on the first abnormality association information and the second abnormality association information corresponding to each sub-gateway; wherein the nodes of the graph structure are power devices under the power grid system, and the edges of the graph structure indicate the power devices associated with the abnormal situation;
[0052] The graph structure is identified and processed according to an anomaly detection model to obtain global anomaly information of the power grid system.
[0053] In a possible implementation, when the edge gateway is used to identify and process the graph structure according to the anomaly detection model to obtain global anomaly information of the power grid system, it is specifically used to:
[0054] Inputting the graph structure into the anomaly detection model for convolution processing to obtain a node feature matrix;
[0055] Based on the fully connected layer in the anomaly detection model, the node feature matrix is identified and processed to obtain global anomaly information of the power grid system.
[0056] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;
[0057] The memory stores computer-executable instructions;
[0058] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.
[0059] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementation methods of the first aspect.
[0060] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0061] An embodiment of the present application provides a method, device, and electronic device for detecting anomalies in a power grid system. The method is applied to a sub-gateway in the power grid system. With the help of the connection relationship between the sub-gateway, the edge gateway, and the power equipment, the power data of the power equipment connected to the sub-gateway is first obtained. Then, based on the base data map corresponding to the sub-gateway obtained by pre-processing the power data under normal working conditions, the obtained power data is processed to obtain abnormal data representing the abnormal conditions of the power equipment under the sub-gateway. The abnormal data is then sent to the edge gateway. The edge gateway determines global abnormal information representing the abnormal conditions of the overall operating status of the power grid system by integrating the abnormal data of each sub-gateway. Finally, the sub-gateway receives the global abnormal information and issues an alarm to the corresponding power equipment based on the global abnormal information, thereby realizing timely and accurate detection of the abnormal conditions of the power equipment under each sub-gateway in the power grid system, and obtaining global abnormal information of the power grid system by integrating the information of each sub-gateway. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0063] Figure 1 A schematic diagram of a method for detecting abnormalities in a power grid system according to an embodiment of the present invention Figure 1 ;
[0064] Figure 2 A schematic diagram of a method for detecting abnormalities in a power grid system according to an embodiment of the present invention Figure 2 ;
[0065] Figure 3 A schematic diagram of a method for detecting abnormalities in a power grid system according to an embodiment of the present invention Figure 3 ;
[0066] Figure 4 A schematic diagram of the structure of an abnormality detection device for a power grid system provided in an embodiment of the present application Figure 1 ;
[0067] Figure 5 A schematic diagram of the structure of an abnormality detection device for a power grid system provided in an embodiment of the present application Figure 2 ;
[0068] Figure 6 This is a schematic diagram of the structure of the electronic device provided in this application.
[0069] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0070] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0071] With the development of smart grid systems, the complexity of power grids and the number of devices are increasing, placing higher demands on the management and control of power equipment and the monitoring of their operational status. Smart grid systems enable remote monitoring and management of power equipment by deploying sub-gateways at various nodes in the grid. These sub-gateways can connect to various power equipment (such as transformers, switchgear, and smart meters) to collect real-time operational data such as voltage, current, power, and frequency.
[0072] Existing technologies primarily focus on monitoring the operating status of individual power devices, using thresholds or simple statistical methods to determine whether a device is experiencing an anomaly. For example, if a device's voltage or current exceeds a preset range, the system will issue an alarm. While this approach can promptly detect anomalies in individual devices, it fails to provide a comprehensive understanding of the overall operation of the power grid system. The power grid is a complex network, and anomalies in a single device may be caused by issues in other devices or within the system.
[0073] Therefore, the present application provides a method, device, and electronic device for detecting anomalies in a power grid system, which can solve the above-mentioned problems.
[0074] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0075] Figure 1 A schematic diagram of a method for detecting abnormalities in a power grid system according to an embodiment of the present invention Figure 1 ,like Figure 1 As shown, the method is applied to a sub-gateway in a power grid system, the power grid system includes an edge gateway and multiple sub-gateways, the edge gateway is connected to the sub-gateway, and the sub-gateway is connected to at least one power device; the method includes:
[0076] S101. Obtain power data of the power equipment connected to the sub-gateway; and process the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway; wherein, the base data map corresponding to the sub-gateway is obtained by processing the power data of the power equipment under the sub-gateway under normal working conditions; the abnormal data corresponding to the sub-gateway represents the abnormal situation of the power equipment under the sub-gateway.
[0077] For example, the entire power grid system consists of an edge gateway and multiple sub-gateways. The edge gateway is interconnected with each sub-gateway, and each sub-gateway is connected to at least one power device. This architecture forms a hierarchical data acquisition and processing network. The edge gateway is at the higher level, responsible for overall coordination and management; the sub-gateway is at the lower level, interacting directly with the power devices and taking on the tasks of data acquisition and preliminary processing.
[0078] Before constructing the base data graph, data must be collected from the power equipment under normal operating conditions within the sub-gateway. The collected power data should cover key parameters such as voltage, current, power, and frequency, which fully reflect the normal operating status of the power equipment. This collected power data under normal operating conditions requires a series of processing operations. First, the data is cleaned to remove any noise, outliers, and missing values to ensure data accuracy and completeness. Feature extraction is then performed on the cleaned data to extract key information that represents the normal operating characteristics of the power equipment from the large amount of raw data. Based on this processed feature data, a base data graph corresponding to the sub-gateway is constructed. The base data graph can be represented in various forms, such as using a graph structure to display the correlations between different power equipment parameters and the normal data range. This base data graph is an important basis for subsequent determination of power equipment anomalies, defining the data characteristics and boundaries of the power equipment under normal conditions.
[0079] Each sub-gateway monitors the connected power equipment in real time and obtains the power data of the power equipment at predetermined time intervals or according to specific trigger conditions (such as changes in equipment status). These data are consistent with the data types collected when constructing the base data map, so that accurate comparative analysis can be performed later. The collected power data needs to be transmitted to the storage unit of the sub-gateway in a timely manner to ensure the integrity and traceability of the data. At the same time, in order to facilitate subsequent processing and analysis, the data can be organized and stored in a certain format, such as in the form of a database table, recording the timestamp, device identification, parameter value and other information of each data.
[0080] After acquiring real-time power data from power equipment, the sub-gateway matches and compares this data with the corresponding base data map. Specifically, for each collected power parameter value, the base data map is searched for the range or pattern of that parameter under normal operating conditions. For example, for voltage parameters, the base data map defines the upper and lower limits of normal voltage. The real-time collected voltage value is compared with this range. If the comparison reveals that a power parameter value exceeds the normal range defined in the base data map, or if the data pattern does not match the normal pattern described in the base data map, a preliminary abnormality can be determined for the power equipment. All data identified as abnormal is aggregated to form abnormal data corresponding to the sub-gateway. The sub-gateway records and tags the detected abnormal data in detail. The record includes information such as the time of the abnormality, the identification of the power equipment involved, the name of the abnormal parameter, the abnormal value, and the deviation from the normal value in the base data map. This tagging information can be used for subsequent classification and analysis of the abnormal data, for example, marking it as a voltage abnormality, a current abnormality, or other different types of abnormality.
[0081] Each sub-gateway independently acquires and processes the power data of the corresponding power equipment, achieving distributed data processing. This approach reduces the data processing burden on edge gateways and upper-layer systems, and improves the data processing efficiency of the entire power grid system.
[0082] S102 , sending the abnormal data corresponding to the sub-gateway to the edge gateway; wherein the abnormal data of each sub-gateway is used to determine the global abnormal information of the power grid system, and the global abnormal information represents the abnormal situation of the overall operation status of the power grid system.
[0083] Exemplarily, a communication connection is established between the sub-gateway and the edge gateway, which can be achieved through a wired network (such as Ethernet) or a wireless network (such as Wi-Fi, 4G / 5G, etc.). The sub-gateway sends the encapsulated exception data to the edge gateway according to the set communication protocol. The communication protocol should ensure the reliable transmission of data, such as using the TCP / IP protocol to ensure the integrity and sequence of the data, or using some protocols with a retransmission mechanism to cope with network instability. Each sub-gateway sends the encapsulated exception data to the edge gateway according to the set communication protocol; during the sending process, the sub-gateway can set certain sending strategies, such as periodic sending (sending the accumulated exception data once every certain period of time) or event-triggered sending (sending immediately when the exception data reaches a certain number or meets specific conditions) to balance the real-time nature of data transmission and the occupancy of network resources.
[0084] After collecting anomaly data from multiple sub-gateways, the edge gateway needs to integrate this data. Because different sub-gateways may detect anomalies in different areas or types of power equipment, the edge gateway must integrate this scattered anomaly information and identify the correlations between them. For example, if power equipment associated with the same power supply line under multiple sub-gateways experiences voltage anomalies, it can be preliminarily determined that there may be a problem with the power supply line.
[0085] Based on the integrated anomaly data, the edge gateway applies pre-defined analysis algorithms and rules to analyze the overall operational status of the power grid system. These algorithms and rules can be developed based on the grid system's topology, the relationships between devices, and historical anomaly data. For example, by analyzing the number, type, and distribution of abnormal devices, as well as the changing trends of abnormal parameters, it can determine whether there are global anomalies in the power grid system, such as the risk of large-scale power outages or unstable grid frequency.
[0086] Based on the results of the anomaly analysis, the edge gateway generates global anomaly information that characterizes the overall operational status of the power grid system. This global anomaly information should include key information such as the anomaly type (e.g., voltage anomaly, frequency anomaly, equipment failure), the severity of the anomaly (e.g., minor, moderate, severe), the affected area (e.g., a substation, a power line), and the potential consequences (e.g., potential power outages for some users, impacts on grid stability, etc.).
[0087] S103: Receive global abnormality information sent by the edge gateway, and issue an alarm to the power equipment corresponding to the sub-gateway based on the global abnormality information.
[0088] Exemplarily, the edge gateway encapsulates the generated global exception information in a predetermined data format. The data format should contain necessary information fields, such as exception identification (used to uniquely identify the global exception information), exception type, severity, affected area, impact consequences, generation time, etc. Determine the sending target, that is, the identification of each sub-gateway that needs to receive the global exception information, so as to carry out subsequent accurate data transmission. The edge gateway sends the encapsulated global exception information to the corresponding sub-gateway according to the set communication protocol
[0089] The sub-gateway parses the received global anomaly information according to a predetermined data format. It extracts key information from the data, such as the anomaly type, severity, affected area, and impact consequences, and stores this information in the corresponding data structure for subsequent analysis and processing. The sub-gateway associates the parsed global anomaly information with the power equipment it monitors. By comparing the affected area with the range of equipment it is responsible for, it determines whether the global anomaly information is related to the power equipment it is responsible for. For example, if the global anomaly information indicates that a voltage anomaly has occurred on a power supply line, and the equipment monitored by the sub-gateway happens to be located on this power supply line, then the sub-gateway will determine that this global anomaly information is related to itself.
[0090] The sub-gateway stores preset alarm rules, which set corresponding alarm levels and alarm methods based on factors such as the type and severity of the abnormality. The sub-gateway matches the global abnormality information after correlation judgment with the alarm rules to determine the alarm level and alarm method that should be triggered. For example, for global abnormal information with a high degree of severity (such as situations that may cause large-scale power outages), the highest level of alarm may be triggered, using various alarm methods such as sound and light alarms and sending text messages to operation and maintenance personnel; for minor global abnormal information, only a lower level of alarm may be triggered, such as displaying a prompt message on the monitoring interface.
[0091] An embodiment of the present application provides an abnormality detection method for a power grid system. The method is applied to a sub-gateway in the power grid system. With the help of the connection relationship between the sub-gateway, the edge gateway, and the power equipment, the power data of the power equipment connected to the sub-gateway is first obtained. Then, based on the base data map corresponding to the sub-gateway obtained by pre-processing the power data under normal working conditions, the obtained power data is processed to obtain abnormal data characterizing the abnormal situation of the power equipment under the sub-gateway. Subsequently, the abnormal data is sent to the edge gateway. The edge gateway determines the global abnormality information characterizing the abnormal situation of the overall operating status of the power grid system by integrating the abnormal data of each sub-gateway. Finally, the sub-gateway receives the global abnormality information and issues an alarm to the corresponding power equipment based on the global abnormality information, thereby realizing timely and accurate detection of the abnormal situation of the power equipment under each sub-gateway in the power grid system, and obtaining the global abnormality information of the power grid system by integrating the information of each sub-gateway.
[0092] Figure 2 A schematic diagram of a method for detecting abnormalities in a power grid system according to an embodiment of the present invention Figure 2 ,like Figure 2 As shown, this embodiment Figure 1 Based on the embodiment, a method for detecting anomalies in a power grid system is described in detail. The method is applied to a sub-gateway in the power grid system. The power grid system includes an edge gateway and multiple sub-gateways. The edge gateway is connected to the sub-gateway, and the sub-gateway is connected to at least one power device. The method includes:
[0093] S201: Acquire power data of the power equipment connected to the sub-gateway.
[0094] For example, this step may refer to the above-mentioned step S101 and will not be described in detail.
[0095] S202 , performing data preprocessing on the power data; wherein the data preprocessing includes one or more of the following: data cleaning processing, data conversion processing, and data standardization processing.
[0096] For example, the power data collected by the sub-gateway includes, but is not limited to, voltage, current, power, power factor, frequency, and equipment operating status (e.g., switch status, fault status). Preprocessing power data is a key step to improve data quality and usability. This includes one or more of the following: data cleaning, data conversion, and data standardization.
[0097] The goal of data cleaning is to remove noise, errors, and missing values from the data to ensure data accuracy and completeness. Noise refers to abnormal values in the data that do not conform to the normal range or pattern. For example, sudden changes in voltage data may be due to sensor failure. Use filtering algorithms (such as sliding average, median filtering, or wavelet transform) to remove noise. For example, for voltage data, you can use a sliding average to smooth the data by calculating the average of the past 10 data points. For example, if the voltage data is [220, 221, 219, 220, 230, 220, 221], where 230 is likely noise. After using a sliding average (with a window size of 3), the data becomes [220, 220, 220, 220]. Check the data for missing values. For example, some data points may be missing due to communication failures. Use interpolation methods (such as linear interpolation or polynomial interpolation) or use the average of adjacent data points to fill in missing values. For example, if a point in the current data is missing, you can use the average of the two preceding and following points to fill in the missing values.
[0098] The purpose of data conversion is to convert data into a format suitable for subsequent analysis. Format conversion involves converting data collected by different devices or sensors into a unified format. For example, voltage data can be converted from "volts" to "kilovolts" or current data can be converted from "amperes" to "milliamperes." Data type conversion involves converting data from one type to another. For example, converting string data to a numeric type. For example, if data is in the string format "220," it is converted to the numeric type 220.
[0099] The purpose of data standardization is to convert data into a unified dimension for subsequent analysis and comparison. Data standardization includes normalization and standardization.
[0100] S203. Compare the base data map corresponding to the sub-gateway and the power data according to the time series matching algorithm to obtain the deviation corresponding to the power data; wherein the deviation represents the degree of deviation between the power data and the base data map corresponding to the sub-gateway; if the deviation corresponding to the power data is greater than or equal to a preset threshold, the power data is determined to be abnormal data.
[0101] For example, historical power data from the power equipment corresponding to the sub-gateway under normal operation is collected. This data should cover a variety of operating scenarios and conditions, such as voltage, current, and power under different load conditions. The time span of the data should be sufficiently long to fully reflect the normal operating characteristics of the equipment. Key features are extracted from the collected historical data. For time series data, common features include mean, variance, maximum, minimum, and periodicity. For example, for voltage data, the mean and variance over different time periods can be calculated to reflect the voltage's stability. The periodic characteristics of voltage data can be extracted using methods such as Fourier transform to understand the cyclical patterns of equipment operation. The extracted features are organized chronologically to construct a base data map. Feature data can be stored in a database as a time series, or the time-varying trends of features can be graphically displayed to form an intuitive base data map. For example, a line chart can be used to display the change in mean voltage over time, and a bar chart can be used to display the distribution of current variance over different time periods.
[0102] Match the acquired power data with the data in the base data map by timestamp. Since the time intervals for data collection may differ, it is necessary to use methods such as interpolation and resampling to align the time axes of the two to ensure that the compared data points correspond in time. For example, if the data in the base data map is collected once an hour, and the real-time power data is collected once a minute, the real-time data can be aggregated by the hour, or the data in the base data map can be interpolated to make it consistent with the time interval of the real-time data. Ensure that the compared data have the same feature dimensions. If the base data map contains multiple features, and the real-time power data may only collect some features, the data needs to be supplemented or filtered to make the features of the two consistent.
[0103] Time series matching algorithms are used to measure the similarity or difference between two time series data. In the power data anomaly detection scenario, the deviation between real-time power data and the base data map can be calculated to determine whether the data is abnormal. Here, three time series matching algorithms, Dynamic Time Warping (DTW) distance, Mahalanobis distance, and cosine similarity, are used, and their results are combined to calculate the deviation.
[0104] DTW is an algorithm used to measure the similarity between two time series. It is suitable for sequences of different lengths or with misaligned time axes. DTW uses dynamic programming to find the optimal matching path between two sequences, minimizing the sum of the distances between corresponding points on the path. In power data anomaly detection, the DTW distance is calculated between the real-time power data sequence and the corresponding sequence in the base data graph. A larger DTW distance indicates a higher degree of deviation between the two sequences, indicating the presence of an anomaly.
[0105] The Mahalanobis distance is a distance metric that considers the correlation between data features. It adjusts the distance calculation based on the covariance matrix of the data and is suitable for situations where there is a certain correlation between features.
[0106] The Mahalanobis distance calculation formula is: M(x,y) =√(xy) T E -1 (xy)
[0107] Among them, E represents the covariance matrix; x represents the power data; and y represents the base data map.
[0108] Cosine similarity measures the directional similarity between two vectors. It calculates the cosine of the angle between the vectors in the power data and the base data map. Values closer to 1 indicate greater similarity. Cosine similarity is suitable for power data where directional variations are important, such as power factor. A larger deviation indicates a greater directional difference between the real-time data and the base data map, suggesting a possible anomaly.
[0109] The calculated power data deviation is compared with a preset threshold. If the deviation is greater than or equal to the threshold, it indicates a significant deviation between the power data and the base data map, potentially indicating an anomaly. If the deviation is less than the threshold, the power data is considered within the normal range. When the deviation is greater than or equal to the threshold, the power data is determined to be abnormal. The abnormal data can then be further marked and recorded, including information such as the time of the anomaly, data characteristics, and the magnitude of the deviation, to facilitate subsequent fault diagnosis and analysis.
[0110] In one example, the abnormal data corresponding to the sub-gateway indicates first abnormality association information, and the first abnormality association information represents the power devices under the same sub-gateway that are associated with the abnormality when the abnormality occurs in the power devices under the sub-gateway.
[0111] Exemplarily, each sub-gateway indicates first abnormality association information by abnormal data obtained by processing power data. The first abnormality association information represents the power devices under the same sub-gateway that are associated with the abnormal situation when the power devices under the sub-gateway have an abnormal situation.
[0112] When a sub-gateway detects abnormal data, it generates "first abnormality association information." This information indicates the range of devices associated with the abnormality. When a device experiences an abnormality, the sub-gateway analyzes whether the abnormality affects other devices under the same sub-gateway or whether there are any correlations with other devices.
[0113] In one example, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity and a third similarity between the power data and the base data map corresponding to the sub-gateway are determined; wherein the first similarity characterizes the similarity in time series length between the power data and the base data map corresponding to the sub-gateway; the second similarity characterizes the similarity in numerical change between the power data and the base data map corresponding to the sub-gateway; the third similarity characterizes the similarity in numerical value between the power data and the base data map corresponding to the sub-gateway; the first similarity, the second similarity and the third similarity are weighted averaged to obtain the deviation corresponding to the power data.
[0114] Exemplarily, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity, and a third similarity between the power data and the base data map corresponding to the sub-gateway are determined.
[0115] The first similarity reflects the similarity between the power data and the base data graph in terms of time series length. The lengths of the corresponding time series in the power data and base data graph are obtained respectively. DTW is used to calculate the similarity between the power data and the base data graph in terms of time series length, yielding the first similarity S1.
[0116] The second similarity reflects the similarity between the power data and the base data map in terms of the amount of change in value. The similarity between the power data and the base data map in terms of the amount of change in value is calculated using a method such as Mahalanobis distance to obtain the second similarity S2.
[0117] The third similarity reflects the similarity between the power data and the base data map in terms of numerical values. The similarity between the power data and the base data map in terms of numerical values is calculated using methods such as Euclidean distance and cosine similarity to obtain the third similarity S3.
[0118] The first, second, and third similarities S1, S2, and S3 are weighted averaged to calculate the deviation of the power data. Based on the application scenario and requirements, weights W1, W2, and W3 are assigned to each similarity, satisfying W1 + W2 + W3 = 1. For example, if the change in value is more important for anomaly detection, W2 can be appropriately increased.
[0119] The calculation formula of deviation D is: D = 1-(W1S1+W2S2+W3S3)
[0120] Among them, D represents the deviation; W1 represents the first weight corresponding to the first similarity; S1 represents the first similarity; W2 represents the second weight corresponding to the second similarity; S2 represents the second similarity; W3 represents the third weight corresponding to the third similarity; S3 represents the third similarity.
[0121] In one example, a two-dimensional matrix conversion process is performed on the base data map corresponding to the sub-gateway to obtain first two-dimensional matrix data, and a two-dimensional matrix conversion process is performed on the power data to obtain second two-dimensional matrix data; and the similarity between the first two-dimensional matrix data and the second two-dimensional matrix data is determined as the first similarity; based on the covariance matrix of the power data and the base data map corresponding to the sub-gateway, the Mahalanobis distance between the power data and the base data map corresponding to the sub-gateway is determined as the second similarity; and the cosine similarity between the power data and the base data map corresponding to the sub-gateway is determined as the third similarity.
[0122] Exemplarily, a two-dimensional matrix conversion process is performed on the base data map corresponding to the sub-gateway. Assuming that the base data map is a one-dimensional time series data with a length of m, it can be regarded as an m×1 matrix as the first two-dimensional matrix data. For example, if the base data map records the voltage values of the power equipment under a sub-gateway at 10 consecutive time points, that is, a one-dimensional sequence with a length of 10, the converted first two-dimensional matrix data is a 10×1 matrix. Similarly, a two-dimensional matrix conversion process is performed on the power data to obtain the second two-dimensional matrix data. If the power data is also a one-dimensional time series with a length of n, the converted second two-dimensional matrix data is an n×1 matrix. Create a matrix D of size m×n to store the distance between the corresponding points of the two sequences. The matrix element D[i,j] represents the distance between the i-th point of the base data map and the j-th point of the power data. For each element D[i,j] in the matrix, calculate the Euclidean distance (or other suitable distance metric) between the i-th point of the base data map and the j-th point of the power data, that is, D[i,j] = distance(base data map[i], power data[j]).
[0123] The calculation formula for the matrix element D[i,j] is:
[0124] D[i,j]=distance(base data map[i], power data[j])
[0125] +min(D[i-1,j],D[i,j-1],D[i-1,i-1])
[0126] Wherein, distance(base data map[i], power data[j]) represents the local distance between the i-th point of the base data map and the j-th point of the power data;
[0127] d[m,n] is the DTW distance between the base data map and the power data; d[m,n] represents the element in the mth row and nth column of the matrix element D[i,j].
[0128] Since smaller DTW distance indicates higher similarity, in order to obtain the similarity value, the DTW distance can be normalized. For example, assuming the maximum possible distance is Dmax (which can be pre-set according to the data range or obtained by calculation), the first similarity S1 is:
[0129]
[0130] Among them, S1 represents the first similarity; d[m,n] represents the DTW distance between the base data map and the power data; Dmax represents the maximum distance between the base data map and the power data.
[0131] The Mahalanobis distance considers the correlation between the base data graph and the characteristics of the power data and is applicable to multidimensional time series data. It adjusts the distance calculation based on the data's covariance matrix, providing a more accurate measure of the degree of difference between two data sets. The smaller the Mahalanobis distance, the more similar the two data sets are.
[0132] Collect the base data map corresponding to the sub-gateway. Assume that the base data map is a p-dimensional time series data, containing N sample points, each sample point is a p-dimensional vector. Calculate the mean vector μ and covariance matrix E of these samples. Each element of the mean vector μ is the average value of the corresponding dimension data, and the element E of the covariance matrix E is ij Represents the covariance between the i-th dimension and the j-th dimension. For the power data, assume that it is also a p-dimensional time series data with a length of M. For each sample point x in the power data (x is a p-dimensional vector), the calculation formula for its Mahalanobis distance with the base data map is as follows:
[0133]
[0134] Among them, E represents the covariance matrix; x represents the power data; μ represents the mean vector of the base data spectrum.
[0135] The calculation formula of the second similarity S2 is:
[0136]
[0137] Among them, S2 represents the second similarity; the average Mahalanobis distance represents the average Mahalanobis distance between all sample points in the power data and the mean vector of the base data spectrum; d M(x,μ) Characterize the Mahalanobis distance between the base data map and the power data.
[0138] Cosine similarity measures the degree of directional similarity between two vectors, with a value range of [-1, 1]. In time series data, the time series is treated as a vector, and the cosine of the angle between the two vectors is calculated to reflect the similarity in their numerical values. A larger cosine similarity indicates a greater similarity in the numerical values of the two time series.
[0139] The power data and the base data graph corresponding to the sub-gateway are represented as vectors. Assume that the power data is a one-dimensional time series of length n, which can be regarded as an n-dimensional vector A; the base data graph is also a one-dimensional time series of length n, which can be regarded as an n-dimensional vector B.
[0140] The calculation formula for cosine similarity is:
[0141]
[0142] Among them, C(A,B) represents the cosine similarity between the power data and the base data graph; A·B represents the dot product of vector A and vector B; ||A|| is the modulus of vector A; ||B|| is the modulus of vector B.
[0143] The calculated cosine similarity is directly used as the third similarity S3, and its value range is [-1, 1]. In order to be consistent with the value range of the first two similarities, it can be normalized to [0, 1]. The calculation formula is:
[0144]
[0145] Among them, S3 represents the third similarity; C(A, B) represents the cosine similarity.
[0146] An embodiment of the present application provides a method for detecting anomalies in a power grid system. The method is applied to a sub-gateway in the power grid system. In an architecture where the power grid system includes an edge gateway and multiple sub-gateways that are interconnected, the sub-gateway first obtains power data of the connected power equipment and performs data preprocessing on the obtained power data. The preprocessing includes one or more methods of data cleaning, data conversion, and data standardization to improve data quality. Subsequently, based on a time series matching algorithm, the preprocessed power data is compared with a base data map obtained in advance for the sub-gateway to obtain a deviation degree that characterizes the degree of deviation between the two. When the deviation degree is greater than or equal to a preset threshold, the power data is determined to be abnormal data, thereby achieving the effect of accurately identifying abnormal data of the power equipment connected to the sub-gateway in the power grid system.
[0147] Figure 3 A schematic diagram of a method for detecting abnormalities in a power grid system according to an embodiment of the present invention Figure 3 ,like Figure 3 As shown, this embodiment Figure 2 Based on the embodiment, a method for detecting anomalies in a power grid system is described in detail. The method is applied to an edge gateway in the power grid system. The power grid system includes an edge gateway and multiple sub-gateways, and the edge gateway is connected to the sub-gateways. The method includes:
[0148] S301. Analyze and process abnormal data of each sub-gateway to obtain second abnormality association information; wherein the second abnormality association information represents the power equipment under different sub-gateways that are associated with an abnormality when the power equipment under the sub-gateway has an abnormality.
[0149] For example, after detecting abnormal data, each sub-gateway reports the abnormal data and its first abnormal association information to the edge gateway. The reported data typically includes a timestamp, sub-gateway ID, abnormal device ID, abnormal characteristics, deviation, and first abnormal association information (associated devices under the same sub-gateway). The edge gateway receives abnormal data from multiple sub-gateways and aggregates the data into a database or data structure. The received abnormal data is cleaned to remove noise, duplicate or invalid data, and the data format is unified to improve data quality.
[0150] The edge gateway extracts key features from abnormal data, such as the anomaly type, occurrence time, device ID, and abnormal value. For continuous data (such as voltage and current), statistical features such as mean, variance, and rate of change can be extracted to more comprehensively describe the abnormal situation. The edge gateway builds a device association model between power devices, specifically including the physical connection relationships between devices, the logical dependencies between devices, and the anomaly association relationships based on historical anomaly data.
[0151] Physical connections are established between devices based on the power system's topology. For example, a transformer has a direct physical connection to downstream devices such as switchgear and distribution boxes. Analyze the data flow and logical dependencies between devices. For example, the operating status of certain devices may affect the monitoring data of other devices. Leverage historical anomaly data to uncover anomaly correlation patterns between devices. For example, when a transformer under a sub-gateway experiences an anomaly, voltage fluctuations in certain switchgear under adjacent sub-gateways are often accompanied.
[0152] Received anomaly data is analyzed in real time, combined with a device association model to identify anomalies that may be related to devices in other sub-gateways. Current anomaly data is matched with historical anomaly patterns to identify similar anomaly scenarios and their associated devices. Association rule mining algorithms (such as the Apriori algorithm) are used to mine anomaly association rules between devices from large amounts of anomaly data. For example, "If the transformer in sub-gateway A experiences a temperature anomaly, the switchgear in sub-gateway B may experience a voltage anomaly."
[0153] The results of the abnormality association analysis are integrated to form second abnormality association information including information such as device ID, abnormality type, abnormality time, associated device ID and associated abnormality type.
[0154] S302. Construct a graph structure based on the first abnormality association information and the second abnormality association information corresponding to each sub-gateway; wherein the nodes of the graph structure are the power equipment under the power grid system, and the edges of the graph structure indicate the power equipment associated with the abnormal situation.
[0155] For example, the first abnormality association information describes the associated power devices under the same sub-gateway when an abnormality occurs in the power devices under the sub-gateway. For each sub-gateway, the first abnormality association information contained therein is traversed to extract the device with the abnormality and the other devices under the same sub-gateway that are associated with it. For example, in sub-gateway A, when an abnormality occurs in device 1, it is associated with devices 2 and 3. Therefore, when constructing the graph structure, it is necessary to treat devices 1, 2, and 3 as nodes and establish edges between devices 1 and 2, and between devices 1 and 3, to represent the abnormality association relationships between them.
[0156] The second anomaly association information identifies the power devices under different sub-gateways that are associated with an abnormality in a power device under a sub-gateway. Similarly, for each sub-gateway, its second anomaly association information is analyzed to identify the device with the abnormality and the devices under different sub-gateways associated with it. For example, if a device 4 in sub-gateway B experiences an abnormality, it is associated with device 5 in sub-gateway C. In the graph structure, devices 4 and 5 are treated as nodes, and an edge is established between them, reflecting the abnormality association across sub-gateways.
[0157] The nodes in the graph structure represent individual power devices in the power grid system. Each node has a unique identifier to accurately distinguish different devices in the graph. Nodes can also contain device attribute information, such as device type, sub-gateway location, and device number. This information helps to more fully understand the characteristics of the device. The edges in the graph structure are used to indicate the association between power devices associated with the abnormal situation. The existence of an edge indicates that when an abnormality occurs, there is some kind of association between the two connected nodes (power devices). This association may be a direct or indirect causal relationship, a mutual influence relationship, etc.
[0158] To build the graph, we first create an empty graph structure with an empty node set and an empty edge set. Next, we iterate over all power devices in the grid system and add each device as a node to the graph's node set. We use the device's unique identifier to ensure that each node appears only once in the graph.
[0159] Next, you need to add connecting edges between each device. Specifically, based on the first anomaly association information, for each sub-gateway, find the device where the anomaly occurred and its associated devices under the same sub-gateway. In the graph structure, for each pair of devices with an anomaly association (i.e., the device with the anomaly and its associated devices), add an edge between their corresponding nodes. Based on the second anomaly association information, similarly add edges between the corresponding nodes for device pairs involved in cross-sub-gateway anomaly associations.
[0160] S303: Identify and process the graph structure according to the anomaly detection model to obtain global anomaly information of the power grid system.
[0161] For example, the anomaly detection model can be a graph convolutional network, a graph attention network, or a long short-term memory (LSTM) network. The graph structure is input into the anomaly detection model, which outputs the anomaly probability of each node and global anomaly information of the power grid system.
[0162] In one example, the graph structure is input into the anomaly detection model for convolution processing to obtain a node feature matrix; based on the fully connected layer in the anomaly detection model, the node feature matrix is identified and processed to obtain global anomaly information of the power grid system.
[0163] For example, the attributes of each power device in the graph structure (such as device type, historical abnormality times, real-time status parameters, etc.) are encoded into a vector to form the initial node feature matrix X∈R N×D , where N is the number of nodes and D is the feature dimension. According to the connection relationship of the edges in the graph structure, the adjacency matrix A∈R is constructed N×N .
[0164] The convolution layer of the anomaly detection model performs convolution processing on the graph structure to obtain a node feature matrix; by stacking multiple convolution layers, the information of neighboring nodes is gradually aggregated to capture local and global features in the graph structure. The calculation formula of the convolution layer is:
[0165]
[0166] Among them, H (l) Characterize the node feature matrix of the lth layer (the initial node feature matrix H (0) =X;W (l) The weight matrix representing the lth layer; Represents the adjacency matrix; σ() represents the activation function, and ReLU is optional.
[0167] After multiple layers of convolution, we get the high-order node feature matrix in is the feature dimension after convolution. The high-order node feature matrix H after convolution (L) Input the fully connected layer to perform feature dimensionality reduction and anomaly score calculation. The calculation formula is as follows:
[0168] P = sigmoid(H (L) W fc +b fc )
[0169] Among them, P represents the abnormal probability of each node; H (L) Characterizes the high-order node feature matrix; W fc Characterize the weights of the fully connected layer of the anomaly detection model; b fc Characterizes the bias of the fully connected layers of anomaly detection models.
[0170] Set an anomaly threshold (e.g., 0.7) based on business requirements and mark nodes in P above the threshold as anomalies. Collect all nodes (devices) marked as anomalies to form a list of anomaly devices. Extract the subgraph containing the anomaly node and its immediate neighbors from the graph structure and analyze the anomaly propagation path. Count the number of sub-gateways, associated devices, and regional distribution of the anomaly device, and generate a global anomaly impact report.
[0171] An embodiment of the present application provides an anomaly detection method for a power grid system, and the method is applied to an edge gateway in the power grid system. In an architecture in which the power grid system includes an edge gateway and multiple sub-gateways that are interconnected, the edge gateway first performs in-depth data analysis and processing on the abnormal data reported by each sub-gateway, and obtains relevant information of each power device under different sub-gateways associated with the power device under the sub-gateway when an abnormality occurs, that is, obtains second abnormality association information; then, combined with the first abnormality association information corresponding to each sub-gateway itself, a graph structure is constructed with the power devices under the power grid system as nodes and the abnormal association relationships as edges; finally, the graph structure is identified and processed using an anomaly detection model, thereby obtaining global abnormality information of the power grid system, thereby achieving accurate identification of potential global anomalies in the power grid system, and providing strong support for fault detection, operation optimization and security assurance of the power grid system.
[0172] Figure 4 A schematic diagram of the structure of an abnormality detection device for a power grid system provided in an embodiment of the present application Figure 1 ,like Figure 4 As shown, the present embodiment provides an abnormality detection device 40 for a power grid system, which is applied to a sub-gateway in the power grid system. The power grid system includes an edge gateway and multiple sub-gateways, the edge gateway is connected to the sub-gateway, and the sub-gateway is connected to at least one power device. The device includes:
[0173] The acquisition module 401 is configured to acquire power data of the power equipment connected to the sub-gateway; and process the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway; wherein the base data map corresponding to the sub-gateway is obtained by processing the power data of the power equipment under the sub-gateway under normal operating conditions; and the abnormal data corresponding to the sub-gateway represents abnormal conditions of the power equipment under the sub-gateway;
[0174] Processing module 402 is used to send abnormal data corresponding to the sub-gateway to the edge gateway; wherein the abnormal data of each sub-gateway is used to determine the global abnormal information of the power grid system, and the global abnormal information represents the abnormal situation of the overall operation status of the power grid system;
[0175] The alarm module 403 is configured to receive global abnormality information sent by the edge gateway and issue an alarm to the power equipment corresponding to the sub-gateway based on the global abnormality information.
[0176] This embodiment provides an abnormality detection device for a power grid system, which can execute the method provided by the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0177] Figure 5 A schematic diagram of the structure of an abnormality detection device for a power grid system provided in an embodiment of the present application Figure 2 ,like Figure 5As shown, the present embodiment provides an abnormality detection device 50 for a power grid system, which is applied to a sub-gateway in the power grid system. The power grid system includes an edge gateway and multiple sub-gateways, the edge gateway is connected to the sub-gateway, and the sub-gateway is connected to at least one power device. The device includes:
[0178] The acquisition module 501 is used to obtain power data of the power equipment connected to the sub-gateway; and process the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway; wherein the base data map corresponding to the sub-gateway is obtained by processing the power data of the power equipment under the sub-gateway under normal operating conditions; and the abnormal data corresponding to the sub-gateway represents abnormal conditions of the power equipment under the sub-gateway;
[0179] Processing module 502 is used to send abnormal data corresponding to the sub-gateway to the edge gateway; wherein the abnormal data of each sub-gateway is used to determine the global abnormal information of the power grid system, and the global abnormal information represents the abnormal situation of the overall operation status of the power grid system;
[0180] The alarm module 503 is configured to receive global abnormality information sent by the edge gateway and issue an alarm to the power equipment corresponding to the sub-gateway based on the global abnormality information.
[0181] In a possible implementation, the acquisition module 501 includes:
[0182] The processing submodule 5011 is configured to compare the base data map corresponding to the sub-gateway and the power data using a time series matching algorithm to obtain a deviation corresponding to the power data; wherein the deviation represents the degree of deviation between the power data and the base data map corresponding to the sub-gateway;
[0183] If the deviation corresponding to the power data is greater than or equal to a preset threshold, the power data is determined to be abnormal data.
[0184] In a possible implementation, the processing submodule 5011 includes:
[0185] Determination module 50111 is used to determine, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity, and a third similarity between the power data and the base data map corresponding to the sub-gateway; wherein the first similarity represents the similarity between the power data and the base data map corresponding to the sub-gateway in terms of time series length; the second similarity represents the similarity between the power data and the base data map corresponding to the sub-gateway in terms of numerical variation; and the third similarity represents the similarity between the power data and the base data map corresponding to the sub-gateway in terms of numerical values;
[0186] A weighted average calculation process is performed on the first similarity, the second similarity, and the third similarity to obtain a deviation corresponding to the power data.
[0187] In a possible implementation, the determining module 50111 includes:
[0188] Performing a two-dimensional matrix conversion process on the base data map corresponding to the sub-gateway to obtain first two-dimensional matrix data, performing a two-dimensional matrix conversion process on the power data to obtain second two-dimensional matrix data; and determining a similarity between the first two-dimensional matrix data and the second two-dimensional matrix data as a first similarity;
[0189] Determine, based on the covariance matrix of the power data and the base data map corresponding to the sub-gateway, a Mahalanobis distance between the power data and the base data map corresponding to the sub-gateway, as the second similarity;
[0190] The cosine similarity between the power data and the base data map corresponding to the sub-gateway is determined as the third similarity.
[0191] In a possible implementation, before processing the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway, the method further includes:
[0192] Perform data preprocessing on power data;
[0193] Among them, data preprocessing includes one or more of the following: data cleaning processing, data conversion processing, and data standardization processing.
[0194] In a possible implementation, the abnormal data corresponding to the sub-gateway indicates first abnormal association information, where the first abnormal association information represents the power devices under the same sub-gateway that are associated with an abnormal situation when the power device under the sub-gateway has an abnormal situation.
[0195] In one possible implementation, the edge gateway is configured to:
[0196] Performing data analysis and processing on the abnormal data of each sub-gateway to obtain second abnormality association information; wherein the second abnormality association information represents the power equipment under different sub-gateways associated with the abnormal situation when the power equipment under the sub-gateway has an abnormal situation;
[0197] A graph structure is constructed based on the first abnormality association information and the second abnormality association information corresponding to each sub-gateway; wherein the nodes of the graph structure are power equipment in the power grid system, and the edges of the graph structure indicate the power equipment associated with the abnormal situation;
[0198] The graph structure is identified and processed according to the anomaly detection model to obtain the global anomaly information of the power grid system.
[0199] In one possible implementation, when the edge gateway is used to identify and process the graph structure according to the anomaly detection model to obtain global anomaly information of the power grid system, it is specifically used to:
[0200] Input the graph structure into the anomaly detection model for convolution processing to obtain the node feature matrix;
[0201] Based on the fully connected layer in the anomaly detection model, the node feature matrix is identified and processed to obtain the global anomaly information of the power grid system.
[0202] This embodiment provides an abnormality detection device for a power grid system, which can execute the method provided by the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0203] Figure 6 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 6 As shown, the electronic device 60 provided in this embodiment includes: at least one processor 601 and a memory 602. Optionally, the device 60 further includes a communication component 603. The processor 601, the memory 602 and the communication component 603 are connected via a bus 604.
[0204] During the specific implementation process, at least one processor 601 executes the computer-executable instructions stored in the memory 602, so that the at least one processor 601 performs the above method.
[0205] The specific implementation process of the processor 601 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0206] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.
[0207] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.
[0208] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified into address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0209] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0210] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0211] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0212] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.
[0213] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.
[0214] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0215] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0216] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.
[0217] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0218] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.
Claims
1. A method for detecting abnormality in a power grid system, characterized in that: The method is applied to a sub-gateway in a power grid system, wherein the power grid system includes an edge gateway and multiple sub-gateways, the edge gateway is connected to the sub-gateway, and the sub-gateway is connected to at least one power device; the method includes: Obtaining power data of the power equipment connected to the sub-gateway; and processing the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway; wherein the base data map corresponding to the sub-gateway is obtained by processing the power data of the power equipment under the sub-gateway under normal operating conditions; and the abnormal data corresponding to the sub-gateway represents the abnormal condition of the power equipment under the sub-gateway; Sending the abnormal data corresponding to the sub-gateway to the edge gateway; wherein the abnormal data of each sub-gateway is used to determine the global abnormal information of the power grid system, and the global abnormal information represents the abnormal situation of the overall operating state of the power grid system; The global abnormality information sent by the edge gateway is received, and an alarm is issued to the power equipment corresponding to the sub-gateway based on the global abnormality information.
2. The method according to claim 1, characterized in that The power data is processed based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway, including: Comparing the base data map corresponding to the sub-gateway and the power data according to a time series matching algorithm to obtain a deviation corresponding to the power data; wherein the deviation represents the degree of deviation between the power data and the base data map corresponding to the sub-gateway; If the deviation corresponding to the power data is greater than or equal to a preset threshold, the power data is determined to be abnormal data.
3. The method according to claim 2, characterized in that According to the time series matching algorithm, the base data map corresponding to the sub-gateway and the power data are compared and processed to obtain the deviation corresponding to the power data, including: Determining, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity, and a third similarity between the power data and the base data map corresponding to the sub-gateway; wherein the first similarity represents the similarity in time series length between the power data and the base data map corresponding to the sub-gateway; the second similarity represents the similarity in numerical value variation between the power data and the base data map corresponding to the sub-gateway; and the third similarity represents the similarity in numerical value between the power data and the base data map corresponding to the sub-gateway; A weighted average calculation process is performed on the first similarity, the second similarity, and the third similarity to obtain a deviation corresponding to the power data.
4. The method according to claim 3, characterized in that Determining, based on the power data and the base data map corresponding to the sub-gateway, a first similarity, a second similarity, and a third similarity between the power data and the base data map corresponding to the sub-gateway, including: Performing a two-dimensional matrix conversion process on the base data map corresponding to the sub-gateway to obtain first two-dimensional matrix data, performing a two-dimensional matrix conversion process on the power data to obtain second two-dimensional matrix data; and determining a similarity between the first two-dimensional matrix data and the second two-dimensional matrix data as the first similarity; Determine, based on a covariance matrix of the power data and a base data map corresponding to the sub-gateway, a Mahalanobis distance between the power data and the base data map corresponding to the sub-gateway, as the second similarity; The cosine similarity between the power data and the base data map corresponding to the sub-gateway is determined as the third similarity.
5. The method according to any one of claims 1 to 4, characterized in that Before processing the power data based on the base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway, the method further includes: performing data preprocessing on the power data; The data preprocessing includes one or more of the following: data cleaning, data conversion, and data standardization.
6. The method according to any one of claims 1 to 4, characterized in that The abnormal data corresponding to the sub-gateway indicates first abnormality association information, where the first abnormality association information represents the power devices under the same sub-gateway that are associated with the abnormality when the power device under the sub-gateway has an abnormality.
7. The method according to claim 6, characterized in that The edge gateway is used to: Performing data analysis and processing on the abnormal data of each sub-gateway to obtain second abnormality association information; wherein the second abnormality association information represents the power equipment under different sub-gateways associated with the abnormal situation when the power equipment under the sub-gateway has an abnormal situation; Constructing a graph structure based on the first abnormality association information and the second abnormality association information corresponding to each sub-gateway; wherein the nodes of the graph structure are power devices under the power grid system, and the edges of the graph structure indicate the power devices associated with the abnormal situation; The graph structure is identified and processed according to an anomaly detection model to obtain global anomaly information of the power grid system.
8. The method according to claim 7, characterized in that When the edge gateway is used to identify and process the graph structure according to the anomaly detection model to obtain global anomaly information of the power grid system, it is specifically used to: Inputting the graph structure into the anomaly detection model for convolution processing to obtain a node feature matrix; Based on the fully connected layer in the anomaly detection model, the node feature matrix is identified and processed to obtain global anomaly information of the power grid system.
9. An abnormality detection device for a power grid system, characterized in that: The device is applied to a sub-gateway in a power grid system, wherein the power grid system includes an edge gateway and multiple sub-gateways, the edge gateway is connected to the sub-gateway, and the sub-gateway is connected to at least one power device; the device includes: An acquisition module is configured to acquire power data of a power device connected to a sub-gateway; and process the power data based on a base data map corresponding to the sub-gateway to obtain abnormal data corresponding to the sub-gateway; wherein the base data map corresponding to the sub-gateway is obtained by processing power data of the power device under the sub-gateway under normal operating conditions; and the abnormal data corresponding to the sub-gateway represents abnormal conditions of the power device under the sub-gateway; a processing module, configured to send abnormal data corresponding to the sub-gateway to the edge gateway; wherein the abnormal data of each sub-gateway is used to determine global abnormal information of the power grid system, wherein the global abnormal information represents abnormal conditions of the overall operating state of the power grid system; An alarm module is configured to receive the global abnormality information sent by the edge gateway and issue an alarm to the power equipment corresponding to the sub-gateway based on the global abnormality information.
10. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 8.
Citation Information
Cited By
FTTR-B multi-tenant distributed anomaly detection method and device, equipment and medium
CN121000641A