Data processing method and electronic equipment

By acquiring operational data from the railway information system, utilizing anomaly mapping information and data characteristics, and predicting the root causes of anomalies based on machine learning models, the problem of low efficiency and insufficient accuracy in fault analysis caused by the dispersion of data from multiple platforms was solved, thus realizing intelligent fault location and efficient operation of the railway information system.

CN120892232APending Publication Date: 2025-11-04BEIJING DAOER TECH CO LTD

Patent Information

Application Number
CN202510990184.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-11-04

AI Technical Summary

Technical Problem

The dispersed data from multiple platforms in the railway information system leads to low efficiency and insufficient accuracy in fault analysis. Relying on manual analysis is time-consuming and easily limited by experience, making it difficult to achieve real-time response and proactive prevention.

Method used

By acquiring operational data from railway information systems, utilizing anomaly mapping information and anomaly data characteristics, and based on machine learning models, the root causes of anomalies can be predicted, reducing reliance on manual intervention and improving the efficiency and accuracy of fault analysis.

Benefits of technology

It has enabled the automation and intelligentization of fault analysis in railway information systems, improved the speed and accuracy of fault location, reduced manual processing time, and enhanced the system's safety and operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120892232A_ABST
    Figure CN120892232A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data processing method and electronic device.The data processing method comprises the steps that operation data in a railway information system are obtained, and the railway information system is used for indicating a system for dispatching and controlling a train; under the condition that an abnormal event is determined based on the operation data, abnormal mapping information is obtained, a to-be-confirmed abnormal root cause corresponding to the abnormal event is determined according to the abnormal mapping information, and the abnormal mapping information is used for indicating a mapping relation between each abnormal event and at least one abnormal root cause; abnormal data features of the abnormal event are obtained, a target root cause in the abnormal root causes to be confirmed is predicted based on the abnormal data features, and the target root cause is used for indicating the root cause triggering the abnormal event in the operation of the railway information system. According to the method, the dependence on manpower in the fault analysis process can be reduced, the fault analysis efficiency is improved, fault attribution is carried out on the abnormal event based on the abnormal mapping information, and then the attribution accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a data processing method and an electronic device. Background Technology

[0002] A railway information system refers to an information technology system used to support railway transportation, operation, management and maintenance. It can integrate computer technology, network communication technology, data processing technology and automatic control technology to achieve real-time monitoring, data collection, information processing, decision support and resource optimization of all aspects of the railway system. Its core objective is to improve the safety, efficiency, reliability and service quality of railway transportation.

[0003] Here, the railway information system can include multiple platforms such as the operation and maintenance system, network management system, channel monitoring system, and TDCS (Training and Development Command System) / CTC (Centralized Traffic Control) electrical system. Therefore, when an alarm occurs in the railway information system, railway electrical maintenance personnel need to retrieve and analyze alarm data across multiple platforms, relying on manual correlation analysis of scattered alarm information to locate the root cause of the system fault. This leads to problems such as low fault analysis efficiency and insufficient accuracy in fault attribution. Summary of the Invention

[0004] In view of this, embodiments of this application provide a data processing scheme to at least partially solve the above-mentioned problems.

[0005] According to a first aspect of the embodiments of this application, a data processing method is provided, including:

[0006] Acquire operational data from a railway information system, wherein the railway information system is used to instruct the system for scheduling and controlling trains;

[0007] If an abnormal event is identified based on the running data, abnormal mapping information is obtained, and the root cause of the abnormal event to be confirmed is determined according to the abnormal mapping information. The abnormal mapping information is used to indicate the mapping relationship between each abnormal event and at least one root cause of the abnormality.

[0008] Obtain the abnormal data features of the abnormal event, and predict the target root cause among the root causes of the anomaly to be confirmed based on the abnormal data features, wherein the target root cause is used to indicate the root cause that triggered the abnormal event during the operation of the railway information system.

[0009] According to a second aspect of the embodiments of the present application, an electronic device is provided, comprising a processor, a memory, a communication interface and a communication bus, the processor, the memory and the communication interface complete communication with each other through the communication bus; the memory is used to store at least one executable instruction, and the executable instruction causes the processor to perform operations corresponding to the method of the first aspect.

[0010] According to a third aspect of the embodiments of the present application, a computer storage medium is provided, and the computer storage medium stores a computer program, and the program is executed by a processor to implement the method of the first aspect.

[0011] According to a fourth aspect of the embodiments of the present application, a computer program product is provided, comprising computer instructions, and the computer instructions instruct a computing device to perform operations corresponding to the method of the first aspect.

[0012] According to the data processing scheme provided by the embodiments of the present application, first, running data in a railway information system can be acquired, wherein the railway information system is used to indicate a system for scheduling and controlling trains. Then, in the case that an abnormal event is determined based on the running data, abnormal mapping information can be acquired, and a to-be-confirmed abnormal root cause corresponding to the abnormal event can be determined according to the abnormal mapping information, wherein the abnormal mapping information is used to indicate a mapping relationship between each abnormal event and at least one abnormal root cause. Next, abnormal data features of the abnormal event can be acquired, and a target root cause in the to-be-confirmed abnormal root cause can be predicted based on the abnormal data features, wherein the target root cause is used to indicate a root cause of triggering the abnormal event in the running of the railway information system, thereby reducing the dependence on manual work in the fault analysis process, improving the fault analysis efficiency, and at the same time, performing fault attribution on the abnormal event based on the abnormal mapping information, thereby improving the attribution accuracy. BRIEF DESCRIPTION OF DRAWINGS

[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments described in the embodiments of the present application, and other drawings can also be obtained by those skilled in the art based on these drawings.

[0014] Figure 1 A step flow chart of a data processing method according to an embodiment of the present application;

[0015] Figure 2 A schematic diagram of abnormal mapping information corresponding to an alarm event according to an embodiment of the present application;

[0016] Figure 3 An architecture diagram of a data processing system according to an embodiment of the present application;

[0017] Figure 4A structural block diagram of a data processing apparatus according to an embodiment of the present application;

[0018] Figure 5 A structural schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0019] In order to enable personnel in the art to better understand the technical solutions in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all embodiments. Based on the embodiments in the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art should belong to the scope of protection of the embodiments of the present application.

[0020] The specific implementation of the embodiments of the present application will be further described below in conjunction with the drawings of the embodiments of the present application.

[0021] In conjunction with the application scenarios on which the execution of the data processing method depends, the application scenarios are described here.

[0022] The railway information system refers to an information technology system for supporting railway transportation, operation, management and maintenance. It can realize real-time monitoring, data collection, information processing, decision support and resource optimization of each link of the railway system by integrating computer technology, network communication technology, data processing technology and automation control technology. The core goal is to improve the safety, efficiency, reliability and service quality of railway transportation.

[0023] Here, the railway information system can include multi-source platforms such as operation and maintenance systems, network management systems, channel monitoring systems and TDCS / CTC electrical systems. Therefore, when an alarm occurs in the railway information system, the railway bureau electrical maintenance personnel need to cross multiple source platforms to retrieve and analyze alarm data, rely on manual correlation analysis of scattered alarm information to locate the root cause of system failure, resulting in low efficiency of fault analysis, insufficient accuracy of attribution, etc.

[0024] Specifically, the data in the multi-source platform railway information system is scattered, the information island is serious, the operation and maintenance, network management, channel monitoring, TDCS / CTC and other systems run independently, the alarm data is scattered and stored, there is a lack of unified integration platform, key information is easily missed, it is difficult to fully grasp the overall fault link, and thus the manual correlation analysis efficiency is low, the accuracy is insufficient, the manual correlation analysis of multi-source alarm data is relied on, a large amount of time is consumed and is easily limited by experience level, the fault positioning speed is slow, the misjudgment risk is high, the fault repair time may be delayed, and the railway transportation safety is affected.

[0025] Meanwhile, too much reliance on manual fault analysis, unable to introduce intelligent algorithms such as causal reasoning, root cause analysis model, etc., cannot automatically identify the potential relevance of cross-system alarms, and fault troubleshooting is highly dependent on personal experience, new employees have high learning costs, and it is difficult to form standardized analysis processes, which limits real-time response capabilities. Specifically, manual processing of multi-platform alarms requires item-by-item checking, making it difficult to respond to sudden alarms or complex concurrent faults in a timely manner, which may lead to fault propagation, such as chain reactions caused by channel interruptions, affecting the normal operation of the train dispatching system (TDCS / CTC).

[0026] In addition, due to the failure to fully exploit the value of data, historical alarm data has not been effectively accumulated and analyzed, and potential faults or maintenance strategies cannot be predicted through data modeling, the operation and maintenance mode remains in the "passive repair" stage, and lacks the ability to transform to "active prevention". At the same time, due to the lack of cross-system coordination mechanism, the interfaces between systems are not unified, and there is a lack of automatic coordination mechanism, which cannot realize the automatic association and priority sorting of alarm information, and maintenance personnel need to manually integrate data, increasing the complexity of work, and it is difficult to distinguish between core faults and secondary alarms.

[0027] Based on this, the embodiments of the present disclosure provide a data processing method. First, the running data in the railway information system can be obtained, wherein the railway information system is used to indicate a system for scheduling and controlling trains. Then, in the case of determining an abnormal event based on the running data, abnormal mapping information is obtained, and the abnormal event corresponding to the to-be-confirmed abnormal root cause is determined according to the abnormal mapping information, wherein the abnormal mapping information is used to indicate the mapping relationship between each abnormal event and at least one abnormal root cause. Next, the abnormal data features of the abnormal event are obtained, and the target root cause in the to-be-confirmed abnormal root cause is predicted based on the abnormal data features, wherein the target root cause is used to indicate the root cause of triggering the abnormal event in the running of the railway information system. Thus, the dependence on manual work in the fault analysis process is reduced, the fault analysis efficiency is improved, the abnormal event is attributed to the fault based on the abnormal mapping information, and the attribution accuracy is improved.

[0028] In the present embodiment, a data processing method is provided, Figure 1 The flowchart of the data processing method according to the embodiments of the present disclosure is shown in Figure 1 The flowchart includes the following steps:

[0029] Step S101, obtaining running data in a railway information system, wherein the railway information system is used to indicate a system for scheduling and controlling trains.

[0030] In the embodiments of the present application, as known from the above, the railway information system can include multiple-source platforms such as an operation and maintenance system, a network management system, a channel monitoring system, and a TDCS / CTC electrical system, and therefore, the operation data can be data obtained by aggregating operation data of each system in the railway information system, wherein the operation data can include alarm data and risk data of each system.

[0031] When collecting operation data, operation data of different channels can be collected through the channel monitoring system, the hardware monitoring system, and the operation and maintenance system. For example, the channel monitoring system can comprehensively collect key operation parameters of network equipment in each system, including power state, working temperature, voltage level, fan operation condition, interface connection state (up / down), interface flow and error rate, MAC address information, and CPU and memory usage. The hardware monitoring system focuses on the health status of hardware equipment, and real-time obtains power supply, temperature, fan state, disk, network card, CPU and memory usage data. At the same time, the network management system is responsible for monitoring the on-off state of the whole network IP to ensure the stability of network connection. In addition, the operation and maintenance system deeply collects the working state of the power supply screen in the computer room, the power environment parameters, and the operation data of the middleware, database, and business application program, and realizes the transformation from "passive repair" to "active prevention".

[0032] Exemplarily, based on the alarm aggregation method, operation data from different systems can be uniformly integrated and correlated. In an optional implementation, alarm data and risk data generated by each platform can be obtained, and through the alarm aggregation method, the alarm data from different systems can be uniformly collected, standardized and correlated to form a unified data set, and a global fault link view can be established based on the data set, so that the operation and maintenance personnel can view the operation state of the entire railway information system from a global perspective without needing to view the alarm information of each system respectively.

[0033] In step S103, when an abnormal event is determined based on the operation data, abnormal mapping information is obtained, and the abnormal event corresponding to the abnormal root cause to be confirmed is determined according to the abnormal mapping information, wherein the abnormal mapping information is used to indicate the mapping relationship between each abnormal event and at least one abnormal root cause.

[0034] In the embodiments of the present application, the abnormal event can include an alarm event and a risk event. Here, the alarm event refers to a notification or signal generated by triggering a preset alarm mechanism of a railway information system due to reasons such as device failure, network anomaly, data error or external attack during operation of the system, wherein the alarm event usually contains key information such as serial number, state, severity level, occurrence time, alarm name, application system and alarm event information of the alarm event. The risk event refers to a potential factor or event that can cause negative impact on the railway information system, which can come from the inside of the system, such as device aging, software vulnerability, etc., or from the outside of the system, such as natural disasters, network attacks, etc.

[0035] When it is determined in the running data that the abnormal event includes an alarm event or a risk event reported by any system, abnormal mapping information can be acquired to determine at least one to-be-confirmed abnormal root cause matched with the abnormal event based on the abnormal mapping information.

[0036] Exemplarily, as shown in Figure 2 FIG. 1 shows a schematic diagram of abnormal mapping information corresponding to an alarm event. Here, the alarm event includes: SNMP (Simple Network Management Protocol) alarm (alarm for detecting network connectivity), gateway loss alarm, LOS (Loss of Signal) / AIS (Alarm Indication Signal) alarm, ping alarm (indicating that a device or a link is in a fault state), down (indicating that a device or a link is in a fault state) / up alarm (opposite to the down alarm, indicating that a device or a link recovers from a fault state to a normal state), shutdown alarm, board card abnormal alarm, CPU alarm, etc.

[0037] As can be seen from Figure 2 , in the abnormal mapping information, the SNMP alarm has a mapping relationship with the abnormal root causes “root cause ping interruption”, “root cause gateway loss” and “root cause board card failure”. The gateway loss alarm has a mapping relationship with the abnormal root causes “root cause gateway loss” and “root cause board card failure”. The LOS / AIS alarm has a mapping relationship with the abnormal root cause “root cause LOS / AIS”. The ping alarm has a mapping relationship with the abnormal root causes “root cause ping interruption”, “root cause gateway loss”, “root cause LOS / AIS”, “root cause interface down / up”, “root cause shutdown log”, “root cause board card failure”. The shutdown alarm has a mapping relationship with the abnormal root cause “root cause shutdown log”. The board card abnormal alarm has a mapping relationship with the abnormal root cause “root cause board card failure”. The CPU alarm has a mapping relationship with “mass data analysis locking root cause (used to indicate further analysis of the CPU alarm abnormal root cause based on device running log, device parameter, etc.)”.

[0038] After determining the alarm event or the risk event matched with the abnormal event in the abnormal mapping information, at least one to-be-confirmed abnormal root cause having a mapping relationship with the alarm event or the risk event can be acquired to determine the target root cause causing the abnormal event based on the to-be-confirmed root cause.

[0039] In step S105, the abnormal data feature of the abnormal event is acquired, and a target root cause in the to-be-confirmed abnormal root cause is predicted based on the abnormal data feature, where the target root cause is used to indicate a root cause triggering the abnormal event in the railway information system operation.

[0040] In the embodiments of the present application, a machine learning model such as a decision tree, a random forest, a support vector machine, etc. can be trained based on the historical operation data and the abnormal root cause that has been determined to obtain a root cause prediction model. It should be understood that the root cause prediction model can predict the target root cause causing the current abnormal event according to the abnormal data feature extracted from the current abnormal event.

[0041] For example, the root cause prediction model can output a prediction result for each to-be-confirmed abnormal root cause, and the prediction result can include a probability value of the to-be-confirmed root cause being the target root cause. Here, the to-be-confirmed root cause with the highest probability value in the corresponding prediction result can be determined as the target root cause.

[0042] In summary, in the embodiments of the present application, first, operation data in a railway information system can be acquired, where the railway information system is used to indicate a system for scheduling and controlling trains. Then, in the case that an abnormal event is determined based on the operation data, abnormal mapping information can be acquired, and to-be-confirmed abnormal root causes corresponding to the abnormal event can be determined according to the abnormal mapping information, where the abnormal mapping information is used to indicate a mapping relationship between each abnormal event and at least one abnormal root cause. Next, an abnormal data feature of the abnormal event can be acquired, and a target root cause in the to-be-confirmed abnormal root cause can be predicted based on the abnormal data feature, where the target root cause is used to indicate a root cause triggering the abnormal event in the railway information system operation, thereby reducing the dependence on manual work in the fault analysis process, improving the fault analysis efficiency, and at the same time, attributing the fault to the abnormal event based on the abnormal mapping information, thereby improving the attribution accuracy.

[0043] In some optional embodiments, before acquiring the abnormal mapping information, the above Figure 1 The corresponding embodiments further include:

[0044] In the case that the operation data includes alarm data of the railway information system in the operation process, the abnormal event is determined according to the alarm data; or in the case that the operation data does not include the alarm data of the railway information system in the operation process, data features of the operation data are extracted, and the abnormal event is determined based on an abnormal data feature in the data features.

[0045] In the embodiments of the present application, as can be seen from the above, the abnormal event can include an alarm event and a risk event, wherein the abnormal data feature can be an event feature of the risk event. In an optional implementation, first, it can be detected whether the running data contains alarm data, if yes, it is determined that an alarm event is detected. In addition, if no alarm data is detected, it is determined that no alarm event is detected, and it is determined whether a risk event is contained.

[0046] For example, when detecting a risk event, first, the data features of the running data can be extracted, for example, time sequence features, spatial features, etc. of the running data are obtained. Then, the data features can be analyzed to obtain abnormal data features that are different from normal running data.

[0047] Here, taking spatial feature analysis as an example, the spatial correlation of the spatial features can be analyzed, considering the mutual relationship between the data in adjacent or nearby areas. For example, the system equipment failure of adjacent track sections can affect each other, and the disease of one track can increase the probability of similar problems of adjacent tracks.

[0048] After obtaining the data features, whether there is a time sequence anomaly, a spatial anomaly, etc. based on the data features, for example, whether there is a trend mutation, a periodic anomaly, a local anomaly, a spatial aggregation anomaly, etc. can be determined. Specifically, when determining whether there is a trend mutation, if the originally stable data trend suddenly changes, it can be a signal of a risk event, such as a sudden peak of traffic flow, then it is determined that a risk event of trend mutation occurs. When determining whether there is a periodic anomaly, when the periodicity of the data is broken, a risk event needs to be alerted, such as the original data flow fluctuation rule is broken, then it is determined that a risk event of periodic anomaly occurs. When determining whether there is a local anomaly, the data at a certain geographic location obviously deviates from the normal level of the surrounding area, such as the signal transmission efficiency of the equipment in a certain area is obviously lower than that of the adjacent pre-fetch, then it is determined that a risk event of local anomaly occurs. When determining whether there is a spatial aggregation anomaly, when the data of multiple adjacent or nearby positions simultaneously appear abnormal, forming a spatial aggregation effect, then it is determined that a risk event of spatial aggregation anomaly occurs.

[0049] In the embodiments of the present application, the abnormal event can include an alarm event and a risk event, so as to timely identify the possible risks in the railway information system, which is helpful to improve the operation efficiency and safety of the railway information system, and can also provide strong support for decision making, resource allocation and long-term planning.

[0050] In some optional implementations, the above and extracting the data features of the running data, and determining the abnormal event based on the abnormal data features in the data features, specifically include:

[0051] Step S11, determining a threshold interval of the data feature based on a corresponding data indicator in the railway information system.

[0052] Step S12, predicting a matching degree of the data feature and the threshold interval based on a preset machine learning model, and determining an abnormal event corresponding to the data indicator when the data feature and the threshold interval are not matched.

[0053] In the embodiments of the present application, the data indicator is used to measure the quantitative standard of the system state. For example, device temperature threshold, communication delay threshold, track circuit voltage range, etc. These indicators can be predefined according to business experience or industry standards. On this basis, the threshold interval can be used to indicate the normal range of the data indicator, and exceeding the range may indicate that there is an abnormality. For example, the threshold interval of the device temperature indicator can be 0℃-60℃, and the threshold interval of the communication delay indicator can be <100ms.

[0054] After determining the threshold interval corresponding to the data feature, the matching degree of the data feature and the threshold interval can be predicted based on a preset machine learning model. Specifically, the preset machine learning model, such as decision tree, random forest, neural network, etc., can be used to determine whether the current data feature meets the threshold interval.

[0055] Exemplarily, the input data feature can be used to indicate the predicted device temperature, communication delay, etc., and the result output by the preset machine learning model can be a matching degree score of the data feature and the threshold interval, such as a probability value of 0-1, which is used to represent the degree of conformity of the data feature and the threshold interval. For example, if the device temperature predicted according to the data feature is 65°C, and the threshold interval is 0℃-60℃, the model will judge that the matching degree is 0, that is, completely unmatched.

[0056] When it is determined that the data feature and the threshold interval are not matched, an abnormal event can be determined based on the data feature, wherein the abnormal event can include a mild abnormality that needs to be immediately focused on, such as an alarm event of device temperature being too high, communication delay increasing, etc., and a severe abnormality that may cause serious consequences, such as a risk event of track circuit failure, signal loss, etc.

[0057] In the embodiments of the present application, the automatic identification and classification of the abnormal events of the railway information system can be realized through data feature extraction, threshold interval setting and machine learning model prediction, so as to quickly find potential problems in a large amount of running data, and to prewarn the alarm or risk event, so as to ensure the safe and efficient operation of the railway system.

[0058] In some optional embodiments, in the case where the number of abnormal events determined according to the alarm data is multiple, the above Figure 1 Corresponding embodiments also include:

[0059] In step S21, co-occurrence abnormal events are determined in abnormal events, where the co-occurrence abnormal events are used to indicate abnormal events having a connection in time and space.

[0060] In step S22, when a co-occurrence rate of the co-occurrence abnormal events meets an abnormal condition, an event scene corresponding to the co-occurrence abnormal events in a railway information system is determined.

[0061] In step S23, a mapping relationship between the co-occurrence abnormal events and the event scene is established, and scene mapping information is obtained.

[0062] In the embodiments of the present application, the co-occurrence abnormal events are used to indicate a plurality of abnormal events having a connection in time and space. These events can be caused by the same root cause, or interact to form a chain reaction. The abnormal events can be aggregated to obtain co-occurrence abnormal events having a connection in time or space. For example, the co-occurrence abnormal events having a connection in time can be a risk event of a sudden drop in train speed in the same section after a failure of a signal device. The co-occurrence abnormal events having a connection in space can be a delay of communication equipment in two adjacent stations, which means that there can be a regional network failure.

[0063] Here, the association rule mining and machine learning algorithm can be used to perform pattern recognition and classification on the abnormal events, and merge frequent co-occurrence alarms into co-occurrence abnormal events in the same event scene. For example, when the network device interface traffic is abnormal, the error rate is high, and the CPU and memory usage rates surge, the system can automatically aggregate them into co-occurrence abnormal events of “network device overload” and initiate a composite alarm.

[0064] Exemplarily, when identifying the co-occurrence abnormal events, time correlation analysis and space correlation analysis can be performed on the abnormal events. For example, when performing the time correlation analysis, a time range, such as 10 minutes or 1 hour, can be defined, and abnormal events occurring within the time range are regarded as co-occurrence abnormal events having a connection in time. When performing the space correlation analysis, a geographical or logical correlation range, such as the same station, the same track section, adjacent equipment, etc., can be defined, and abnormal events occurring within the range are regarded as co-occurrence abnormal events having a connection in space.

[0065] After determining the co-occurrence abnormal events, it can be determined whether the co-occurrence rate of the co-occurrence abnormal events meets an abnormal condition, wherein the co-occurrence rate can be represented as the number of times that two or more abnormal events occur simultaneously in an event or spatial range / the total number of abnormal events in the event or spatial range. Here, the abnormal condition can include a co-occurrence rate threshold, and when the co-occurrence rate exceeds the threshold, the co-occurrence abnormal events are considered to have significance. For example, if the co-occurrence rate of multiple co-occurrence abnormal events is greater than 80%, it indicates that the two abnormal events are highly correlated and can be caused by the same reason.

[0066] In addition, a machine learning model can be used to assist in identifying co-occurrence abnormal events. Specifically, the co-occurrence patterns of abnormal events can be automatically discovered using association rule mining, such as the Apriori algorithm, graph neural networks, or spatio-temporal sequence models. In the machine learning model, the type, timestamp, location, and other information of the abnormal events can be input as features into the model, and the output can be the combination of co-occurrence abnormal events and their association strength, such as confidence and support.

[0067] After determining the co-occurrence abnormal events, the specific fault mode or business impact scenario corresponding to the co-occurrence abnormal events can be determined, based on the event scenario corresponding to the co-occurrence abnormal events. For example, event scenario 1 is a signal system failure causing train operation abnormalities, and the co-occurrence abnormal events corresponding to event scenario 1 can be signal device failure and train speed drop. For another example, event scenario 2 is a core network failure causing systemic risk, and the co-occurrence abnormal events corresponding to event scenario 2 can be multiple station communication delays and scheduling system paralysis.

[0068] For example, in determining the co-occurrence abnormal events and the corresponding event scenario, abnormal event 1 is an alarm event of a signal display error, and abnormal event 2 is a risk event of a train appearing to advance a signal in the same section. The co-occurrence analysis of the two is as follows:

[0069] First, the temporal correlation of the two can be analyzed, and if abnormal event 1 and abnormal event 2 occur successively within 5 minutes, it indicates that there is a temporal correlation between the two. Then, the spatial correlation of the two can be analyzed, and if abnormal event 1 and abnormal event 2 occur in the same running section of a train, it indicates that there is a spatial correlation between the two. At the same time, historical data shows that the co-occurrence rate of such events is 90%, which is much higher than the normal threshold. Then, abnormal event 1 and abnormal event 2 can be determined as co-occurrence abnormal events, and the event scenario corresponding to the co-occurrence abnormal events can be determined as signal system failure causing train operation safety risk.

[0070] In the embodiments of the present application, the co-occurrence abnormal events can be identified and analyzed in the railway information system, the spatio-temporal correlation of the abnormal events can be mined, the scattered alarms and risk events can be connected into a complete fault scenario, thereby realizing the upgrade from "single event processing" to "systematic risk prevention and control", and combining machine learning, the event scenario can be efficiently located, and important support can be provided for intelligent operation and safety management of the railway system.

[0071] In some optional embodiments, after detecting the abnormal event in the railway information system, the above Figure 1 Corresponding embodiments further include:

[0072] In step S31, scenario mapping information is acquired.

[0073] In step S32, when the co-occurrence abnormal event of the abnormal event is determined, the target event scenario corresponding to the co-occurrence abnormal event is determined based on the scenario mapping information.

[0074] In step S33, an alarm prompt is generated according to the target event scenario.

[0075] In the embodiments of the present application, after detecting the abnormal event, it can be judged whether the abnormal event is a co-occurrence abnormal event, and after the abnormal event is a co-occurrence abnormal event, the target event scenario corresponding to the co-occurrence abnormal event is determined based on the scenario mapping information.

[0076] For example, if the abnormal event is an alarm event of communication interruption of a station network management system, after detecting the co-occurrence abnormal event of the abnormal event: the data loss event of the TDCS / CTC system of the adjacent station, the event scenario "regional network failure leading to multiple system collaborative failure" corresponding to the co-occurrence abnormal event in the scenario mapping information can be determined as the target event scenario.

[0077] After the target event scenario is determined, an alarm prompt can be generated based on the target event scenario, for example, an alarm prompt containing the words "regional network failure leading to multiple system collaborative failure" is displayed, and the processing strategy "please start redundant network switching and check the physical line" is displayed in the alarm prompt.

[0078] In the embodiments of the present application, the co-occurrence abnormal events can be identified and analyzed based on the scenario mapping information, the spatio-temporal correlation of the abnormal events can be mined, the upgrade from "single event processing" to "systematic risk prevention and control" can be further realized, and combining machine learning, the event scenario can be efficiently located, and important support can be provided for intelligent operation and safety management of the railway system.

[0079] In some optional embodiments, the step S105 of predicting the target root cause in the to-be-confirmed abnormal root cause based on the abnormal data features includes:

[0080] In step S1051, when the number of abnormal root causes to be confirmed is multiple, weights corresponding to the abnormal root causes to be confirmed are obtained, wherein the weights are used to indicate the contribution factors of the abnormal root causes to be confirmed to the abnormal event.

[0081] In step S1052, based on the weights, a verification order of the abnormal root causes to be confirmed is determined, so as to indicate that the verification model verifies the abnormal root causes to be confirmed based on the verification order, and obtains the target root cause matching the abnormal data feature prediction.

[0082] In the embodiments of the present application, when the number of abnormal root causes to be confirmed is multiple, weights set in advance for each abnormal root cause to be confirmed can be obtained, wherein the weights are used to quantify the "contribution degree" of each abnormal root cause to the abnormal event, so the greater the weight, the higher the possibility of the root cause leading to the abnormal event. Therefore, the verification order of the abnormal root causes to be confirmed can be from high to low weight, so as to preferentially verify the abnormal root causes to be confirmed with high weight.

[0083] For example, a decision tree, a random forest, a neural network, or the like can be used to verify the abnormal root causes to be confirmed to obtain the target root cause, wherein the verification model can include an automated rule engine or a diagnostic tool.

[0084] For example, if the abnormal event is a signal machine display error, which leads to abnormal train operation, the abnormal root causes corresponding to the abnormal event include root cause A: signal machine power module failure, root cause B: signal machine communication interface loosening, and root cause C: signal machine software configuration error, wherein the weights of the root causes A-C are 0.6, 0.3, and 0.1 respectively, then the verification order can be root cause A, root cause B, and root cause C.

[0085] In the verification process, the power module of the device can be checked first, if the power voltage is found to be abnormal, the root cause A is confirmed as the target root cause, and the verification is stopped. If the power module is normal, the communication interface is checked, if the interface is found to be loose, the root cause B is confirmed as the target root cause. If both of the above are normal, the software configuration is checked to verify the root cause C.

[0086] In addition, after the target root cause of the abnormal event is verified, the following steps can be performed:

[0087] The historical target root cause corresponding to the abnormal event is obtained, and based on the historical target root cause, the weight of the abnormal root cause to be confirmed corresponding to the abnormal event is adjusted.

[0088] In the embodiments of the present application, after the target root cause of the abnormal event is verified, the weight of the abnormal root cause to be confirmed corresponding to the abnormal event can be adjusted according to the result feedback of the verified target root cause, so as to optimize the verification strategy for the abnormal event subsequently.

[0089] For example, the historical target root causes can be acquired, and the weight of the to-be-confirmed abnormal root cause can be adjusted according to a proportion of a determined number of current target root causes in the historical target root causes. For example, if the number of historical target root causes is N, and the determined number of current target root causes is n+1, the weight corresponding to the current target root cause can be (n+1) / N, and the weight of other to-be-confirmed root causes is adaptively adjusted.

[0090] In the embodiments of the present application, in the railway information system, the target root cause can be efficiently located from the multiple to-be-confirmed root causes through the weight distribution and verification sequence optimization, so that the most possible cause is verified preferentially, and thus the efficiency and accuracy of fault troubleshooting are improved.

[0091] In some optional implementations, in a case where the determined abnormal event is multiple, the step S105 further includes:

[0092] In the step S41, a current train scheduling strategy in the railway information system is acquired.

[0093] In the step S42, a processing priority of the abnormal event is determined based on a correlation degree of the abnormal event and the current train scheduling strategy, so as to sequentially execute the step of determining the target root cause of the abnormal event based on the processing priority.

[0094] In the embodiments of the present application, the current train scheduling strategy is used to indicate a train operation plan generated by the railway information system according to a real-time running state, including a train operation diagram, an interval occupation plan, a route arrangement, etc. The correlation degree of the abnormal event and the current train scheduling strategy is used to indicate an influence degree of the abnormal event on the current scheduling strategy. The priority is used to indicate that in a case where multiple abnormal events are concurrent, a more critical abnormal event is preferentially processed.

[0095] For example, in the determination of the correlation degree of the abnormal event and the current train scheduling strategy, a correlation rule can be acquired, where the correlation rule is a correlation rule of the abnormal event and the scheduling strategy defined according to a prior rule, etc. For example, the correlation rule can be that the correlation degree score of the signal machine failure and the current train scheduling strategy is 9, the correlation degree score of the communication delay and the current train scheduling strategy is 7, and the correlation degree score of the device overheating and the current train scheduling strategy is 5.

[0096] After the correlation degree score of the abnormal event is determined, the correlation degree score can be sorted to obtain the processing priority of the abnormal event. Specifically, the correlation degree score is sorted from high to low to generate the processing priority. For example, the correlation degree score of the signal machine failure is 9, the correlation degree score of the communication interruption is 7, and the correlation degree score of the device overheating is 5, so that the sorting of the processing priority can be signal machine failure, communication interruption, and device overheating.

[0097] In the embodiments of the present application, the processing priority is determined based on the correlation degree of the abnormal event and the current scheduling strategy, which can realize accurate resource allocation and efficient fault processing, so as to quickly identify the abnormal event that has the greatest impact on the transportation order, and ensure the safety of train operation and the stable execution of the scheduling strategy.

[0098] In some optional embodiments, the above Figure 1 The corresponding embodiments further include:

[0099] Step S51, obtaining a preset abnormal root cause.

[0100] Step S52, analyzing the historical operation data of the railway information system to obtain a historical abnormal event matched with each preset abnormal root cause.

[0101] Step S53, establishing a mapping relationship between the preset abnormal root cause and the matched historical abnormal event to obtain abnormal mapping information.

[0102] In the embodiments of the present application, the historical fault cases can be sorted based on expert experience, so as to extract common abnormal root causes to obtain the preset abnormal root causes, such as Figure 2 After obtaining the preset abnormal root cause, the historical operation data can be obtained to obtain the abnormal event matched with the abnormal root cause.

[0103] Exemplarily, the historical operation data of the railway information system can be obtained based on the operation and maintenance log, the monitoring system, the scheduling system, etc., and the abnormal event in the historical operation data is determined to associate and analyze the preset abnormal root cause and the historical abnormal event.

[0104] In the association and analysis of the preset abnormal root cause and the historical abnormal event, in an optional embodiment, the occurrence frequency of each preset abnormal root cause in the historical data can be counted, and the corresponding historical abnormal event can be extracted. For example, the historical abnormal event A caused by the preset abnormal root cause A commonly occurs in 80% of the fault cases, and then the mapping relationship between the preset abnormal root cause A and the historical abnormal event A can be established.

[0105] In another optional embodiment, a supervised learning model such as a decision tree or a random forest can be used to identify the mapping relationship between the preset abnormal root cause and the historical abnormal event. Specifically, the input features of the supervised learning model can include the attributes of the historical abnormal event in the historical operation data, such as type, location, time, etc., and output the root cause label corresponding to the historical abnormal event, and determine the abnormal root cause matched with the historical abnormal event in the preset abnormal root cause based on the root cause label.

[0106] In the embodiments of the present application, the abnormal mapping information can be established through the association analysis of the preset abnormal root cause and the historical operation data, the rapid mapping from the abnormal event to the root cause can be realized, and important support can be provided for the fault diagnosis, predictive maintenance and intelligent operation and maintenance of the railway information system.

[0107] To sum up, in the embodiments of the present application, first, the operation data in the railway information system can be acquired, wherein the railway information system is used to indicate a system for scheduling and controlling trains. Then, the abnormal mapping information can be acquired in the case that an abnormal event is determined based on the operation data, and the abnormal event corresponding to the to-be-confirmed abnormal root cause is determined according to the abnormal mapping information, wherein the abnormal mapping information is used to indicate the mapping relationship between each abnormal event and at least one abnormal root cause. Next, the abnormal data features of the abnormal event can be acquired, and the target root cause in the to-be-confirmed abnormal root cause is predicted based on the abnormal data features, wherein the target root cause is used to indicate the root cause that triggers the abnormal event in the operation of the railway information system, thereby reducing the dependence on manual work in the fault analysis process, improving the fault analysis efficiency, and based on the abnormal mapping information, the fault attribution of the abnormal event is performed, and thus the attribution accuracy is improved.

[0108] The embodiments of the present disclosure also provide a data processing system for executing the data processing method as shown in the above Figure 1 The architecture diagram of the data processing system is shown as Figure 3 The data processing system includes a collection alarm unit, a data processing model and a fault root cause positioning unit, specifically:

[0109] The collection alarm unit is used to collect the operation data of the railway information system, and the collection alarm unit can include a network management subunit, a channel monitoring subunit, an operation and maintenance subunit and a hardware monitoring subunit. Here, the collection alarm unit can alarm the abnormal event after the data processing model determines the abnormal event based on the operation data.

[0110] The data processing model is used to adopt an intelligent alarm aggregation and convergence method based on the operation data collected by the collection alarm unit, so as to effectively improve the alarm processing efficiency. The method first integrates various types of raw data collected by the channel monitoring, hardware monitoring, network management and operation and maintenance system, including network equipment status, hardware health indicators, IP on-off status and computer room environment parameters, etc. Then, through data cleaning and standardization processing, redundant information can be eliminated, a unified alarm model can be established, and the abnormal event can be determined in the operation data based on the alarm model.

[0111] The fault root cause positioning unit is used to determine the target root cause of the abnormal event, and the specific determination method of the target root cause is described in the above Figure 1 corresponding embodiments, which will not be described here.

[0112] Referring to Figure 4 , a structural block diagram of a data processing apparatus is shown, comprising:

[0113] The acquisition module 401 is configured to acquire operation data in a railway information system, wherein the railway information system is used to indicate a system for scheduling and controlling trains.

[0114] The first determination module 402 is configured to acquire abnormal mapping information in a case where an abnormal event is determined based on the operation data, and determine a to-be-confirmed abnormal root cause corresponding to the abnormal event according to the abnormal mapping information, wherein the abnormal mapping information is used to indicate a mapping relationship between each abnormal event and at least one abnormal root cause.

[0115] The second determination module 403 is configured to acquire abnormal data features of the abnormal event, and predict a target root cause in the to-be-confirmed abnormal root cause based on the abnormal data features, wherein the target root cause is used to indicate a root cause triggering the abnormal event in the operation of the railway information system.

[0116] The embodiments of the present disclosure further provide an electronic device having the data processing apparatus shown in the above Figure 4 .

[0117] Please refer to Figure 5 , Figure 5 is a structural schematic diagram of an electronic device provided by an optional embodiment of the present disclosure, as shown in Figure 5 , the electronic device comprises one or more processors 10, a memory 20, and an interface for connecting various components, including a high-speed interface and a low-speed interface. Various components are communicatively connected to each other by using different buses, and can be installed on a common motherboard or in other ways as needed. The processor can process instructions executed in the electronic device, including instructions stored in the memory or on the memory to display graphical information of a GUI on an external input / output device such as a display device coupled to the interface. In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple storage devices. Similarly, multiple electronic devices can be connected, each device providing part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 5 In the above

[0118] The processor 10 can be a central processor, a network processor, or a combination thereof. The processor 10 can further include a hardware chip. The hardware chip can be an application specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device can be a complex programmable logic device, a field programmable logic gate array, a general array logic, or any combination thereof.

[0119] The memory 20 stores instructions executable by the at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.

[0120] The memory 20 can include a program region and a data region. The program region can store an operating system and application programs required by at least one function. The data region can store data created according to use of the electronic device, and the like. In addition, the memory 20 can include a high-speed random access memory, and can further include a non-transitory memory such as at least one of a magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some optional embodiments, the memory 20 can optionally include a memory disposed remotely with respect to the processor 10, and these remote memories can be connected to the electronic device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0121] The memory 20 can include a volatile memory such as a random access memory, and can also include a non-volatile memory such as a flash memory, a hard disk, or a solid state disk. The memory 20 can further include a combination of the above-mentioned types of memories.

[0122] The electronic device further includes a communication interface 30 for communication of the electronic device with other devices or communication networks.

[0123] The embodiments of the present application also provide a computer storage medium having a computer program stored thereon, which, when executed by a processor, implements the path planning method described in any one of the above method embodiments.

[0124] The embodiments of the present application also provide a computer program product including computer instructions, which instruct a computing device to perform operations corresponding to the path planning method described in any one of the above method embodiments.

[0125] It should be noted that, according to the needs of implementation, each component / step described in the embodiments of the present application can be split into more components / steps, or two or more components / steps or parts of the operation of the components / steps can be combined into a new component / step, to achieve the purpose of the embodiments of the present application.

[0126] The methods according to the embodiments of the present application described above can be implemented in hardware, firmware, or software, or a combination of them, and can be stored in a recording medium such as a CD ROM, RAM, floppy disk, hard disk, or magneto-optical disk, or be downloaded by a network from a remote recording medium or a non-transitory machine-readable medium originally stored in a local recording medium and then stored in a local recording medium, so that the methods described herein can be processed by such software using a general-purpose computer, a special-purpose processor, or programmable or special-purpose hardware such as an ASIC or an FPGA. It can be understood that the computer, processor, microprocessor controller, or programmable hardware includes a storage component (for example, RAM, ROM, flash memory, etc.) that can store or receive software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods described herein. In addition, when a general-purpose computer accesses the code for implementing the methods shown herein, the execution of the code will convert the general-purpose computer into a special-purpose computer for executing the methods shown herein.

[0127] Those skilled in the art can appreciate that the units and method steps of the examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of the present application.

[0128] The above embodiments are only used to illustrate but not limit the embodiments of the present application, and a person of ordinary skill in the art can make various changes and modifications without departing from the spirit and scope of the embodiments of the present application, therefore all equivalent technical solutions belong to the scope of the embodiments of the present application, and the patent protection scope of the embodiments of the present application should be defined by the claims.

Claims

1. A data processing method, characterized in that, include: Acquire operational data from a railway information system, wherein the railway information system is used to instruct the system for scheduling and controlling trains; If an abnormal event is identified based on the running data, abnormal mapping information is obtained, and the root cause of the abnormal event is determined according to the abnormal mapping information. The abnormal mapping information is used to indicate the mapping relationship between each abnormal event and at least one root cause. Obtain the abnormal data features of the abnormal event, and predict the target root cause among the root causes of the anomaly to be confirmed based on the abnormal data features, wherein the target root cause is used to indicate the root cause that triggered the abnormal event during the operation of the railway information system.

2. The method according to claim 1, characterized in that, The method further includes: Before obtaining the anomaly mapping information, if the operational data includes alarm data from the railway information system during operation, the abnormal event is determined based on the alarm data; or If the operational data does not include alarm data from the railway information system during operation, data features of the operational data are extracted, and abnormal events are determined based on abnormal data features in the data features.

3. The method according to claim 2, characterized in that, The step of extracting data features from the operational data and determining abnormal events based on abnormal data features in the data features includes: Based on the data indicators corresponding to the data features in the railway information system, the threshold range of the data features is determined; The matching degree between the data features and the threshold range is predicted based on a preset machine learning model, and when the data features do not match the threshold range, the abnormal event corresponding to the data indicator is determined.

4. The method according to claim 2, characterized in that, The method further includes: If there are multiple abnormal events determined based on the alarm data, co-occurring abnormal events are identified among the abnormal events, wherein the co-occurring abnormal events are used to indicate abnormal events that are related in time and space. When the co-occurrence rate of the co-occurrence anomaly meets the anomaly condition, the event scenario corresponding to the co-occurrence anomaly in the railway information system is determined. Establish a mapping relationship between the co-occurring abnormal events and the event scenarios to obtain scenario mapping information.

5. The method according to claim 4, characterized in that, The method further includes: After an abnormal event is detected in the railway information system, the scene mapping information is obtained; When a co-occurring abnormal event is identified, the target event scenario corresponding to the co-occurring abnormal event is determined based on the scene mapping information. An alarm notification is generated based on the target event scenario.

6. The method according to claim 1, characterized in that, The prediction of the target root cause among the unconfirmed anomalies based on the abnormal data features includes: When there are multiple unconfirmed root causes of anomalies, the weights corresponding to the unconfirmed root causes of anomalies are obtained, wherein the weights are used to indicate the contribution factor of the unconfirmed root cause to the occurrence of the abnormal event. Based on the weights, the verification order of the anomaly root causes to be confirmed is determined, so as to instruct the verification model to verify the anomaly root causes to be confirmed based on the verification order, and obtain the target root causes that match the anomaly data feature prediction.

7. The method according to claim 6, characterized in that, The method further includes: Obtain the historical target root cause corresponding to the abnormal event, and adjust the weight of the unconfirmed abnormal root cause corresponding to the abnormal event based on the historical target root cause.

8. The method according to claim 6, characterized in that, The method further includes: If multiple abnormal events are identified, the current train dispatching strategy in the railway information system is obtained. Based on the correlation between the abnormal event and the current train scheduling strategy, the processing priority of the abnormal event is determined, and the steps of determining the target root cause of the abnormal event are executed sequentially based on the processing priority.

9. The method according to claim 1, characterized in that, The method further includes: Obtain the preset root cause of the exception; Based on the historical operational data of the railway information system, historical abnormal events are obtained that match each of the preset abnormal root causes. Establish a mapping relationship between the preset abnormal root cause and the matching historical abnormal event to obtain abnormal mapping information.

10. An electronic device, comprising: The processor, memory, communication interface, and communication bus are provided, wherein the processor, memory, and communication interface communicate with each other via the communication bus. The memory is used to store at least one executable instruction that causes the processor to perform an operation corresponding to the method as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Abnormality processing method and device

    CN113868008A

  • Abnormality detection method and system applied to intelligent television mainboard system

    CN116962673A

Cited By

  • Internet of Things connection fault root cause positioning method, device, equipment and program product

    CN121509212A