A cloud platform-based window remote control system
By embedding a dual-mode control kernel and a sovereignty drift quantization module within the edge controller, the contradiction between dynamic optimization and security determinism in the cloud platform window remote control system is resolved. This enables reliable response and covert attack defense under extreme conditions, and constructs a multi-layered adaptive security defense system.
Patent Information
- Application Number
- CN202511503507.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-21
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2045-10-21
AI Technical Summary
Existing cloud-based remote window control systems suffer from security determinism conflicts when pursuing dynamic optimization and are vulnerable to covert attacks, which may lead to unreliable responses in extreme emergency situations and insufficient ability to resist attacks that contaminate external data sources.
Employing a dual-mode control kernel embedded in the edge controller, combined with a control sovereignty drift quantification module, an adaptive sovereignty intervention module, and a network collaborative failure risk monitoring module, the system ensures the determinism and security of emergency response by quantifying risk scores and dynamically adjusting the permissions of the learning model. It also monitors the system status at the global level and triggers recalibration events to eliminate potential risks.
It achieves the goal of optimizing energy consumption while ensuring deterministic safety response under extreme conditions, resisting covert attacks, and constructing a multi-layered adaptive security defense system to ensure reliable system execution in emergencies such as fires.
Smart Images

Figure CN120972598B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent building control, specifically to a remote window control system based on a cloud platform. Background Technology
[0002] Cloud-based remote window control systems are widely used in modern smart buildings. By integrating advanced algorithms, they can intelligently adjust based on data such as weather, indoor environment, and user habits to optimize building energy consumption. The introduction of cutting-edge technologies such as federated continuous learning enables devices deployed at the network edge, such as window controllers, to continuously evolve and achieve personalized energy-saving strategies.
[0003] There is an inherent technical conflict between these intelligent systems that pursue dynamic optimization and scenarios such as fire safety that require absolute reliability and deterministic responses. The continuous evolution of learning models introduces unpredictability in behavior, which may lead to modifications of the control parameters of the underlying hardware, causing it to deviate from its safety-verified initial state. In extreme emergencies such as fires, this deviation may cause emergency commands designed for general scenarios to fail. When a large number of devices experience such failures, it can trigger systemic coordinated failures, resulting in serious consequences.
[0004] Existing systems are insufficiently protected against covert attacks that compromise external data sources. These attacks do not directly damage the system but instead exploit its own optimization mechanisms to accelerate the drift of its internal state towards insecure boundaries, rendering traditional security measures ineffective. Therefore, a new technical solution is urgently needed to resolve the contradiction between dynamic intelligent optimization and static security determinism, and to defend against covert attacks that exploit system optimization mechanisms.
[0005] The information disclosed in the background section above is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0006] The purpose of this invention is to provide a cloud platform-based remote window control system to solve the problems mentioned in the background art.
[0007] The technical solution of the present invention includes:
[0008] The edge controller has an embedded dual-mode control kernel, which is used to execute energy-optimized control logic driven by a federated continuous learning model in normal mode to achieve energy saving. When an emergency command is received, it switches to emergency mode and executes a deterministic security protocol stack that is isolated from the logic of normal mode to ensure deterministic security response under extreme conditions.
[0009] The edge controller's built-in control sovereignty drift quantization module is used to periodically calculate the degree of deviation between the current window's underlying control parameter vector and the preset baseline safety parameter vector, and generate a control sovereignty drift score to quantify the systemic risks accumulated due to continuous learning and optimization.
[0010] The edge controller's built-in adaptive sovereignty intervention module is used to dynamically generate learning influence factors to suppress the modification permissions of the federated continuous learning model based on the control sovereignty drift score, thereby constituting dynamic negative feedback regulation.
[0011] The network collaborative failure risk monitoring module located on the cloud platform is used to aggregate the control sovereignty drift scores uploaded by all edge controllers in the network, and monitor the drift of the entire system state toward the collaborative failure boundary from two dimensions: dynamic trend and static state.
[0012] The sovereign forced regression module is used to trigger a network-wide recalibration event when the network collaborative failure risk monitoring module detects that the drift speed or average drift value exceeds a preset safety threshold. This forces all edge controllers to restore the underlying control parameter vectors to the baseline safe state, thereby eliminating potential systemic risks.
[0013] Preferably, the control sovereignty drift quantization module is configured according to the formula... Calculate the control sovereignty drift score ;
[0014] To control sovereignty drift scoring, The number of key control parameters, For parameter index, For the first Risk weights for each parameter For the first The current values of the parameters, For the first Formal verification of the safety baseline value for each parameter.
[0015] Preferably, the control parameter vector Includes physical actuation parameters that directly affect the window's emergency opening capability, such as motor starting torque and maximum operating speed; safety baseline values. These parameter values, derived from formal verification methods before the equipment leaves the factory, ensure successful execution of the emergency protocol under all operating conditions; risk weights. These are preset parameters determined through offline sensitivity analysis, which is used to quantify a single parameter. The impact of deviations on the success rate of emergency activation.
[0016] Preferably, the adaptive sovereign intervention module updates the amount of the original parameters calculated by the federated continuous learning model. Learning Influence Factor Multiply to get the actual update amount. and apply the actual update volume The underlying control parameters are updated to achieve dynamic negative feedback adjustment of permissions for the federated continuous learning model.
[0017] Preferably, when controlling sovereignty drift score Not greater than the preset local alert threshold for sovereignty drift At that time, according to the formula Perform calculations. The preset attenuation index;
[0018] When controlling sovereignty drift score Greater than the local warning threshold At that time, we will learn about the impact factor. Set it to 0 to completely cut off the learning model's ability to modify the underlying parameters.
[0019] Preferably, the local alert threshold The method for determining this is as follows: by establishing a simulation network containing multiple window nodes, the average value of the nodes in the network is determined. The value is obtained by reducing the proportion of emergency command coordination failure windows to a level that is close to the legal limit, and then making a safety reduction on the level value to ensure that the system intervenes before approaching the danger boundary.
[0020] Preferably, the monitoring process of the network collaborative failure risk monitoring module is as follows: [The text abruptly ends here, likely due to an incomplete sentence or missing information.] Control sovereignty drift score uploaded by each edge controller And according to the formula The network average sovereignty drift was calculated. Simultaneously calculate the time-varying rate of change of the network's average sovereignty drift. This allows for risk assessment from both dynamic trends and static states.
[0021] Preferably, the triggering condition for the sovereignty mandatory reversion module is defined as satisfying any of the following logical conditions:
[0022] Time-varying rate of change of network average sovereignty drift greater than the preset rate of change critical trigger threshold Or, the current value of the network's average sovereignty drift. Greater than the preset average CSD global static threshold .
[0023] Preferably, the rate of change critical trigger threshold The setting is derived from simulations of rapid coordinated attack scenarios, aiming to capture the acceleration of risks; global static threshold. The set value is less than the local warning threshold. The physical meaning is that even if a large number of nodes in the network reach the local maximum warning line, as long as the overall average risk level of the system exceeds a medium-high level, the system is considered to be in an unhealthy metastable state, and potential systemic risks need to be eliminated through forced regression.
[0024] Preferably, the execution process of the recalibration event is as follows: once the triggering condition is met, the sovereign forced regression module immediately broadcasts a network recalibration command to the entire network. After receiving the command, all edge controllers unconditionally change the underlying control parameter vector. Force reset to safe baseline value And reset the state of the local federated continuous learning model, thereby enabling all nodes to... The value is instantly reset to zero, bringing the entire system's security state back to its initial, deterministically verified baseline.
[0025] This invention provides an improved cloud platform-based remote window control system, which has the following improvements and advantages compared to the prior art:
[0026] 1. This invention innovatively proposes and quantifies the core technical indicator of control sovereignty drift, providing a measurable dimension for assessing the potential risks introduced by dynamic learning systems. Through the control sovereignty drift quantification module built into the edge controller, the system can periodically calculate the deviation between the current control parameter vector and the formally verified safety baseline value, transforming this abstract systemic risk into a precise and objective control sovereignty drift score. This score is based on a weighted statistical analysis of the deviation of key control parameters, where the weights are derived from offline sensitivity analysis of emergency activation success rate, and the safety baseline is derived from the completeness test before the equipment leaves the factory. This design makes risk assessment no longer a vague qualitative judgment, but a quantitative analysis with clear physical meaning and solid technical basis, providing a reliable decision-making foundation for subsequent risk management.
[0027] 2. This invention constructs a multi-layered, adaptive security defense system from local to global, from soft control to hard reset, greatly improving system security without sacrificing daily optimization efficiency. At the local level, the edge controller's built-in adaptive sovereignty intervention module dynamically generates learning influence factors based on control sovereignty drift scores, forming a rapidly responding dynamic negative feedback adjustment closed loop. This mechanism can smoothly suppress the federated continuous learning model's modification permissions on underlying parameters, providing ample optimization space when the risk is low, and non-linearly tightening permissions when the risk approaches a threshold, until exceeding the local warning threshold. Complete disconnection enables refined and continuous control of risks. At the global level, the network collaborative failure risk monitoring module located on the cloud platform monitors the average sovereignty drift of the entire network from two dimensions: static state and dynamic trend. This allows it to effectively identify slowly accumulating systemic risks and rapidly developing collaborative attacks. Once the risk in any dimension exceeds the security threshold, the sovereignty forced regression module will trigger a network-wide recalibration event, forcing all edge controllers to restore their control parameters and learning models to the initial security baseline. This global, strong intervention mechanism provides the ultimate security guarantee for the entire system, ensuring that risks can be eliminated.
[0028] 3. This invention ensures the absolute priority of safety logic and behavioral determinism from a system architecture perspective. The dual-mode control kernel embedded in the edge controller completely isolates the energy consumption optimization control logic driven by the federated continuous learning model in daily mode from the safety protocol stack with deterministic behavior in emergency mode. This design ensures that no matter how the state of the daily learning model drifts, the execution path of emergency commands remains independent, reliable, and undisturbed. It resolves the conflict between intelligent optimization and safety determinism, enabling the system to safely enjoy the daily energy consumption optimization benefits brought by federated continuous learning while ensuring deterministic safety response capabilities under extreme conditions such as fires. Attached Figure Description
[0029] The present invention will be further explained below with reference to the accompanying drawings and embodiments:
[0030] Figure 1 This is a flowchart of the system of the present invention. Detailed Implementation
[0031] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to specific embodiments. Example 1
[0032] Please see Figure 1 This invention provides a cloud platform-based remote window control system, comprising:
[0033] The edge controller's embedded dual-mode control kernel executes energy-optimized control logic driven by a federated continuous learning model in normal mode. This federated continuous learning model is based on a lightweight neural network, such as an MLP, and its input data includes indoor temperature, humidity, PM2.5, outdoor weather data, and users' historical window opening habits. The model's goal is to predict the optimal window opening and closing state to minimize energy consumption. Each edge controller trains the model locally and only uploads the model parameter updates to the cloud platform. The cloud platform aggregates the parameter updates from all devices using a federated averaging algorithm to form a global model, and then distributes the updated model back to each edge controller, forming a closed-loop learning process to achieve energy savings. Upon receiving an emergency command, it switches to emergency mode and executes a deterministic safety protocol stack that is isolated from the logic of normal mode to ensure deterministic safety response under extreme conditions.
[0034] The edge controller's built-in control sovereignty drift quantization module is used to periodically calculate the degree of deviation between the current window's underlying control parameter vector and the preset baseline safety parameter vector, and generate a control sovereignty drift score to quantify the systemic risks accumulated due to continuous learning and optimization.
[0035] The edge controller's built-in adaptive sovereignty intervention module is used to dynamically generate learning influence factors to suppress the modification permissions of the federated continuous learning model based on the control sovereignty drift score, thereby constituting dynamic negative feedback regulation.
[0036] The network collaborative failure risk monitoring module located on the cloud platform is used to aggregate the control sovereignty drift scores uploaded by all edge controllers in the network, and monitor the drift of the entire system state toward the collaborative failure boundary from two dimensions: dynamic trend and static state.
[0037] The sovereign forced regression module is used to trigger a network-wide recalibration event when the network cooperative failure risk monitoring module detects that the drift speed or average drift value exceeds a preset safety threshold. This forces all edge controllers to restore the underlying control parameter vectors to the baseline safe state, thereby eliminating potential systemic risks.
[0038] This invention provides a cloud platform-based remote window control system. The system aims to solve the core technical contradiction of how to ensure the deterministic safety response under extreme conditions such as fire while pursuing dynamic energy consumption optimization in intelligent control systems. The system architecture includes edge controllers deployed on each window terminal and a central cloud platform for collaborative management.
[0039] The dual-mode control kernel embedded in the edge controller aims to isolate routine optimization logic from emergency safety logic, ensuring the independence and reliability of the two modes. In this embodiment, the kernel serves as the core operating system functional component of the edge controller. In routine mode, the kernel is configured to execute energy-optimized control logic driven by a federated continuous learning model. This logic continuously adjusts window control strategies based on dynamic data such as weather, indoor environment, and user habits, with the goal of saving building energy. When an emergency command is received, for example, from the building's fire protection system, the kernel is configured to immediately switch to emergency mode. In emergency mode, the system executes a safety protocol stack that is logically completely isolated from routine mode and exhibits deterministic behavior.
[0040] The dual-mode kernel can be implemented using hardware virtualization technology based on dual operating systems. A lightweight real-time operating system is responsible for running the emergency safety protocol stack, while another general-purpose operating system, such as Linux, is responsible for power optimization logic. The two operating systems ensure that they do not interfere with each other through memory isolation and task priority management at the underlying level. Emergency instructions will trigger hardware interrupts, which are directly taken over by the RTOS with the highest priority, thereby ensuring the determinism of emergency response.
[0041] This protocol stack is a formally verified program embedded in the controller. It takes over the hardware control of the window with the highest priority, ensuring that actions such as emergency smoke exhaust can be executed deterministically, unaffected by the state of the daily learning model.
[0042] The control sovereignty drift quantification module built into the edge controller aims to provide a measurable metric for assessing the systemic risks introduced by continuous learning. In this embodiment, the module is configured to periodically calculate the degree of deviation between the control parameter vector at the bottom layer of the current window and a preset baseline safety parameter vector. This degree of deviation is quantified into a specific numerical score, namely the control sovereignty drift score. This score characterizes the degree of penetration of the learning model into the control of the underlying hardware, providing a basis for decision-making for subsequent risk intervention.
[0043] The adaptive sovereignty intervention module built into the edge controller aims to dynamically adjust the permissions of the learning model based on the quantified risk score, forming a localized negative feedback control loop. In this embodiment, the module dynamically generates a learning impact factor based on the score output by the control sovereignty drift quantification module. This factor is used to suppress the permission of the federated continuous learning model to directly modify the underlying control parameters. The higher the score, the greater the risk of the system deviating from the safety baseline, and the smaller the learning impact factor, thereby weakening or even cutting off the learning model's further changes to the system behavior.
[0044] The network collaboration failure risk monitoring module located on the cloud platform aims to monitor the systemic risks of the entire control network from a global perspective. In this embodiment, the module is deployed on a cloud server and is responsible for aggregating the control sovereignty drift scores periodically uploaded by all edge controllers in the network.
[0045] Communication between the edge controller and the cloud platform uses the MQTT protocol, and scoring data is transmitted in encrypted JSON format. Each message includes a timestamp and digital signature to prevent data tampering and replay attacks. When a recalibration event is triggered, the sovereignty forced regression module broadcasts a separate, highest-priority MQTT topic command to ensure timely delivery and reliable execution of the command.
[0046] It not only focuses on the instantaneous values of the scores of each node, but more importantly, it comprehensively evaluates whether the state of the entire system is drifting toward the dangerous boundary of collaborative failure from two dimensions: dynamic trend, i.e., drift speed, and static state, i.e. drift average.
[0047] The purpose of the sovereign forced regression module is to perform a global forced reset when systemic risks accumulate to an unacceptable level, in order to eliminate potential systemic risks. In this embodiment, this module is also located on the cloud platform. When the network collaborative failure risk monitoring module detects that the risk drift speed or average risk of the entire network exceeds a preset safety threshold, this module is configured to trigger a network-wide recalibration event. This event will force all edge controllers in the network to restore their underlying control parameter vectors to the initial baseline safety state.
[0048] Through the collaborative work of the above modules, this system establishes a multi-layered, adaptive security defense system from local to global, from soft control to hard reset. The technical effect is that it provides a measurable dimension for the conflict between dynamic learning optimization and static security determinism, namely control sovereignty drift. Based on this core indicator, the system can safely enjoy the daily energy consumption optimization benefits brought by federated continuous learning while ensuring deterministic response capabilities under extreme conditions such as fires. It effectively solves the dilemma of choosing between economic value and survival value for intelligent systems and can resist covert attacks that utilize the system optimization mechanism.
[0049] Emergency commands from the building's fire protection system, such as fire alarm signals, are broadcast via a separate, high-priority MQTT topic. The command packets are in lightweight binary format and contain a unique transaction ID and digital signature. The real-time operating system in the dual-mode control kernel listens for this topic and, upon receiving a valid message with a specific command code, immediately triggers a hardware interrupt, thereby enabling rapid switching to emergency mode.
[0050] The concept of control sovereignty drift and its management mechanism proposed in this system address the systemic risks arising from continuous learning and optimization. In practical applications, this system will work in conjunction with various security measures such as communication encryption, data integrity verification, hardware redundancy, and software security updates to jointly construct a comprehensive and robust security defense system for intelligent control systems. Example 2
[0051] The control sovereignty drift quantization module follows the formula Calculate the control sovereignty drift score ;
[0052] To control sovereignty drift scoring, The number of key control parameters, For parameter index, For the first Risk weights for each parameter For the first The current values of the parameters, For the first Formal verification of the security baseline value for each parameter;
[0053] Control parameter vector Includes physical actuation parameters that directly affect the window's emergency opening capability, such as motor starting torque and maximum operating speed; safety baseline values. These parameter values, derived from formal verification methods before the equipment leaves the factory, ensure successful execution of the emergency protocol under all operating conditions; risk weights. These are preset parameters determined through offline sensitivity analysis, which is used to quantify a single parameter. The impact of deviations on the success rate of emergency activation;
[0054] Based on Example 1, this embodiment limits the implementation of the control sovereignty drift quantification module; the core function of this module is to calculate the control sovereignty drift score through a specific mathematical model, thereby transforming the abstract system risk into a precise numerical value.
[0055] To further clarify, in order to quantify the systemic risks that may compromise the determinism of emergency responses due to continuous learning and optimization, this embodiment introduces a control sovereignty drift score. The scoring method is adapted based on the weighted root mean square error principle in statistics, and the quantification process is defined as follows: in: The control sovereignty drift score is a dimensionless normalized risk measure that quantifies the degree of deviation of the current control state from the absolute safety baseline. It is calculated by this module.
[0056] This refers to the number of key control parameters involved in the risk assessment. It is a preset integer, which is determined after screening all parameters in the window control system that affect the safety response.
[0057] The parameter index is a counter variable used to iterate through all key control parameters;
[0058] It is the first The risk weights of each parameter are preset dimensionless parameters; their function is to characterize the degree of impact of deviations from different parameters on overall safety. Set to be the normalization sensitivity of the dimensionless They are positively correlated. In this embodiment, it can be directly set... Risk weight The method for determining this parameter is as follows: it is obtained through offline sensitivity analysis; this sensitivity analysis aims to quantify a single parameter. Deviation on emergency activation success rate The impact of this; to address the issue of dimensional consistency, this embodiment introduces normalization sensitivity. The concept and calculation formula are as follows: The sensitivity analysis process is as follows: An offline simulation environment is established, incorporating physical simulation models, such as fluid dynamics models, capable of simulating the opening process of a window under different air pressure differences and smoke loads. Within this environment, Monte Carlo simulation methods are used to analyze each key parameter. At its safety baseline value Perform minor random disturbances in the vicinity and record the emergency activation success rate under each disturbance. Calculate using numerical differentiation methods .because This represents the dimensionless success rate (ratio). Having physical units Therefore, the partial derivatives The dimension of is the reciprocal of the parameter's unit; compare it with a baseline value that has the same physical units. After multiplication, the physical units cancel each other out, resulting in a dimensionless normalized sensitivity. And use this to determine risk weights Emergency activation success rate; Emergency Activation Success Rate For a single parameter The partial derivatives; No. The normalization sensitivity of each parameter. Its physical meaning is that when the parameter... When a unit relative change occurs near its safety baseline value, the success rate of activation is affected. The magnitude of the impact;
[0059] in This is the safety baseline value for this parameter; this is the normalization sensitivity. In a physical sense, this can be understood as, when the parameter... When a unit relative change occurs near its safety baseline value, the success rate of activation is affected. The magnitude of the impact is represented by a dimensionless value; risk weight. Set to be the normalization sensitivity of the dimensionless A positive correlation exists; for example, it can be directly set as follows: This ensures that deviations from key safety parameters are subject to higher penalty weights that conform to the principle of dimensional consistency.
[0060] It is the first The formal verification safety baseline value for each parameter is a preset reference value; its function is to provide an absolutely safe anchor point for risk assessment; the safety baseline value The source is: before the equipment leaves the factory, a set of parameter values that can ensure 100% successful execution of the window emergency opening protocol are determined by conducting a completeness test on the execution of the protocol under all possible working conditions through formal verification methods.
[0061] In this embodiment, the control parameter vector This includes physical execution parameters that directly affect the window's emergency opening capability; for example, we can define... This is the starting torque of the motor. This is the maximum operating speed, and so on. These physical execution parameters include at least the motor starting torque and maximum operating speed; deviations in the motor starting torque may prevent the window from opening under smoke load or pressure differential, while deviations in the maximum operating speed may affect the opening sequence of the coordinated smoke exhaust window; incorporating these directly related physical parameters into the scoring calculation ensures the accuracy of the score. Strong correlation with actual security risks;
[0062] The technical advantage of this embodiment lies in that, through the above formula and parameter definitions, the vague concept of system risk is transformed into a calculable, comparable, and physically meaningful mathematical indicator. This quantitative approach not only makes risk assessment more objective and accurate, but also introduces risk weights based on sensitivity analysis. and security baselines derived from formal verification This greatly improves the accuracy and reliability of the risk assessment model, providing a solid decision-making basis for subsequent adaptive intervention and global reset;
[0063] This risk assessment model is based on the assumption that deviations in key parameters have relatively independent effects. Although weights were determined through sensitivity analysis, in practical applications, synergistic deviations of multiple parameters may generate more complex nonlinear risks. Future research could consider introducing higher-dimensional sensitivity analysis or machine learning-based risk models to more accurately capture the synergistic effects between parameters, thereby further improving the model's physical fidelity.
[0064] During the sensitivity analysis, Monte Carlo simulations generated at least 10,000 random perturbation samples to ensure the convergence and reliability of the statistical results. The fluid dynamics model was calibrated and validated using actual physical experimental data to ensure high fidelity in simulating the opening behavior of windows under extreme pressure differences and smoke loads, thereby guaranteeing the calculated sensitivity. It can accurately reflect the dose-effect relationship between parameters and physical effects.
[0065] Example 3
[0066] The adaptive sovereign intervention module updates the amount of raw parameters calculated by the federated continuous learning model. Learning Influence Factor Multiply to get the actual update amount. and apply the actual update volume The underlying control parameters are updated to achieve dynamic negative feedback adjustment of permissions for the federated continuous learning model.
[0067] Learning Influence Factor The calculation process is as follows:
[0068] When controlling sovereignty drift score Not greater than the preset local alert threshold for sovereignty drift At that time, according to the formula Perform calculations. The preset attenuation index;
[0069] When controlling sovereignty drift score Greater than the local warning threshold At that time, we will learn about the impact factor. Set it to 0 to completely cut off the learning model's ability to modify the underlying parameters;
[0070] Local alert threshold The method for determining this is as follows: by establishing a simulation network containing multiple window nodes, the average value of the nodes in the network is determined. The value is obtained by reducing the level value to a level that makes the proportion of emergency command coordination failure windows approach the legal upper limit, and then ensuring that the system intervenes before approaching the danger boundary.
[0071] Based on Example 1, this embodiment provides a detailed explanation of the working mechanism of the adaptive sovereignty intervention module. This module constitutes the first line of defense for local security, and its core lies in smoothly suppressing the potential risky behavior of the learning model through a precise negative feedback mechanism.
[0072] This adaptive sovereign intervention module updates the original parameters calculated by the federated continuous learning model. Learning Influence Factor with Dynamic Computation Multiply to obtain the actual update amount applied to the system. The regulation process is defined as: in, Original parameter update amount. Calculated by the federated continuous learning model; Learning impact factor. This is located in... The dimensionless adjustment coefficient between them is used to suppress the federated continuous learning model's authority to modify the underlying control parameters; Actual update volume. (Based on the original update volume) Learning Influence Factor Multiplying them together yields the result;
[0073] The system applies this modulated actual update amount. The underlying control parameters are updated; this process enables dynamic negative feedback adjustment of the permission to modify the federated continuous learning model: when the system deviates from the safety baseline, i.e. When the value increases, The value will automatically decrease, thereby tightening the learning model's control and suppressing further deviations.
[0074] Learning Influence Factor The computation process is designed as a piecewise function, with the design concept derived from gain scheduling in control theory, to achieve smooth suppression of the learning process rather than hard cut-off; its underlying logic is:
[0075] When the control sovereignty drift score is calculated by the control sovereignty drift quantification module Not greater than the preset local alert threshold for sovereignty drift hour, Calculate using the following formula: in: In other words, the learning impact factor is a range of... The dimensionless adjustment coefficients between them are calculated by this module; The current control sovereignty drift score is derived from the control sovereignty drift quantification module mentioned above. The local alert threshold for sovereignty drift is a preset dimensionless key security parameter, which defines the trigger boundary for local risk intervention. The preset attenuation index is a dimensionless parameter used to adjust the nonlinearity of the suppression curve; attenuation index The value is adjusted experimentally to obtain the desired suppression curve shape. For example, setting it to 2 can achieve loose permissions when the risk is low, while achieving fast, non-linear permission tightening when the risk approaches the threshold.
[0076] When controlling sovereignty drift score Greater than the local warning threshold When this occurs, it indicates that the risk of the local node has reached an unacceptable level, and at this point, the learning impact factor is initiated. It is directly set to 0; this will completely cut off the learning model's permission to modify the underlying parameters, achieving the strongest level of local protection.
[0077] Among them, the local warning threshold The determination method has sufficient technical basis; the calibration process is as follows: define the cooperative failure window ratio in the simulation network as... and the safety limits set by regulations or safety standards. In the simulated network, by adjusting the average of the nodes Value, calibrated to make To allow for a safety margin, the local warning threshold will be set. The safety reduction value set as this threshold is: in A safety factor, a preset value less than 1, is used to determine the critical average score. Perform safety reductions to determine local alert thresholds.
[0078] The simulation network consists of hundreds of virtual window control nodes, each simulating complete sovereignty drift quantization and adaptive intervention logic; the cooperative failure window ratio... Defined as: the ratio of the number of windows that failed to open on time or as required after an emergency smoke extraction command was triggered, due to control parameters deviating from the safety baseline, to the total number of windows; the simulation gradually increases the number of nodes by simulating a continuous learning process during normal operation. Value, and record at the same time Until it reaches the safety limit set by regulations. For example, at 5%, record the current average.
[0079] in A preset safety factor of less than 1, such as 0.75, is used to ensure that the system will intervene proactively long before the actual danger boundary is reached.
[0080] The gain effect of this embodiment is that it establishes a localized and continuous risk control closed loop that is responsive and smoothly adjustable. This mechanism can adaptively and softly regulate the risks generated during the learning process without affecting the daily energy consumption optimization of the system, and only hard cut off when the risk truly touches the local safety red line. Compared with a simple threshold alarm system, this refined control method greatly improves the intelligence level and operating efficiency of the system, and achieves a better balance between safety and economy.
[0081] Example 4
[0082] The monitoring process of the network collaborative failure risk monitoring module is as follows: It aggregates control sovereignty drift scores uploaded by N edge controllers in the network. And according to the formula The network average sovereignty drift was calculated. Simultaneously calculate the time-varying rate of change of the network's average sovereignty drift. This allows for risk assessment from both dynamic trend and static state dimensions; among which, The number of edge controllers in the network; No. Control sovereignty drift score uploaded by each edge controller; Network average sovereignty drift reflects the overall risk level of the entire system at the current moment.
[0083] The trigger condition for the sovereign mandatory reversion module is defined as satisfying any of the following logical conditions:
[0084] Time-varying rate of change of network average sovereignty drift greater than the preset rate of change critical trigger threshold Alternatively, the current value of the network's average sovereignty drift. Greater than the preset average CSD global static threshold
[0085] Rate of change critical trigger threshold The setting is derived from simulations of rapid coordinated attack scenarios, aiming to capture the acceleration of risks; global static threshold. The set value is less than the local warning threshold. The physical meaning is that even if a large number of nodes in the network do not reach the local maximum warning line, as long as the overall average risk level of the system exceeds a medium to high level, the system is considered to be in an unhealthy metastable state, and potential systemic risks need to be eliminated through forced regression.
[0086] The recalibration event execution process is as follows: Once the triggering condition is met, the sovereign forced regression module immediately broadcasts a network recalibration command to the entire network. Upon receiving this command, all edge controllers unconditionally force-reset the underlying control parameter vector p to the safe baseline value pr and reset the state of their local federated continuous learning model, thereby enabling all nodes to achieve recalibration. The value is instantly reset to zero, allowing the entire system's security state to return to its initial, deterministically verified baseline.
[0087] Based on Example 1, this embodiment refines the collaborative working mechanism of the network collaboration failure risk monitoring module and the sovereignty forced regression module located on the cloud platform; this mechanism constitutes the ultimate security guarantee for dealing with global risks.
[0088] The monitoring process of the network collaborative failure risk monitoring module begins with data aggregation; this module is configured to periodically receive data from the network. Each edge controller uploads its own control sovereignty drift score. Based on the aggregated data, the core function of this module is to perform parallel risk assessment from both dynamic trend and static state dimensions; the calculation process is as follows:
[0089] Calculate the average sovereignty drift of the network The formula is: This value reflects the overall risk level of the entire system at the current moment; this is an assessment from the static state dimension.
[0090] Calculate the time-varying rate of change of the network's average sovereignty drift. This value reflects the growth rate of the overall risk level of the system, which is an assessment of the dynamic trend dimension;
[0091] The triggering condition for the sovereign mandatory regression module is defined as a combination of any of the following logical conditions to ensure the completeness of monitoring and avoid blind spots that may exist in a single dimension: in: That is, the time change rate of the network average sovereignty drift is calculated in real time by the network cooperation failure risk monitoring module; This is a preset rate of change threshold; its function is to capture the acceleration of risk, specifically designed to address covert and rapid coordinated attack scenarios. The threshold is calibrated by simulating typical rapid coordinated attack scenarios in a simulation environment and recording the time rate of change of the network's average sovereignty drift under such scenarios. The distribution of these parameters, and a typical rapid coordinated attack scenario, can be simulated as follows: Attackers exploit vulnerabilities in the system's optimization mechanism to inject malicious parameter updates into a large number of edge controllers within a short period, causing their underlying control parameters to drift rapidly and synchronously towards dangerous areas; the simulation simulates this by setting a globally synchronized attack parameter. The rapid growth, and use this to define the threshold. And select the high quantile of this distribution, such as the 95th percentile, as the critical trigger threshold for the rate of change. To ensure sensitive detection of the rate of risk growth with significant attack characteristics; the dimension is the reciprocal of time. The current value of the network average sovereignty drift is calculated in real time by the network cooperation failure risk monitoring module; It is a preset average global static CSD threshold; its setting value is logically less than the aforementioned local alert threshold. Right now For example, if but It can be set to 0.60; the physical meaning is that even if a large number of nodes in the network reach the local maximum warning threshold, it will still be able to prevent such occurrences. However, as long as the overall average risk level of the system exceeds the medium-high level, that is... If the entire system is considered to be in an unhealthy metastable state, then forced regression is also needed to eliminate potential systemic risks.
[0092] Once any of the above triggering conditions is met, the sovereign forced regression module will immediately execute a network-wide recalibration event. This event is mandatory and global: the module immediately broadcasts a network recalibration command to the entire network; upon receiving this command, all edge controllers are designed to unconditionally perform the following operations: [The command is then executed by] recalibrating the underlying control parameter vectors... Force reset to the initial security baseline value Reset or clear the state of the local federated continuous learning model; the direct result of this operation is that all nodes... The value is instantly reset to zero, thus restoring the entire system's security state to its initial, deterministically verified, and absolutely secure baseline.
[0093] The gain effect of this embodiment lies in establishing a final, globally strong intervention control closed loop that is effective against both slow risk accumulation and rapid coordinated attacks; through dual-dimensional risk monitoring (i.e., static level and dynamic trend) and dual thresholds... The triggering logic greatly enhances the system's ability to identify and respond to complex attack patterns and unknown risks; the sovereign forced return mechanism, as the ultimate safeguard, ensures that no matter how the system state drifts, it can always be forcibly pulled back to the known safe origin, thus providing a security guarantee for the long-term stable operation of the entire intelligent control system.
[0094] To ensure the long-term robustness of the system, in addition to calibrating the thresholds, we conducted multi-dimensional stress tests on the entire system. Test scenarios included, but were not limited to, simulating sudden anomalies in sensor data, continuous network packet loss, and risk drift at different speeds across different window nodes. Test results showed that when network communication interruption exceeded a preset time, the cloud platform triggered a timeout alarm and notified the edge controller to enter local protection mode. When data from certain nodes was abnormal, the calculation of the network average was smoothed using methods such as weighted averaging or median filtering to avoid unnecessary global regression triggered by a single outlier. These measures collectively ensured that the system maintained deterministic safety responses and overall operational stability in the face of various anomalies.
[0095] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A cloud platform-based remote window control system, characterized in that, include: The edge controller has an embedded dual-mode control kernel, which is used to execute energy-optimized control logic driven by a federated continuous learning model in normal mode to achieve energy saving. When an emergency command is received, it switches to emergency mode and executes a deterministic security protocol stack that is isolated from the logic of normal mode to ensure deterministic security response under extreme conditions. The edge controller's built-in control sovereignty drift quantization module is used to periodically calculate the degree of deviation between the current window's underlying control parameter vector and the preset baseline safety parameter vector, and generate a control sovereignty drift score to quantify the systemic risks accumulated due to continuous learning and optimization. The edge controller's built-in adaptive sovereignty intervention module is used to dynamically generate learning influence factors to suppress the modification permissions of the federated continuous learning model based on the control sovereignty drift score, thereby constituting dynamic negative feedback regulation. The network collaborative failure risk monitoring module located on the cloud platform is used to aggregate the control sovereignty drift scores uploaded by all edge controllers in the network, and monitor the drift of the entire system state toward the collaborative failure boundary from two dimensions: dynamic trend and static state. The sovereign forced regression module is used to trigger a network-wide recalibration event when the network cooperative failure risk monitoring module detects that the drift speed or average drift value exceeds a preset safety threshold. This forces all edge controllers to restore the underlying control parameter vectors to the baseline safe state, thereby eliminating potential systemic risks. The control sovereignty drift quantization module follows the formula Calculate the control sovereignty drift score To control sovereignty drift scoring, The number of key control parameters, For parameter index, For the first Risk weights for each parameter For the first The current values of the parameters, For the first Formal verification of the security baseline value for each parameter; The learning impact factor The calculation process is as follows: When controlling sovereignty drift score Not greater than the preset local alert threshold for sovereignty drift At that time, according to the formula Perform calculations. The preset attenuation index; When controlling sovereignty drift score Greater than the local warning threshold At that time, we will learn about the impact factor. Set it to 0 to completely cut off the learning model's ability to modify the underlying parameters.
2. The cloud platform-based remote window control system according to claim 1, characterized in that, The control parameter vector Includes physical actuation parameters that directly affect the window's emergency opening capability, such as motor starting torque and maximum operating speed; safety baseline values. These parameter values, derived from formal verification methods before the equipment leaves the factory, ensure successful execution of the emergency protocol under all operating conditions; risk weights. These are preset parameters determined through offline sensitivity analysis, which is used to quantify a single parameter. The impact of deviations on the success rate of emergency activation.
3. The cloud platform-based remote window control system according to claim 1, characterized in that, The adaptive sovereign intervention module updates the original parameters calculated by the federated continuous learning model. Learning Influence Factor Multiply to get the actual update amount. and apply the actual update volume The underlying control parameters are updated to achieve dynamic negative feedback adjustment of permissions for the federated continuous learning model.
4. The cloud platform-based remote window control system according to claim 1, characterized in that, The local alert threshold The method for determining this is as follows: by establishing a simulation network containing multiple window nodes, the average value of the nodes in the network is determined. The value is obtained by reducing the proportion of emergency command coordination failure windows to a level that is close to the legal limit, and then making a safety reduction on the level value to ensure that the system intervenes before approaching the danger boundary.
5. A cloud platform-based remote window control system according to claim 1, characterized in that, The monitoring process of the network collaborative failure risk monitoring module is as follows: It aggregates the control sovereignty drift scores uploaded by N edge controllers in the network. And according to the formula The network average sovereignty drift was calculated. Simultaneously calculate the time-varying rate of change of the network's average sovereignty drift. This allows for risk assessment from both dynamic trend and static state dimensions.
6. A cloud platform-based remote window control system according to claim 5, characterized in that, The trigger condition for the sovereign mandatory reversion module is defined as satisfying any of the following logical conditions: Time-varying rate of change of network average sovereignty drift greater than the preset rate of change critical trigger threshold Alternatively, the current value of the network's average sovereignty drift. Greater than the preset average CSD global static threshold .
7. A cloud platform-based remote window control system according to claim 6, characterized in that, The rate of change critical trigger threshold The setting is derived from simulations of rapid coordinated attack scenarios, aiming to capture the acceleration of risks; global static threshold. The set value is less than the local warning threshold. The physical meaning is that even if a large number of nodes in the network do not reach the local maximum warning line, as long as the overall average risk level of the system exceeds a medium-high level, the system is considered to be in an unhealthy metastable state, and potential systemic risks need to be eliminated through forced regression.
8. A cloud platform-based remote window control system according to claim 1, characterized in that, The recalibration event is executed as follows: once the triggering condition is met, the sovereign forced regression module immediately broadcasts a network recalibration command to the entire network. Upon receiving this command, all edge controllers unconditionally change the underlying control parameter vector. Force reset to safe baseline value And reset the state of the local federated continuous learning model, thereby enabling all nodes to... The value is instantly reset to zero, bringing the entire system's security state back to its initial, deterministically verified baseline.
Citation Information
Patent Citations
Intelligent zero-carbon-emission park building energy-saving control method and system and medium
CN119270645A
Industrial robot real-time adaptive control method and system based on digital twinning
CN120755887A