A power distribution network safety risk assessment system and method

By using the hierarchical risk assessment process and multi-level model of the power distribution network safety risk assessment system, the problem of misjudgment of electricity consumption behavior during holidays and electricity promotion periods has been solved, and the accurate identification and risk assessment of disguised electricity consumption behavior has been achieved.

CN120975564BActive Publication Date: 2026-04-03STATE GRID ANHUI ELECTRIC POWER CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

During holidays and electricity promotion periods, Gaussian mixture models struggle to distinguish between normal and abnormal electricity consumption behaviors. Furthermore, spoofed electricity consumption behaviors can be disguised as normal ones, making it difficult to accurately identify malicious electricity consumption behaviors and increasing the difficulty of detection.

Method used

A power distribution network safety risk assessment system is adopted, including a data acquisition module, an anomaly analysis module, a scenario assessment module, and a feedback module. Through a hierarchical risk assessment process and a set of risk judgment thresholds, combined with a basic scenario association model, a Transformer deep learning model, and an enhanced abnormal behavior recognition model, multi-level risk assessment is carried out.

Benefits of technology

It improves the accuracy of risk assessment of electricity consumption behavior during special periods, accurately identifies disguised malicious electricity consumption behavior, and ensures the safety of the power distribution network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120975564B_ABST
    Figure CN120975564B_ABST
Patent Text Reader

Abstract

This invention relates to the field of power grid risk assessment technology, and discloses a distribution network safety risk assessment system and method. The system includes a data acquisition module, an anomaly analysis module, a scenario assessment module, and a feedback module. It collects user data from the distribution network, performs anomaly analysis on the user data to obtain anomaly data, then performs special scenario judgments on the anomaly data based on pre-collected environmental data, re-labels the anomaly data based on the judgment results of the special scenario judgments, and finally feeds back the re-labeled anomaly data to the power grid control terminal. This invention improves the accuracy of risk assessment of user electricity consumption behavior in the distribution network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power grid risk assessment technology, and in particular to a distribution network safety risk assessment system and method. Background Technology

[0002] In the operation of power systems, to effectively monitor user electricity consumption behavior, Gaussian mixture models of normal user behavior are often used to conduct anomaly analysis on user electricity consumption data, thereby identifying abnormal data. However, when dealing with special periods such as holidays and electricity promotions, the following shortcomings exist:

[0003] First, during holidays and electricity promotion periods, various commercial activities are frequently carried out, leading to a significant increase in user electricity load. Such normal electricity fluctuations can easily cause Gaussian mixture models to misjudge normal user data as abnormal data, failing to conduct special scenario judgments for abnormal data. In addition, some users exploit monitoring vulnerabilities in the distribution network, using highly covert methods such as falsifying distributed energy grid connection data and tampering with smart meter signals to disguise malicious electricity consumption as normal electricity consumption. Against the complex backdrop of continuously high electricity load during holidays, a large amount of normal high-load electricity data can interfere with the monitoring system. The lack of risk assessment for abnormal data makes it difficult to accurately identify such disguised behavior from massive amounts of data, increasing the difficulty of detection. Summary of the Invention

[0004] This invention provides a power distribution network safety risk assessment system and method, the main purpose of which is to solve the problem of low accuracy in risk assessment of electricity consumption behavior in power distribution networks.

[0005] To achieve the above objectives, the present invention provides a power distribution network safety risk assessment system, characterized in that the system comprises: a data acquisition module, an anomaly analysis module, a scenario assessment module, and a feedback module, wherein:

[0006] The data acquisition module is used to collect user data in the power distribution network;

[0007] The anomaly analysis module is used to perform anomaly analysis on the user data to obtain abnormal data;

[0008] The scenario assessment module is used to perform special scenario judgment on the abnormal data based on pre-collected environmental data, and to re-label the abnormal data based on the judgment result of the special scenario judgment.

[0009] If the judgment result indicates that the abnormal data is not in a special scenario, then the abnormal data is marked with a risk label.

[0010] If the judgment result indicates that the abnormal data is in a special scenario, then the hierarchical risk assessment process is entered. Based on the hierarchical risk assessment process and the preset risk judgment threshold set, the abnormal data is classified and risked to obtain the relabeled abnormal data. The hierarchical risk assessment process includes: basic risk assessment, joint risk assessment and enhanced analysis assessment.

[0011] The feedback module is used to send the re-marked abnormal data back to the power grid control terminal.

[0012] Optionally, the implementation steps of the basic risk assessment are as follows:

[0013] Based on a preset basic scenario association model, scenario analysis is performed on the abnormal data to obtain a basic scenario risk score. The basic scenario risk score is then numerically compared with the basic scenario risk thresholds in the risk judgment threshold set.

[0014] If the basic scenario risk score exceeds the basic scenario risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated.

[0015] If the basic scenario risk score does not exceed the basic scenario risk threshold, then proceed to the joint risk assessment.

[0016] Optionally, the step of performing scenario analysis on the abnormal data based on a preset basic scenario association model to obtain a basic scenario risk score includes:

[0017] Step 1: Obtain the basic scene set of the environmental data and the current scene of the abnormal data;

[0018] Step 2: Input the set of basic scenes into the basic scene association model, and calculate the association degree between the current scene and each basic scene. The formula for calculating the association degree is as follows:

[0019]

[0020] In the formula, Weights representing load similarity Weights representing differences in behavioral distribution. Weights representing spatiotemporal features Indicates load similarity. The Kourbak-Leibler divergence represents the probability distribution of attack behaviors. This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios Indicates the first The aforementioned basic scenarios. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Indicates time weighting, Indicates the regional weight. Indicates that the current scenario is related to the first The degree of relevance of the aforementioned basic scenarios;

[0021] The basic scene set is represented as follows: ;

[0022] In the formula, This represents the set of basic scenarios. This refers to the first basic scenario. This indicates the number of the basic scenarios;

[0023] Step 3: Select several basic scenarios similar to the current scenario, and calculate the risk score of each basic scenario by combining the historical risk values ​​and correlation of the basic scenarios. The calculation formula for the risk score of the basic scenario is as follows:

[0024]

[0025] In the formula, This indicates the risk score for the aforementioned basic scenario. This indicates the number of the selected basic scenarios with the highest relevance. Indicates that the current scenario is related to the first The degree of correlation between the aforementioned basic scenarios Indicates the first The historical risk values ​​of the aforementioned basic scenarios This indicates the identifier for the basic scene.

[0026] Optionally, the steps for implementing the joint risk assessment are as follows:

[0027] Based on the aforementioned basic scene association model and the preset abnormal behavior recognition model, the abnormal data is jointly analyzed to obtain a joint risk score. The joint risk score is then numerically compared with the joint risk thresholds in the risk judgment threshold set.

[0028] If the joint risk score exceeds the joint risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated.

[0029] If the joint risk score does not exceed the joint risk threshold, then proceed to the enhanced analysis and evaluation.

[0030] Optionally, the joint analysis of the abnormal data based on the basic scene association model and the preset abnormal behavior recognition model to obtain a joint risk score includes:

[0031] Step a: Extract and encode features from the anomalous data using the Transformer deep learning model to obtain a high-dimensional feature vector of the anomalous data:

[0032]

[0033] In the formula, This represents the high-dimensional feature vector. This indicates the abnormal data. This indicates that the Transformer deep learning model is used to extract and encode features from the abnormal data.

[0034] Step b: Calculate the Euclidean distance between the high-dimensional feature vector and the normal sample feature vector to obtain the abnormal behavior depth score, wherein the calculation formula for the abnormal behavior depth score is as follows:

[0035]

[0036] In the formula, This represents the feature vector of a normal sample. This represents the high-dimensional feature vector. This indicates the depth score of the abnormal behavior. This represents the norm of the difference between the normal sample feature vector and the high-dimensional feature vector;

[0037] Step c: Perform joint analysis on the basic scenario risk score and the abnormal behavior depth score to obtain a joint risk score, wherein the calculation formula for the joint risk score is as follows:

[0038]

[0039] In the formula, This indicates the risk score for the aforementioned basic scenario. This represents the normalized depth score of the abnormal behavior. Indicates the weighting coefficient. This refers to the joint risk score.

[0040] Optionally, the implementation steps of the enhanced analysis and evaluation are as follows:

[0041] The basic scene association model and the abnormal behavior recognition model are enhanced to obtain the enhanced scene association model and the enhanced abnormal behavior recognition model, respectively.

[0042] Based on the enhanced scenario association model, the abnormal data is subjected to enhanced scenario analysis to obtain an enhanced basic scenario risk score, and an enhanced abnormal behavior depth score is generated based on the enhanced abnormal behavior recognition model.

[0043] A joint analysis is performed on the enhanced basic scenario risk score and the enhanced abnormal behavior depth score to obtain an enhanced joint risk score. The enhanced joint risk score is then numerically compared with the enhanced joint threshold in the risk judgment threshold set.

[0044] If the enhanced joint risk score exceeds the enhanced joint threshold, the abnormal data will be marked with risk, and the graded risk determination will be terminated.

[0045] If the enhanced joint risk score does not exceed the enhanced joint threshold, the abnormal data is marked normally.

[0046] Optionally, the basic scenario association model is enhanced to obtain an enhanced scenario association model. Based on the enhanced scenario association model, enhanced scenario analysis is performed on the abnormal data to obtain an enhanced basic scenario risk score, including:

[0047] The weights of the load similarity, the behavior distribution difference, and the spatiotemporal feature are enhanced to obtain the enhanced weights of the load similarity, the behavior distribution difference, and the spatiotemporal feature, respectively.

[0048] The enhanced correlation degree is generated based on the weights of the enhanced load similarity, the weights of the enhanced behavior distribution differences, and the weights of the enhanced spatiotemporal features.

[0049] The formula for calculating the weight of the enhanced load similarity is as follows:

[0050]

[0051] In the formula, This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios This indicates that the variance of a given random variable is calculated. The weights representing the similarity of the enhanced loads;

[0052] The formula for calculating the weight of the enhanced behavior distribution difference is as follows:

[0053]

[0054] In the formula, The Kourbak-Leibler divergence represents the probability distribution of attack behaviors. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Represents the maximum value function. The weights representing the differences in the distribution of the enhanced behavior;

[0055] The formula for calculating the weights of the enhanced spatiotemporal features is as follows:

[0056]

[0057] In the formula, Indicates the first The aforementioned basic scenarios. Indicates time weighting, Indicates the regional weight. Represents the maximum value function. The weights represent the enhanced spatiotemporal features;

[0058] The formula for calculating the enhanced correlation degree is as follows:

[0059]

[0060] In the formula, The weights representing the similarity of the enhanced loads, The weights representing the differences in the distribution of the enhanced behavior are... The weights represent the enhanced spatiotemporal features. Indicates load similarity. The Kourbak-Leibler divergence represents the probability distribution of attack behaviors. This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios Indicates the first The aforementioned basic scenarios. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Indicates time weighting, Indicates the regional weight. This indicates the enhanced correlation degree;

[0061] Several basic scenarios similar to the current scenario are selected, and the historical risk values ​​and correlations of these basic scenarios are combined to calculate the enhanced basic scenario risk score. The calculation formula for the enhanced basic scenario risk score is as follows:

[0062]

[0063] In the formula, This represents the enhanced basic scenario risk score. This indicates the number of the selected basic scenarios with the highest relevance. This indicates the enhanced correlation. Indicates the first The historical risk values ​​of the aforementioned basic scenarios This indicates the identifier for the basic scene.

[0064] Optionally, the abnormal behavior recognition model is enhanced to obtain an enhanced abnormal behavior recognition model, and an enhanced abnormal behavior depth score is generated based on the enhanced abnormal behavior recognition model, including:

[0065] Based on the enhanced abnormal behavior recognition model, the abnormal data is subjected to feature enhancement and masking processing to obtain enhanced high-dimensional feature vectors. The enhanced abnormal behavior recognition model is a hybrid architecture of multi-head attention and CNN. The algorithm for generating the enhanced high-dimensional feature vectors is as follows:

[0066]

[0067] In the formula, This indicates that the Transformer deep learning model is used to extract and encode features from the abnormal data. This indicates that an attention mask is generated for the anomalous data. This indicates the abnormal data. Indicates to The output high-dimensional feature vector is subjected to local convolution operation. This represents the enhanced high-dimensional feature vector;

[0068] The Euclidean distance between the enhanced high-dimensional feature vector and the normal sample feature vector is calculated to obtain the enhanced abnormal behavior depth score.

[0069] Optionally, the formula for calculating the enhanced joint risk score is as follows:

[0070]

[0071] In the formula, This represents the enhanced basic scenario risk score. Indicates the weighting coefficient. This represents the normalized, enhanced depth score of the abnormal behavior. This indicates the enhanced joint risk score.

[0072] To address the above problems, the present invention also provides a method for assessing the safety risks of a power distribution network, the method comprising:

[0073] S1. Collect user data in the power distribution network;

[0074] S2. The user data is subjected to anomaly analysis to obtain abnormal data;

[0075] S3. Based on the pre-collected environmental data, perform special scenario judgment on the abnormal data, and re-mark the abnormal data based on the judgment result of the special scenario judgment:

[0076] S31. If the judgment result indicates that the abnormal data is not in a special scenario, then the abnormal data is marked with a risk label.

[0077] S32. If the judgment result indicates that the abnormal data is in a special scenario, then the hierarchical risk assessment process is entered. Based on the hierarchical risk assessment process and the preset risk judgment threshold set, the abnormal data is hierarchically risk judged to obtain the re-labeled abnormal data. The hierarchical risk assessment process includes: basic risk assessment, joint risk assessment and enhanced analysis assessment.

[0078] S4. Feed back the re-marked abnormal data to the power grid control terminal.

[0079] Compared with the prior art, the present invention has the following beneficial effects:

[0080] 1. This invention uses pre-collected environmental data to make special scenario judgments on abnormal data. During special periods such as holidays and electricity promotions, the power distribution network can identify these special scenarios and thus avoid directly misjudging high load electricity consumption data as abnormal data, thereby improving the accuracy of risk assessment of electricity consumption behavior during special periods.

[0081] 2. By employing a tiered risk assessment process and a set of risk judgment thresholds, the abnormal data is classified and risk-judged. The tiered risk assessment begins with a basic risk assessment, which analyzes the correlation between abnormal data and historical scenarios based on a basic scenario association model to preliminarily determine the risk. If the basic scenario risk score does not reach the basic scenario risk threshold, the assessment proceeds to the next level, avoiding misjudgment based on a single standard. The joint risk assessment combines an abnormal behavior identification model to comprehensively assess behavior and scenarios. Enhanced analysis and assessment further uncover data characteristics. The multi-level assessment is comprehensive and in-depth, accurately identifying malicious electricity use behaviors disguised by illegal users. The set of risk judgment thresholds is set based on historical data of the distribution network, equipment safety parameters, and industry standards, providing quantitative standards for each level of assessment. During the assessment, the calculated risk score is compared with the corresponding threshold, and the risk is judged based on the result, improving the accuracy of risk assessment of user electricity use behavior in the distribution network. Attached Figure Description

[0082] Figure 1 This is a system architecture diagram of a power distribution network safety risk assessment system provided in an embodiment of the present invention;

[0083] Figure 2 This is a flowchart illustrating a power distribution network safety risk assessment method provided in an embodiment of the present invention.

[0084] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0085] like Figure 1 The figure shown is a system architecture diagram of a power distribution network safety risk assessment system provided in an embodiment of the present invention.

[0086] The power distribution network safety risk assessment system 100 of this invention can be set up in a cloud server. In terms of implementation, it can be implemented as one or more service devices, or as an application installed in the cloud (e.g., a mobile service operator's server, server cluster, etc.), or it can be developed as a website. Depending on the functions implemented, the power distribution network safety risk assessment system 100 may include a data acquisition module 101, an anomaly analysis module 102, a scenario assessment module 103, and a feedback module 104. The module described in this invention can also be called a unit, which refers to a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.

[0087] In this embodiment of the invention, each of the above-mentioned modules in the distribution network safety risk assessment system can be implemented independently and can call other modules. Here, "calling" can be understood as one module connecting to multiple modules of another type and providing corresponding services to those connected modules. In the distribution network safety risk assessment system provided by this embodiment of the invention, the applicable scope of the distribution network safety risk assessment system architecture can be adjusted by adding modules and directly calling them without modifying the program code, achieving cluster-based horizontal expansion to quickly and flexibly expand the distribution network safety risk assessment system. In practical applications, the above-mentioned modules can be set in the same device or different devices, or they can be set in virtual devices, such as service instances in a cloud server.

[0088] The following describes the various components and specific workflow of the power distribution network security risk assessment system, using specific embodiments as examples:

[0089] The data acquisition module is used to collect user data in the power distribution network;

[0090] The user data includes real-time and historical electricity consumption data, power parameters, time-of-use statistics, electricity anomaly monitoring data, and the current scenario.

[0091] In detail, real-time electricity consumption data refers to the current electricity consumption information of users collected by the power system at a frequency of seconds or minutes through devices such as smart meters and sensors. Real-time electricity consumption data covers several important indicators: instantaneous power directly reflects the user's current electricity load, and through this data, the user's real-time electricity demand can be clearly understood; current and voltage waveforms are key evidence for detecting power quality problems, and can be used to keenly detect abnormal conditions such as harmonic distortion and voltage sag; power factor can effectively measure the user's electricity efficiency and provide support for assessing the rationality of electricity consumption; in addition, sudden increases or decreases in load may not only indicate equipment failures such as motor short circuits, but in some cases, there is also suspicion of data tampering.

[0092] In detail, time-of-use (TOU) statistics are collected through smart meters, data acquisition terminals, and related communication networks. TOU statistics, with their systematic data collection and analysis model, play an indispensable role in understanding user electricity consumption behavior, especially in identifying abnormal electricity usage data. The working mechanism of TOU statistics revolves around dividing the 24 hours of a day into three typical periods: peak, valley, and flat. Within this framework, the system comprehensively collects and statistically analyzes key data such as user electricity consumption and power consumption for each period. Through horizontal comparison and vertical analysis of this data, the system can clearly depict the user's electricity consumption patterns at different times, constructing a unique electricity consumption behavior model. When the data for a certain period deviates significantly from the model's norm, it can be quickly located, assisting the power department in promptly identifying potential problems such as electricity theft and abnormal electricity usage caused by equipment malfunctions.

[0093] In detail, abnormal electricity consumption monitoring data refers to data collected through real-time monitoring of various electrical parameters during a user's electricity usage process, identifying deviations from normal electricity consumption patterns. These parameters include power consumption, current, voltage, and power factor. For example, a significant jump or drop in power within a short period, current far exceeding the equipment's rated value, abnormal voltage fluctuations, and a power factor severely deviating from the reasonable range all fall under the category of abnormal electricity consumption monitoring data. Smart meters are the core devices for data acquisition. With their built-in sensors, they can collect key data such as voltage, current, and power at high frequency. Through established communication protocols, smart meters can transmit the collected data to a concentrator, achieving real-time data transmission. Furthermore, smart meters can identify and mark abnormal data based on user-preset thresholds, greatly improving the targeting of data collection. The electricity data management system stores long-term electricity consumption data, providing historical evidence for analyzing abnormal electricity consumption behavior. When an anomaly occurs, staff can retrieve historical data to deeply analyze the time, frequency, and trends of the anomaly, thereby determining whether the anomaly is sporadic or persistent, providing strong support for developing solutions.

[0094] The anomaly analysis module is used to perform anomaly analysis on the user data to obtain abnormal data;

[0095] In detail, the encrypted user data is decrypted to restore the original user data. Key features are extracted from the decrypted user data, including core dimensions such as electricity consumption during time periods, operation frequency, and electricity consumption behavior patterns. These features will serve as the basic input for subsequent analysis. The extracted key features are standardized to eliminate the influence of different units on the analysis results. All features are converted to a unified unit using methods such as Z-score to ensure that each feature has equal weight in the analysis.

[0096] Hierarchical clustering is an unsupervised machine learning method that groups user data with similar characteristics. Its specific implementation process is as follows:

[0097] Each user's data point is considered as an independent initial cluster. For example, if there are 1000 users in the system, the initial state is 1000 clusters.

[0098] Calculate the pairwise characteristic distances between all data points (using the Euclidean distance formula) to form an N×N symmetric distance matrix; find the two closest data points in the distance matrix (e.g., the distance between the electricity consumption patterns of user A and user B is 0.2, which is the minimum value in the entire field), and merge them into a new cluster AB;

[0099] The average linking method is used to recalculate the distance between the new cluster AB and all other clusters: for example, the distance between AB and user C = (the distance between A and C + the distance between B and C) / 2.

[0100] The algorithm continuously searches for the minimum distance in the current distance matrix and merges them. After each merge, the distance matrix is ​​updated. This process gradually forms a tree diagram. The merging process terminates when the minimum distance exceeds a set similarity threshold (e.g., 0.5).

[0101] For each cluster obtained through hierarchical clustering, statistics for the data points within it are calculated to obtain the basic attributes of each cluster. For example, for clusters ABC and D, the mean, median, standard deviation, and other statistics for their respective data points need to be calculated. These statistics can intuitively reflect the central tendency, dispersion, and other characteristics of the data within each cluster.

[0102] Based on the calculated cluster statistics and basic attributes, clusters that can represent normal user behavior are identified. The basis for identification is usually that the behavior patterns presented by these clusters conform to the regular electricity consumption characteristics of most users. After determining the normal behavior clusters, key features that can characterize normal electricity consumption behavior are extracted from them, such as the range of electricity power consumption in a specific time period and the peak and valley variation patterns of electricity consumption.

[0103] Using the key features and statistics obtained in the previous step, the parameters of the Gaussian mixture model are estimated. The Gaussian mixture model consists of multiple Gaussian distributions. By setting its parameters, the probability distribution of normal behavior patterns can be accurately described. Based on the characteristics of the normal behavior clustering data, the mean, covariance and other parameters of each Gaussian distribution are determined, thereby constructing a Gaussian mixture model of normal behavior.

[0104] The newly collected user data is analyzed using a Gaussian mixture model of normal behavior. The probability density value of these new data points under the Gaussian mixture model of each normal behavior cluster is calculated. This value reflects the degree of matching between the new data and the normal behavior pattern. The calculated probability density value is compared with a preset threshold. If the probability density value of the new data point under the Gaussian mixture model of all normal behavior clusters is less than or equal to the preset threshold, it indicates that the new data point differs significantly from the established normal behavior pattern. It can be marked as a potential abnormal behavior for further in-depth analysis and investigation.

[0105] The scenario assessment module is used to perform special scenario judgment on the abnormal data based on pre-collected environmental data, and to re-label the abnormal data based on the judgment result of the special scenario judgment.

[0106] If the judgment result indicates that the abnormal data is not in a special scenario, then the abnormal data is marked with a risk label.

[0107] If the judgment result indicates that the abnormal data is in a special scenario, then the hierarchical risk assessment process is entered. Based on the hierarchical risk assessment process and the preset risk judgment threshold set, the abnormal data is classified and risked to obtain the relabeled abnormal data. The hierarchical risk assessment process includes: basic risk assessment, joint risk assessment and enhanced analysis assessment.

[0108] In this embodiment of the invention, the specific process by which the scene evaluation module performs special scene judgment on the abnormal data based on pre-collected environmental data is as follows:

[0109] The scenario assessment module obtains data from multiple databases: on the one hand, it extracts the power distribution network data and the current scenario when the abnormal data occurs. The power distribution network data includes user power consumption, current, voltage, etc.; on the other hand, it collects the environmental data of the same period, such as time characteristics, and whether the user's area is a concentrated area of ​​commercial promotion activities. If the current scenario of the abnormal data shows that it is during an extreme holiday, and the user's area is a commercial center, and the power consumption increases significantly during the peak promotion period, then it is determined that the abnormal data is in an extreme holiday promotion scenario. It checks whether the fluctuation of the power consumption data of the abnormal data shows irregular characteristics and is too different from the power consumption pattern of users of the same type in the same area during similar time periods. If it meets the condition that "the fluctuation of power consumption data deviates from the average of users of the same type > the preset deviation threshold, and the time is during an extreme holiday, and the area is a concentrated area of ​​commercial promotion", then there may be user faking abnormal behavior.

[0110] In detail, because simple anomaly analysis of the user data cannot meet the needs of accurate judgment in special scenarios, the hierarchical risk assessment process aims to deeply analyze abnormal data, and through multi-dimensional and hierarchical assessment, give a more refined risk level, thereby improving the accuracy and pertinence of risk management and control of the power distribution network.

[0111] In this embodiment of the invention, the implementation steps of the basic risk assessment are as follows:

[0112] Based on a preset basic scenario association model, scenario analysis is performed on the abnormal data to obtain a basic scenario risk score. The basic scenario risk score is then numerically compared with the basic scenario risk thresholds in the risk judgment threshold set.

[0113] If the basic scenario risk score exceeds the basic scenario risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated.

[0114] If the basic scenario risk score does not exceed the basic scenario risk threshold, then proceed to the joint risk assessment.

[0115] In detail, the basic scenario risk threshold is a preset standard used to measure the basic scenario risk score in the basic risk assessment stage of the graded risk assessment process. It is a key indicator for determining whether abnormal data poses a risk. The basic scenario risk threshold is determined based on historical data accumulated from the long-term operation of the distribution network, the safe operating parameters of power equipment, and industry standards and regulations. For example, by analyzing a large amount of scenario data under normal and abnormal power consumption conditions, and comprehensively considering the risk probability under different scenarios, a value that can effectively distinguish between normal and risky scenarios is determined as the threshold.

[0116] In this embodiment of the invention, the step of performing scenario analysis on the abnormal data based on a preset basic scenario association model to obtain a basic scenario risk score includes:

[0117] Step 1: Obtain the basic scene set of the environmental data and the current scene of the abnormal data;

[0118] The basic scenario set refers to a set of representative basic scenarios predefined during the operation of the distribution network. The basic scenarios cover typical electricity consumption patterns and their corresponding environmental data (such as load surge ratio, abnormal behavior probability, spatiotemporal weight, etc.) for different time periods, special events (such as holidays, promotional activities), and regional characteristics (such as commercial areas, residential areas).

[0119] In detail, each basic scenario includes the following elements: historical load surge ratio, historical anomaly probability, and spatiotemporal weight.

[0120] Historical load surge ratio refers to the ratio of peak load to average load in a distribution network under a specific scenario, quantifying the degree of sudden increase in electricity load in that scenario.

[0121]

[0122] Peak load is obtained by selecting the maximum power value within the current time period from the real-time electricity consumption data collected by smart meters or SCADA systems; the average load is obtained by calculating the average power of all sampling points within the current time period.

[0123] In detail, the historical anomaly probability refers to the probability of abnormal electricity consumption behavior occurring in a specific scenario. The historical anomaly probability is based on historical data statistics and reflects the prevalence of abnormal behavior in that scenario.

[0124]

[0125] For example, Z-score analysis can be used to detect anomalies in user electricity consumption data (total data volume). If the probability density value of a data point is lower than the threshold, it is marked as abnormal data. Within the analysis time window (such as the past 24 hours), the amount of abnormal data is counted.

[0126] In detail, the spatiotemporal weight is used to quantify the influence of time weight and regional weight on electricity consumption behavior. It is set based on experience or data analysis. The spatiotemporal weight reflects the influence of specific time periods (such as holidays and nighttime) on electricity consumption behavior, while the regional weight reflects the differences in electricity consumption characteristics of different regions (such as commercial areas, industrial areas, and residential areas).

[0127] Step 2: Input the set of basic scenes into the basic scene association model, and calculate the association degree between the current scene and each basic scene. The formula for calculating the association degree is as follows:

[0128]

[0129] In the formula, Weights representing load similarity Weights representing differences in behavioral distribution. Weights representing spatiotemporal features Indicates load similarity. The Kourbak-Leibler divergence represents the probability distribution of attack behaviors. This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios Indicates the first The aforementioned basic scenarios. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Indicates time weighting, Indicates the regional weight. Indicates that the current scenario is related to the first The degree of relevance of the aforementioned basic scenarios;

[0130] The correlation is used to quantify the comprehensive similarity between the current scenario and historical scenarios in terms of load, attack behavior, and spatiotemporal dimensions, and to infer the risk of the current scenario through historical scenarios.

[0131] The basic scene set is represented as follows: ;

[0132] In the formula, This represents the set of basic scenarios. This refers to the first basic scenario. This indicates the number of the basic scenarios;

[0133] Step 3: Select several basic scenarios similar to the current scenario, and calculate the risk score of each basic scenario by combining the historical risk values ​​and correlation of the basic scenarios. The calculation formula for the risk score of the basic scenario is as follows:

[0134]

[0135] In the formula, This indicates the risk score for the aforementioned basic scenario. This indicates the number of the selected basic scenarios with the highest relevance. Indicates that the current scenario is related to the first The degree of correlation between the aforementioned basic scenarios Indicates the first The historical risk values ​​of the aforementioned basic scenarios This indicates the identifier for the basic scene.

[0136] For example, the basic scene set includes three basic scenes:

[0137]

[0138] Set the weights for load similarity ( The weight of the behavioral distribution difference is set to 0.4. The spatiotemporal feature weights are set to 0.3. The value is 0.3, and ;

[0139] Calculate the load surge ratio for the current scenario ( The current peak load is detected to be 1800kW, and the average load is 1000kW. ;

[0140] The probability of detecting abnormal behavior in the current scene is calculated as follows: The system records power once per minute, for a total of 60 times per hour. If nine of these records exceed 1500kW (a fixed threshold), the count is considered abnormal. ;

[0141] Based on the first basic scenario For example:

[0142]

[0143] Similarly, we can conclude that: , ;

[0144] Select the two most relevant basic scenarios, sort them, and then choose... and ;

[0145] Calculate the basic scenario risk score :

[0146]

[0147] The preset basic scenario risk threshold is 0.7. 0.648 is less than 0.7. Although it does not reach 0.7, the risk is relatively high. It may be malicious behavior disguised as normal electricity use. Therefore, it will enter the joint risk assessment.

[0148] In this embodiment of the invention, the steps for implementing the joint risk assessment are as follows:

[0149] Based on the aforementioned basic scene association model and the preset abnormal behavior recognition model, the abnormal data is jointly analyzed to obtain a joint risk score. The joint risk score is then numerically compared with the joint risk thresholds in the risk judgment threshold set.

[0150] If the joint risk score exceeds the joint risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated.

[0151] If the joint risk score does not exceed the joint risk threshold, then proceed to the enhanced analysis and evaluation.

[0152] In this embodiment of the invention, the step of jointly analyzing the abnormal data based on the basic scene association model and the preset abnormal behavior recognition model to obtain a joint risk score includes:

[0153] Step a: Extract and encode features from the anomalous data using the Transformer deep learning model to obtain a high-dimensional feature vector of the anomalous data:

[0154]

[0155] In the formula, This represents the high-dimensional feature vector. This indicates the abnormal data. This indicates that the Transformer deep learning model is used to extract and encode features from the abnormal data.

[0156] Step b: Calculate the Euclidean distance between the high-dimensional feature vector and the normal sample feature vector to obtain the abnormal behavior depth score, wherein the calculation formula for the abnormal behavior depth score is as follows:

[0157]

[0158] In the formula, This represents the feature vector of a normal sample. This represents the high-dimensional feature vector. This indicates the depth score of the abnormal behavior. This represents the norm of the difference between the normal sample feature vector and the high-dimensional feature vector;

[0159] Step c: Perform joint analysis on the basic scenario risk score and the abnormal behavior depth score to obtain a joint risk score, wherein the calculation formula for the joint risk score is as follows:

[0160]

[0161] In the formula, This indicates the risk score for the aforementioned basic scenario. This represents the normalized depth score of the abnormal behavior. Indicates the weighting coefficient. Used to balance scenario risks and behavioral anomalies This refers to the joint risk score.

[0162] For example, collecting feature vectors from normal samples Normal sample feature vector A 521-dimensional vector trained from historical normal data, a normal sample feature vector. for ;

[0163] Input the abnormal data into the Transformer deep learning model , Electricity power sequence, setting for ;

[0164] The Transformer deep learning model outputs a high-dimensional feature vector, which is... ;

[0165] Calculate the depth score of abnormal behavior :

[0166]

[0167] To ensure Values ​​in It is necessary to Normalization is performed to obtain the normalized abnormal behavior depth score, assuming... The historical maximum value is 5.0. The formula for calculating the normalized abnormal behavior depth score is as follows:

[0168] set up The score is 0.6, and the basic scenario risk score is obtained from the above steps. The joint risk score is approximately 0.65. :

[0169] The set joint risk threshold is 0.65. If 0.646 is less than 0.65, meaning the joint risk score fails to exceed the joint risk threshold, then the enhanced analysis and evaluation will proceed.

[0170] In this embodiment of the invention, the implementation steps of the enhanced analysis and evaluation are as follows:

[0171] The basic scene association model and the abnormal behavior recognition model are enhanced to obtain an enhanced scene association model and an enhanced abnormal behavior recognition model, respectively. The abnormal data are analyzed based on the enhanced scene association model to obtain an enhanced basic scene risk score. An enhanced abnormal behavior depth score is generated based on the enhanced abnormal behavior recognition model.

[0172] A joint analysis is performed on the enhanced basic scenario risk score and the enhanced abnormal behavior depth score to obtain an enhanced joint risk score. The enhanced joint risk score is then numerically compared with the enhanced joint threshold in the risk judgment threshold set.

[0173] If the enhanced joint risk score exceeds the enhanced joint threshold, the abnormal data will be marked with risk, and the graded risk determination will be terminated.

[0174] If the enhanced joint risk score does not exceed the enhanced joint threshold, the abnormal data is marked normally.

[0175] In this embodiment of the invention, the basic scenario association model is enhanced to obtain an enhanced scenario association model. Based on the enhanced scenario association model, enhanced scenario analysis is performed on the abnormal data to obtain an enhanced basic scenario risk score, including:

[0176] The weights of the load similarity, the behavior distribution difference, and the spatiotemporal feature are enhanced to obtain the enhanced weights of the load similarity, the behavior distribution difference, and the spatiotemporal feature, respectively.

[0177] The enhanced correlation degree is generated based on the weights of the enhanced load similarity, the weights of the enhanced behavior distribution differences, and the weights of the enhanced spatiotemporal features.

[0178] The formula for calculating the weight of the enhanced load similarity is as follows:

[0179]

[0180] In the formula, This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios This indicates that the variance of a given random variable is calculated. The weights representing the similarity of the enhanced loads;

[0181] The ratio of the variance of the current scenario load surge to the sum of the variances of all basic scenarios is used as the weight. The more significant the load fluctuation in the current scenario (the larger the variance), the higher the weight, highlighting abnormal load scenarios.

[0182] The formula for calculating the weight of the enhanced behavior distribution difference is as follows:

[0183]

[0184] In the formula, The Kourbak-Leibler divergence represents the probability distribution of attack behaviors. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Represents the maximum value function. The weights representing the differences in the distribution of the enhanced behavior;

[0185] The formula for calculating the weights of the enhanced spatiotemporal features is as follows:

[0186]

[0187] In the formula, Indicates the first The aforementioned basic scenarios. Indicates time weighting, Indicates the regional weight. Represents the maximum value function. The weights represent the enhanced spatiotemporal features;

[0188] By combining time and regional weights and normalizing them according to the basic scenario, we can integrate spatiotemporal features, strengthen the correlation between spatiotemporally adjacent scenarios, avoid the dominance of a single basic scenario, and balance the global contribution.

[0189] The formula for calculating the enhanced correlation degree is as follows:

[0190]

[0191] In the formula, The weights representing the similarity of the enhanced loads, The weights representing the differences in the distribution of the enhanced behavior are... The weights represent the enhanced spatiotemporal features. Indicates load similarity. The Kourbak-Leibler divergence represents the probability distribution of attack behaviors. This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios Indicates the first The aforementioned basic scenarios. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Indicates time weighting, Indicates the regional weight. This indicates the enhanced correlation degree;

[0192] Several basic scenarios similar to the current scenario are selected, and the historical risk values ​​and correlations of these basic scenarios are combined to calculate the enhanced basic scenario risk score. The calculation formula for the enhanced basic scenario risk score is as follows:

[0193]

[0194] In the formula, This represents the enhanced basic scenario risk score. This indicates the number of the selected basic scenarios with the highest relevance. This indicates the enhanced correlation. Indicates the first The historical risk values ​​of the aforementioned basic scenarios This indicates the identifier for the basic scene.

[0195] In detail, the enhanced scene association model improves the accuracy of identifying abnormal or critical scenes by dynamically adjusting the weights of the optimized model. The Kourbach-Leibler divergence is used to measure the information content of the difference between two probability distributions (such as the distribution of attack behavior), and the larger the value, the more significant the difference. The basic scene association model is upgraded to the enhanced scene association model to improve the accuracy of scene analysis.

[0196] For example, suppose we have the following basic scene set and current scene data:

[0197]

[0198] Current load surge ratio 1.8, the probability of abnormal behavior detected in the current scene. The variance of the load surge ratio in the current scenario is 0.15. The covariance of the historical load surge ratio in the basic scenario is 0.2. It is 0.5

[0199] Calculate the weights for the enhanced load similarity:

[0200] , , ;

[0201] Calculate the weights of the differences in behavior distribution after reinforcement:

[0202] Calculate the weights of the enhanced spatiotemporal features:

[0203] Taking the basic scenario S1 as an example, calculate its enhanced correlation degree:

[0204]

[0205] Similarly, calculation , .

[0206] Select the two most relevant basic scenarios, sort them, and then choose... and ;

[0207] Calculate the enhanced base scenario risk score:

[0208]

[0209] In this embodiment of the invention, the abnormal behavior recognition model is enhanced to obtain an enhanced abnormal behavior recognition model. Based on the enhanced abnormal behavior recognition model, an enhanced abnormal behavior depth score is generated, including:

[0210] Based on the enhanced abnormal behavior recognition model, the abnormal data is subjected to feature enhancement and masking processing to obtain enhanced high-dimensional feature vectors. The enhanced abnormal behavior recognition model is a hybrid architecture of multi-head attention and CNN. The algorithm for generating the enhanced high-dimensional feature vectors is as follows:

[0211]

[0212] In the formula, This indicates that the Transformer deep learning model is used to extract and encode features from the abnormal data. This indicates that an attention mask is generated for the anomalous data. This indicates the abnormal data. Indicates to The output high-dimensional feature vector is subjected to local convolution operation. This represents the enhanced high-dimensional feature vector;

[0213] The Euclidean distance between the enhanced high-dimensional feature vector and the normal sample feature vector is calculated to obtain the enhanced abnormal behavior depth score.

[0214] In detail, multi-head attention is a core component of Transformer. It captures the dependencies between different dimensions of data (such as temporal, spatial, and feature-related relationships) by computing multiple sets of attention weights in parallel. CNN (convolutional neural network) is used to extract local features (such as short-term fluctuation patterns in electricity consumption data) and enhance the model's sensitivity to abnormal details. Attention masking dynamically filters out irrelevant data (such as electricity consumption values ​​during normal periods) and focuses on abnormal periods or abnormal features. Euclidean distance is used to quantify the difference between abnormal data and normal samples. The larger the distance, the higher the probability of an anomaly.

[0215] For example, strengthening the input of abnormal behavior recognition models. for Collect feature vectors of normal samples Normal sample feature vector for ;

[0216] Transformer deep learning model Feature extraction and encoding are performed to obtain high-dimensional feature vectors: ;

[0217]

[0218] Generate mask:

[0219] Calculate the enhanced high-dimensional feature vector: ;

[0220] Calculate the enhanced Euclidean distance:

[0221] Normalizing the enhanced Euclidean distance yields the normalized enhanced anomalous behavior depth score: ;

[0222] In this embodiment of the invention, the calculation formula for the enhanced joint risk score is as follows:

[0223]

[0224] In the formula, This represents the enhanced basic scenario risk score. Indicates the weighting coefficient. This represents the normalized, enhanced depth score of the abnormal behavior. This indicates the enhanced joint risk score.

[0225] Used to adjust the proportion of reinforced scenario risk score and reinforced behavioral abnormality score in the reinforced joint risk score. The larger the value, the more dependent it is on scenario risks (such as holiday load patterns). A smaller value indicates a greater focus on behavioral anomalies (such as current harmonic distortion and data tampering). By analyzing a large number of historical cases, the contribution ratio of scenario risk and behavioral anomalies to real risk is calculated. If the system has extremely low tolerance for behavioral anomalies (such as electricity theft), the value needs to be reduced. To increase the weighting of abnormal behavior, if it is necessary to reduce false alarms (such as avoiding misjudging normal load during holidays), the weighting can be increased. It emphasizes the rationality of the scenario.

[0226] For example, setting The threshold for reinforcement is set to 0.64, and the reinforcement risk score is calculated as follows:

[0227]

[0228] The enhanced joint risk score is 0.6478, and the enhanced joint threshold is 0.64. Since 0.6478 is greater than 0.64, meaning the enhanced joint risk score exceeds the enhanced joint threshold, the abnormal data is marked as risk, and the graded risk assessment is terminated.

[0229] The feedback module is used to send the re-marked abnormal data back to the power grid control terminal.

[0230] In detail, the feedback module, as the final output link of the distribution network safety risk assessment system, bears the important responsibility of effectively transmitting the system analysis results to the power grid control terminal. Through standardized data interfaces and intelligent decision-making suggestion mechanisms, this module ensures that power grid operation and maintenance personnel can obtain risk information in a timely and accurate manner and take corresponding measures.

[0231] Reference Figure 2 The diagram shown is a flowchart illustrating a power distribution network safety risk assessment method according to an embodiment of the present invention. In this embodiment, the power distribution network safety risk assessment method includes:

[0232] S1. Collect user data in the power distribution network;

[0233] S2. Perform anomaly analysis on the user data to obtain abnormal data;

[0234] S3. Based on the pre-collected environmental data, perform special scenario judgment on the abnormal data, and re-mark the abnormal data based on the judgment result of the special scenario judgment:

[0235] S31. If the judgment result indicates that the abnormal data is not in a special scenario, then the abnormal data is marked with a risk label.

[0236] S32. If the judgment result indicates that the abnormal data is in a special scenario, then the hierarchical risk assessment process is entered. Based on the hierarchical risk assessment process and the preset risk judgment threshold set, the abnormal data is hierarchically risk judged to obtain the re-labeled abnormal data. The hierarchical risk assessment process includes: basic risk assessment, joint risk assessment and enhanced analysis assessment.

[0237] S4. Feed back the re-marked abnormal data to the power grid control terminal.

[0238] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0239] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0240] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A power distribution network safety risk assessment system, characterized in that, The system includes: a data acquisition module, an anomaly analysis module, a scene evaluation module, and a feedback module, wherein: The data acquisition module is used to collect user data in the power distribution network; The anomaly analysis module is used to perform anomaly analysis on the user data to obtain abnormal data; The scenario assessment module is used to perform special scenario judgment on the abnormal data based on pre-collected environmental data, and to re-label the abnormal data based on the judgment result of the special scenario judgment. If the judgment result indicates that the abnormal data is not in a special scenario, then the abnormal data is risk-marked, including: Extract the power distribution network data at the time the abnormal data occurred and the current scenario. The power distribution network data includes the user's power consumption, current, and voltage. If the current scenario of the abnormal data is an unusual date, and the user's location is a commercial center, and the power consumption increases significantly, then the abnormal data is determined to be in a special scenario. If the judgment result indicates that the abnormal data falls under a special scenario, then a tiered risk assessment process is initiated. Based on this process and a preset set of risk thresholds, the abnormal data is assessed for tiered risk to obtain relabeled abnormal data. The tiered risk assessment process includes: basic risk assessment, joint risk assessment, and enhanced analysis assessment, including: Based on a preset basic scenario association model, scenario analysis is performed on the abnormal data to obtain a basic scenario risk score. The basic scenario risk score is then numerically compared with the basic scenario risk thresholds in the risk judgment threshold set. If the basic scenario risk score exceeds the basic scenario risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated. If the basic scenario risk score does not exceed the basic scenario risk threshold, then proceed to the joint risk assessment; including: Based on the aforementioned basic scene association model and the preset abnormal behavior recognition model, the abnormal data is jointly analyzed to obtain a joint risk score. The joint risk score is then numerically compared with the joint risk thresholds in the risk judgment threshold set. If the joint risk score exceeds the joint risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated. If the joint risk score does not exceed the joint risk threshold, then proceed to the enhanced analysis and evaluation. The feedback module is used to send the re-marked abnormal data back to the power grid control terminal.

2. The power distribution network safety risk assessment system as described in claim 1, characterized in that, The abnormal data is analyzed based on a preset basic scenario association model to obtain a basic scenario risk score, including: Step 1: Obtain the basic scene set of the environmental data and the current scene of the abnormal data; Step 2: Input the set of basic scenes into the basic scene association model, and calculate the association degree between the current scene and each basic scene. The formula for calculating the association degree is as follows: In the formula, Weights representing load similarity Weights representing differences in behavioral distribution. Weights representing spatiotemporal features Indicates load similarity, The Kourbak-Leibler divergence represents the probability distribution of attack behavior. This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios Indicates the first The aforementioned basic scenarios. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Indicates time weight, Indicates the regional weight. Indicates that the current scenario is related to the first The degree of relevance of the aforementioned basic scenarios; The basic scene set is represented as follows: ; In the formula, This represents the set of basic scenarios. This refers to the first basic scenario. This indicates the number of the basic scenarios; Step 3: Select several basic scenarios similar to the current scenario, and combine them with the historical risk values ​​of the basic scenarios. and correlation Calculate the basic scenario risk score ,in, This indicates the risk score for the aforementioned basic scenario. Identifiers representing the basic scene. Indicates the first The historical risk values ​​of the aforementioned basic scenarios.

3. The power distribution network safety risk assessment system according to claim 1, characterized in that, The joint analysis of the abnormal data based on the basic scene association model and the preset abnormal behavior recognition model to obtain a joint risk score includes: Step a: Extract and encode features from the anomalous data using the Transformer deep learning model to obtain a high-dimensional feature vector of the anomalous data: In the formula, This represents the high-dimensional feature vector. This indicates the abnormal data. This indicates that the Transformer deep learning model is used to extract and encode features from the abnormal data. Step b: Calculate the Euclidean distance between the high-dimensional feature vector and the normal sample feature vector to obtain the abnormal behavior depth score, wherein the calculation formula for the abnormal behavior depth score is as follows: In the formula, This represents the feature vector of a normal sample. This represents the high-dimensional feature vector. This indicates the depth score of the abnormal behavior. This represents the norm of the difference between the normal sample feature vector and the high-dimensional feature vector; Step c: Perform joint analysis on the basic scenario risk score and the abnormal behavior depth score to obtain a joint risk score, wherein the calculation formula for the joint risk score is as follows: In the formula, This indicates the risk score for the aforementioned basic scenario. This represents the normalized depth score of the abnormal behavior. Indicates the weighting coefficient. This refers to the joint risk score.

4. The power distribution network safety risk assessment system according to claim 1, characterized in that, The steps for implementing the enhanced analysis and evaluation are as follows: The basic scene association model and the abnormal behavior recognition model are enhanced to obtain the enhanced scene association model and the enhanced abnormal behavior recognition model, respectively. Based on the enhanced scenario association model, the abnormal data is subjected to enhanced scenario analysis to obtain an enhanced basic scenario risk score, and an enhanced abnormal behavior depth score is generated based on the enhanced abnormal behavior recognition model. A joint analysis is performed on the enhanced basic scenario risk score and the enhanced abnormal behavior depth score to obtain an enhanced joint risk score. The enhanced joint risk score is then numerically compared with the enhanced joint threshold in the risk judgment threshold set. If the enhanced joint risk score exceeds the enhanced joint threshold, the abnormal data will be marked with risk, and the graded risk determination will be terminated. If the enhanced joint risk score does not exceed the enhanced joint threshold, the abnormal data is marked normally.

5. The power distribution network safety risk assessment system according to claim 2, characterized in that, The basic scenario association model is enhanced to obtain an enhanced scenario association model. Based on the enhanced scenario association model, enhanced scenario analysis is performed on the abnormal data to obtain an enhanced basic scenario risk score, including: The weights of the load similarity, the behavior distribution difference, and the spatiotemporal feature are enhanced to obtain the enhanced weights of the load similarity, the behavior distribution difference, and the spatiotemporal feature, respectively. The enhanced correlation degree is generated based on the weights of the enhanced load similarity, the weights of the enhanced behavior distribution differences, and the weights of the enhanced spatiotemporal features. The formula for calculating the weight of the enhanced load similarity is as follows: In the formula, This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios This indicates that the variance of a given random variable is calculated. The weights representing the similarity of the enhanced loads; The formula for calculating the weight of the enhanced behavior distribution difference is as follows: In the formula, The Kourbak-Leibler divergence represents the probability distribution of attack behavior. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Represents the maximum value function. The weights representing the differences in the distribution of the enhanced behavior; The formula for calculating the weights of the enhanced spatiotemporal features is as follows: In the formula, Indicates the first The aforementioned basic scenarios. Indicates time weight, Indicates the regional weight. Represents the maximum value function. The weights represent the enhanced spatiotemporal features; The formula for calculating the enhanced correlation degree is as follows: In the formula, The weights representing the similarity of the enhanced loads, The weights representing the differences in the distribution of the enhanced behavior are... The weights represent the enhanced spatiotemporal features. Indicates load similarity, The Kourbak-Leibler divergence represents the probability distribution of attack behavior. This indicates the load surge ratio in the current scenario. Indicates the first The historical load surge ratio of the aforementioned basic scenarios Indicates the first The aforementioned basic scenarios. This represents the probability of abnormal behavior detected in the current scene. Indicates the first The historical anomaly probability of each of the aforementioned basic scenarios. Indicates time weight, Indicates the regional weight. This indicates the enhanced correlation degree; Several basic scenarios similar to the current scenario are selected, and the historical risk values ​​and correlations of these basic scenarios are combined to calculate the enhanced basic scenario risk score. The calculation formula for the enhanced basic scenario risk score is as follows: In the formula, This represents the enhanced basic scenario risk score. This indicates the number of the selected basic scenarios with the highest relevance. This indicates the enhanced correlation. Indicates the first The historical risk values ​​of the aforementioned basic scenarios This indicates the identifier for the basic scene.

6. The power distribution network safety risk assessment system according to claim 4, characterized in that, The abnormal behavior recognition model is enhanced to obtain an enhanced abnormal behavior recognition model. Based on the enhanced abnormal behavior recognition model, an enhanced abnormal behavior depth score is generated, including: Based on the enhanced abnormal behavior recognition model, the abnormal data is subjected to feature enhancement and masking processing to obtain enhanced high-dimensional feature vectors. The enhanced abnormal behavior recognition model is a hybrid architecture of multi-head attention and CNN. The algorithm for generating the enhanced high-dimensional feature vectors is as follows: In the formula, This indicates that the Transformer deep learning model is used to extract and encode features from the abnormal data. This indicates that an attention mask is generated for the anomalous data. This indicates the abnormal data. Indicates to The output high-dimensional feature vector is subjected to local convolution operation. This represents the enhanced high-dimensional feature vector; The Euclidean distance between the enhanced high-dimensional feature vector and the normal sample feature vector is calculated to obtain the enhanced abnormal behavior depth score.

7. The power distribution network safety risk assessment system according to claim 4, characterized in that, The formula for calculating the enhanced joint risk score is as follows: In the formula, This represents the enhanced basic scenario risk score. Indicates the weighting coefficient. This represents the normalized, enhanced depth score of the abnormal behavior. This refers to the enhanced joint risk score.

8. A method for assessing the safety risks of a power distribution network, characterized in that, The method includes: S1. Collect user data in the power distribution network; S2. The user data is subjected to anomaly analysis to obtain abnormal data; S3. Based on the pre-collected environmental data, perform special scenario judgment on the abnormal data, and re-mark the abnormal data based on the judgment result of the special scenario judgment: S31. If the judgment result indicates that the abnormal data is not in a special scenario, then the abnormal data is risk-marked, including: Extract the power distribution network data at the time the abnormal data occurred and the current scenario. The power distribution network data includes the user's power consumption, current, and voltage. If the current scenario of the abnormal data is an unusual date, and the user's location is a commercial center, and the power consumption increases significantly, then the abnormal data is determined to be in a special scenario. S32. If the judgment result indicates that the abnormal data is in a special scenario, then the hierarchical risk assessment process is initiated. Based on the hierarchical risk assessment process and a preset set of risk judgment thresholds, the abnormal data is subjected to hierarchical risk judgment to obtain relabeled abnormal data. The hierarchical risk assessment process includes: basic risk assessment, joint risk assessment, and enhanced analysis assessment, including: Based on a preset basic scenario association model, scenario analysis is performed on the abnormal data to obtain a basic scenario risk score. The basic scenario risk score is then numerically compared with the basic scenario risk thresholds in the risk judgment threshold set. If the basic scenario risk score exceeds the basic scenario risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated. If the basic scenario risk score does not exceed the basic scenario risk threshold, then proceed to the joint risk assessment; including: Based on the aforementioned basic scene association model and the preset abnormal behavior recognition model, the abnormal data is jointly analyzed to obtain a joint risk score. The joint risk score is then numerically compared with the joint risk thresholds in the risk judgment threshold set. If the joint risk score exceeds the joint risk threshold, the abnormal data will be marked as risk and the risk classification process will be terminated. If the joint risk score does not exceed the joint risk threshold, then proceed to the enhanced analysis and evaluation. S4. Feed back the re-marked abnormal data to the power grid control terminal.

Citation Information

Patent Citations

  • Service scene disposal risk evaluation method and system for power monitoring system

    CN111723367A

  • Power grid risk assessment method and assessment system

    CN115456410A

Cited By

  • A power distribution network power supply safety risk management system and method

    CN122509669A