Abnormal event tracing method and device of power system, computer equipment, storage medium and computer program product

By combining the isolated forest algorithm and Gaussian mixture model with the power system topology, efficient source tracing of abnormal events in the power grid system is achieved, solving the problem of anomaly identification and handling in the power grid system, and improving fault response speed and system stability.

CN120975964APending Publication Date: 2025-11-18CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511082915.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

When faced with complex anomalies, existing power grid systems struggle to accurately identify the source and propagation path of problems, resulting in an inability to handle abnormal events in a timely and effective manner.

Method used

An isolated forest algorithm and Gaussian mixture model are used to detect and trace anomalies in the power system's operating status dataset. By combining the power system topology, abnormal power equipment is identified and the source of abnormal events is traced.

Benefits of technology

It improves the fault detection rate and response speed, accurately identifies the source of anomalies, limits the scope of faults, and enhances the stability and reliability of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120975964A_ABST
    Figure CN120975964A_ABST
Patent Text Reader

Abstract

The invention relates to an abnormal event tracing method and device of a power system, computer equipment, a storage medium and a computer program product. The method comprises the following steps: acquiring an operation state data set of a power system under the condition of receiving abnormal alarm information sent by a power monitoring system; performing anomaly detection on the operation state data set by adopting an isolated forest algorithm to obtain a candidate abnormal operation state data set; inputting the candidate abnormal operation state data set into a Gaussian mixture model to determine target abnormal operation state data in the candidate abnormal operation state data set; performing association mapping on the target abnormal operation state data and the topological structure of the power system, determining abnormal power equipment corresponding to the target abnormal operation state data, and obtaining time sequence data of the abnormal power equipment; and tracing the abnormal event based on the time sequence data of each abnormal power device, and generating an abnormal event tracing result. By adopting the method, the abnormity of the power grid system can be efficiently processed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power distribution network technology, and in particular to a method, apparatus, computer equipment, storage medium and computer program product for tracing abnormal events in a power system. Background Technology

[0002] As the scale and complexity of power grid systems continue to expand, ensuring their stable operation becomes increasingly challenging.

[0003] Currently, power grid monitoring systems often rely on simple threshold alarm mechanisms. However, this approach struggles to effectively identify complex anomalies, especially in the face of fluctuating environmental conditions and load variations. When anomalies occur, it is also difficult to accurately pinpoint the exact source of the problem or determine its propagation path, leading to a failure to address abnormal events promptly and effectively.

[0004] Therefore, traditional technologies have the problem of being unable to efficiently handle anomalies in the power grid system. Summary of the Invention

[0005] Therefore, it is necessary to provide a method, apparatus, computer equipment, computer-readable storage medium, and computer program product for tracing abnormal events in a power system that can efficiently handle anomalies in the power grid system, addressing the aforementioned technical problems.

[0006] A method for tracing the source of abnormal events in a power system, the method comprising:

[0007] Upon receiving an abnormal alarm message from the power monitoring system, the system acquires the power system's operational status dataset. The operational status dataset includes parameter data for multiple operational status dimensions corresponding to each timestamp.

[0008] The isolated forest algorithm is used to detect anomalies in the runtime state dataset to obtain a candidate abnormal runtime state dataset.

[0009] The candidate abnormal running state dataset is input into the Gaussian mixture model to determine the target abnormal running state data in the candidate abnormal running state dataset;

[0010] The target abnormal operating status data is associated and mapped with the power system topology to determine the abnormal power equipment corresponding to the target abnormal operating status data and obtain the time series data of the abnormal power equipment.

[0011] The abnormal events are traced back to their source based on the time series data of each abnormal power device, and the abnormal event tracing results are generated; the abnormal event tracing results include the abnormal situation of the source power device.

[0012] In one embodiment, the candidate abnormal running state dataset is input into a Gaussian mixture model to determine the target abnormal running state data from the candidate abnormal running state dataset, including:

[0013] The candidate abnormal running state dataset is input into the Gaussian mixture model, and the probability that each candidate abnormal running state data in the candidate abnormal running state dataset belongs to normal data is determined by the Gaussian mixture model.

[0014] Candidate abnormal operating state data with a probability of belonging to normal data below a preset threshold are identified as target abnormal operating state data.

[0015] In one embodiment, the abnormal operating state data of the target is mapped to the power system topology to determine the abnormal power equipment corresponding to the abnormal operating state data, including:

[0016] Retrieve topology information corresponding to the power system topology from the power system topology database; the topology information includes the equipment identifier of each power device.

[0017] The device identifier corresponding to the target abnormal operating status data is matched with the device identifier of each power device to identify the abnormal power device among the power devices.

[0018] In one embodiment, the abnormal event is traced based on the time-series data of each abnormal power device, generating an abnormal event tracing result, including:

[0019] For any abnormal power device, trace back the time series data of the abnormal power device to determine the timestamp of the first occurrence of the abnormality, and use it as the target timestamp.

[0020] The source power equipment is determined based on the parameter data of each power equipment under each operating status dimension corresponding to the target timestamp;

[0021] If the current abnormal operating mode of the source power equipment matches any historical abnormal operating mode of the source power equipment, the time series data of the source power equipment is compared with the time series data of adjacent power equipment to determine whether the abnormality was triggered by the source power equipment; adjacent power equipment refers to the power equipment that is adjacent to the source power equipment.

[0022] If the anomaly is determined to be triggered by a source power device, the anomaly details of the source power device are determined to generate anomaly event tracing results.

[0023] In one embodiment, the method further includes:

[0024] Construct a power flow calculation model for power systems;

[0025] For any source power equipment, the power flow calculation model is used to simulate the operating state of the power system when an abnormal situation occurs in the source power equipment, and the power flow calculation data is obtained.

[0026] Based on power flow calculation data and time series data of source power equipment, the propagation path of anomalies of source power equipment is determined in the power system topology.

[0027] In one embodiment, the method further includes:

[0028] The power system topology diagram in the monitoring interface of the power monitoring system displays the identifiers of the source power equipment;

[0029] In response to a triggered operation targeting the identifier of a source power device in the power system topology diagram, the abnormal propagation path of the source power device is displayed in the power system topology diagram.

[0030] An abnormal event tracing device for a power system, the device comprising:

[0031] The acquisition module is used to acquire the power system's operating status dataset when it receives abnormal alarm information from the power monitoring system; the operating status dataset includes parameter data under multiple operating status dimensions corresponding to each timestamp;

[0032] The detection module is used to perform anomaly detection on the runtime state dataset using the isolated forest algorithm to obtain a candidate abnormal runtime state dataset.

[0033] The determination module is used to input the candidate abnormal running state dataset into the Gaussian mixture model in order to determine the target abnormal running state data in the candidate abnormal running state dataset;

[0034] The association module is used to associate and map the target abnormal operating status data with the power system topology, determine the abnormal power equipment corresponding to the target abnormal operating status data, and obtain the time series data of the abnormal power equipment.

[0035] The source tracing module is used to trace the source of abnormal events based on the time series data of each abnormal power device and generate abnormal event source tracing results; the abnormal event source tracing results include the abnormal situation of the source power device.

[0036] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described above.

[0037] A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method described above.

[0038] A computer program product includes a computer program that, when executed by a processor, implements the steps of the method described above.

[0039] The aforementioned methods, devices, computer equipment, storage media, and computer program products for tracing abnormal events in power systems acquire a power system operation status dataset upon receiving abnormal alarm information from a power monitoring system. This operation status dataset includes parameter data across multiple operation status dimensions corresponding to various timestamps. An isolated forest algorithm is used to detect anomalies in the operation status dataset, resulting in a candidate abnormal operation status dataset. This candidate abnormal operation status dataset is then input into a Gaussian mixture model to identify target abnormal operation status data within the dataset. Finally, the target abnormal operation status data is mapped to the power system topology to determine the abnormal power equipment corresponding to the target abnormal operation status data, thus identifying the abnormal operation status. Time-series data of power equipment; based on the time-series data of each abnormal power equipment, the abnormal events are traced to their source, generating abnormal event tracing results; the abnormal event tracing results include the abnormal situation of the source power equipment; thus, by using the isolated forest algorithm to perform initial anomaly detection on the operating status dataset, and using the Gaussian mixture model for further anomaly detection, compared with the traditional threshold alarm mechanism, it can more accurately and quickly identify complex abnormal situations, greatly improving the fault detection rate and response speed. At the same time, combined with the power system topology, it can accurately identify the source of the anomaly and accurately trace its origin, which helps to take targeted measures to limit the scope of the fault, prevent larger-scale power outages, and improve the stability and reliability of the power system. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0041] Figure 1 This is an application environment diagram of an abnormal event tracing method for a power system in one embodiment;

[0042] Figure 2 This is a flowchart illustrating an abnormal event tracing method for a power system in one embodiment;

[0043] Figure 3 This is a flowchart illustrating an abnormal event tracing method for a power system in another embodiment;

[0044] Figure 4This is a structural block diagram of an abnormal event tracing device for a power system in one embodiment;

[0045] Figure 5 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0046] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0047] The abnormal event tracing method for power systems provided in this application embodiment can be applied to, for example... Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or placed on a cloud or other network server. Upon receiving an anomaly alarm from the power monitoring system, server 104 acquires the power system's operating status dataset; the operating status dataset includes parameter data under multiple operating status dimensions corresponding to each timestamp; server 104 uses the isolated forest algorithm to perform anomaly detection on the operating status dataset, obtaining candidate abnormal operating status datasets; server 104 inputs the candidate abnormal operating status datasets into a Gaussian mixture model to determine the target abnormal operating status data from the candidate abnormal operating status datasets; server 104 associates and maps the target abnormal operating status data with the power system topology to determine the abnormal power equipment corresponding to the target abnormal operating status data, and acquires the time series data of the abnormal power equipment; server 104 traces the source of the abnormal event based on the time series data of each abnormal power equipment, generating anomaly event tracing results; the anomaly event tracing results include the abnormal situation of the source power equipment. The terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, and smart in-vehicle systems. Portable wearable devices can include smartwatches, smart bracelets, and head-mounted devices. The server 104 can be implemented using a standalone server or a server cluster consisting of multiple servers.

[0048] In one exemplary embodiment, such as Figure 2 As shown, a method for tracing the source of abnormal events in a power system is provided, which can be applied to... Figure 1 Taking server 104 as an example, the explanation includes the following steps S202 to S210. Wherein:

[0049] Step S202: Upon receiving an abnormal alarm message from the power monitoring system, obtain the power system's operating status dataset; the operating status dataset includes parameter data under multiple operating status dimensions corresponding to each timestamp.

[0050] Among them, the power monitoring system can refer to a system that monitors the operating status of the power system and has anomaly alarm functions.

[0051] Among them, abnormal alarm information can refer to the abnormal alarm icon flashing on the interface of the power monitoring system, or it can refer to the abnormal alarm prompt sound issued by the power monitoring system.

[0052] The power system can include various power equipment such as substations, transmission lines, and distribution stations.

[0053] The operational status dataset can include operational status data of different power equipment at different historical time points. The operational status data of any power equipment at any historical time point includes parameter data of the power equipment under multiple operational status parameter dimensions at that historical time point. The historical time point can correspond to a timestamp.

[0054] In practical applications, the initial operating status dataset needs to be preprocessed to obtain the operating status dataset. The preprocessing process is as follows: The initial operating status dataset undergoes noise filtering and missing value repair. A sliding window mean filter is used to eliminate transient interference, and missing data is filled using linear interpolation to obtain the repaired operating status dataset. The repaired operating status dataset is then normalized by eliminating dimensional differences based on the Z-score algorithm and scaling the data to a uniform range to obtain the normalized operating status dataset. Detection features are extracted from the normalized operating status dataset (time-series dataset), including extracting frequency domain features (such as fundamental frequency components, harmonic components, and spectral energy) from voltage and current time-series data using Fast Fourier Transform, and calculating statistical features within the sliding window (such as mean, variance, maximum, and minimum values) to obtain a statistical feature dataset. The statistical feature dataset is then associated with the power grid topology information, the data stream is segmented by fixed duration, and a device ID, timestamp, and topology level label are added to each data block.

[0055] The above-mentioned calculation of statistical characteristics within a sliding window involves setting a fixed-length sliding window and moving the time series data point by point, calculating the statistical characteristics within each window, such as mean, variance, maximum value, and minimum value. By observing the changes in these statistical characteristics, the time points and trends of anomalies can be identified. For example, assuming the window length is set to 10 data points, for the current data series [10A, 12A, 13A, 11A, 10A, 9A, 8A, 7A, 6A, 5A], the mean of the sliding window is (10+12+13+11+10+9+8+7+6+5) / 10=9.3A; the variance can be obtained using the variance calculation formula, reflecting the degree of data fluctuation within the window; the maximum value is 13A, and the minimum value is 5A. These statistical characteristics can describe the state characteristics of the current within this time window from different perspectives.

[0056] The aforementioned association of statistical feature datasets with power grid topology information involves segmenting data streams according to fixed time intervals and adding device IDs, timestamps, and topology level tags to each data block. This means matching and associating data collected by smart sensors with topology information stored in the power grid topology database, such as the devices, their connections, and hierarchical structures, based on the device IDs corresponding to the sensor installation locations. For example, a dataset might contain temperature, current, and voltage data for transformer T1 in substation 1. After processing, this data is segmented into several data blocks in one-minute intervals. Each data block is labeled with a device ID (T1), a timestamp (e.g., 2024-01-01 08:00:00 - 08:01:00), and a topology level tag (identifying the level of T1 within substation 1 and its connection locations with upstream and downstream devices), thus achieving a correlation between the data and the power grid topology.

[0057] Among them, the operating status dimension can refer to indicators such as temperature, voltage, and current that characterize the operating status of power equipment.

[0058] Among them, the parameter data in the operating status dimension can refer to the temperature value in the temperature dimension, the voltage value in the voltage dimension, or the current value in the current dimension, etc.

[0059] Optionally, when the server receives an abnormal alarm message from the power monitoring system, it can obtain the operating status dataset collected by the smart sensors deployed in the power system. The operating status dataset may include the temperature, voltage, and current values ​​of different power equipment at various historical time points.

[0060] Step S204: The isolated forest algorithm is used to detect anomalies in the running status dataset to obtain a candidate abnormal running status dataset.

[0061] Among them, the Isolation Forest algorithm is an unsupervised machine learning algorithm for anomaly detection. Its basic principle is based on the idea of ​​random forest. It divides the data space by randomly selecting features and random feature values, thereby constructing multiple isolation trees. In the process of constructing isolation trees, normal points usually require more partitioning steps to be isolated, while outlier points, due to their sparsity, are isolated in fewer partitioning steps.

[0062] The candidate abnormal operating state dataset can include multiple candidate abnormal operating state data. These candidate abnormal operating state data are initially determined using the Isolation Forest algorithm. The target abnormal operating state data in step S206 is the final abnormal operating state data determined by further judging the candidate abnormal operating state data using a Gaussian mixture model. In practical applications, the candidate abnormal operating state data or the target abnormal operating state data can include device ID, timestamp, and abnormal indicators (such as specific abnormal values ​​for temperature, current, and voltage).

[0063] Optionally, the server uses the isolated forest algorithm to perform preliminary anomaly detection on the runtime status dataset to obtain a candidate abnormal runtime status dataset.

[0064] In practical applications, step S204 is implemented as follows:

[0065] To construct an isolated forest model, multiple isolated trees are generated by randomly partitioning the feature space. Specifically, this involves: randomly selecting a feature and a split point obtained from the data processing module to divide the dataset into two subsets; recursively repeating the above steps until each subset contains only one sample or reaches the predetermined tree height; and repeating the above steps to construct multiple random binary trees, i.e., a forest.

[0066] Based on the preprocessed running status dataset, the path length of each data point is calculated, and an anomaly score is generated based on the path length. Specifically, this includes: for each data point, calculating its path length in each isolated tree, where the data point represents the extracted feature; calculating the average path length in all isolated trees; generating an anomaly score based on the average path length; the anomaly score has a range of (0, 1), and the smaller the path length, the closer the anomaly score is to 1, indicating that the data point is more likely to be an anomaly.

[0067] Set an abnormal score threshold, and mark data with abnormal scores exceeding the abnormal score threshold as candidate abnormal running status data, and output the candidate abnormal running status data and its timestamp.

[0068] Step S206: Input the candidate abnormal running state dataset into the Gaussian mixture model to determine the target abnormal running state data in the candidate abnormal running state dataset.

[0069] Among them, Gaussian Mixture Model (GMM) is a clustering algorithm based on a probability model.

[0070] Optionally, the server inputs the candidate abnormal running state dataset into the Gaussian mixture model to determine the target abnormal running state data from the candidate abnormal running state dataset.

[0071] Step S208: Associate and map the target abnormal operating status data with the power system topology to determine the abnormal power equipment corresponding to the target abnormal operating status data and obtain the time series data of the abnormal power equipment.

[0072] Among them, the power system topology represents the connection relationship between different power devices in the power system.

[0073] The abnormal power equipment corresponding to the target abnormal operating status data can refer to the power equipment to which the target abnormal operating status data belongs. For example, when the target abnormal operating status data is the current value corresponding to equipment 1, the abnormal power equipment can be identified as equipment 1.

[0074] Among them, the time series data of abnormal power equipment can refer to the historical time series data corresponding to the target abnormal operating status data of abnormal power equipment. For example, when the abnormal power equipment is equipment 1 and the target abnormal operating status data is the current value of equipment 1 at timestamp A, the time series data of abnormal power equipment is the current series data of equipment 1 before timestamp A.

[0075] Optionally, the server associates and maps the target abnormal operating status data with the power system topology to determine the abnormal power equipment corresponding to the target abnormal operating status data and obtains the time series data of the abnormal power equipment.

[0076] Step S210: Based on the time series data of each abnormal power device, trace the source of the abnormal event and generate the abnormal event tracing result; the abnormal event tracing result includes the abnormal situation of the source power device.

[0077] The results of abnormal event tracing can include the source power equipment that was ultimately identified as causing the abnormality in the power system and thus triggering the abnormal alarm information, as well as the specific abnormal situation of that source power equipment.

[0078] Among them, the source power equipment can refer to the power equipment that causes the power system abnormality. The source power equipment may be abnormal or not. When the source power equipment is not abnormal, it refers to the power equipment that affects the operating status of the abnormal power equipment. Starting from the time series data of the abnormal power equipment, the source power equipment can be located.

[0079] Among them, abnormal conditions of source power equipment can refer to the abnormal type of the source power equipment, such as abnormal current, abnormal voltage, or abnormal temperature.

[0080] Optionally, the server traces the source of the abnormal event based on the time-series data of each abnormal power device, and generates the abnormal event tracing result, that is, determines the source power device that caused the abnormality.

[0081] In the aforementioned method for tracing the source of abnormal events in a power system, upon receiving an abnormal alarm message from the power monitoring system, the operating status dataset of the power system is obtained. This dataset includes parameter data across multiple operating status dimensions corresponding to each timestamp. An isolated forest algorithm is used to detect anomalies in the operating status dataset, resulting in a candidate abnormal operating status dataset. This candidate abnormal operating status dataset is then input into a Gaussian mixture model to identify the target abnormal operating status data. Finally, the target abnormal operating status data is mapped to the power system topology to determine the corresponding abnormal power equipment, and the time-series data of the abnormal power equipment is obtained. Based on the time-series data of each abnormal power device, the abnormal events are traced to their source, generating abnormal event tracing results. The abnormal event tracing results include the abnormal conditions of the source power device. Thus, by using the isolated forest algorithm for initial anomaly detection on the operating status dataset and using a Gaussian mixture model for further anomaly detection, compared with the traditional threshold alarm mechanism, complex anomalies can be identified more accurately and quickly, greatly improving the fault detection rate and response speed. At the same time, combined with the power system topology, the source of the anomaly can be accurately identified and traced accurately, which helps to take targeted measures to limit the scope of the fault, prevent larger-scale power outages, and improve the stability and reliability of the power system.

[0082] In an exemplary embodiment, the candidate abnormal running state dataset is input into a Gaussian mixture model to determine the target abnormal running state data in the candidate abnormal running state dataset, including: inputting the candidate abnormal running state dataset into a Gaussian mixture model, determining the probability that each candidate abnormal running state data in the candidate abnormal running state dataset belongs to normal data through the Gaussian mixture model; and determining the candidate abnormal running state data whose probability of belonging to normal data is lower than a preset threshold as the target abnormal running state data.

[0083] The preset threshold can be set according to actual needs; for example, it can be set to 0.4.

[0084] Optionally, after selecting candidate abnormal operating state datasets using the isolated forest algorithm, the server inputs the candidate abnormal operating state datasets into a Gaussian mixture model. The Gaussian mixture model determines the probability that each candidate abnormal operating state data in the candidate abnormal operating state dataset belongs to normal data, and the candidate abnormal operating state data whose probability of belonging to normal data is lower than a preset threshold is identified as the target abnormal operating state data.

[0085] In this embodiment, by inputting the candidate abnormal operating state dataset into a Gaussian mixture model, the probability that each candidate abnormal operating state data in the candidate abnormal operating state dataset belongs to normal data is determined by the Gaussian mixture model; candidate abnormal operating state data whose probability of belonging to normal data is lower than a preset threshold is determined as target abnormal operating state data; in this way, abnormal operating state data can be further filtered out based on the probability distribution characteristics of the data, making the anomaly detection more accurate.

[0086] In an exemplary embodiment, associating and mapping target abnormal operating status data with power system topology to determine the abnormal power equipment corresponding to the target abnormal operating status data includes: obtaining topology information corresponding to the power system topology from a power system topology database; the topology information includes the equipment identifier of each power equipment; matching the equipment identifier corresponding to the target abnormal operating status data with the equipment identifier of each power equipment to determine the abnormal power equipment among the power equipment.

[0087] The power system topology database stores topology information such as the connection relationships and hierarchical structure between power equipment.

[0088] Optionally, the server obtains the topology information corresponding to the power system topology from the power system topology database, matches the device identifier corresponding to the target abnormal operating status data with the device identifier of each power device, thereby identifying the abnormal power device.

[0089] In practical applications, the server retrieves the connection relationships and hierarchical structure (including topology information such as substations, transmission lines, and distribution equipment) between power devices from the power system topology database; it matches the device IDs in the target abnormal operating status data with the device IDs in the topology structure to determine the abnormal power devices corresponding to the target abnormal operating status data; based on the matching results, it uses a graph algorithm to traverse the power system topology structure to determine the specific location of the abnormal device node in the power grid; it marks the determined abnormal device nodes and records their hierarchy and connection relationships in the topology structure.

[0090] During the association mapping process, the device connection relationships and hierarchical structure are first obtained from the power grid topology database. Then, the device IDs in the target abnormal operating status data are compared and matched with the device IDs in the topology structure to determine the device node corresponding to the target abnormal operating status data. For example, if the device ID in the target abnormal operating status data is "Line Tower L2-3", after matching with the power system topology structure, it is determined that it corresponds to the 3rd line tower node on transmission line No. 2, thus clarifying the specific location where the anomaly occurred.

[0091] In this embodiment, topology information corresponding to the power system topology is obtained from the power system topology database. The topology information includes the device identifier of each power device. The device identifier corresponding to the target abnormal operating status data is matched with the device identifier of each power device to identify the abnormal power device. In this way, when an anomaly occurs, the target abnormal operating status data can be accurately associated with the specific power device, thereby quickly identifying the specific abnormal device, providing a clear target for subsequent fault handling, and saving troubleshooting time.

[0092] In an exemplary embodiment, the abnormal event is traced based on the time series data of each abnormal power device to generate an abnormal event tracing result, including: for any abnormal power device, tracing back the time series data of the abnormal power device to determine the timestamp of the first occurrence of the abnormality as the target timestamp; determining the source power device based on the parameter data of each power device under each operating state dimension corresponding to the target timestamp; if the current abnormal operating mode of the source power device matches any historical abnormal operating mode of the source power device, comparing the time series data of the source power device with the time series data of adjacent power devices to determine whether the abnormality was triggered by the source power device; adjacent power devices are those adjacent to the source power device; if the abnormality is determined to be triggered by the source power device, determining the abnormality of the source power device to generate the abnormal event tracing result.

[0093] Among them, the current abnormal operation mode can refer to the current abnormal operation mode of the equipment, which represents the current operation pattern of the equipment, while the historical abnormal operation mode can refer to the abnormal operation patterns that have occurred in the past, which represents the operation pattern of the equipment when abnormalities occur.

[0094] In practical applications, historical anomaly records that are similar to the current target abnormal operating status data can be retrieved from historical anomaly data, including information such as anomaly type, occurrence time, and device ID;

[0095] Optionally, for any abnormal power device, the server traces back the time series data of the abnormal power device to determine the timestamp of the first occurrence of the abnormality, which is used as the target timestamp. Based on the parameter data of each power device under each operating state dimension corresponding to the target timestamp, the source power device is determined. If the current abnormal operating mode of the source power device matches any historical abnormal operating mode of the source power device, it is said that the source power device is the power device that caused the abnormality. To further confirm, the time series data of the source power device can be compared with the time series data of adjacent power devices to determine whether the abnormality was triggered by the source power device. If it is determined that the abnormality was triggered by the source power device, the specific abnormal situation of the source power device is determined to generate the abnormal event tracing result.

[0096] In practical applications, historical anomaly records similar to the current anomaly data can be retrieved from historical anomaly data, including anomaly type, occurrence time, and device ID. Based on the anomaly time series, a time-series backtracking algorithm is used to trace back from the current anomaly time point to identify the timestamp of the first occurrence of the anomaly. The timestamp of the earliest occurrence of the anomaly is matched with the timestamps of device nodes in the device topology to determine the source device of the earliest occurrence of the anomaly. The anomaly pattern of the source device (features such as anomaly frequency and anomaly duration) is analyzed and compared with historical anomaly patterns to verify the accuracy of the source device identification. The identification result of the source device is verified by comparing the operating status data of the source device with the data of adjacent devices.

[0097] For example, suppose a power system experiences abnormal current fluctuations. The server filters historical records from the historical anomaly database that show anomalies with the same anomaly type (current anomaly), occurrence time, and device ID as the current anomaly. Starting from the current anomaly time (e.g., 10:00 on January 2, 2024), the server traces back based on time series data and finds that the earliest current anomaly occurred at transformer No. 3 at 09:45 on January 2, 2024. This timestamp is compared with the timestamps of each device node in the device topology to determine that transformer No. 3 is the source device. The accuracy is then verified by comparing with historical anomaly patterns, thus completing the source tracing.

[0098] In this embodiment, for any abnormal power device, the time series data of the abnormal power device is traced backward to determine the timestamp of the first occurrence of the abnormality, which is used as the target timestamp. Based on the parameter data of each power device under each operating state dimension corresponding to the target timestamp, the source power device is determined. If the current abnormal operating mode of the source power device matches any historical abnormal operating mode of the source power device, the time series data of the source power device is compared with the time series data of adjacent power devices to determine whether the abnormality was triggered by the source power device. Adjacent power devices are those adjacent to the source power device. If the abnormality is determined to be triggered by the source power device, the abnormality of the source power device is determined to generate the abnormal event tracing result. In this way, the historical abnormal operating modes of power devices can be combined for preliminary tracing, and the accuracy of the tracing result can be verified by comparing the time series data of adjacent power devices.

[0099] In an exemplary embodiment, the method further includes: constructing a power flow calculation model for the power system; simulating the operating state of the power system when an abnormal situation occurs in any source power device using the power flow calculation model to obtain power flow calculation data; and determining the abnormal propagation path of the source power device in the power system topology based on the power flow calculation data and the time series data of the source power device.

[0100] Among them, the power flow calculation model can collect data such as current distribution data, voltage distribution data, and temperature distribution data of each power device when an anomaly occurs, which can characterize the operating rules of each power device.

[0101] Among them, power flow calculation data can be data that characterizes the operating rules of each power device, such as current distribution data, voltage distribution data, and temperature distribution data.

[0102] Optionally, the server constructs a power flow calculation model for the power system. For any source power device, the power flow calculation model simulates the operating state of the power system when an abnormal situation occurs in the source power device, and obtains power flow calculation data. Based on the power flow calculation data and the time series data of the source power device, the server determines the abnormal propagation path of the source power device in the power system topology.

[0103] In practical applications, power flow calculation models can be used to simulate the current and voltage distribution when an anomaly occurs, and obtain power flow data for each node. Time series data of the target anomaly operation status data can be analyzed to identify the time sequence and propagation trend of the anomaly. By combining the power flow calculation data and the time series data of the target anomaly operation status data, graph algorithms can be used to trace the propagation path of the anomaly in the power system topology network, and determine the direction and range of the anomaly propagation from the source power equipment to other equipment.

[0104] For example, the server can construct a power flow calculation model based on power grid parameters to simulate the current and voltage distribution data of each node when an anomaly occurs. If an anomaly is found in transformer No. 3, the current of its downstream distribution cabinet No. 4 will show an upward trend. By analyzing the time series data of the target abnormal operating status, it is found that the anomaly started from transformer No. 3 at 09:45 and successively affected distribution cabinet No. 4, which showed a data anomaly at 09:47. Combining the power flow calculation data and the time series data, the graph algorithm is used to trace the path of the anomaly from transformer No. 3 along the connecting line to distribution cabinet No. 4 in the topology network. The direction of propagation is determined to be from the transformer to the distribution cabinet, and the affected area includes some electrical equipment connected to distribution cabinet No. 4.

[0105] In this embodiment, a power flow calculation model for the power system is constructed. For any source power device, the power flow calculation model simulates the operating state of the power system when an abnormal situation occurs in the source power device, and obtains power flow calculation data. Based on the power flow calculation data and the time series data of the source power device, the abnormal propagation path of the source power device is determined in the power system topology. In this way, the abnormal propagation path can be accurately determined, which helps to take targeted measures to limit the scope of the fault, prevent larger-scale power outages, and effectively reduce the risk of large-scale power outages caused by equipment failure.

[0106] In one exemplary embodiment, the method further includes: displaying the identifier of the source power equipment in the power system topology map of the monitoring interface of the power monitoring system; and displaying the abnormal propagation path of the source power equipment in the power system topology map in response to a trigger operation on the identifier of the source power equipment in the power system topology map.

[0107] Among them, the power system topology diagram can represent the deployment location of each power device in the power system, as well as the relationship between different power devices.

[0108] Among them, the identifiers of the source power equipment can be displayed in a preset shape in the power system topology diagram.

[0109] The triggering action can be a click action.

[0110] Optionally, the power system topology map in the monitoring interface of the power monitoring system displays the identifier of the source power equipment. When the user clicks on the identifier, the server responds to the click operation and displays the abnormal propagation path of the source power equipment in the power system topology map.

[0111] In this embodiment, the identifiers of source power equipment are displayed on the power system topology map in the monitoring interface of the power monitoring system. In response to a trigger operation on the identifier of the source power equipment in the power system topology map, the abnormal propagation path of the source power equipment is displayed in the power system topology map. Thus, by directly displaying the identifiers of source power equipment in the power system topology map of the monitoring interface, operators can quickly focus on critical equipment. When an anomaly occurs, operators do not need to compare and search through a large amount of equipment information to find the source equipment, greatly shortening the time for locating the origin of the anomaly. When users need to know more specific anomaly propagation paths, they can trigger the identifier of the source power equipment to quickly determine the scope of the fault's impact, providing a clear direction for subsequent maintenance and recovery work.

[0112] In practical applications, abnormal operating status data and anomaly event tracing results can also be stored in the blockchain. This not only enhances data security and integrity but also provides an immutable historical record for subsequent fault investigation, improving the efficiency and accuracy of maintenance work. Specifically, abnormal data and anomaly propagation path diagrams can be packaged into data blocks, and a unique digital fingerprint can be generated for each data block. These data fingerprints are then distributed and stored on the blockchain across multiple nodes of the power grid. When anyone queries the data, the data fingerprint is automatically verified, and an alarm is issued if data tampering is detected. Viewing permissions can also be set for different personnel; for example, maintenance personnel can view details, while auditors can only view logs.

[0113] In another embodiment, such as Figure 3 As shown, a method for tracing the source of abnormal events in a power system is provided, which can be applied to... Figure 1 Taking server 104 as an example, the following steps are included:

[0114] Step S302: Upon receiving an abnormal alarm message from the power monitoring system, obtain the power system's operating status dataset; the operating status dataset includes parameter data under multiple operating status dimensions corresponding to each timestamp.

[0115] Step S304: The isolated forest algorithm is used to detect anomalies in the running status dataset to obtain a candidate abnormal running status dataset.

[0116] Step S306: Input the candidate abnormal running state dataset into the Gaussian mixture model, and determine the probability that each candidate abnormal running state data in the candidate abnormal running state dataset belongs to normal data through the Gaussian mixture model.

[0117] Step S308: Candidate abnormal operating state data with a probability of belonging to normal data lower than a preset threshold are identified as target abnormal operating state data.

[0118] Step S310: Associate and map the target abnormal operating status data with the power system topology to determine the abnormal power equipment corresponding to the target abnormal operating status data and obtain the time series data of the abnormal power equipment.

[0119] Step S312: Based on the time series data of each abnormal power device, trace the abnormal event to its source and generate the abnormal event tracing result; the abnormal event tracing result includes the abnormal situation of the source power device.

[0120] It should be noted that the specific limitations of the above steps can be found in the specific limitations of a method for tracing the source of abnormal events in a power system described above.

[0121] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0122] Based on the same inventive concept, this application also provides an abnormal event tracing device for power systems to implement the above-described method for tracing abnormal events in power systems. The solution provided by this device is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the abnormal event tracing device for power systems provided below can be found in the limitations of the abnormal event tracing method for power systems described above, and will not be repeated here.

[0123] In one exemplary embodiment, such as Figure 4 As shown, a device for tracing abnormal events in a power system is provided, comprising: an acquisition module 402, a detection module 404, a determination module 406, an association module 408, and a tracing module 410, wherein:

[0124] The acquisition module 402 is used to acquire the power system's operating status dataset when it receives an abnormal alarm message from the power monitoring system; the operating status dataset includes parameter data under multiple operating status dimensions corresponding to each timestamp;

[0125] Detection module 404 is used to perform anomaly detection on the running state dataset using the isolated forest algorithm to obtain a candidate abnormal running state dataset;

[0126] The determination module 406 is used to input the candidate abnormal running state dataset into the Gaussian mixture model in order to determine the target abnormal running state data in the candidate abnormal running state dataset;

[0127] The association module 408 is used to associate and map the target abnormal operating status data with the power system topology, determine the abnormal power equipment corresponding to the target abnormal operating status data, and obtain the time series data of the abnormal power equipment.

[0128] The tracing module 410 is used to trace the source of abnormal events based on the time series data of each abnormal power equipment and generate the abnormal event tracing results; the abnormal event tracing results include the abnormal situation of the source power equipment.

[0129] In one embodiment, the determining module 406 is specifically used to input the candidate abnormal running state dataset into the Gaussian mixture model, and determine the probability that each candidate abnormal running state data in the candidate abnormal running state dataset belongs to normal data through the Gaussian mixture model; and determine the candidate abnormal running state data whose probability of belonging to normal data is lower than a preset threshold as the target abnormal running state data.

[0130] In one embodiment, the association module 408 is specifically used to obtain the topology information corresponding to the power system topology from the power system topology database; the topology information includes the device identifier of each power device; the device identifier corresponding to the target abnormal operating status data is matched with the device identifier of each power device to determine the abnormal power device among the power devices.

[0131] In one embodiment, the tracing module 410 is specifically used to trace the time series data of any abnormal power equipment backward to determine the timestamp of the first occurrence of the abnormality, which is used as the target timestamp; determine the source power equipment based on the parameter data of each power equipment under each operating state dimension corresponding to the target timestamp; if the current abnormal operating mode of the source power equipment matches any historical abnormal operating mode of the source power equipment, compare the time series data of the source power equipment with the time series data of adjacent power equipment to determine whether the abnormality was triggered by the source power equipment; adjacent power equipment refers to the power equipment adjacent to the source power equipment; if it is determined that the abnormality was triggered by the source power equipment, determine the abnormal situation of the source power equipment to generate the abnormal event tracing result.

[0132] In one embodiment, the apparatus further includes: a construction module for constructing a power flow calculation model for the power system; for any source power device, simulating the operating state of the power system when an abnormal situation occurs in the source power device using the power flow calculation model to obtain power flow calculation data; and determining the abnormal propagation path of the source power device in the power system topology based on the power flow calculation data and the time series data of the source power device.

[0133] In one embodiment, the device further includes: a response module for displaying the identifier of the source power equipment in the power system topology diagram on the monitoring interface of the power monitoring system; and for displaying the abnormal propagation path of the source power equipment in the power system topology diagram in response to a trigger operation on the identifier of the source power equipment in the power system topology diagram.

[0134] Each module in the aforementioned power system anomaly tracing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the computer device's memory as software, so that the processor can call and execute the corresponding operations of each module.

[0135] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores data on the source of abnormal events in the power system. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a method for tracing the source of abnormal events in a power system.

[0136] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0137] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, which, when executed by the processor, causes the processor to perform the steps of the above-described method for tracing abnormal events in a power system. The steps of this method for tracing abnormal events in a power system can be the steps in the methods described in the various embodiments above.

[0138] In one embodiment, a computer-readable storage medium is provided, storing a computer program that, when executed by a processor, causes the processor to perform the steps of the above-described method for tracing abnormal events in a power system. The steps of this method for tracing abnormal events in a power system may be the steps in the methods for tracing abnormal events in a power system described in the various embodiments above.

[0139] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, causes the processor to perform the steps of the above-described method for tracing abnormal events in a power system. The steps of this method for tracing abnormal events in a power system may be the steps in the methods for tracing abnormal events in a power system described in the various embodiments above.

[0140] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0141] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0142] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for tracing the source of abnormal events in a power system, characterized in that, The method includes: Upon receiving an abnormal alarm message from the power monitoring system, the system acquires a power system operation status dataset; the operation status dataset includes parameter data under multiple operation status dimensions corresponding to each timestamp. The isolated forest algorithm is used to perform anomaly detection on the running state dataset to obtain a candidate abnormal running state dataset; The candidate abnormal operating state dataset is input into a Gaussian mixture model to determine the target abnormal operating state data in the candidate abnormal operating state dataset; The target abnormal operating status data is associated and mapped with the power system topology to determine the abnormal power equipment corresponding to the target abnormal operating status data, and the time series data of the abnormal power equipment is obtained. The abnormal events are traced based on the time series data of each of the abnormal power devices to generate abnormal event tracing results; the abnormal event tracing results include the abnormal situation of the source power device.

2. The method according to claim 1, characterized in that, The step of inputting the candidate abnormal operating state dataset into a Gaussian mixture model to determine the target abnormal operating state data from the candidate abnormal operating state dataset includes: The candidate abnormal running state dataset is input into the Gaussian mixture model, and the probability that each candidate abnormal running state data in the candidate abnormal running state dataset belongs to normal data is determined by the Gaussian mixture model. Candidate abnormal operating state data whose probability of belonging to normal data is lower than a preset threshold are identified as target abnormal operating state data.

3. The method according to claim 1, characterized in that, The step of associating and mapping the target abnormal operating state data with the power system topology to determine the abnormal power equipment corresponding to the target abnormal operating state data includes: The topology information corresponding to the power system topology is obtained from the power system topology database; the topology information includes the device identifier of each power device. The device identifier corresponding to the target abnormal operating status data is matched with the device identifier of each of the power devices to identify the abnormal power device among the power devices.

4. The method according to claim 1, characterized in that, The process of tracing the source of abnormal events based on the time-series data of each of the abnormal power devices, and generating abnormal event tracing results, includes: For any of the abnormal power devices, the time series data of the abnormal power devices are traced backward to determine the timestamp of the first occurrence of the abnormality, which is used as the target timestamp. The source power equipment is determined based on the parameter data of each power equipment under each operating state dimension corresponding to the target timestamp; If the current abnormal operating mode of the source power equipment matches any historical abnormal operating mode of the source power equipment, the time series data of the source power equipment is compared with the time series data of adjacent power equipment to determine whether the abnormality was triggered by the source power equipment; the adjacent power equipment is the power equipment that is adjacent to the source power equipment. If the anomaly is determined to be triggered by the source power equipment, the anomaly condition of the source power equipment is determined to generate the anomaly event tracing result.

5. The method according to claim 1, characterized in that, The method further includes: Construct a power flow calculation model for the power system; For any of the aforementioned source power devices, the power flow calculation model is used to simulate the operating state of the power system when the aforementioned abnormal situation occurs at the source power device, thereby obtaining power flow calculation data; Based on the power flow calculation data and the time series data of the source power equipment, the abnormal propagation path of the source power equipment is determined in the power system topology.

6. The method according to claim 5, characterized in that, The method further includes: The power system topology diagram in the monitoring interface of the power monitoring system displays the identifiers of the source power equipment; In response to a triggered operation targeting the identifier of the source power device in the power system topology diagram, the abnormal propagation path of the source power device is displayed in the power system topology diagram.

7. A device for tracing abnormal events in a power system, characterized in that, The device includes: The acquisition module is used to acquire the power system's operating status dataset upon receiving abnormal alarm information from the power monitoring system; the operating status dataset includes parameter data under multiple operating status dimensions corresponding to each timestamp; The detection module is used to perform anomaly detection on the running state dataset using the isolated forest algorithm to obtain a candidate abnormal running state dataset; The determination module is used to input the candidate abnormal operating state dataset into the Gaussian mixture model in order to determine the target abnormal operating state data in the candidate abnormal operating state dataset; The association module is used to associate and map the target abnormal operating status data with the power system topology, determine the abnormal power equipment corresponding to the target abnormal operating status data, and obtain the time series data of the abnormal power equipment. The tracing module is used to trace the source of abnormal events based on the time series data of each of the abnormal power devices and generate abnormal event tracing results; the abnormal event tracing results include the abnormal situation of the source power device.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Cited By

  • Intelligent traceability method and system for power dispatching system

    CN122087672A