Anomaly detection method for electricity meter used to identify user electricity theft
By segmenting and clustering the current and voltage data of electricity meters, abnormal risks of electricity theft can be identified, solving the problem of difficulty in identifying intermittent electricity theft in existing technologies and achieving higher identification accuracy.
Patent Information
- Application Number
- CN202511793647.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-03-06
- Estimated Expiration
- 2045-12-02
AI Technical Summary
Existing methods for identifying electricity theft by users are unable to accurately identify intermittent electricity theft, leading to the identification model mislearning as normal electricity consumption patterns and affecting the timely response of the electricity management system.
By analyzing the current and voltage data of users' electricity meters, a current waveform diagram is constructed and segmented to obtain the three-dimensional features of the current data segments. Similar data segments are clustered using clustering methods. Combined with the characteristics of current and voltage changes, the risk of abnormal electricity theft is assessed.
It improves the accuracy of electricity theft identification, reduces the impact of noise and equipment failure data on the identification results, and can promptly identify intermittent electricity theft.
Smart Images

Figure CN121234274B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of electricity theft detection technology, and specifically to an abnormal electricity meter detection method for identifying user electricity theft. Background Technology
[0002] With the intelligent development of power systems, smart meters are widely used in distribution networks. Combined with automation systems, smart meters collect multi-dimensional electricity consumption data such as current and voltage in real time, enabling automated analysis of user electricity consumption behavior and monitoring of grid operation status. However, with the widespread adoption of smart meters, some users are stealing electricity by tampering with metering devices and rewiring circuits, causing economic losses to power supply companies and affecting the fairness of electricity metering and the safety of grid operation. Therefore, timely and accurate identification of users engaging in electricity theft based on meter monitoring data is a crucial aspect of automated electricity management.
[0003] Existing methods for identifying electricity theft primarily rely on analyzing historical electricity usage data to predict normal usage patterns. When a user's electricity consumption deviates significantly from these patterns, an anomaly warning is issued. However, some users, in an attempt to evade surveillance, engage in electricity theft at specific times. This data exhibits clear periodicity and regularity, which may be mislearned by the anomaly detection model as normal usage patterns, making it difficult to accurately identify such anomalies. Summary of the Invention
[0004] To address the aforementioned technical problems, the present invention aims to provide an abnormal electricity meter detection method for identifying user electricity theft, the specific technical solution of which is as follows:
[0005] One embodiment of the present invention provides an anomaly detection method for electricity meters for identifying user electricity theft, the method comprising:
[0006] The current and voltage at various times within a preset time period are collected using the user's electricity meter; a current waveform diagram is constructed based on the current, and the current at all times is segmented using the inflection points in the current waveform diagram to obtain different current data segments;
[0007] The three-dimensional features of a current data segment are obtained based on the time length of the segment, the current difference between the two endpoints, and the slope of each current. Different clusters are obtained by clustering based on the three-dimensional features of each current data segment.
[0008] The first probability of abnormal fluctuations in electricity theft in a cluster is obtained by averaging the distance between every two current data segments in the cluster; the second probability of abnormal fluctuations in electricity theft in a cluster is obtained by averaging the current changes in each current data segment in the cluster.
[0009] The third probability of abnormal electricity theft fluctuation in a cluster is obtained by comparing the changes in current in each current data segment with the changes in voltage corresponding to each current data segment. The average of the first, second and third probabilities of abnormal electricity theft fluctuation in a cluster is the comprehensive probability of abnormal electricity theft fluctuation in that cluster.
[0010] The degree of abnormal electricity theft risk for a user's electricity meter is determined by the time length of each current data segment within the cluster with the highest probability of abnormal fluctuations in overall electricity theft, the time span of the current data segments contained in the cluster, and the probability of abnormal fluctuations in overall electricity theft within the cluster.
[0011] Preferably, the three-dimensional features of a current data segment are obtained based on the time length of the current data segment, the current difference between the two endpoints, and the slope values of each current, including:
[0012] The average slope of the slope of each current in a current data segment is recorded as the average slope. The time length of the current data segment, the current difference between the two endpoints, and the average slope are normalized to obtain the normalized time length, the degree of current change, and the current fluctuation amplitude of the current data segment, which constitute the three-dimensional features of the current data segment.
[0013] Preferably, the probability of a first abnormal fluctuation in electricity theft within a cluster is obtained based on the average distance between every two current data segments in the cluster, including:
[0014] Calculate the reciprocal of the average distance between every two current data segments in a cluster and normalize it to obtain the probability of the first abnormal fluctuation in electricity theft in that cluster.
[0015] Preferably, the probability of a second abnormal fluctuation in electricity theft within a cluster is obtained based on the changes in current in each current data segment within that cluster, including:
[0016] The mean of the slope values corresponding to each current in a current data segment is obtained as the average current fluctuation rate of the current data segment; the mean of the average current fluctuation rate of all current data segments in the cluster is negative and normalized to obtain the second probability of abnormal fluctuation of electricity theft in the cluster.
[0017] Preferably, the probability of a third abnormal fluctuation in electricity theft within a cluster is obtained based on the difference between the changes in current in each current data segment and the changes in the corresponding voltage in each current data segment, including:
[0018] The average slope of the voltage at each moment corresponding to a current data segment is taken as the average voltage fluctuation rate of that current data segment. The absolute value of the difference between the average current fluctuation rate and the average voltage fluctuation rate of a current data segment in a cluster is calculated and denoted as the current-voltage change difference of that current data segment. The average current-voltage change difference of all current data segments in the cluster is calculated and normalized to obtain the third abnormal fluctuation probability of electricity theft in that cluster.
[0019] Preferably, the degree of electricity theft risk for the user's electricity meter is obtained based on the time length of each current data segment within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft, the time span of the current data segments included in the cluster, and the probability of abnormal fluctuations in comprehensive electricity theft within the cluster, including:
[0020] The earliest start time in the current data segments within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft is obtained as the start time of the cluster. The latest end time in the current data segments within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft is obtained as the end time of the cluster. The difference between the end time and the start time is obtained and normalized to obtain the time span of the current data segments included in the cluster. The sum of the durations of the current data segments within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft is obtained and compared with a preset time period to obtain the duration ratio of the cluster. The probability of abnormal fluctuations in comprehensive electricity theft, the duration ratio of the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft, and the time span of the current data segments included in the cluster are multiplied to obtain the degree of abnormal electricity theft risk of the user's electricity meter.
[0021] The embodiments of the present invention have at least the following beneficial effects: This application utilizes the user's electricity meter to collect the current and voltage at various times within a preset time period. Then, based on the changes in the current data, the collected current sequence is segmented to obtain current data segments. The characteristics of the current data segments are then analyzed to obtain the three-dimensional features of each current data segment. Subsequently, current data segments with similar three-dimensional features are clustered together to obtain clusters. This can effectively extract the data corresponding to intermittent electricity theft and analyze the abnormal electricity theft behavior in each cluster. This can greatly reduce the occurrence of regular electricity theft behavior being judged as normal electricity consumption behavior and improve the accuracy of electricity theft behavior identification.
[0022] Furthermore, by analyzing the density of the clusters, the rate of current fluctuation in the data segments within the clusters, and the synchronicity of current and voltage changes, the probability of electricity theft anomalies in the user's electricity meter data is determined, resulting in first, second, and third probabilities of electricity theft anomalies. This effectively reduces the impact of abnormal data generated by noise, equipment malfunctions, and other non-electricity theft behaviors on the accuracy of the electricity theft assessment results. Finally, based on the time length of each current data segment within the cluster with the highest probability of comprehensive electricity theft anomalies, the time span of the current data segments contained in each cluster, and the comprehensive probability of electricity theft anomalies in each cluster, the degree of electricity theft anomaly risk of the user's electricity meter is obtained, thus improving the accuracy of electricity theft identification and detection. Attached Figure Description
[0023] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a flowchart of an abnormal energy meter detection method for identifying user electricity theft, provided in an embodiment of the present invention. Detailed Implementation
[0025] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a method for detecting abnormal electricity meter behavior for identifying user electricity theft according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0026] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0027] The following describes in detail, with reference to the accompanying drawings, a specific scheme for an abnormal energy meter detection method for identifying user electricity theft provided by the present invention.
[0028] Example:
[0029] The main application scenario of this invention is as follows: Some users often steal electricity at intervals to avoid being detected. When users steal electricity at fixed intervals, the periodicity and regularity of this behavior make it easy for traditional electricity theft detection models to learn as normal electricity consumption patterns, making it difficult to identify such behavior and affecting the timeliness of abnormal responses from the electricity management system. Therefore, this application analyzes the regularity and characteristics of electricity theft to identify and detect such behavior.
[0030] Please see Figure 1 The diagram illustrates a method flowchart for detecting abnormal electricity meter readings for identifying user electricity theft, provided by an embodiment of the present invention. The method includes the following steps:
[0031] Step S1: Collect the current and voltage at each moment within a preset time period using the user's electricity meter; construct a current waveform diagram based on the current, and use the inflection points in the current waveform diagram to segment the current at all moments to obtain different current data segments.
[0032] Since electricity theft by users is usually evident in current data, it is necessary to monitor user current data in real time. However, because short-circuiting is a common method of electricity theft, it often leads to an imbalance between current and voltage data, so it is also necessary to analyze the risk of abnormal electricity theft in conjunction with voltage data.
[0033] Therefore, current and voltage data are collected in real time from the user's electricity meter at various times within a preset time period, with data collected every 1 second. For ease of subsequent analysis, the current and voltage data need to be normalized separately.
[0034] Since the abnormal current data caused by a user's single act of electricity theft may not be obvious and can be easily confused with other anomalies (such as equipment failure), the preset time period is one week for the user, and the analysis and evaluation are based on the monitoring data of the user within one week.
[0035] Because normal current typically exhibits some fluctuation, to avoid these fluctuations interfering with the analysis of current trends and other characteristics, the Loess smoothing algorithm is first used to smooth the current at each time point. Then, a current waveform is constructed using the smoothed current at all time points to obtain inflection points. Inflection points refer to data points where the slope changes from positive to negative. Here, the slope refers to the slope of the straight line formed by the data point and the data points before and after it. If the slope before (or after) a data point is 0 but the slope after (or before) it is not 0, it is also considered an inflection point. Based on the corresponding time of the obtained inflection points, the sequence of currents at each time point is divided into multiple data segments (the data point at the inflection point is assigned to the data segment preceding it), denoted as the current data segment.
[0036] Step S2: Obtain the three-dimensional features of a current data segment based on the time length of the current data segment, the current difference between the two endpoints, and the slope value of each current; perform clustering based on the three-dimensional features of each current data segment to obtain different clusters.
[0037] Since the methods used by the same user to steal electricity are usually consistent, the current behavior during the theft period should be similar. Therefore, we obtain the average of the time length of each current data segment, the current difference between the two endpoints (the current value at the end of the data segment minus the current value at the beginning of the data segment), and the average slope value of each data point position, which is the average slope (here, the slope value refers to the slope of the straight line formed by each data point and the data point at the previous moment; for the first data point, it is represented by the slope of the straight line formed by that data point and the second data point). To facilitate the analysis of the similarity of each historical data segment based on these three characteristics, the above three characteristic values are normalized to obtain the normalized time length, current change degree, and current fluctuation amplitude of the current data segment, which constitute the three-dimensional features of the current data segment.
[0038] Furthermore, a three-dimensional coordinate system is established based on normalized time length, current variation degree, and current fluctuation amplitude. Each data segment is treated as a whole (i.e., a point), and its corresponding three-dimensional features are placed into the coordinate system according to the feature values of each dimension. The k-means clustering method is used to cluster the points in the coordinate system, that is, to cluster each current data segment, where the k value is determined according to the elbow method. This yields multiple clusters. Since the same user uses the same method of electricity theft, the data segments generated by the theft behavior will also be grouped into the same category. Therefore, by analyzing the abnormal electricity theft behavior of the data segments in each category, the risk level of abnormal electricity theft by the user can be analyzed.
[0039] Step S3: Obtain the first probability of abnormal fluctuation in electricity theft for a cluster based on the average distance between every two current data segments in the cluster; obtain the second probability of abnormal fluctuation in electricity theft for a cluster based on the changes in current in each current data segment in the cluster.
[0040] Since the methods of electricity theft by the same user are usually consistent each time, the corresponding data should show similarity when electricity theft occurs at different times. However, normal current data may not always reflect consistent user electricity demand, and some noise data and equipment failure data are often highly random. Therefore, data generated by regular electricity theft behavior has a relatively higher similarity. Thus, based on the density of current data segments in each cluster, the probability of abnormal fluctuations in data within each cluster representing electricity theft is calculated in terms of data feature similarity.
[0041] Specifically, the reciprocal of the average distance between any two current data segments in a cluster is calculated and normalized to obtain the first probability of abnormal electricity theft fluctuations for that cluster. The first probability of abnormal electricity theft fluctuations represents the likelihood that data within a cluster exhibits abnormal electricity theft fluctuations based on the similarity of data features. The distance is calculated using Euclidean distance based on the three-dimensional features of two current data segments. A smaller average distance indicates a higher density of points within the cluster, meaning more similar data features, and thus a higher probability of electricity theft.
[0042] However, some users' electricity demands may exhibit strong regularity, such as factories operating under fixed patterns. The normal electricity consumption data of these users may show high density in the clusters obtained through the aforementioned clustering process, thus requiring further differentiation. Under normal electricity usage conditions, current changes are typically relatively gradual due to the transition processes required for equipment startup, shutdown, and state switching. In contrast, short-circuiting, a common method of electricity theft, causes the current to drop rapidly to a low level, resulting in a much faster rate of change compared to normal electricity consumption data.
[0043] The probability of a second abnormal fluctuation in electricity theft within a cluster is determined by analyzing the current changes in each current data segment within that cluster. Specifically, the average slope value corresponding to each current in a current data segment is taken as the average current fluctuation rate of that current data segment.
[0044] The specific calculation model for the average current fluctuation rate is as follows:
[0045] ,
[0046] in, This represents the average rate of change of current fluctuation in the l-th current data segment within the u-th cluster. This represents the total number of data points (total number of currents) contained in the l-th current data segment within the u-th cluster. This represents the current slope value of the i-th current in the l-th data segment of the u-th cluster, obtained using the same method as described above.
[0047] Furthermore, by combining the average current fluctuation rate of all data segments within the same cluster, the probability of abnormal fluctuations in the data within each cluster representing electricity theft is calculated based on the current change rate. Specifically, the mean of the average current fluctuation rate of all current data segments within a cluster is negativeized and normalized to obtain the second probability of abnormal electricity theft fluctuation for that cluster.
[0048] The specific calculation model for the probability of abnormal fluctuations in the second electricity theft is as follows:
[0049] ,
[0050] in, This represents the probability that the data in the u-th cluster represents an abnormal fluctuation in electricity theft rate, which is also the probability of the second abnormal fluctuation in electricity theft in the u-th cluster. This represents the total number of points contained in the u-th cluster (each point corresponds to a current data segment). This represents the average current fluctuation rate of the l-th data segment in the u-th cluster. This represents the average rate of change of current fluctuation across all current data segments in the u-th cluster. This indicates that electricity theft typically causes a drop in current; the faster the rate of drop, the more likely it is an abnormal fluctuation in electricity flow. `norm` represents the normalization function.
[0051] This allows us to obtain the probability of first and second abnormal fluctuations in electricity theft for each cluster.
[0052] Step S4: Obtain the third probability of abnormal electricity theft fluctuations for a cluster based on the difference between the changes in current and the corresponding voltage in each current data segment of the cluster; the average of the first, second and third probabilities of abnormal electricity theft fluctuations for a cluster is the comprehensive probability of abnormal electricity theft fluctuations for the cluster.
[0053] The above steps analyzed the current characteristics, identifying the first and second probabilities of abnormal fluctuations in electricity theft for each cluster. However, under normal electricity usage, current and voltage typically change synchronously. Electricity theft causes the electricity meter to only detect a portion of the usage, meaning the monitored data does not match the actual usage, resulting in no correlation between current and voltage changes. For example, electricity theft involving short-circuiting a line only causes a decrease in current data while the voltage remains almost unchanged. Therefore, further joint analysis combining voltage characteristics is needed.
[0054] Therefore, the third probability of abnormal fluctuations in electricity theft in a cluster can be obtained based on the difference between the changes in current in each current data segment and the changes in voltage corresponding to each current data segment.
[0055] Specifically, the average slope of the voltage at each moment corresponding to a current data segment is taken as the average voltage fluctuation rate of that current data segment. The slope of the voltage at each moment is calculated in the same way as the slope of the voltage at the previous moment; the slope of the voltage at a moment is the slope of the straight line formed by the voltage at that moment and the voltage at the previous moment.
[0056] The specific calculation model for the average voltage fluctuation rate is as follows:
[0057] ,
[0058] in, This represents the average voltage fluctuation rate of the l-th current data segment in the u-th cluster. This represents the total number of data points contained in the l-th current data segment within the u-th cluster. This represents the slope value of the voltage corresponding to the position of the i-th data point in the l-th data segment within the u-th cluster (at the i-th time).
[0059] Furthermore, the absolute value of the difference between the average current fluctuation rate and the average voltage fluctuation rate of a current data segment in a cluster is calculated and denoted as the current-voltage change difference of that current data segment. The mean of the current-voltage change differences of all current data segments in the cluster is calculated and normalized to obtain the third probability of abnormal fluctuations in electricity theft in that cluster.
[0060] The specific calculation model for the probability of abnormal fluctuations in the third type of electricity theft is as follows:
[0061] ,
[0062] in, This represents the probability that the data in the u-th cluster exhibits abnormal fluctuations related to electricity theft in terms of the synchronicity of changes in electricity meter data; that is, the probability of the third abnormal fluctuation in electricity theft within the u-th cluster. This represents the total number of points contained in the u-th cluster (each point corresponds to a current data segment). This represents the average rate of change of current fluctuation in the l-th current data segment within the u-th cluster. This represents the average voltage fluctuation rate of the l-th current data segment in the u-th cluster. The difference between current and voltage changes represents the degree of difference between the changes in current and voltage. The larger the absolute value of this difference, the more likely it is to be an abnormal electricity theft. `norm` represents the normalization function.
[0063] Therefore, the first, second, and third abnormal fluctuation probabilities of electricity theft for each cluster can be obtained. By comprehensively considering the degree to which each cluster conforms to electricity theft behavior in the above data performance, specifically, the average of the first, second, and third abnormal fluctuation probabilities of electricity theft for a cluster is calculated as the comprehensive abnormal fluctuation probability of that cluster. Using the average degree of performance of a cluster on the three abnormal electricity theft characteristics, it can be indicated that the data characteristics in the cluster must all meet the above characteristics for it to be more likely that there is regular electricity theft behavior.
[0064] Step S5: Based on the time length of each current data segment within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft, the time span of the current data segments contained in the cluster, and the probability of abnormal fluctuations in comprehensive electricity theft of the cluster, obtain the degree of abnormal electricity theft risk of the user's electricity meter.
[0065] The above steps obtained the overall probability of abnormal fluctuations in electricity theft for each cluster. The higher the probability of abnormal fluctuations in electricity theft, the more likely electricity theft occurred within the time period contained in that cluster, and the more representative it is for detecting electricity theft. Therefore, the cluster with the highest probability of abnormal fluctuations in electricity theft was selected for analysis.
[0066] The more current data segments contained in the cluster with the highest probability of abnormal fluctuations in electricity theft, the more frequently the user has engaged in electricity theft. Furthermore, the longer the duration of the abnormal current data segments, the more severe the user's electricity theft. Therefore, by analyzing the total duration of the current data segments in the cluster with the highest probability of abnormal fluctuations in electricity theft, the overall temporal distribution range of the current data segments in the cluster, and the probability that the data in the cluster represents abnormal fluctuations in electricity theft (comprehensive probability of abnormal fluctuations in electricity theft), the degree of abnormal electricity theft risk for the current user is calculated.
[0067] The degree of abnormal electricity theft risk for a user's electricity meter is determined by the time length of each current data segment within the cluster with the highest probability of abnormal fluctuations in overall electricity theft, the time span of the current data segments contained in the cluster, and the probability of abnormal fluctuations in overall electricity theft within the cluster.
[0068] Specifically, the earliest start time among the current data segments within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft is obtained as the start time of the cluster; the latest end time among the last time of each current data segment within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft is obtained as the end time of the cluster; the difference between the end time and the start time is obtained and normalized to obtain the time span of the current data segments included in the cluster; the sum of the durations of each current data segment within the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft is obtained and compared with a preset time period to obtain the duration ratio of the cluster; the probability of abnormal fluctuations in comprehensive electricity theft, the duration ratio of the cluster with the highest probability of abnormal fluctuations in comprehensive electricity theft, and the time span of the current data segments included in the cluster are multiplied to obtain the degree of abnormal electricity theft risk of the user's electricity meter.
[0069] The specific calculation model for the abnormal risk level of electricity theft from electricity meters is as follows:
[0070] ,
[0071] Where E represents the degree of abnormal risk of electricity theft from the user's electricity meter; The cluster representing the highest probability of abnormal fluctuations in overall electricity theft; This indicates the number of current data segments within the cluster with the highest probability of abnormal fluctuations in overall electricity theft; T represents the preset time period, i.e., one week. This represents the duration of the l-th current data segment within the cluster where the probability of abnormal fluctuations in overall electricity theft is highest. This refers to the percentage of time spent in the cluster, which is the proportion of the current data segment in the total time. The larger the percentage, the more serious the user's electricity theft. The cutoff time is the latest time in the time sequence among the last moments of each current data segment within the cluster where the probability of abnormal fluctuations in electricity theft is highest. The earliest time in the sequence of the start times of each current data segment within the cluster with the highest probability of abnormal fluctuations in electricity theft is the start time of that cluster. This indicates the total temporal distribution range of the current data segments within the cluster. The current data segment contained in the cluster is the time span, and norm is the normalization function.
[0072] This allows us to determine the degree of abnormal electricity theft risk from a user's electricity meter. Based on the obtained degree of abnormal electricity theft risk E, users' electricity meters are sorted from high to low. The management center can then conduct electricity theft risk investigations in order of the degree of abnormal electricity theft risk.
[0073] In summary, this application utilizes clustering to obtain current data with similar fluctuation characteristics. Then, by combining the consistency of data within each cluster with electricity theft data, it identifies the cluster with the largest abnormal fluctuations in electricity theft data, which is also the cluster most likely to exhibit electricity theft (the cluster with the highest overall probability of abnormal fluctuations in electricity theft). Finally, based on the frequency and duration of abnormal fluctuations in electricity theft within the cluster with the highest overall probability of abnormal fluctuations in electricity theft, the degree of electricity theft risk from the electricity meter is assessed. An early warning of electricity theft is then issued based on this degree of risk. Compared to traditional identification methods, the electricity theft behavior identification model established in this application is not limited to the analysis of users' normal electricity consumption patterns and can effectively improve the accuracy of identifying regular electricity theft behavior.
[0074] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0075] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
[0076] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A power meter anomaly detection method for user electricity theft behavior identification, characterized in that, The method comprises: acquiring, by a user's electric energy meter, current and voltage of each time point in a preset time period of the user; constructing a current waveform graph according to the current, and segmenting the current of all time points by using the inflection points in the current waveform graph to obtain different current data segments; obtaining three-dimensional features of a current data segment according to a time length of the current data segment, a current difference of two endpoints and a slope value of each current; clustering the three-dimensional features of each current data segment to obtain different clusters; obtaining a first electricity stealing abnormal fluctuation possibility of a cluster according to an average value of distances between each two current data segments in the cluster; obtaining a second electricity stealing abnormal fluctuation possibility of the cluster according to a change condition of the current in each current data segment in the cluster; obtaining a third electricity stealing abnormal fluctuation possibility of the cluster according to a difference between the change condition of the current in each current data segment in the cluster and a change condition of voltage corresponding to each current data segment; taking an average value of the first electricity stealing abnormal fluctuation possibility, the second electricity stealing abnormal fluctuation possibility and the third electricity stealing abnormal fluctuation possibility of the cluster as a comprehensive electricity stealing abnormal fluctuation possibility of the cluster; obtaining an electricity stealing abnormal risk degree of the electric energy meter of the user according to a time length of each current data segment in a cluster with the largest comprehensive electricity stealing abnormal fluctuation possibility, a time span of the current data segments contained in the cluster and the comprehensive electricity stealing abnormal fluctuation possibility of the cluster. 2.The electric energy meter abnormality detection method for user electricity stealing behavior identification of claim 1, wherein, The method comprises: obtaining an average value of the slope values of each current in a current data segment as an average slope; normalizing the time length of the current data segment, the current difference of two endpoints and the average slope to obtain a normalized time length, a current change degree and a current fluctuation amplitude of the current data segment, and combining the normalized time length, the current change degree and the current fluctuation amplitude to obtain the three-dimensional features of the current data segment. 3.The electric energy meter abnormality detection method for user electricity stealing behavior identification of claim 1, wherein, The method comprises: calculating an inverse of the average value of the distances between each two current data segments in a cluster and normalizing the inverse to obtain the first electricity stealing abnormal fluctuation possibility of the cluster. 4.The electric energy meter abnormality detection method for user electricity stealing behavior identification of claim 1, wherein, The method comprises: obtaining an average value of the slope values of each current in a current data segment as an average slope; normalizing the time length of the current data segment, the current difference of two endpoints and the average slope to obtain a normalized time length, a current change degree and a current fluctuation amplitude of the current data segment, and combining the normalized time length, the current change degree and the current fluctuation amplitude to obtain the three-dimensional features of the current data segment.
5. The electric energy meter anomaly detection method for user electricity stealing behavior identification according to claim 1, characterized in that, The method comprises: The average value of the slope values of the voltage at each time corresponding to one current data segment is taken as the average voltage fluctuation change rate of the current data segment; the absolute value of the difference between the average current fluctuation change rate and the average voltage fluctuation change rate of one current data segment in a cluster is taken as the current-voltage change difference of the current data segment; the average of the current-voltage change differences of all current data segments in the cluster is taken and normalized to obtain the third electricity stealing abnormal fluctuation possibility of the cluster.
6. The electric energy meter anomaly detection method for user electricity stealing behavior identification according to claim 1, characterized in that, The electricity stealing abnormal risk degree of the user is obtained according to the time length of each current data segment in the cluster with the largest comprehensive electricity stealing abnormal fluctuation possibility, the time span of the current data segments included in the cluster and the comprehensive electricity stealing abnormal fluctuation possibility of the cluster, and includes: The earliest one of the starting time of each current data segment in the cluster with the largest comprehensive electricity stealing abnormal fluctuation possibility is taken as the starting time of the cluster; the latest one of the last time of each current data segment in the cluster with the largest comprehensive electricity stealing abnormal fluctuation possibility is taken as the ending time of the cluster; the difference between the ending time and the starting time is obtained and normalized to obtain the time span of the current data segments included in the cluster; the sum of the time length of each current data segment in the cluster with the largest comprehensive electricity stealing abnormal fluctuation possibility is compared with a preset time period to obtain the time length proportion of the cluster; the comprehensive electricity stealing abnormal fluctuation possibility of the cluster with the largest comprehensive electricity stealing abnormal fluctuation possibility, the time length proportion and the time span of the current data segments included in the cluster are multiplied to obtain the electricity stealing abnormal risk degree of the user.
Citation Information
Patent Citations
Stability evaluation method for operation process of electric energy meter
CN118152836A
Intelligent sensing and identifying method for circuit fault of semiconductor hybrid solid-state circuit breaker
CN120597150A