Comprehensive alarm grading processing method and platform based on multi-source heterogeneous data fusion

By using a comprehensive alarm classification and processing method that integrates multi-source heterogeneous data, the problems of redundant alarm information and false alarms/missed alarms in generator sets have been solved, achieving efficient fault diagnosis and safe equipment operation.

CN121259986APending Publication Date: 2026-01-02GD POWER DEVELOPMENT CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511505968.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Existing alarm processing methods for generator sets cannot effectively integrate heterogeneous data from multiple sources, leading to false alarms, missed alarms, and information redundancy, making it difficult to meet the needs of high reliability and high intelligence in operation and maintenance management.

Method used

A comprehensive alarm classification and processing method is adopted, which integrates multi-source heterogeneous data fusion, including data acquisition, noise filtering, hierarchical parsing, synchronous modeling of data structure, real-time data stream analysis, trend fitting, trend change detection and security threat level assessment, to generate standardized alarm forms and make adaptive emergency early warning decisions.

Benefits of technology

It enables comprehensive alarm classification and processing for generator sets, reduces false alarm rate, improves fault diagnosis accuracy, supports root cause analysis and precise maintenance, ensures safe equipment operation, and reduces the burden of manual monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121259986A_ABST
    Figure CN121259986A_ABST
Patent Text Reader

Abstract

The invention relates to the field of generator set grading early warning, in particular to a comprehensive alarm grading processing method and platform based on multi-source heterogeneous data fusion. The method comprises the following steps: collecting a multi-source heterogeneous data stream of a generator set, and carrying out noise filtering to obtain a filtered heterogeneous data stream; performing hierarchical analysis on the generator set, performing data structure synchronous modeling based on the filtering heterogeneous data stream, and constructing a data asset map; performing real-time data flow analysis on the data asset atlas, performing data flow trend fitting, and constructing a data trend dynamic result; trend sudden change detection and equipment fault inference are carried out on the data trend dynamic result, and all associated data streams of abnormal fault points are extracted; and performing security threat level dynamic evaluation based on all the associated data streams, and performing adaptive emergency early warning decision processing. According to the invention, emergency disposal efficiency and decision scientificity are improved, manual monitoring pressure is reduced, and safe operation of equipment is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of generator set hierarchical early warning, and in particular to a comprehensive alarm hierarchical processing method and platform based on multi-source heterogeneous data fusion. Background Technology

[0002] During generator unit operation, the equipment generates a large amount of real-time monitoring data, such as temperature, pressure, vibration, current, voltage, speed, and oil level. This data originates from different types of sensors and monitoring systems, exhibiting "multi-source heterogeneity" characteristics, including inconsistent sampling frequencies, diverse data structures, and varying data quality. Various abnormal states that may occur during unit operation, such as equipment aging, system disturbances, control failures, and external environmental interference, can trigger complex alarm messages. These alarm messages may occur independently or be interconnected and mutually influential, resulting in a large number of alarm signals of varying levels and information redundancy, posing a significant challenge to the judgment and decision-making of on-site maintenance personnel. Traditional alarm handling methods often employ static threshold settings and segmented monitoring, relying solely on alarm information generated by a single sensor or subsystem for response. This method is not only prone to false alarms, missed alarms, and duplicate alarms, but also fails to effectively integrate and hierarchically identify alarms when facing correlated faults under complex operating conditions. In addition, existing systems generally lack the ability to intelligently analyze alarm information, and cannot achieve dynamic evaluation, cause tracing and trend prediction of alarm events, making it difficult to meet the high reliability and high intelligence operation and maintenance management requirements of modern generator sets. Summary of the Invention

[0003] To address the aforementioned technical problems, this invention proposes a comprehensive alarm classification processing method and platform based on multi-source heterogeneous data fusion, thereby resolving at least one of the aforementioned technical issues.

[0004] To achieve the above objectives, this invention provides a comprehensive alarm classification processing method based on multi-source heterogeneous data fusion, comprising the following steps:

[0005] Step S1: Collect multi-source heterogeneous data streams from the generator set, perform noise filtering, and obtain filtered heterogeneous data streams;

[0006] Step S2: Perform hierarchical analysis of the generator set and synchronously model the data structure based on the filtered heterogeneous data stream to construct a data asset map;

[0007] Step S3: Perform real-time data flow analysis on the data asset map, fit the data flow trend, and construct dynamic data trend results;

[0008] Step S4: Detect sudden changes in the data trend and infer equipment faults, and extract all associated data streams of abnormal fault points;

[0009] Step S5: Based on all the associated data streams, perform dynamic assessment of security threat levels and adaptive emergency warning decision processing.

[0010] Preferably, step S1 specifically involves the following steps:

[0011] Establish a unified data interface standard for generator sets; collect multi-source heterogeneous data streams based on the unified data interface standard;

[0012] The timestamp format of the multi-source heterogeneous data stream is identified, and time consistency processing is performed to obtain a timestamp-standardized data stream;

[0013] Detect the out-of-limit data of the timestamp-standardized data stream and calculate the rate of change of the data;

[0014] Based on the out-of-limit data and the rate of change of the data, abnormal data removal is performed to obtain an abnormal optimized heterogeneous data stream.

[0015] High-frequency sensor noise filtering is applied to the abnormal optimized heterogeneous data stream to obtain the filtered heterogeneous data stream.

[0016] Preferably, the multi-source heterogeneous data stream includes DCS, TCS, auxiliary network, NCS, video surveillance, intelligent monitoring panel and fire detection data.

[0017] Preferably, step S2 specifically involves the following steps:

[0018] The generator set is analyzed hierarchically to extract a four-layer architecture; the four-layer architecture of the generator set includes the generator set, system, equipment and measuring points;

[0019] Based on the four-layer architecture of the generator set, data association matching is performed on the filtered heterogeneous data stream to obtain the matching relationship between the structure and the data source;

[0020] Based on the matching relationship, a multi-level retrieval index mapping is performed to construct a multi-level data retrieval architecture;

[0021] The logical structure of the generator set's four-layer architecture is analyzed, and the data structure is synchronously modeled based on the multi-layer data retrieval architecture to construct a data asset graph.

[0022] Preferably, step S3 specifically involves the following steps:

[0023] Define the length of the multi-scale time period and generate analysis time windows at multiple scales;

[0024] Real-time data stream analysis is performed on the data asset map based on the analysis time window to generate data stream features at multiple time scales; the data stream features include short-term fluctuations, medium-term changes, and long-term trends.

[0025] Data flow trend fitting is performed on the data flow features to construct a data flow trend curve;

[0026] The data stream is smoothed and confidence intervals are calculated to construct dynamic results of data trends.

[0027] Preferably, the specific steps of step S4 are as follows:

[0028] Perform trend abruptness detection on dynamic data trends and mark trend abruptness points;

[0029] Calculate the magnitude and timing of the trend abrupt change points;

[0030] Based on the magnitude and timing of the changes, analyze the change patterns and identify the change patterns at abrupt change points.

[0031] Based on the change pattern of the mutation point, normal operation changes and equipment failures are inferred. When the equipment failure is determined, all associated data streams of the abnormal failure point are extracted.

[0032] Preferably, the specific steps of step S5 are as follows:

[0033] Based on all the associated data streams, the physical location of the physical unit is determined to obtain the physical location information of the faulty equipment.

[0034] Identify faulty equipment nodes and fault types based on the physical location information of the faulty equipment;

[0035] Based on the faulty device node and fault type, a dynamic assessment of the security threat level is performed to generate a fault risk level.

[0036] Standardized alarm notices are generated based on the fault risk level, and adaptive emergency warning decision-making is performed.

[0037] Preferably, a dynamic assessment of the security threat level is performed based on the faulty device node and fault type to generate a fault risk level, wherein the fault risk level includes a first-level risk level, a second-level risk level, a third-level risk level, and a fourth-level risk level. The specific determination of the fault risk level includes:

[0038] When the faulty equipment node is a core component of the generator set, including the generator rotor, stator, main bearing, and excitation system; and the fault type is high temperature, short circuit, mechanical fracture, oil pressure loss, or arc discharge, a Level 1 risk level is generated.

[0039] When the faulty equipment node is an important functional component, including the cooling system, water pump, oil pump, speed control system, and main control relay, and the fault type is leakage, overload, abnormal vibration, or temperature rise, a level 2 risk level is generated.

[0040] When the faulty equipment node is an auxiliary device, including the lubrication system, sensors, and measurement and control unit; and the fault type is signal drift, minor blockage, or slight overheating, a three-level risk level is generated;

[0041] When the faulty node is a monitoring or communication node, including data acquisition modules and communication links; and the fault type is transient signal loss or sensor calibration deviation, a four-level risk level is generated.

[0042] Preferably, the standardized alarm forms include Class I, Class II, Class III and Class IV alarm forms;

[0043] In addition, the generation of standardized alarm orders based on fault risk level specifically means: generating corresponding standardized alarm orders based on fault risk level, that is, level 1 risk level corresponds to type 1 alarm order, level 2 risk level corresponds to type 2 alarm order, level 3 risk level corresponds to type 3 alarm order, and level 4 risk level corresponds to type 4 alarm order.

[0044] The adaptive emergency early warning decision processing specifically involves: triggering an emergency broadcast mechanism for a type of alarm, uploading the information to the cloud platform, and contacting maintenance personnel;

[0045] The second type of alarm triggers the information push mechanism and sends it to maintenance personnel for confirmation.

[0046] For Category III and IV alarms, an abnormal event information stream for the generator set is generated and saved to the historical alarm log.

[0047] This specification also provides a comprehensive alarm classification and processing platform based on multi-source heterogeneous data fusion, used to execute the comprehensive alarm classification and processing method based on multi-source heterogeneous data fusion as described above, including:

[0048] The data acquisition module performs noise filtering on the multi-source heterogeneous data streams acquired from the generator set to obtain a filtered heterogeneous data stream.

[0049] The structure analysis module is based on hierarchical analysis of generator sets and synchronous modeling of data structure based on filtered heterogeneous data streams to construct a data asset map.

[0050] The data flow analysis module performs real-time data flow analysis on the data asset map, fits data flow trends, and constructs dynamic data trend results.

[0051] The mutation detection module detects trend mutations and infers equipment faults based on dynamic results of data trends, and extracts all associated data streams of abnormal fault points.

[0052] The graded early warning processing module is used to dynamically assess the security threat level based on all the associated data streams and to perform adaptive emergency early warning decision processing.

[0053] The beneficial effects of this invention are specifically as follows: It comprehensively acquires heterogeneous data from multiple sources, including sensors, monitoring systems, operation logs, and environmental monitoring, ensuring the multi-dimensionality and completeness of information sources. Through noise filtering, it effectively reduces random interference and measurement errors in the data, improving data stability and reliability. It forms high-quality basic data input, avoiding misjudgments and instability caused by data noise in subsequent analysis and modeling. Through hierarchical analysis, the complex system structure of the generator set can be decomposed into multiple levels (such as equipment layer, component layer, and sensor layer), achieving clear logical division. Synchronous modeling ensures that data from different sources and with different structures can be integrated within a unified data framework, solving the problem of direct interface between heterogeneous data. The constructed data asset map achieves a panoramic mapping of equipment, components, and data, providing a foundation for subsequent data traceability, status monitoring, and knowledge association. Through real-time data stream analysis, it enables dynamic monitoring of the generator set's operating status, improving sensitivity to anomalies and potential hazards. Trend fitting can capture the changing patterns of equipment operating parameters, thereby identifying potential deterioration trends or performance degradation characteristics. The generated dynamic data trend results provide a quantitative and traceable basis for subsequent fault prediction and early warning decisions. Trend mutation detection enables rapid identification of critical changes from normal to abnormal operating conditions, avoiding the lag of traditional static threshold detection. The fault inference mechanism combines multi-source data for cross-validation, improving fault diagnosis accuracy and reducing false alarm rates. By extracting the associated data streams of abnormal fault points, multi-dimensional tracing of fault causes is possible, supporting root cause analysis and precise maintenance. Safety threat level assessment quantifies and classifies risks of different types and severity, forming a hierarchical alarm mechanism to avoid information overload caused by "full alarms." The dynamic assessment mechanism allows the system to automatically adjust alarm levels according to changes in the operating environment and data, ensuring real-time assessment and flexibility. Adaptive emergency warning decision processing intelligently matches different response strategies based on assessment results, improving emergency response efficiency and the scientific nature of decision-making. Ultimately, this achieves comprehensive alarm classification processing for generator sets, ensuring safe equipment operation while reducing the burden of manual monitoring. Attached Figure Description

[0054] Figure 1 This is a flowchart illustrating the steps of a comprehensive alarm classification and processing method based on multi-source heterogeneous data fusion according to the present invention.

[0055] Figure 2 This is a detailed flowchart illustrating the implementation steps of step S1.

[0056] Figure 3 This is a detailed flowchart illustrating the implementation steps of step S2;

[0057] Figure 4 This is a flowchart illustrating the detailed implementation steps of step S3. Detailed Implementation

[0058] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.

[0059] This application provides a comprehensive alarm classification processing method and platform based on multi-source heterogeneous data fusion. The executing entities of the comprehensive alarm classification processing method and platform based on multi-source heterogeneous data fusion include, but are not limited to, mechanical equipment, data processing platforms, cloud server nodes, network upload devices, etc., which can be considered as general computing nodes in this application. The data processing platform includes, but is not limited to, at least one of an audio-visual management system, an information management system, and a cloud-based data management system.

[0060] Please see Figures 1 to 4 This invention provides a comprehensive alarm classification processing method based on multi-source heterogeneous data fusion, comprising the following steps:

[0061] Step S1: Collect multi-source heterogeneous data streams from the generator set, perform noise filtering, and obtain filtered heterogeneous data streams;

[0062] Step S2: Perform hierarchical analysis of the generator set and synchronously model the data structure based on the filtered heterogeneous data stream to construct a data asset map;

[0063] Step S3: Perform real-time data flow analysis on the data asset map, fit the data flow trend, and construct dynamic data trend results;

[0064] Step S4: Detect sudden changes in the data trend and infer equipment faults, and extract all associated data streams of abnormal fault points;

[0065] Step S5: Based on all the associated data streams, perform dynamic assessment of security threat levels and adaptive emergency warning decision processing.

[0066] In the embodiments of the present invention, see Figure 1 This is a flowchart illustrating the steps of a comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to the present invention. In this example, the steps of the comprehensive alarm classification processing method based on multi-source heterogeneous data fusion include:

[0067] Step S1: Collect multi-source heterogeneous data streams from the generator set, perform noise filtering, and obtain filtered heterogeneous data streams.

[0068] In this embodiment, control parameter data streams from the generator set's DCS are collected, including key operating parameters such as turbine speed, main steam pressure, and generator power. The sampling frequency is set to 100Hz, and data transmission uses the Modbus TCP protocol. Simultaneously, protection signal data from the TCS is collected, covering safety parameters such as overspeed protection, vibration protection, and axial displacement protection. The sampling frequency is 1kHz to ensure rapid response characteristics. Auxiliary equipment operating data from the auxiliary network, such as the status information of circulating water pumps, feed water pumps, and air compressors, are acquired, with a sampling frequency of 10Hz. Network monitoring data from the NCS is accessed to monitor network health parameters such as communication link status, data transmission latency, and network packet loss rate. Image data streams from video surveillance are integrated, and visual features of equipment operating status are extracted using computer vision technology, with a frame rate set to 25fps. Comprehensive analysis results from the intelligent monitoring panel and alarm signals from fire detection are also collected. The acquired multi-source heterogeneous data were preprocessed. First, the data format was standardized, converting data from different protocols and formats into a standard time series format. Then, a Kalman filter algorithm was used to process sensor measurement noise, with the filter parameters set to process noise variance Q=0.01 and measurement noise variance R=0.1. A median filter was used to remove impulse noise, with a window size of 5 sampling points. For electromagnetic interference noise, a Butterworth low-pass filter was used, with the cutoff frequency set to twice the signal frequency and the filter order set to 4th order. Finally, a high-quality filtered heterogeneous data stream with a signal-to-noise ratio improved by 15-20dB was obtained.

[0069] Step S2: Perform hierarchical analysis of the generator set, and synchronously model the data structure based on the filtered heterogeneous data stream to construct a data asset map.

[0070] In this embodiment, the generator set is systematically analyzed in a hierarchical structure, and a four-level hierarchical architecture is constructed: the unit level includes two main units, Unit 1 and Unit 2; the system level is subdivided into eight main systems, including steam turbine, boiler, generator, and auxiliary systems; the equipment level covers 156 key devices such as steam turbine body, speed control, and lubricating oil; and the measurement point level includes more than 5,000 monitoring points of types such as temperature, pressure, vibration, and flow. Data structure synchronous modeling is performed based on filtered heterogeneous data streams. Neo4j graph database is used as the storage engine to establish an entity-relationship-attribute triple model. Entity node types are defined as four types: Unit, System, Equipment, and Point. Relationship types include 12 semantic relationships such as Contains, Connects, Effects, and Monitors. Attribute information is configured for each entity node: Unit nodes include attributes such as capacity, commissioning date, and manufacturer; System nodes include attributes such as name, type, affiliated unit, commissioning date, and rated capacity; Equipment nodes include attributes such as model, manufacturer, rated parameters, installation location, and safety level; and Point nodes include attributes such as measurement range, accuracy level, and alarm threshold.

[0071] The topology of the data asset graph is constructed, and the force-directed layout algorithm is used to optimize the node positions. The distance between nodes reflects the strength of the association, and the thickness of the edges represents the amount of data flow. A multi-dimensional index system is established, including time index, spatial index, and semantic index, which supports complex queries with millisecond-level response. The graph scale reaches 50,000 nodes and 150,000 edge relationships. After the graph is constructed, consistency verification is performed to ensure that the data integrity reaches more than 99.9%.

[0072] Step S3: Perform real-time data flow analysis on the data asset map, fit the data flow trend, and construct dynamic results of the data trend.

[0073] In this embodiment, real-time data stream analysis is performed based on the constructed data asset graph. Apache Kafka is used as the streaming data processing platform, configured with 32 partitions and a replication factor of 3 to ensure high availability and fault tolerance. The real-time data processing throughput reaches 1 million records per second, with an average latency controlled within 10 milliseconds. Trend fitting analysis is performed on multi-dimensional time series data using a sliding time window mechanism. The window size is set to 1 hour, and the sliding step size is 1 minute, achieving near real-time trend capture. A combined prediction model is used for data trend fitting, including the ARIMA time series model, the Long Short-Term Memory (LSTM) network, and the Transformer attention mechanism model. The ARIMA model parameters are set to p=3, d=1, and q=2, suitable for parameter trend analysis with good stationarity. The LSTM network structure contains two hidden layers with 128 neurons per layer, a learning rate of 0.001, and a batch size of 64. The Transformer model uses a 6-layer encoder-decoder structure with 8 attention heads and a hidden layer dimension of 512. A multi-scale trend analysis framework was established, with a short-term trend window of 15 minutes to capture operational changes and transient processes; a medium-term trend window of 4 hours to identify equipment performance changes and load fluctuations; and a long-term trend window of 24 hours to monitor equipment aging and performance degradation. A dynamic data trend result display was constructed, including trend curves, confidence intervals, and prediction intervals. Trend fitting accuracy was evaluated using the root mean square error (RMSE), with a target of controlling it within 5% of the original data standard deviation. A trend anomaly metric was established, triggering an anomaly flag when the actual value deviates from the predicted value by more than three times the standard deviation.

[0074] Step S4: Detect sudden changes in the data trend and infer equipment faults, and extract all associated data streams of abnormal fault points.

[0075] In this embodiment, high-precision trend change detection is performed on the dynamic results of data trends. A multi-algorithm fusion detection strategy is adopted, including the Statistical Process Control (SPC) method, the CUSUM change point detection algorithm, and wavelet transform-based change detection. The SPC control chart sets the control limit to 3σ, where σ is the standard deviation of the data. An anomaly is determined when seven consecutive points are on the same side of the mean or two consecutive points exceed the 2σ control limit. The CUSUM algorithm sets the decision interval h to 5σ and the drift δ to 1.5σ. A trend change is identified when the cumulative sum exceeds the decision interval. The wavelet transform uses the Daubechies 4 wavelet basis with a decomposition level of 6. The change point location is detected by the modulus maxima of the wavelet coefficients. Two methods, rule-based reasoning and case-based reasoning, are integrated. The rule base contains 1200 fault diagnosis rules, covering typical fault modes of major equipment such as steam turbines, generators, and boilers. The case base stores 3000 historical fault cases, each containing complete information such as fault phenomena, fault causes, and handling measures. The fault inference confidence level is calculated using a fuzzy logic method, with a confidence threshold of 0.7. Inference results exceeding the threshold are processed in subsequent steps. When a sudden trend change is detected, all associated data streams within a 30-minute time window before and after the abnormal fault point are automatically extracted. The associated range is determined by the topological relationship of the graph, including data from directly connected upstream and downstream equipment, data from related equipment within the same area, and reference data from similar historical operating conditions. The total number of associated data streams is typically between 500 and 2000 measurement points, with 100,000 to 500,000 data records, providing ample information support for comprehensive fault analysis.

[0076] Step S5: Based on all the associated data streams, perform dynamic assessment of security threat levels and adaptive emergency warning decision processing.

[0077] In this embodiment, real-time data streams collected by DCS / TCS / NCS, combined with information such as equipment tag number and measurement point code, are used to automatically associate fault signals with physical equipment, and the physical location of the equipment is accurately located based on a 3D model or BIM platform. The equipment is identified as a core or secondary node based on its functional classification, and the fault type is determined by combining the alarm content, level, and duration.

[0078] After fault identification, a dynamic security threat assessment is conducted based on the importance of the nodes and the severity of the faults, classifying them into four risk levels. The assessment process incorporates historical equipment data, operating load, and alarm logic to ensure the accuracy and reliability of the assessment results.

[0079] Based on the evaluation results, the system automatically generates a standardized alarm sheet, which includes equipment information, alarm details, and handling suggestions, and activates a hierarchical early warning mechanism according to the alarm level to achieve linkage responses such as operation interface prompts, phone / broadcast pushes, etc. High-level alarms will also trigger the recommendation of emergency response plans. The system adaptively adjusts the handling strategy according to the operating conditions, and tracks data changes after fault handling to dynamically optimize the content of the plan, forming a closed-loop risk control mechanism.

[0080] In this embodiment, refer to Figure 2 , which is a schematic diagram of the detailed implementation steps of step S1. In this embodiment, the detailed implementation steps of step S1 include:

[0081] Establish a unified data interface standard for the generator set; collect multi-source heterogeneous data streams based on the unified data interface standard; the multi-source heterogeneous data streams include DCS, TCS, auxiliary network, NCS, video monitoring, intelligent monitoring panel, and fire detection data;

[0082] Identify the timestamp format of the multi-source heterogeneous data stream and perform time consistency processing to obtain a timestamp-standardized data stream;

[0083] Detect the overlimit data of the timestamp-standardized data stream and calculate the data change rate;

[0084] Perform abnormal data elimination processing according to the overlimit data and the data change rate to obtain an abnormally optimized heterogeneous data stream;

[0085] Perform high-frequency sensor element noise filtering on the abnormally optimized heterogeneous data stream to obtain a filtered heterogeneous data stream.

[0086] In this embodiment, the interface protocols of various data sources are standardized. For example, DCS (Distributed Control System) generally uses Modbus or OPC UA protocols, TCS (Turbine Control System) may be based on the IEC 60870 standard, auxiliary network monitoring mostly uses RS485 or CAN bus interfaces, NCS (Network Control System) supports TCP / IP protocols, while video surveillance, intelligent monitoring panels, and fire detection involve RTSP, HTTP, or customized protocols. By establishing a unified interface standard, all heterogeneous data is uniformly encapsulated into a four-tuple data structure with timestamp, device number, data type, and data value, and a unified sampling period (e.g., 100 ms) and data transmission format (e.g., JSON or binary compressed stream) are specified. Under this standard, different data can interact on the same bus, achieving efficient cross-platform integration. Through the interface adaptation module, data from DCS, TCS, auxiliary network, NCS, video surveillance, intelligent monitoring panels, and fire detection are connected to a unified data bus. Each type of data source has different characteristics: for example, DCS and TCS collect generator operating parameters such as speed, power, and steam pressure; auxiliary networks provide voltage, current, and power distribution monitoring signals; NCS provides scheduling and control command data; video surveillance provides real-time video frame streams; intelligent monitoring panels output switch quantities and protection signals; and fire detection provides temperature, smoke, and flame alarm data. During data acquisition, high-frequency data (such as speed and voltage) is sampled at the millisecond level, while low-frequency data (such as fire alarms) is sampled at the second level.

[0087] Because each system operates independently, their timestamp formats and time synchronization mechanisms often differ. For example, DCS uses millisecond timestamps, TCS uses second-level timestamps, video surveillance is based on UTC time, and fire protection uses local time. The timestamp format and benchmark for each type of data are identified, and then unified calibration is performed using Network Time Protocol (NTP) or GPS time synchronization. A timestamp conversion module standardizes all timestamps to a unified UTC millisecond format. Considering network latency and transmission deviation, a sliding window algorithm is used for time alignment, for example, setting a 100 ms window to ensure that data from different sources at the same time correspond in time. The resulting timestamp-standardized data stream provides time-consistent input for subsequent anomaly detection and filtering, avoiding data misjudgment and information inconsistency caused by time drift. Threshold ranges are set according to the generator set and auxiliary network operation specifications; for example, the generator output voltage is rated at 13.8 kV with an allowable fluctuation range of ±5%; the turbine speed is rated at 3000 rpm with an allowable error of ±50 rpm. Real-time threshold judgment is performed on each data point; data exceeding the range is marked as out-of-limit data. Simultaneously, by calculating the difference and rate of change between adjacent sampling points, abnormal abrupt changes can be identified. For example, a 20% increase in current within 10 ms is identified as a rapid fluctuation. By combining over-limit detection and rate of change calculation, potential abnormal operating states or measurement errors can be comprehensively identified.

[0088] Data exceeding thresholds and inconsistent with the physical laws governing equipment operation are marked as anomalous data and replaced using nearest neighbor interpolation or trend fitting. For example, if a sampling point has a voltage value of 15.5 kV, exceeding the normal upper limit, and a neighboring point is around 13.9 kV, linear interpolation is used to correct the data at that point. For rapidly fluctuating anomalous points, smoothing can be achieved using moving averages or Kalman filtering to eliminate non-physical jumps. The resulting optimized heterogeneous data stream not only maintains data continuity and reliability but also avoids misleading subsequent analyses due to outliers, improving overall data quality and stability. After removing anomalous data, the remaining data stream may still be affected by high-frequency sensor noise, especially in high-frequency sampling signals such as current, voltage, and speed. To eliminate high-frequency noise, the data stream needs to be filtered. Filters are designed based on sensor characteristics; for example, a low-pass filter with a cutoff frequency of 2 kHz can be used for a 10 kHz sampling rate current signal to suppress high-frequency noise while preserving the main signal characteristics. For video frame data, time-domain mean filtering is used to reduce inter-frame noise. The filtering process also requires adaptive adjustment of filtering parameters. For example, the filtering intensity should be appropriately reduced when the signal fluctuates drastically to avoid erasing the details of the real signal.

[0089] In this embodiment, see Figure 3 The diagram below illustrates the detailed implementation steps of step S2. In this embodiment, the detailed implementation steps of step S2 include:

[0090] The generator set is analyzed hierarchically to extract a four-layer architecture; the four-layer architecture of the generator set includes the generator set, system, equipment and measuring points;

[0091] Based on the four-layer architecture of the generator set, data association matching is performed on the filtered heterogeneous data stream to obtain the matching relationship between the structure and the data source;

[0092] Based on the matching relationship, a multi-level retrieval index mapping is performed to construct a multi-level data retrieval architecture;

[0093] The logical structure of the generator set's four-layer architecture is analyzed, and the data structure is synchronously modeled based on the multi-layer data retrieval architecture to construct a data asset graph.

[0094] In this embodiment, by analyzing the generator set's operational structure and data acquisition point distribution, it can be decomposed into a four-layer architecture: the generator set layer, the system layer, the equipment layer, and the measurement point layer. The generator set layer, as the top layer, encompasses the overall macroscopic operation of the entire generator set; the system layer is divided into functional modules such as turbine control system (TCS), generator control, distributed control system (DCS), auxiliary network monitoring, and cooling monitoring; the equipment layer is further refined into physical equipment such as pumps, valves, generator bodies, transformers, and cooling systems; and the measurement point layer corresponds to specific sensors, detection instruments, and monitoring interfaces, such as temperature sensors, voltage transformers, current transformers, and fire detectors. The filtered and optimized heterogeneous data stream is then matched with the specific architecture layers. Key attributes, such as equipment number, signal type, sampling timestamp, and signal value, are extracted from each record in the data stream and matched one by one with the entities in the four-layer architecture. For example, if a temperature signal is acquired from a temperature sensor of the generator set's cooling water, the data stream should be assigned to "generator set layer - cooling monitoring module - temperature sensor - sampling point" during the matching process.

[0095] The matching process requires the use of a standardized tagging system, such as a four-level coding method of "unit code - system code - equipment code - measurement point code," to achieve unique identification and rapid matching. Simultaneously, a complete mapping table of the data source needs to be established to ensure accurate traceability during future retrieval and retrieval.

[0096] A hierarchical index mapping relationship is established for each data point. For example, at the unit level, all data can be quickly located by unit number; at the system level, all operating data of related equipment can be retrieved by functional module; at the equipment level, historical and real-time operating information of specific equipment can be locked; and at the measurement point level, the signal flow of a single sensor can be accurately located. To improve retrieval efficiency, a combination of inverted index and hash mapping can be used to ensure millisecond-level response capability even under large-scale data storage and retrieval conditions. Simultaneously, the index architecture needs to support multi-condition combined queries, such as "temperature and pressure data of a certain unit-system-equipment within a specific time range". Using the concept of knowledge graph modeling, units, systems, equipment, and measurement points are defined as nodes, and the membership relationships, functional dependencies, and signal flow directions between nodes are used as edges to construct a globally resolvable network structure. For example, an "inclusion" relationship is established between generator unit nodes and turbine nodes, a "composition" relationship is established between nodes and equipment nodes, and a "monitoring" relationship is established between equipment nodes and measurement point nodes. Through this modeling, the originally scattered data and structural information can be integrated into a unified graph. Subsequently, by combining a multi-layered retrieval architecture, synchronous modeling of data and logic is achieved, enabling the data to be updated in real time and linked for querying within the asset map.

[0097] This case also provides an embodiment: In a thermal power plant, when Unit 1 is operating at full load, the DCS system detects abnormal fluctuations in the boiler water level. The sensor number is BWT-001. Between 08:00 and 08:05, the water level dropped from the normal 950mm to 890mm, a decrease of approximately 60mm, exceeding the set control limit (3σ≈40mm). Simultaneously, the PLC system records an unexpected change in the opening of the main steam regulating valve V-002 during the same time period, suddenly increasing from 65% to 92%, within the normal fluctuation range of ±10%. The vibration monitoring system collects data in real time from the vibration sensor X-003 on the generator main shaft, recording the vibration amplitude once per second. Between 08:02 and 08:06, the vibration increased from 0.12mm to 0.35mm, exceeding the equipment's allowable peak value of 0.3mm, triggering a trend change detection due to cumulative over-limit.

[0098] First, these measuring points are mapped to a four-layer architecture: the boiler water level sensor BWT-001 belongs to the boiler water level control valve equipment and is part of the boiler system; the main steam regulating valve V-002 belongs to the turbine system; and the generator main shaft vibration sensor X-003 belongs to the generator system. All equipment belongs to Unit 1. Through multi-layer index mapping, the system can quickly locate the equipment and system where the alarm measuring point is located. Subsequently, the system automatically extracts historical data for 30 minutes before and after the anomaly point, involving approximately 1,500 measuring points and approximately 300,000 data records, including boiler burner temperature (200–650℃), feedwater pump flow rate (50–120 m³ / h), turbine speed (2990–3000 rpm), and generator stator temperature (80–105℃), etc.

[0099] Correlation analysis using data asset mapping revealed that a drop in boiler water level caused turbine load fluctuations, which in turn triggered abnormal generator shaft vibration. Simultaneously, 15 similar cases were identified in the historical case database, involving boiler water level control valve malfunctions leading to turbine load fluctuations and excessive shaft vibration. It was deduced that the primary cause of this anomaly was insufficient boiler feedwater supply. Based on the equipment importance and the magnitude of the anomaly, the system classified the boiler water level drop as a Level 1 alarm, and the main steam regulating valve malfunction and generator shaft vibration as Level 2 alarms. Automatic handling suggestions were generated, including immediately checking the status of the boiler feedwater pump and control valves, adjusting steam valves to stabilize the load, and continuously monitoring generator vibration.

[0100] In this embodiment, reference Figure 4 The diagram below illustrates the detailed implementation steps of step S3. In this embodiment, the detailed implementation steps of step S3 include:

[0101] Define the length of the multi-scale time period and generate analysis time windows at multiple scales;

[0102] Real-time data stream analysis is performed on the data asset map based on the analysis time window to generate data stream features at multiple time scales; the data stream features include short-term fluctuations, medium-term changes, and long-term trends.

[0103] Data flow trend fitting is performed on the data flow features to construct a data flow trend curve;

[0104] The data stream is smoothed and confidence intervals are calculated to construct dynamic results of data trends.

[0105] In this embodiment, three typical time scales—short-term, medium-term, and long-term—are defined based on the dynamic characteristics of generator unit operation. For example, the short-term time window can be defined as 5 seconds to 1 minute, mainly used to capture rapid fluctuations in real-time operating parameters; the medium-term time window is defined as 10 minutes to 1 hour, used to identify changes in operating condition switching, load adjustment, and equipment response; and the long-term time window is defined as 12 hours to several days or even a week, mainly used to analyze the accumulated trend characteristics of the generator unit during long-term operation. By dividing the time window into multiple scales, a layered interpretation of data characteristics at different levels can be achieved, thereby avoiding the problem of missing trend information caused by a single time scale. Through the signal sampling sequence within the time window, characteristic indicators such as fluctuation amplitude, mean deviation rate, and trend slope are calculated. Under the short-term time window, the data flow characteristics are mainly manifested as rapid fluctuations and instantaneous anomalies, such as the instantaneous rise in cooling water temperature during a sudden load increase; under the medium-term time window, the data flow characteristics can be reflected as slow changes caused by operating condition switching, such as the transitional changes in boiler steam pressure during load adjustment; under the long-term time window, the data flow characteristics are mainly manifested as cumulative trends, such as the slow rise in bearing temperature due to wear. By extracting features at different time scales at the data asset mapping level, multi-level operational status analysis can be achieved, from measurement points to equipment and even the entire unit. Based on time series fitting methods, such as multinomial regression, moving average fitting, or exponential smoothing fitting, trend modeling is performed on data points at different time scales. Short-term trend curves can use low-order multinomial fitting or moving average methods to highlight the directionality of local fluctuations; medium-term trend curves can use weighted regression models to emphasize the trajectory of changes in operating conditions; long-term trend curves typically use exponential smoothing fitting to highlight the gradually accumulating trend. To ensure the reliability of the fitted curves, statistical testing of the residuals is necessary to ensure that the fitting results accurately reflect the actual operating characteristics. For example, when the long-term trend curve of the vibration amplitude of a certain piece of equipment continues to rise and exceeds a preset slope threshold, it can serve as a potential early warning signal.

[0106] After the trend curve is constructed, further smoothing and confidence interval calculations are needed to generate more stable and predictive data trend dynamics. Smoothing aims to remove high-frequency noise interference with trend judgment. Common methods include weighted moving averages and Kalman filtering, which can significantly reduce data fluctuations while maintaining the overall trend. Confidence interval calculation, based on historical fluctuation ranges and residual variance, provides the upper and lower limits of possible future trend fluctuations. For example, at a 95% confidence level, if the predicted range of a temperature trend curve is 85℃~90℃, it means that the temperature of the device is highly unlikely to exceed this range in the future. By combining the trend curve and confidence intervals, not only can a stable description of the current state be provided, but also dynamic predictions of future operating conditions can be generated.

[0107] In this embodiment, step S4 includes the following steps:

[0108] Perform trend abruptness detection on dynamic data trends and mark trend abruptness points;

[0109] Calculate the magnitude and timing of the trend abrupt change points;

[0110] Based on the magnitude and timing of the changes, analyze the change patterns and identify the change patterns at abrupt change points.

[0111] Based on the change pattern of the mutation point, normal operation changes and equipment failures are inferred. When the equipment failure is determined, all associated data streams of the abnormal failure point are extracted.

[0112] In this embodiment, the slope, second derivative, and residual distribution of the trend curve are calculated in real time and compared with preset thresholds. When the slope suddenly increases or reverses within a short period of time and exceeds the set threshold (e.g., the rate of temperature increase exceeds 2°C / minute, or the rate of current change exceeds 5A / second), it can be identified as a trend inflection point. Simultaneously, to avoid misjudgment caused by single-point anomalies, statistical confirmation is also required using multiple sampling points within a sliding window. For example, an inflection point is only marked when all five consecutive sampling points exceed the fluctuation threshold. Marked trend inflection points are recorded with timestamps and associated with specific measurement points, devices, and nodes in the data asset map, enabling global tracking and subsequent analysis of inflection events. The data value of the inflection point is compared with the mean or median of the stable interval before the inflection to obtain the inflection amplitude; simultaneously, the precise time of the inflection is recorded using timestamps. For example, the outlet pressure of a cooling water pump rapidly drops from 0.8 MPa to 0.5 MPa at 10:35, a change of 0.3 MPa, corresponding to an inflection rate of 0.05 MPa / minute. This calculation of magnitude and time points not only quantifies the intensity of mutations but also provides input features for subsequent pattern recognition. Furthermore, the calculation of magnitude and time points can be combined with confidence intervals; when a mutation value exceeds the upper or lower limit of the 95% confidence interval, it can be identified as a high-confidence anomalous mutation. This calculation process transforms the discovery of mutations from a qualitative process to a quantitative one.

[0113] After obtaining the magnitude and timing of the abrupt change, it is necessary to analyze its change patterns to distinguish between different types of operational fluctuations and potential risks. Methods for identifying change patterns include rate characteristic analysis, relative amplitude comparison, and cross-validation of multi-source data. For example, if the pressure value of a device drops sharply within a short period, accompanied by a synchronous decrease in the flow rate signal, it can be analyzed as a change in normal operation caused by load switching; conversely, if the pressure drops sharply but the flow rate does not change accordingly, it may indicate valve jamming or pump damage. Change pattern analysis can also be combined with medium- and long-term trend curves. When a continuous deviation occurs after the abrupt change point without any signs of stabilization, it indicates that the abnormal trend is more likely related to a fault. Change patterns are classified into four categories: normal operating condition fluctuations, periodic operational fluctuations, abnormal fluctuations, and persistent unstable fluctuations. Each category has corresponding judgment logic and confidence levels, thereby achieving high-precision identification of abrupt change points.

[0114] In this embodiment, the change pattern is analyzed based on the change magnitude and time point to identify the change pattern of the abrupt change point. The specific determination logic is as follows:

[0115] (1) Fluctuations under normal operating conditions

[0116] Characteristics: The fluctuations are small in magnitude and short in duration, and the price quickly returns to normal levels after the fluctuations.

[0117] Judgment criteria: The change range is within the allowable range (e.g., temperature change ≤ ±3℃, pressure change ≤ ±0.05MPa, current change ≤ ±5% of rated value); the duration is short (generally less than 1 to 2 minutes); it usually occurs during normal operation phases such as start-up, shutdown, regulating valve operation, or load fine adjustment; the changes at relevant measuring points are consistent, and the system returns to stability after the change.

[0118] Typical scenarios include: turbine load adjustment, cooling pump switching, and voltage fine-tuning.

[0119] (2) Periodic operational fluctuations

[0120] Characteristics: The magnitude and duration of mutations repeat regularly, appearing periodically.

[0121] Judgment criteria: The same type of change occurs repeatedly within a fixed or approximately time interval; the amplitude change is stable and within the range of historical cycle fluctuations; it is usually related to periodic control or automatic adjustment actions; the system can return to normal after each fluctuation.

[0122] Typical scenarios: periodic switching of circulating water pumps, periodic fluctuations in deaerator pressure regulation, and automatic adjustment of boiler combustion.

[0123] (3) Abnormal fluctuations

[0124] Characteristics: The mutation magnitude is significantly beyond the normal range, but the duration is short and recovery is possible after the event.

[0125] Judgment criteria: The change amplitude exceeds the set threshold (e.g., temperature rise > 5℃ / min, pressure drop > 0.1MPa / min); the fluctuation duration is short (generally less than 5 minutes), but the rate of change is significantly higher than the normal adjustment speed; there is no planned operation background (non-start-stop, non-switching); local signal abnormality, which does not appear synchronously at the relevant measuring points.

[0126] Typical scenarios include: instantaneous sensor drift, valve jamming, sudden jumps in control signals, and short-term current surges.

[0127] (4) Persistent instability fluctuations (fault type)

[0128] Characteristics: large fluctuation range, long duration, inability to automatically stabilize, often accompanied by multiple parameter anomalies.

[0129] Judgment criteria: The amplitude is significantly exceeded (e.g., pressure continues to drop >0.3MPa, temperature continues to rise >10℃); the duration is relatively long (more than 10 minutes or has not recovered to a stable value); there is no operation record and it is accompanied by abnormalities at other measuring points (e.g., vibration, current); the trend continues to deviate from the baseline, showing an unstable or deteriorating trend.

[0130] Typical scenarios include equipment failures such as decreased cooling water pump efficiency, bearing overheating, steam seal leakage, and generator current imbalance.

[0131] After pattern recognition is completed, it is necessary to infer the abrupt events to distinguish between normal operational changes and equipment failures.

[0132] In this embodiment, fluctuations under normal operating conditions and periodic operational fluctuations are determined as normal operation, while abnormal fluctuations and persistent unstable fluctuations are determined as equipment failures.

[0133] When a pattern is determined to be normal operation, it is archived as an operation record; when a pattern matches the characteristics of a device fault, it is determined to be a "sudden fault." At this point, it is necessary to further extract all related data streams of the fault point, including multi-parameter signals from the same device (such as temperature, pressure, and current) and upstream and downstream signals that are logically coupled to the device. Through this data stream extraction, a complete fault evolution chain diagram can be constructed, clarifying the background, scope of impact, and potential propagation paths of the fault.

[0134] In this embodiment, step S5 includes the following steps:

[0135] Based on all the associated data streams, the physical location of the physical unit is determined to obtain the physical location information of the faulty equipment.

[0136] Identify faulty equipment nodes and fault types based on the physical location information of the faulty equipment;

[0137] Based on the faulty device node and fault type, a dynamic assessment of the security threat level is performed to generate a fault risk level.

[0138] Standardized alarm notices are generated based on the fault risk level, and adaptive emergency warning decision-making is performed.

[0139] In this embodiment, the physical location of the generator set is determined through comprehensive analysis of multiple data streams. These data streams typically include equipment operating data, sensor data, control system feedback, and on-site equipment monitoring data. Position sensors (such as GPS positioning systems, RFID tags, or wireless sensor networks) are used to locate each device and its related components. By combining real-time monitoring data from the sensors with the equipment's operating status information, the precise physical location of the faulty device can be confirmed.

[0140] If a device malfunctions, the data stream can indicate its corresponding region, unit, equipment type (such as generator rotor, main bearing, etc.), and even specific component. Fault information includes indicators such as temperature, pressure, current, and vibration. These parameters are acquired through a monitoring system, then compared with known standard operating data of the equipment to identify deviations and infer the specific location of the fault. Through data fusion technology, combined with a 3D positioning model (such as an IoT-based equipment positioning system or BIM technology), precise location of the equipment can be achieved. Through these steps, the physical location information of the faulty equipment is accurately extracted, providing crucial support for subsequent fault diagnosis.

[0141] Node type refers to the functional role of equipment in a generator set, such as generator rotor, main bearing, speed control system, etc.; while fault type refers to the specific form of fault that occurs in the equipment, such as high temperature, short circuit, arc discharge, abnormal vibration, etc. This process mainly relies on real-time monitoring data of the equipment (such as temperature, pressure, current, vibration, etc.), and is analyzed and judged through predetermined threshold models or machine learning models.

[0142] By utilizing data collected from sensors and combining it with the design characteristics of the equipment, fault types are determined through model algorithms. For example, abnormal temperature may indicate overheating, while overload may be related to exceeding power limits. Fault types such as short circuits and mechanical fractures can be identified through current waveforms or vibration sensor data. The analytical methods used in this process include time-series data analysis, frequency domain analysis (FFT analysis), and fault diagnosis methods based on pattern recognition. In experiments, machine learning algorithms (such as support vector machines and neural networks) can be trained based on historical operating data of different types of equipment to automatically identify fault types and their corresponding nodes.

[0143] If the temperature sensor detects abnormally high temperatures, the system, based on the equipment model, determines that the fault occurs in the generator's main bearing or rotor and automatically identifies it as a high-temperature fault. If abnormal vibration signals are detected, it may indicate a mechanical fracture or overload fault.

[0144] Based on the identified faulty equipment nodes and fault types, the process proceeds to the security threat level assessment phase. In this phase, the fault is classified according to its severity, the importance of the faulty node, and its impact on the entire unit. This process typically involves quantitative analysis based on fault impact assessment models (such as fault tree analysis and risk matrices).

[0145] In this embodiment, a dynamic assessment of the security threat level is performed based on the faulty device node and the fault type to generate a fault risk level. The specific assessment criteria are as follows:

[0146] When the faulty equipment node is a core component of the generator set, including the generator rotor, stator, main bearing, and excitation system; and the fault type is high temperature, short circuit, mechanical fracture, oil pressure loss, or arc discharge, a Level 1 risk level is generated.

[0147] When the faulty equipment node is an important functional component, including the cooling system, water pump, oil pump, speed control system, and main control relay, and the fault type is leakage, overload, abnormal vibration, or temperature rise, a level 2 risk level is generated.

[0148] When the faulty equipment node is an auxiliary device, including the lubrication system, sensors, and measurement and control unit; and the fault type is signal drift, minor blockage, or slight overheating, a three-level risk level is generated;

[0149] When the faulty node is a monitoring or communication node, including data acquisition modules and communication links; and the fault type is transient signal loss or sensor calibration deviation, a four-level risk level is generated.

[0150] In this embodiment, Level 1 risk level represents the highest threat level, requiring immediate emergency response; Level 2 risk level indicates a relatively high risk, requiring rapid confirmation and intervention by maintenance personnel; Level 3 risk level mainly represents minor deviations and serves as a reference and alert; Level 4 risk level pertains to status events during normal equipment operation and is primarily used for maintenance log recording. This four-layer structure ensures that alarms are neither excessively redundant nor overlook critical risks.

[0151] During the assessment, the weights of fault nodes and fault types need to be dynamically adjusted based on historical experience and the importance of the equipment. By combining simulation experiments with historical data, the assessment criteria for each fault can be adjusted. For example, in the case of high-temperature faults, the risk assessment of the rotor and stator may be more severe than that of high-temperature faults in auxiliary equipment. Therefore, the risk assessment model is dynamically adjusted, and the fault risk level is updated in real time using real-time monitoring data.

[0152] In addition, the risk level can be determined by combining the parameter fluctuation range, duration, and importance of the faulty equipment. For example, if the temperature signal exceeds the rated value by more than 30% and lasts for more than 5 minutes, a level 1 risk level is generated; if it only exceeds the rated value by 10% and lasts for less than 2 minutes, a level 3 or level 4 risk level is generated.

[0153] Based on the risk level of the fault, the system automatically generates standardized alarm reports and makes adaptive emergency warning decisions. Standardized alarm reports typically include information such as the specific equipment node experiencing the fault, the fault type, the risk level, recommended emergency response measures, and the priority response level.

[0154] In this embodiment, the specific steps for generating standardized alarm orders based on fault risk levels and performing adaptive emergency early warning decision processing are as follows:

[0155] The standardized alarm forms include Class I, Class II, Class III and Class IV alarm forms;

[0156] The adaptive emergency early warning decision processing specifically involves: triggering an emergency broadcast mechanism for a type of alarm, uploading the information to the cloud platform, and contacting maintenance personnel;

[0157] The second type of alarm triggers the information push mechanism and sends it to maintenance personnel for confirmation.

[0158] For Category III and IV alarms, an abnormal event information stream for the generator set is generated and saved to the historical alarm log.

[0159] In this embodiment, after the fault risk level is calculated, the results need to be standardized into alarm forms of a unified format to facilitate hierarchical management and response. Specifically, alarm forms are divided into four categories based on the fault node and fault type: Category I alarm forms correspond to extremely high risk (Level 1 risk), Category II alarm forms correspond to high risk (Level 2 risk), Category III alarm forms correspond to medium risk (Level 3 risk), and Category IV alarm forms correspond to low risk (Level 4 risk). This hierarchical standard ensures differentiated measures are taken under different severity conditions. Standardization of alarm forms also includes a unified content format, which must include the faulty device name, physical location information, fault type, propagation path, impact range, risk level, and timestamp information.

[0160] In this embodiment, Level 1 risk level corresponds to Class 1 alarm, Level 2 risk level corresponds to Class 2 alarm, Level 3 risk level corresponds to Class 3 alarm, and Level 4 risk level corresponds to Class 4 alarm.

[0161] When an alarm is classified as Class 1, an emergency response must be triggered immediately. The alarm information is pushed in real-time to the unit's local system's audible and visual alarms, generating voice announcements and light alerts to ensure on-site operators receive the abnormal signal immediately. Simultaneously, the alarm information, including all associated data streams, device physical location, and propagation path details, is packaged and uploaded to the cloud platform via a high-speed communication interface. Upon receiving the data, the cloud platform automatically synchronizes the information to the operations and maintenance center and initiates a remote linkage mechanism to directly contact the responsible operations and maintenance personnel. In terms of experimental parameters, to ensure controllable latency, information upload and notification triggering must be completed within 5 seconds, and the voice announcement must cover the control room and critical operating areas. This step, through a dual local and remote mechanism, ensures that major risk events can be handled quickly and accurately, avoiding greater losses due to human error delays.

[0162] When an alarm is classified as Category II (high risk but not extremely high risk), a relatively mild handling method will be adopted. The alarm will be sent to the mobile terminal or control panel of relevant maintenance personnel via an information push mechanism. The push notification includes the equipment number, location, fault type, current operating parameters, and historical trends, allowing maintenance personnel to quickly determine whether immediate intervention is necessary. For example, if a cooling water pump experiences current fluctuations but remains within a controllable range, a Category II alarm will be generated and a notification will be pushed, prompting maintenance personnel to confirm and conduct on-site inspection. The push mechanism is generally based on local area network communication and mobile messaging services, ensuring message delivery within 30 seconds. After receiving the push notification, maintenance personnel can confirm via their terminal; the platform will automatically record the confirmation time and processing status, forming a closed loop.

[0163] When an alarm is classified as Category III or IV, it indicates that the anomaly is in the medium or low risk range. The platform will not trigger immediate manual intervention. Instead, it will generate an information stream of generator set anomaly events, recording the alarm content and saving it to the historical alarm log. The information stream includes the alarm time, equipment location, abnormal parameter values, risk level, and trend curve. Category III alarms are mainly used for suggestive monitoring, such as minor voltage fluctuations or short-term sensor deviations; Category IV alarms are mostly for low-risk situations, such as momentary signal loss or data packet delays. Saving this information is crucial for subsequent maintenance work. On one hand, it provides data support for long-term equipment health assessment; on the other hand, in the event of a major failure, historical logs can be used to trace early signs and assist in root cause analysis. The log storage period can be set to at least five years, with a storage frequency ranging from milliseconds to seconds to meet the traceability needs of different equipment types. Through this mechanism, Category III and IV alarms can play a role in long-term monitoring and knowledge accumulation without disrupting real-time operation.

[0164] In this embodiment, a comprehensive alarm classification and processing platform based on multi-source heterogeneous data fusion is provided for executing the comprehensive alarm classification and processing method based on multi-source heterogeneous data fusion as described above, including:

[0165] The data acquisition module performs noise filtering on the multi-source heterogeneous data streams acquired from the generator set to obtain a filtered heterogeneous data stream.

[0166] The structure analysis module is based on hierarchical analysis of generator sets and synchronous modeling of data structure based on filtered heterogeneous data streams to construct a data asset map.

[0167] The data flow analysis module performs real-time data flow analysis on the data asset map, fits data flow trends, and constructs dynamic data trend results.

[0168] The mutation detection module detects trend mutations and infers equipment faults based on dynamic results of data trends, and extracts all associated data streams of abnormal fault points.

[0169] The graded early warning processing module is used to dynamically assess the security threat level based on all the associated data streams and to perform adaptive emergency early warning decision processing.

[0170] Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of the equivalents of the application are intended to be included within the invention.

[0171] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein are implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.

Claims

1. A comprehensive alarm classification processing method based on multi-source heterogeneous data fusion, characterized in that, Includes the following steps: Step S1: Collect multi-source heterogeneous data streams from the generator set, perform noise filtering, and obtain filtered heterogeneous data streams; Step S2: Perform hierarchical analysis of the generator set and synchronously model the data structure based on the filtered heterogeneous data stream to construct a data asset map; Step S3: Perform real-time data flow analysis on the data asset map, fit the data flow trend, and construct dynamic data trend results; Step S4: Detect sudden changes in the data trend and infer equipment faults, and extract all associated data streams of abnormal fault points; Step S5: Based on all the associated data streams, perform dynamic assessment of security threat levels and adaptive emergency warning decision processing.

2. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 1, characterized in that, The specific steps of step S1 are as follows: Establish a unified data interface standard for generator sets; collect multi-source heterogeneous data streams based on the unified data interface standard; The timestamp format of the multi-source heterogeneous data stream is identified, and time consistency processing is performed to obtain a timestamp-standardized data stream; Detect the out-of-limit data of the timestamp-standardized data stream and calculate the rate of change of the data; Based on the out-of-limit data and the rate of change of the data, abnormal data removal is performed to obtain an abnormal optimized heterogeneous data stream. High-frequency sensor noise filtering is applied to the abnormal optimized heterogeneous data stream to obtain the filtered heterogeneous data stream.

3. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 2, characterized in that, The multi-source heterogeneous data streams include DCS, TCS, auxiliary network, NCS, video surveillance, intelligent monitoring panels, and fire detection data.

4. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 1, characterized in that, The specific steps of step S2 are as follows: The generator set is analyzed hierarchically to extract a four-layer architecture; the four-layer architecture of the generator set includes the generator set, system, equipment and measuring points; Based on the four-layer architecture of the generator set, data association matching is performed on the filtered heterogeneous data stream to obtain the matching relationship between the structure and the data source; Based on the matching relationship, a multi-level retrieval index mapping is performed to construct a multi-level data retrieval architecture; The logical structure of the generator set's four-layer architecture is analyzed, and the data structure is synchronously modeled based on the multi-layer data retrieval architecture to construct a data asset graph.

5. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 1, characterized in that, Step S3 is as follows: Define the length of the multi-scale time period and generate analysis time windows at multiple scales; Real-time data stream analysis is performed on the data asset map based on the analysis time window to generate data stream features at multiple time scales; the data stream features include short-term fluctuations, medium-term changes, and long-term trends. Data flow trend fitting is performed on the data flow features to construct a data flow trend curve; The data stream is smoothed and confidence intervals are calculated to construct dynamic results of data trends.

6. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 1, characterized in that, The specific steps of step S4 are as follows: Perform trend abruptness detection on dynamic data trends and mark trend abruptness points; Calculate the magnitude and timing of the trend abrupt change points; Based on the magnitude and timing of the changes, analyze the change patterns and identify the change patterns at abrupt change points. Based on the change pattern of the mutation point, normal operation changes and equipment failures are inferred. When the equipment failure is determined, all associated data streams of the abnormal failure point are extracted.

7. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 1, characterized in that, The specific steps of step S5 are as follows: Based on all the associated data streams, the physical location of the physical unit is determined to obtain the physical location information of the faulty equipment. Identify faulty equipment nodes and fault types based on the physical location information of the faulty equipment; Based on the faulty device node and fault type, a dynamic assessment of the security threat level is performed to generate a fault risk level. Standardized alarm notices are generated based on the fault risk level, and adaptive emergency warning decision-making is performed.

8. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 7, characterized in that, Based on the faulty device node and fault type, a dynamic assessment of the security threat level is performed to generate a fault risk level. This fault risk level includes four levels: Level 1, Level 2, Level 3, and Level 4. The specific determination of the fault risk level includes: When the faulty equipment node is a core component of the generator set, including the generator rotor, stator, main bearing, and excitation system; and the fault type is high temperature, short circuit, mechanical fracture, oil pressure loss, or arc discharge, a Level 1 risk level is generated. When the faulty equipment node is an important functional component, including the cooling system, water pump, oil pump, speed control system, and main control relay, and the fault type is leakage, overload, abnormal vibration, or temperature rise, a level 2 risk level is generated. When the faulty equipment node is an auxiliary device, including the lubrication system, sensors, and measurement and control unit; and the fault type is signal drift, minor blockage, or slight overheating, a three-level risk level is generated; When the faulty node is a monitoring or communication node, including data acquisition modules and communication links; and the fault type is transient signal loss or sensor calibration deviation, a four-level risk level is generated.

9. The comprehensive alarm classification processing method based on multi-source heterogeneous data fusion according to claim 7, characterized in that, The standardized alarm forms include Class I, Class II, Class III and Class IV alarm forms; In addition, the generation of standardized alarm orders based on fault risk level specifically means: generating corresponding standardized alarm orders based on fault risk level, that is, level 1 risk level corresponds to type 1 alarm order, level 2 risk level corresponds to type 2 alarm order, level 3 risk level corresponds to type 3 alarm order, and level 4 risk level corresponds to type 4 alarm order. The adaptive emergency early warning decision processing specifically involves: triggering an emergency broadcast mechanism for a type of alarm, uploading the information to the cloud platform, and contacting maintenance personnel; The second type of alarm triggers the information push mechanism and sends it to maintenance personnel for confirmation. For Category III and IV alarms, an abnormal event information stream for the generator set is generated and saved to the historical alarm log.

10. A comprehensive alarm hierarchical processing platform based on multi-source heterogeneous data fusion, characterized in that, The method for implementing the comprehensive alarm classification processing method based on multi-source heterogeneous data fusion as described in any one of claims 1-9 includes: The data acquisition module performs noise filtering on the multi-source heterogeneous data streams acquired from the generator set to obtain a filtered heterogeneous data stream. The structure analysis module is based on hierarchical analysis of generator sets and synchronous modeling of data structure based on filtered heterogeneous data streams to construct a data asset map. The data flow analysis module performs real-time data flow analysis on the data asset map, fits data flow trends, and constructs dynamic data trend results. The mutation detection module detects trend mutations and infers equipment faults based on dynamic results of data trends, and extracts all associated data streams of abnormal fault points. The graded early warning processing module is used to dynamically assess the security threat level based on all the associated data streams and to perform adaptive emergency early warning decision processing.