Power industry compliance treatment method and system based on multi-module cooperation

By adopting a multi-module collaborative approach to compliance governance in the power industry, the problems of insufficient full lifecycle management and isolated module operation in existing technologies have been solved, achieving full lifecycle security management and dynamic defense, and improving the compliance and security of the power industry.

CN121526529AActive Publication Date: 2026-02-13BEIJING BRON S&T
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511726993.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-24
Publication Date
2026-02-13
Estimated Expiration
2045-11-24

AI Technical Summary

Technical Problem

Existing technologies in the power industry lack full lifecycle management of generative artificial intelligence, which cannot effectively prevent models from developing biases or violations due to faulty data. Furthermore, each safety module operates in isolation, making it difficult to form a systematic and closed-loop compliance governance system, and thus failing to meet the needs of complex application scenarios with high safety requirements.

Method used

By configuring qualification and compliance modules, building process protection modules, establishing risk operation systems, and integrating multimodal audit engines, security knowledge bases, and adversarial optimization modules, information interaction and collaborative linkage between modules are achieved, forming a closed-loop governance process.

Benefits of technology

It achieves full lifecycle security control from data processing to service deployment, improves compliance, stability and regulatory oversight, significantly reduces compliance and violation risks, and enhances the system's dynamic defense capabilities and risk identification accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121526529A_ABST
    Figure CN121526529A_ABST
Patent Text Reader

Abstract

The invention provides a power industry compliance management method and system based on multi-module collaboration, and the method achieves the automatic verification and dynamic management of the access qualification of an operation main body through configuring a qualification compliance block to be in butt joint with a data grading and classification system. A process protection module is constructed, a supervision strategy analysis engine is embedded in data processing, model training and service deployment stages, compliance rules are extracted and executed in real time, and context-aware compliance verification is carried out in combination with a multi-modal auditing engine and a security knowledge base; a risk operation system is established, a model operation state and external threats are continuously monitored, and a red-blue adversarial optimization module is linked to generate an attack sample to improve defense capability; and a closed-loop treatment process is formed through cooperation of multiple modules. According to the method, the compliance response efficiency is improved, the cross-department cooperation capability is enhanced, and intelligent compliance treatment and self-adaptive safety protection of the whole life cycle of the power industry are realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of artificial intelligence and power system safety collaborative management, and in particular to a power industry compliance management method and system based on multi-module collaboration. BACKGROUND

[0002] In the prior art, the content review of generative artificial intelligence is mostly concentrated in the single-point detection of the output stage, relying on keyword matching or simple rule filtering, only for post-interception of text content, which is difficult to deal with the security risks of complex multi-modal content. Such methods have obvious shortcomings in critical infrastructure fields such as power: lack of effective control of data input, model training and other early stages, unable to prevent models from producing bias or violating tendencies due to "sick data"; the review engine runs in isolation and is not linked with industry knowledge base and business systems (such as SCADA, EMS), resulting in insufficient semantic understanding in professional scenarios and frequent misjudgment and omissions; in the face of interactive requests involving power grid dispatching, equipment status and other high-security requirements, traditional mechanisms cannot achieve structured analysis and operation constraint checking of operation instructions, and there is a risk of generating misleading suggestions. In addition, existing systems generally ignore the closed-loop utilization of risk data, lack the ability to feed back user feedback and abnormal behavior to training and review optimization, leading to static and rigid security protection. At the same time, enterprise qualification compliance management is still an independent process and does not form dynamic linkage with algorithm filing, security assessment and other links, making it difficult to meet the regulatory requirements of algorithm credibility and full-process traceability in the power industry. Overall, the current technology remains in the "after-the-fact remediation" mode and has not yet built an intelligent security governance system covering the entire life cycle of data, training and deployment, integrating multi-modal review, dynamic knowledge update and red-blue confrontation evolution. SUMMARY

[0003] Therefore, in order to solve the technical problems of non-timely compliance response and non-uniform execution standards caused by scattered data sources, rule update lag and low cross-departmental collaboration efficiency in the compliance management process of the power industry, a power industry compliance management method and system based on multi-module collaboration are proposed The present application protects a power industry compliance management method based on multi-module collaboration, comprising the following steps: step 1, configuring a qualification compliance module to verify and manage the access qualification of the operating subject; step 2, building a process protection module to implement corresponding security control strategies in the data processing stage, model training stage and service deployment stage; step 3, establishing a risk operation system to continuously monitor the internal model running state and respond to abnormal events in the external environment; step 4, integrating multi-modal review engines, security knowledge bases and confrontation optimization modules to realize information interaction and collaborative linkage between modules.

[0004] Further, the qualification and scale module is connected with the data classification system of the power enterprise, and the training data is divided into production control type, management information type and public service type data levels; according to the divided data levels, the corresponding qualification reporting path is automatically matched.

[0005] Further, when it is identified that the model training data is substation inspection image data, it is determined that it belongs to sensitive data, a special record process is triggered, a data desensitization scheme, an access control strategy and a submission requirement of a third-party security evaluation report are generated.

[0006] Further, in the process of constructing the process protection module, a regulatory policy analysis engine is embedded to obtain policy files in real time; natural language processing technology is used to perform semantic analysis on the policy files to extract structured compliance rules; the structured compliance rules are converted into executable verification logic; the verification logic is synchronized to the multi-modal audit engine and the security knowledge base to update the corresponding audit rules.

[0007] Further, the security knowledge base is connected with the energy management system and the power distribution management system of the power enterprise through API to obtain power grid topology, device state and load level data in real time; when the multi-modal audit engine performs compliance verification, the power grid topology, device state and load level data are called as context basis; the process protection module is connected with the algorithm trust registration platform of the power industry to support on-chain storage and verification of model record information; technical documents including model input and output boundary definition, training data source traceability table and security alignment test report are automatically generated; the technical documents are submitted to the industry supervision platform through API for pre-examination.

[0008] Further, in the process of running the risk operation system, the regulatory side feedback instructions are continuously received; the regulatory side feedback instructions are associated with the new attack mode output by the red and blue confrontation optimization module for analysis; based on the results of the association analysis, the compliance check items in the multi-modal audit engine are dynamically updated; when a data poisoning attack behavior against the power load prediction model is detected, the qualification and scale module triggers the review mechanism; the function of the model is suspended through the process protection module, and event reporting information is sent to the industry supervision platform through the API interface.

[0009] Further, the natural language request input by the user is parsed into an operation instruction tree, the SCADA system is linked to verify whether the operation violates the N1 safety criteria, and whether there is an abnormal operation sequence is judged through time series data analysis; the graphical scheduling suggestion output by the model is extracted to extract the power flow distribution and voltage interval parameters, and the compliance is compared with the preset operation boundary.

[0010] Further, inject the regulatory side feedback instructions received in the risk operation system and the detected attack behaviors into the red-blue confrontation optimization module to generate data poisoning attack samples and instruction confusion attack vectors for the power load prediction model; update the defense strategy based on the reinforcement learning algorithm, adjust the model input verification rules and abnormal response threshold; analyze the misjudgment cases of the multi-modal audit engine using the corpus security screening sub-module, and construct a training sample set containing visual camouflage and semantic camouflage composite features; through the rule extraction engine, natural language processing is performed on the accident report and dispatch abnormal record to extract event patterns with time constraint and causal logic; the generated event patterns are embedded in the knowledge graph of the security knowledge base in the form of ontology, and are associated with real-time power grid operation data to realize linked reasoning.

[0011] Further, when the multi-modal audit engine performs the audit operation, for text data in the power system, an integrated power industry sensitive word library is called to identify abnormal semantic combinations, and semantic analysis is performed in combination with the context; for image and / or video stream data, target detection and OCR technology are used to detect whether there is equipment state tampering, illegal labeling or alarm information shielding in the substation inspection video; for audio data, voiceprint recognition is used to distinguish between authorized and unauthorized personnel, and to detect simulated dispatch instructions generated by voice synthesis.

[0012] The application also provides a compliance management system based on multi-module cooperation, comprising: a qualification management module for verifying and managing the legal access qualifications of the operation subject; a process protection module for implementing corresponding security control strategies in the data processing stage, the model training stage and the service deployment stage; a risk operation system module for continuously monitoring the internal model running state and responding to abnormal events in the external environment; by integrating a multi-modal audit engine, a security knowledge base and a confrontation optimization module, information interaction and cooperative linkage between the qualification management module, the process protection module and the risk operation system module are realized.

[0013] The application protects a power industry compliance management method and system based on multi-module cooperation, which realizes automatic verification and dynamic management of the legal access qualification of the operation subject through the configuration qualification module, effectively improving the compliance review efficiency and accuracy of the subject access link; a process protection module is constructed and differential security control strategies are implemented at each stage of data processing, model training and service deployment, realizing the whole life cycle of safe closed-loop control, significantly enhancing the data security and system stability of the key link; a risk operation system is established to continuously monitor the internal model running state and respond to abnormal events in the external environment in time, improving the system's perception and emergency disposal capabilities for potential risks; by integrating multi-modal audit engines, security knowledge bases and counter-optimization modules, information sharing and collaborative linkage between functional units are promoted, and the intelligent decision-making level and adaptive defense capability of the overall system are enhanced; on this basis, relying on the deep cooperation of the qualification module, the process protection module and the risk operation system, a closed-loop management process covering pre-event prevention, in-process control and post-event response is formed, and the compliance management capability and safe operation level of the power industry in complex business scenarios are comprehensively improved. BRIEF DESCRIPTION OF DRAWINGS

[0014] The accompanying drawings are included to provide a further understanding of the application, and constitute a part of the specification, illustrate embodiments of the application, and are used to explain the application, and do not constitute a limitation on the application. In the drawings: Figure 1 : The flowchart of the power industry compliance management method based on multi-module cooperation provided by the embodiments of the application; Figure 2 : The schematic diagram of the power industry compliance management system based on multi-module cooperation provided by the embodiments of the application. DETAILED DESCRIPTION

[0015] In order to make the purpose, technical scheme and advantages of the embodiments of the application more clear, the technical scheme in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only a part of the embodiments of the application, not all the embodiments of the application. The components of the embodiments of the application described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the application provided in the drawings is not intended to limit the scope of the claimed application, but only represents selected embodiments of the application. Based on the embodiments of the application, every other embodiment obtained by those skilled in the art without creative labor belongs to the scope of protection of the application.

[0016] The existing generation AI content review scheme mainly relies on keyword filtering, single modal (such as text) review and manual review mechanism, which has significant technical limitations: first, its review range is limited to the model output stage, and cannot cover the whole life cycle links such as data preparation, model training, service deployment and supervision record, which leads to the difficulty in effectively preventing endogenous security risks; second, it lacks unified review capability for multi-modal content such as images, audios and videos, and cannot cope with diversified content risks in complex application scenarios; third, the sensitive problem processing method is too rigid, usually adopting simple blocking or shielding strategy, lacking classification disposal and compliance answer mechanism, which sacrifices user experience and knowledge service ability while ensuring compliance. In addition, the security modules are running in isolation, lacking of collaborative mechanism, which is difficult to form a systematic and closed-loop compliance management system. Especially in the power industry and other high compliance requirement scenarios, the existing scheme is difficult to meet the comprehensive management needs of legal access, continuous monitoring and dynamic response.

[0017] Based on this, as shown in the Figure 1 The embodiment of the present application provides a power industry compliance management method based on multi-module cooperation, which realizes information interaction and collaborative linkage between each link by configuring qualification compliance module, building process protection module, establishing risk operation system, and integrating multi-modal review engine, security knowledge base and countermeasure optimization module, and finally forming a closed-loop management process. Specifically, it includes the following steps: Step 1, configure the qualification compliance module to verify and manage the legal access qualification of the operation subject; Step 2, build the process protection module, and implement corresponding security control strategies in the data processing stage, model training stage and service deployment stage; Step 3, establish a risk operation system to continuously monitor the internal model running state and respond to abnormal events in the external environment; Step 4, by integrating multi-modal review engine, security knowledge base and countermeasure optimization module, realize information interaction and collaborative linkage between qualification compliance module, process protection module and risk operation system and other modules; based on the cooperative operation of qualification compliance module and other modules, a closed-loop management process is formed.

[0018] The embodiment of the application provides a power industry compliance management method based on multi-module cooperation, which can realize safe management and control of the whole life cycle from data processing to service deployment, ensures that the operation subject has legal access qualification through the qualification module, and improves the compliance basic guarantee capability; the process protection module implements differentiated security strategies in each stage of data processing, model training and service deployment, effectively preventing potential risks in each link; the risk operation system realizes continuous monitoring of the internal operation state of the model and rapid response to external abnormal events, and enhances the dynamic defense capability of the system; the integration of the multi-modal audit engine, the security knowledge base and the confrontation optimization module not only supports joint audit of various content types such as text, image, audio and video, but also continuously optimizes the security of the model through the red-blue confrontation mechanism, and improves the risk identification accuracy; each module forms a closed-loop management process through cooperation and linkage, breaks the problem of module island in the traditional scheme, significantly improves the compliance, stability and supervisability of the power industry AI system in complex environment, and the overall risk prevention and control coverage rate is close to 100%, which greatly reduces the compliance violation risk.

[0019] S101 Configure the qualification module, and verify and manage the legal access qualification of the operation subject. As a pre-control unit of the compliance management of the generative artificial intelligence system in the power industry, the module first verifies whether the power operation enterprise has legal qualifications such as algorithm filing and content service license according to the supervision requirements in the field of key information infrastructure, and establishes a dynamic updated enterprise qualification archive. On this basis, the qualification module further interfaces with the data classification system of the power enterprise, divides the training data into production control type, management information type, public service type and the like, and ensures that the data of different security levels follow the corresponding compliance path in the use process.

[0020] Preferably, according to the divided data level, the corresponding qualification declaration path is automatically matched. When the system identifies that the training data to be used by the model involves a specific business domain, a differentiated approval process is started based on a pre-set classification rule engine.

[0021] For example, for production control type data, the system compulsorily requires completion of network security level protection two or more authentication, and associates the technical clauses in the 'Electric Power Monitoring System Security Protection Regulations' for compliance comparison; for management information type data, an internal authorization approval chain and a data use log audit scheme need to be submitted; and for public service type data, in addition to meeting the basic filing conditions, a public influence evaluation review is also required.

[0022] When the model training data is identified as substation inspection image data, it is determined that it belongs to sensitive data, triggering a special filing process, generating a data desensitization scheme, an access control policy, and a submission requirement for a third-party security assessment report. In specific implementation, the system identifies that such images belong to the "production control II area" category through metadata tags, and immediately activates the high-risk data processing flow, automatically generating a data desensitization implementation scheme containing pixel-level blur processing or local masking strategy, while configuring a fine-grained access permission control matrix to limit authorized operation and maintenance personnel to call related data sets on designated terminals.

[0023] Preferably, the system links with external security evaluation agencies to push the materials under review and track the progress of third-party security assessment reports, ensuring that all prerequisites are met before entering the model training phase. The above mechanism realizes the full-process automation response from data attribute identification to qualification path guidance, ensuring that power AI applications develop in an orderly manner within the legal and compliant framework.

[0024] S102 Build a process protection module to implement corresponding security control strategies in the data processing stage, model training stage, and service deployment stage. As the core defense line of AI governance in the power industry, this module runs through the entire life cycle of generative models, setting measurable, traceable, and auditable security control points at each key link. In the data processing stage, the corpus security screening submodule performs computer automatic review and manual review double filtration on input data, focusing on removing biased, illegal, or sensitive information; in the model training stage, introduce a security alignment mechanism and a red-blue confrontation optimization process to actively find and fix potential vulnerabilities; in the service deployment stage, establish an output content real-time interception and operation behavior trace mechanism to ensure controllable and manageable external service processes.

[0025] Preferably, during the construction of the process protection module, a regulatory policy analysis engine is embedded to obtain policy documents in real time and use natural language processing techniques to perform semantic analysis on the policy documents, extract structured compliance rules, and then convert the structured compliance rules into executable verification logic. The engine continuously captures the latest regulations, notices, and technical guidelines released by regulatory departments, accurately extracts prohibited and restricted clauses such as "prohibition of using AI to generate false load forecasts" and "do not arbitrarily call dispatching instruction data" through named entity recognition and dependency syntax analysis, and converts them into formalized rule items. For example, for the regulation "main transformer overload operation shall not exceed 2 hours", the system automatically generates a time window-constrained time sequence logic judgment condition and injects it into the audit and control process.

[0026] Preferably, the verification logic is synchronized to the multi-modal audit engine and the security knowledge base to update the corresponding audit rules. Among them, the security knowledge base is connected with the EMS energy management system and the DMS power distribution management system of the power enterprise through the API to obtain the power grid topology, device state and load level data in real time, so that the audit decision has the running state perception ability. When the model output involves switching operation suggestion or power flow adjustment scheme, the multi-modal audit engine dynamically calls the actual operation parameters of the current power grid as the context basis in the compliance verification process to judge whether the suggestion violates the N-1 safety criterion or there is a five-prevention locking conflict. At the same time, the process protection module establishes an interface with the algorithm trust registration platform of the power industry to support the on-chain notarization and verification of model filing information. In the pre-deployment stage, the system automatically generates technical documents that meet the requirements of specifications such as “Power Artificial Intelligence Edge Side Model Technical Specification” (T / CES 103-2022), including model input and output boundary definition, training data source traceability table and safety alignment test report, and submits the above materials to the industry supervision platform through the standardized API to complete the pre-examination, realizing the integration of internal control and external compliance. This mechanism effectively improves the timeliness and accuracy of process protection, ensuring the legal, safe and reliable operation of AI systems.

[0027] S103 Establish a risk operation system to continuously monitor the internal model running state and respond to abnormal events in the external environment. As the dynamic response center of the compliance governance of the power industry, the system integrates log collection, behavior analysis, threat early warning and emergency response functions to realize closed-loop monitoring of the running of generative AI models in the whole time domain. The system collects model input and output records, calling frequency, access subject identity and other running data in real time, and identifies operation sequences deviating from the normal mode in combination with the preset behavior baseline model; at the same time, it connects with external public opinion monitoring platforms and industry safety reporting systems to timely perceive policy changes, new attack methods and social risk events, forming a risk perception network of internal and external cooperation.

[0028] Preferably, during the operation process after the establishment of the risk operation system, the system continuously receives feedback instructions from the regulatory side and analyzes the new attack patterns output by the red-blue confrontation optimization module in association with the feedback instructions from the regulatory side, and then dynamically updates the compliance check items in the multi-modal audit engine. When a data poisoning attack behavior against the power load prediction model is detected, the system automatically triggers the review mechanism of the qualification scale module, suspends the function calling permission of the related model through the process protection module, and sends structured event reporting information including attack time, data source path, impact range and other elements to the industry supervision platform through the API interface, ensuring that major risk events are traceable, auditable and intervenable.

[0029] Preferably, the regulatory side feedback instructions received in the risk operation system and the detected attack behaviors are injected into the red-blue confrontation optimization module to generate data poisoning attack samples and instruction confusion attack vectors for the power load prediction model, simulating an attack scenario in which a malicious user induces the model to output an incorrect peak shaving recommendation by injecting false load time series data. On this basis, the red side updates the defense strategy based on the reinforcement learning algorithm, dynamically adjusts the model input verification rules and abnormal response threshold, and improves the robustness to hidden attacks. At the same time, the corpus security screening submodule is used to perform backtracking analysis on the misjudgment cases generated by the multi-modal audit engine in actual operation, focusing on excavating cross-modal composite attack features, such as the logical contradiction between the switch position signal tampered by PS (photoshop) and its supporting text report in the inspection image, and constructing a training sample set containing visual camouflage and semantic camouflage composite features for optimizing the discrimination ability of the audit model. The rule extraction engine can also perform natural prediction processing on unstructured text such as accident reports and dispatch anomaly records, such as extracting typical event patterns such as "a busbar maintenance error caused by cross-region power supply instructions during maintenance, resulting in over-level tripping", and converting them into formal expressions with temporal constraints and causal logic, and embedding them into the knowledge graph of the security knowledge base in the form of ontology. The knowledge graph further links with the real-time operation data of EMS, DMS and other systems, supports context-aware compliance reasoning when generating operation suggestions, and significantly enhances the forward-looking and accuracy of risk identification. The above mechanism realizes the evolution from passive response to active defense, enabling the risk operation system to have the ability of continuous evolution.

[0030] S104 realizes information interaction and collaborative linkage between modules by integrating multi-modal audit engine, security knowledge base and confrontation optimization module. This mechanism, as the technical hub of the compliance governance system in the power industry, breaks through the limitations of module isolation and response lag in traditional content audit, and builds an intelligent collaborative architecture with "perception-judgment-decision-feedback" as the core. The multi-modal audit engine is responsible for real-time analysis of all types of user input and model output, its processing process deeply depends on the laws, regulations, industry standards and operation procedures collected in the security knowledge base, and through bidirectional data exchange with the red-blue confrontation optimization module, the identification ability of new attack modes is improved. The three are connected through a unified message bus and rule scheduling center to realize state synchronization and instruction transmission, ensuring consistent security policy execution in complex business scenarios.

[0031] Preferably, when the multi-modal auditing engine performs the auditing operation, an integrated power industry sensitive word library is called for text data in the power system, abnormal semantic combinations are identified, and semantic analysis is performed in combination with context. For example, when the user input request contains co-occurrence of keywords such as “relay protection setting value modification” and “bypassing the approval process”, the system determines that it is a high-risk instruction inducing behavior, and an enhanced verification process is started. For example, for image and / or video stream data, target detection and OCR technology are used to detect whether there is device state tampering, illegal labeling or alarm information shielding in the substation inspection video. Specifically, by positioning the key device area, combining OCR to extract the digital indication and text label in the picture, and comparing with the historical record to determine whether there is parameter forgery. Furthermore, for audio data, voiceprint recognition is used to distinguish between authorized and unauthorized personnel, and to detect simulated dispatch instructions generated by voice synthesis. The use of spectral feature analysis and LSTM classifier to identify whether there are TTS generation traces prevents attackers from impersonating dispatchers to issue illegal instructions through voice cloning.

[0032] The above multi-modal analysis results are all written into the log database of the risk operation system in real time, and are injected into the red-blue confrontation optimization module as negative samples to generate more realistic attack vectors. At the same time, all newly discovered violation patterns are analyzed by the rule extraction engine and converted into structured expressions and stored in the security knowledge base to form inferable compliance rule nodes, supporting context-related judgments in subsequent auditing tasks. This collaborative mechanism significantly improves the semantic understanding depth and risk identification accuracy of the system in the power professional scene, realizing the innovation from single-mode filtering to cross-modal joint research and judgment.

[0033] In another embodiment of the present application, based on the cooperation of the qualification integration module, the process protection module and the risk operation system, a closed-loop governance process can be formed. The closed-loop governance process runs through the whole life cycle of the generated artificial intelligence model in the power industry, realizing seamless connection from admission control, process protection to dynamic response. Before the model goes online, the qualification integration module verifies the qualification and data use permission of the enterprise subject, ensures that it has the legal qualification to participate in the key business of the power grid, and automatically matches the corresponding record path according to the data classification result; the process protection module synchronously embeds the verification logic extracted by the supervision strategy analysis engine, and prepositions the compliance requirements to each stage of data processing, model training and service deployment, forming a multi-level security line; after entering the running stage, the risk operation system continuously collects model behavior logs, external attack signals and supervision feedback instructions, drives the multi-modal auditing engine and the security knowledge base to update dynamically, and improves the identification ability of new threats.

[0034] When the risk operation system detects abnormal events such as data poisoning attacks on load forecasting models or scheduling instruction impersonation behaviors, not only real-time alarms and function suspension mechanisms are triggered, but also event features are injected into the red-blue confrontation optimization module and the corpus security screening sub-module in reverse, to enhance the quality control of subsequent training data and the iteration of defense strategies. At the same time, after the event information is structured, it is returned to the qualification integration module, triggering the review process of related model qualifications, and through the API, it submits an audit package to the industry supervision platform, realizing the dynamic calibration of compliance status. Throughout the process, all modules realize data interconnection and strategy linkage through a unified rule engine, message queue and knowledge graph, making governance actions change from static approval to dynamic evolution, and ultimately building a full-cycle closed-loop governance system that can be prevented in advance, controlled in the middle, traced after the event, and managed throughout the process, fully improving the safety, compliance and sustainability of AI applications in the power industry.

[0035] In another embodiment of the application, preferably, the red-blue confrontation optimization module generates an algorithm for data poisoning attack samples of the power load forecasting model: adopt "FGSM gradient ascent poisoning + timing consistency correction" - first, select the grid daily load data for nearly 1 year; second, input the sample into the load forecasting model, and use the model + artificially generated poisoning sample; third, avoid load sudden change exposure through timing smoothing processing, finally inject 10% poisoning sample into the model training set, ensure that the model prediction bias after poisoning > 10% and the DTW distance with normal sample < 0.1 (concealment standard). Instruction confusion attack vector construction method: based on the power industry business data to build "terminology variation library", adopt "synonymous replacement + syntax variation + format tampering" three layers of construction - synonymous replacement selects dispatching terminology synonyms through WordNet, replacement proportion is controlled at 30%; syntax variation is realized by omitting key parameters and adding fuzzy expressions (such as "adjust to a reasonable range"); format tampering is for dispatching instruction structured fields (such as "execution time limit" "operation object ID"), fine-tune within the compliance format, ensure that the attack vector is syntax compliant but semantically ambiguous. The specific algorithm of the red side to update the defense strategy based on reinforcement learning: adopt PPO (Proximal Policy Optimization) algorithm, the policy network is 2-layer MLP, the core parameter configuration - discount factor γ = 0.99 (emphasize long-term defense effect), clip parameter ε = 0.2, GAE parameter λ = 0.95; the state space is defined as [attack type (0 = data poisoning / 1 = instruction confusion), model accuracy, grid load level (0 = low / 1 = normal / 2 = high), regulatory feedback label (0 = none / 1 = mild / 2 = severe)], the action space includes "adjust input verification threshold, update multi-modal audit rules, supplement security knowledge base attack mode, trigger qualification compliance module review" 4 kinds of actions; complete 1 round of policy iteration every 15 days, after iteration, the optimal defense strategy is packaged as a rule package, synchronized to the process protection, multi-modal audit and other modules through the unified message bus, ensure that the defense strategy and attack mode are dynamically adapted.

[0036] In yet another embodiment of the present application, on the basis of the real-time analysis of the power system interaction content by the above-mentioned multi-modal auditing engine, a deep semantic understanding and operation constraint checking mechanism based on business logic is further introduced to enhance the safety control capability of key dispatching operations. Specifically, when a user initiates a power grid control request through natural language, a command semantic analysis model is first called to convert the unstructured input into a structured operation instruction tree, which clearly defines the operation object, action type, target parameter and execution time sequence and other elements. For example, when the user proposes a request of "adjusting the load of a certain 220 kV line to 80%", the system automatically disassembles it into an operation chain of "line selection-power regulation-target value setting", and extracts the involved device number and regional topology.

[0037] Then the operation instruction tree is sent to the operation rule checking unit in the process protection module, the real-time operation mode of the SCADA system is obtained, and it is checked whether the operation violates the N-1 safety criterion specified in the "Power System Safety and Stability Guidelines". At the same time, time sequence data analysis is performed in combination with historical operation logs to identify whether there are abnormal operation sequence patterns such as high-frequency continuous voltage regulation and cross-zone reverse transmission, to prevent malicious users from avoiding auditing through fragmented instructions. If potential risks are found, the system immediately blocks the request transmission path and returns a compliance prompt message to the client.

[0038] For the output content generated by the model, especially the graphical suggestions related to power dispatching decision support, such as power flow diagram, voltage distribution heat map or switching operation schematic diagram, the multi-modal auditing engine starts a special parameter extraction process. Using image semantic segmentation technology to locate the key areas in the chart, it automatically identifies core parameters such as power flow distribution values, voltage interval ranges, load rate curves, and compares them with the device operation boundaries, static stability limits and other preset thresholds defined in the relevant standards. If it is detected that there are overloading of main transformers, out-of-limit of bus voltage and other non-compliant situations in the proposed scheme, the system determines that the output is high-risk content, triggers the interception and correction mechanism, and ensures that all externally provided auxiliary decision results meet the actual operation constraints of the power system.

[0039] The above-mentioned deep checking process relies on the ontological rule set modeled in the safety knowledge base and is synchronized with the EMS energy management system, so that the auditing behavior has the ability of spatio-temporal context awareness. This mechanism not only improves the judgment accuracy of the multi-modal auditing engine in professional scenarios, but also strengthens the coordination depth between the process protection module and the risk operation system, further perfecting the closed-loop governance chain from user input to model output.

[0040] Please refer to Figure 2 The structure of a power industry compliance governance system based on multi-module cooperation provided by the embodiment of the present application is shown in the figure. The governance system 100 comprises: The qualification integration module 110 is used for verifying and managing the legal access qualification of the power industry operation subject. The qualification integration module 110 is connected with the data hierarchical classification system of the power enterprise, divides the data used for model training into several data levels such as production control type, management information type and public service type, and automatically matches the corresponding qualification declaration path according to the division result. For example, when the substation inspection image data is identified as training data, it is determined that it belongs to the sensitive data type, and a special record process is triggered to generate technical documents containing data desensitization scheme, access control strategy and third-party security evaluation report submission requirements.

[0041] The process protection module 120 is used for implementing corresponding security control strategies in the data processing stage, the model training stage and the service deployment stage. The process protection module 120 is embedded with a supervision strategy analysis engine, which can obtain policy documents published by the state or industry in real time, perform semantic analysis on the policy text by using natural language processing technology, extract structured compliance rules, and convert them into executable verification logic. The verification logic is synchronized to the multi-modal audit engine and the security knowledge base to dynamically update the audit rule set.

[0042] The risk operation system module 130 is used for continuously monitoring the running state of the internal artificial intelligence model and responding to abnormal events in the external environment. The risk operation system module 130 continuously receives feedback instructions from the regulatory agency, correlates the feedback instructions with the new attack patterns output by the red-blue confrontation optimization module, dynamically adjusts the compliance check items in the multi-modal audit engine based on the analysis result, and triggers the review mechanism of the qualification integration module 110 when detecting data poisoning attack behavior against the power load prediction model. The service function of the related model is suspended through the process protection module 120, and the event reporting information is sent to the industry supervision platform through the API interface.

[0043] The multi-modal audit engine 140 is integrated in the system core layer and is used for performing cross-modal compliance review operations. For text data in the power system, a built-in power industry sensitive word library is called to identify abnormal semantic combinations and perform deep semantic analysis in combination with the context. For image or video stream data, a target detection algorithm and an OCR technology are used to jointly detect whether there are device state tampering, illegal labeling or alarm information shielding violations in the substation inspection video. For audio data, voiceprint recognition technology is used to distinguish between authorized and unauthorized personnel identities, and to detect whether there are simulated dispatching instructions generated by voice synthesis.

[0044] The security knowledge base 150 stores power industry compliance rules, historical accident cases, dispatching exception records, and knowledge graph information; the security knowledge base 150 is connected with the EMS energy management system and the DMS power distribution management system of the power enterprise through an API, acquires power grid topology structure, device operation state, and load level data in real time, and provides context support when the multi-modal auditing engine 140 performs compliance verification; at the same time, the security knowledge base 150 receives the results output by the rule extraction engine, performs natural language processing on the accident reports and dispatching exception records, extracts event patterns with time sequence constraints and causal logic, and embeds the knowledge graph in the form of ontology, to realize linkage reasoning with real-time power grid data.

[0045] The adversarial optimization module 160 includes a red-blue adversarial sub-module and a corpus security screening sub-module; the red-blue adversarial sub-module receives the supervision feedback instructions and known attack behaviors reported by the risk operation system module 130, generates data poisoning attack samples and instruction confusion attack vectors for the power load prediction model; the red party iteratively updates the defense strategy based on the reinforcement learning algorithm, dynamically adjusts the model input verification rules and abnormal response thresholds; the corpus security screening sub-module is used to analyze the misjudgment cases of the multi-modal auditing engine 140, construct a training sample set containing visual masking and semantic camouflage composite features, and improve the auditing accuracy.

[0046] Further, the governance system 100 can also be configured with an operation instruction analysis unit for parsing a natural language request input by a user into a structured operation instruction tree; the operation instruction tree is linked to the SCADA system for operation legality verification, judges whether the security criteria are violated, and identifies potential abnormal operation sequences through time sequence data analysis; for the graphical dispatching suggestions output by the model, the tidal flow distribution and voltage interval parameters are extracted and compared with the preset power system operation boundary to ensure that the output content meets the safety specifications.

[0047] Further, the process protection module 120 is connected with the algorithm credible registration platform of the power industry through an API, supports on-chain notarization and verification of model filing information; the system automatically generates technical documents including model input and output boundary definition, training data source traceability table, and safety alignment test report, and automatically submits them to the industry supervision platform through an API to complete the pre-examination process.

[0048] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device, and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0049] In the embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. The above are merely exemplary embodiments of the present application, for example, the division of the functional modules is merely logical division, and there can be other division manners in actual implementation; multiple modules or components can be combined or integrated into a single unit, and the present application can be implemented in other manners by using other manners of integration. The coupling or direct coupling or indirect coupling between the modules can be in electrical form, or mechanical form, or in the form of communication interface, and can be integrated in other forms.

[0050] The components described as separate components can not be physically separate, and their positions are not limited to a single device, and can be distributed in multiple computing nodes as needed. If the functional units are implemented in the form of software and sold or used as products, they can be stored in a nonvolatile computer-readable storage medium. Therefore, the technical solutions of the present application can be embodied in the form of software product. The software product is stored in a storage medium, and includes a plurality of instructions for enabling an electronic device to perform all or part of the steps of the method of the embodiments of the present application. The storage medium includes a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, and the like, which can store program codes.

[0051] Finally, it should be noted that: the above only describes the specific implementation of the present application, and is not a limitation. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify, replace or change the technical solutions recorded in the foregoing embodiments without departing from the spirit and scope of the present application; and these modifications, changes or replacements should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the scope defined by the claims.

Claims

1. A compliance governance method for the power industry based on multi-module collaboration, characterized in that, Includes the following steps: Step 1: Configure the qualification and compliance module to verify and manage the access qualifications of operating entities; Step 2: Construct a process protection module and implement corresponding security control strategies in the data processing stage, model training stage, and service deployment stage. Step 3: Establish a risk operation system to continuously monitor the operation status of internal models and respond to and handle abnormal events in the external environment; Step 4: By integrating the multimodal audit engine, security knowledge base, and adversarial optimization module, information interaction and collaborative linkage between the modules are achieved.

2. The power industry compliance governance method based on multi-module collaboration as described in claim 1, characterized in that, The qualification and compliance module is integrated with the data classification and grading system of power companies, dividing the training data into production control, management information, and public service data levels. Based on the defined data levels, the corresponding qualification application path is automatically matched.

3. The power industry compliance governance method based on multi-module collaboration as described in claim 2, characterized in that, When the model training data is identified as substation inspection image data, it is determined to be sensitive data, triggering a special filing process and generating requirements for submitting data anonymization schemes, access control policies, and third-party security assessment reports.

4. The power industry compliance governance method based on multi-module collaboration according to claim 1, characterized in that, During the construction of the process protection module, a regulatory strategy parsing engine is embedded to obtain policy documents in real time. Natural language processing technology is used to perform semantic analysis on the policy document to extract structured compliance rules; The structured compliance rules are converted into executable verification logic; The verification logic is synchronized to the multimodal audit engine and security knowledge base to update the corresponding audit rules.

5. The power industry compliance governance method based on multi-module collaboration according to claim 4, characterized in that, The safety knowledge base is connected to the power company's energy management system and power distribution management system via API to obtain real-time data on power grid topology, equipment status and load level. When the multimodal audit engine performs compliance verification, it calls the power grid topology, equipment status, and load level data as contextual basis. An interface was established between the process protection module and the algorithm trust registration platform of the power industry to support on-chain storage and verification of model filing information; Automatically generate technical documentation, including model input / output boundary definitions, training data source traceability tables, and security alignment test reports; The technical documentation was submitted to the industry regulatory platform via API for preliminary review.

6. The power industry compliance governance method based on multi-module collaboration according to claim 5, characterized in that, During the operation of the risk management system, we continuously receive feedback instructions from the regulatory side; The regulatory feedback instructions are correlated with the novel attack patterns output by the red-blue team optimization module; Based on the results of correlation analysis, the compliance check items in the multimodal audit engine are dynamically updated; When a data poisoning attack targeting the power load forecasting model is detected, the qualification and compliance module's review mechanism is triggered. The model's functionality is suspended via the process protection module, and event reporting information is sent to the industry regulatory platform via the API interface.

7. The power industry compliance governance method based on multi-module collaboration according to claim 6, characterized in that, The user's natural language input request is parsed into an operation instruction tree, and the SCADA system is linked to verify whether the operation violates the N1 safety rule. The time series data is analyzed to determine whether there is an abnormal operation sequence. The graphical scheduling suggestions output by the model are used to extract power flow distribution and voltage range parameters, and then compared with the preset operating boundaries for compliance.

8. The power industry compliance governance method based on multi-module collaboration according to claim 6, characterized in that, The regulatory feedback instructions received in the risk operation system and the detected attack behaviors are injected into the red-blue team optimization module to generate data poisoning attack samples and instruction obfuscation attack vectors for the power load forecasting model. The red team updates its defense strategy based on reinforcement learning algorithms, adjusting the model input verification rules and abnormal response thresholds. The corpus security screening submodule is used to analyze the misjudgment cases of the multimodal review engine and construct a training sample set containing composite features of visual occlusion and semantic masquerading. The rule extraction engine performs natural language processing on accident reports and scheduling anomaly records to extract event patterns with temporal constraints and causal logic. The generated event patterns are embedded into the knowledge graph of the security knowledge base in the form of ontology, and linked with real-time power grid operation data to achieve linked reasoning.

9. The power industry compliance governance method based on multi-module collaboration according to claim 1, characterized in that, When the multimodal audit engine performs audit operations, it calls the integrated power industry sensitive word library to identify abnormal semantic combinations for text data in the power system, and performs semantic analysis in combination with the context. For image and / or video stream data, target detection and OCR technology are used to detect whether there is equipment status tampering, illegal annotation or alarm information obscuring in substation inspection videos; For audio data, voiceprint recognition is used to distinguish between authorized and unauthorized personnel, and simulated dispatch instructions generated by speech synthesis are detected.

10. A compliance governance system based on multi-module collaboration, characterized in that, include: The qualification and compliance module is used to verify and manage the legal access qualifications of operating entities; The process protection module is used to implement corresponding security control strategies in the data processing stage, model training stage, and service deployment stage respectively. The risk operation system module is used to continuously monitor the operating status of internal models and respond to and handle abnormal events in the external environment. By integrating a multimodal audit engine, a security knowledge base, and an adversarial optimization module, information exchange and collaborative linkage are achieved among the modules of the qualification and compliance configuration module, the process protection construction module, and the risk operation system module.

Citation Information

Patent Citations

  • Block chain ecological security collaborative supervision method

    CN117972704A

  • Block chain ecological security collaborative supervision system

    CN118041914A

  • Network security compliance intelligent protection system for enterprise multi-source data fusion

    CN119966735A

  • Network security penetration detection method and system based on artificial intelligence

    CN120050079A

  • Authentication process management system and method for multi-node dynamic warning and compliance supervision

    CN120373568A