Power industry compliance management method and system based on multi-module cooperation

By configuring qualification and compliance modules, process protection modules, and risk operation systems in the power industry, and integrating modules such as multimodal audit engines, the problem of insufficient full lifecycle management of generative artificial intelligence in the power industry in existing technologies has been solved, realizing full lifecycle security closed-loop governance and improving compliance and dynamic defense capabilities.

CN121526529BActive Publication Date: 2026-07-21BEIJING BRON S&T
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING BRON S&T
Filing Date
2025-11-24
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies in the power industry lack full lifecycle management of generative artificial intelligence, which cannot effectively prevent models from developing biases or violations due to faulty data. Furthermore, each security module operates in isolation, making it difficult to form a systematic and closed-loop compliance governance system and unable to cope with the security risks of complex multimodal content.

Method used

By configuring qualification and compliance modules, building process protection modules, and establishing a risk operation system, and integrating a multimodal audit engine, security knowledge base, and adversarial optimization modules, information interaction and collaborative linkage between modules are achieved, forming a closed-loop governance process.

Benefits of technology

It achieves full lifecycle security control from data processing to service deployment, improves compliance, stability and regulatory oversight, significantly reduces compliance and violation risks, and enhances the system's dynamic defense capabilities and risk identification accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121526529B_ABST
    Figure CN121526529B_ABST
Patent Text Reader

Abstract

The application provides a power industry compliance management method and system based on multi-module cooperation. By configuring a qualification management module to dock a data hierarchical classification system, automatic verification and dynamic management of the qualification of an operating subject are realized. A process protection module is constructed, a supervision strategy analysis engine is embedded in the data processing, model training and service deployment stages, compliance rules are extracted and executed in real time, and context-aware compliance verification is performed in combination with a multi-modal audit engine and a security knowledge base. A risk operation system is established to continuously monitor the model running state and external threats, and an attack sample is generated by a red-blue confrontation optimization module to improve defense capabilities. Through multi-module cooperation, a closed-loop management process is formed. The method improves compliance response efficiency, enhances cross-department collaboration capabilities, and realizes intelligent compliance management and adaptive security protection throughout the life cycle of the power industry.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of collaborative management of artificial intelligence and power system safety, specifically to a power industry compliance governance method and system based on multi-module collaboration. Background Technology

[0002] In existing technologies, content moderation in generative AI often focuses on single-point detection at the output stage, relying on keyword matching or simple rule filtering. It only intercepts text content post-processing, making it difficult to address the security risks of complex, multimodal content. Such methods exhibit significant shortcomings in critical infrastructure sectors like power: a lack of effective control over early stages such as data input and model training, failing to prevent bias or violations due to "faulty data"; isolated operation of the moderation engine, without integration with industry knowledge bases or business systems (such as SCADA and EMS), leading to insufficient semantic understanding in specialized scenarios and frequent misjudgments and omissions; and inability of traditional mechanisms to achieve structured parsing and operational constraint verification of high-security requests involving grid dispatch and equipment status, posing a risk of generating misleading suggestions. Furthermore, existing systems generally neglect the closed-loop utilization of risk data, lacking the ability to feed user feedback and abnormal behavior back into training and moderation optimization, resulting in static and rigid security protection. Simultaneously, enterprise qualification compliance management remains an independent process, lacking dynamic linkage with algorithm registration and security assessment, failing to meet the power industry's regulatory requirements for algorithm reliability and full traceability. Overall, current technologies remain in a "post-incident remediation" mode and have not yet built an intelligent security governance system that covers the entire lifecycle of data, training, and deployment, and integrates multimodal auditing, dynamic knowledge updates, and red team / blue team exercises. Summary of the Invention

[0003] Based on this, in order to address the technical problems of untimely compliance response and inconsistent implementation standards in the power industry's compliance governance process caused by fragmented data sources, lagging rule updates, and low efficiency of cross-departmental collaboration, a multi-module collaborative compliance governance method and system for the power industry is proposed. This invention protects a multi-module collaborative compliance governance method for the power industry, comprising the following steps: Step 1, configuring a qualification compliance module to verify and manage the access qualifications of operating entities; Step 2, constructing a process protection module to implement corresponding security control strategies in the data processing, model training, and service deployment stages; Step 3, establishing a risk operation system to continuously monitor the internal model's operating status and respond to abnormal events in the external environment; Step 4, achieving information interaction and collaborative linkage between modules by integrating a multimodal audit engine, a security knowledge base, and an adversarial optimization module.

[0004] Furthermore, the qualification and compliance module is integrated with the data classification system of power companies, dividing the training data into production control, management information, and public service data levels; based on the data level classification, the corresponding qualification application path is automatically matched.

[0005] Furthermore, when the model training data is identified as substation inspection image data, it is determined to be sensitive data, triggering a special filing process and generating requirements for submitting data anonymization schemes, access control policies, and third-party security assessment reports.

[0006] Furthermore, in the process of building the process protection module, a regulatory strategy parsing engine is embedded to obtain policy documents in real time; natural language processing technology is used to perform semantic analysis on the policy documents to extract structured compliance rules; the structured compliance rules are converted into executable verification logic; and the verification logic is synchronized to the multimodal audit engine and security knowledge base to update the corresponding audit rules.

[0007] Furthermore, the security knowledge base is integrated with the power company's energy management system and distribution management system via API to obtain real-time data on grid topology, equipment status, and load levels. When the multimodal audit engine performs compliance verification, it uses the grid topology, equipment status, and load level data as contextual basis. The process protection module is interfaced with the power industry's algorithm trust registration platform to support on-chain storage and verification of model filing information. Technical documents are automatically generated, including model input / output boundary definitions, training data source traceability tables, and security alignment test reports. The technical documents are submitted to the industry regulatory platform via API for pre-review.

[0008] Furthermore, during the operation of the risk operation system, it continuously receives feedback instructions from the regulatory side; it performs correlation analysis between the regulatory feedback instructions and the new attack patterns output by the red team / blue team optimization module; based on the results of the correlation analysis, it dynamically updates the compliance check items in the multimodal audit engine; when a data poisoning attack is detected against the power load forecasting model, it triggers the review mechanism of the qualification and compliance module; it suspends the function of the model through the process protection module and sends event reporting information to the industry regulatory platform via the API interface.

[0009] Furthermore, the user's input natural language request is parsed into an operation instruction tree, and the SCADA system is linked to verify whether the operation violates the N1 safety criteria. Time series data analysis is used to determine whether there is an abnormal operation sequence. The power flow distribution and voltage range parameters of the graphical scheduling suggestions output by the model are extracted and compared with the preset operating boundaries for compliance.

[0010] Furthermore, the regulatory feedback instructions received from the risk operation system and the detected attack behaviors are injected into the red-blue team optimization module to generate data poisoning attack samples and instruction obfuscation attack vectors targeting the power load forecasting model. The red team updates the defense strategy based on reinforcement learning algorithms, adjusting the model input verification rules and abnormal response thresholds. The corpus security screening submodule is used to analyze misjudgment cases of the multimodal audit engine and construct a training sample set containing composite features of visual occlusion and semantic camouflage. The rule extraction engine performs natural language processing on accident reports and scheduling anomaly records to extract event patterns with temporal constraints and causal logic. The generated event patterns are embedded into the knowledge graph of the security knowledge base in the form of ontology and linked with real-time power grid operation data to achieve linkage reasoning.

[0011] Furthermore, when the multimodal audit engine performs audit operations, for text data in the power system, it calls the integrated power industry sensitive word library to identify abnormal semantic combinations and performs semantic analysis in combination with the context; for image and / or video stream data, it uses object detection and OCR technology to detect whether there is equipment status tampering, illegal annotation or alarm information obscuring in substation inspection videos; for audio data, it distinguishes authorized and unauthorized personnel through voiceprint recognition and detects simulated dispatch instructions generated by speech synthesis.

[0012] This invention also provides a compliance governance system based on multi-module collaboration, comprising: a qualification compliance module for verifying and managing the legal access qualifications of operating entities; a process protection module for implementing corresponding security control strategies in the data processing, model training, and service deployment stages; a risk operation system module for continuously monitoring the internal model's operating status and responding to abnormal events in the external environment; and by integrating a multimodal audit engine, a security knowledge base, and an adversarial optimization module, information interaction and collaborative linkage among the qualification compliance module, process protection module, and risk operation system module are achieved.

[0013] This invention protects a multi-module collaborative compliance governance method and system for the power industry. By configuring a qualification compliance module, it achieves automated verification and dynamic management of the legal access qualifications of operating entities, effectively improving the efficiency and accuracy of compliance review in the entity access process. It constructs a process protection module and implements differentiated security control strategies at each stage of data processing, model training, and service deployment, realizing closed-loop security management throughout the entire lifecycle and significantly enhancing data security and system stability in key areas. It establishes a risk operation system to continuously monitor the internal model's operating status and respond promptly to abnormal events in the external environment, improving the system's ability to perceive potential risks and its emergency response capabilities. By integrating a multimodal audit engine, a security knowledge base, and an adversarial optimization module, it promotes information sharing and collaborative linkage among functional units, enhancing the overall system's intelligent decision-making level and adaptive defense capabilities. Based on this, relying on the deep collaboration of the qualification compliance module, process protection module, and risk operation system, it forms a closed-loop governance process covering pre-event prevention, in-event control, and post-event response, comprehensively improving the power industry's compliance governance capabilities and safe operation level in complex business scenarios. Attached Figure Description

[0014] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This application provides a schematic diagram of a multi-module collaborative compliance governance method for the power industry. Figure 2 This application provides a schematic diagram of a power industry compliance governance system based on multi-module collaboration. Detailed Implementation

[0015] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. Based on the embodiments of this application, every other embodiment obtained by those skilled in the art without inventive effort falls within the scope of protection of this application.

[0016] Existing generative AI content moderation solutions primarily rely on keyword filtering, single-modal (e.g., text) review, and manual review mechanisms, which have significant technical limitations: First, their review scope is limited to the model output stage, failing to cover the entire lifecycle, including data preparation, model training, service deployment, and regulatory filing, making it difficult to effectively control inherent security risks. Second, they lack unified review capabilities for multimodal content such as images, audio, and video, failing to address diverse content risks in complex application scenarios. Third, the handling of sensitive issues is too rigid, typically employing simple blocking or shielding strategies, lacking categorized handling and compliance-based response mechanisms, sacrificing user experience and knowledge service capabilities while ensuring compliance. Furthermore, the various security modules operate in isolation, lacking collaborative mechanisms, making it difficult to form a systematic, closed-loop compliance governance system. Especially in scenarios with high compliance requirements, such as the power industry, existing solutions struggle to meet the comprehensive governance needs of legal access, continuous monitoring, and dynamic response.

[0017] Based on this, such as Figure 1 As shown, embodiments of the present invention provide a compliance governance method for the power industry based on multi-module collaboration. This method configures a qualification compliance module, constructs a process protection module, establishes a risk operation system, and integrates a multimodal audit engine, a security knowledge base, and an adversarial optimization module to achieve information interaction and collaborative linkage between various stages, ultimately forming a closed-loop governance process. Specifically, it includes the following steps: Step 1: Configure the qualification and compliance module to verify and manage the legal access qualifications of the operating entity; Step 2: Construct a process protection module and implement corresponding security control strategies in the data processing stage, model training stage, and service deployment stage. Step 3: Establish a risk operation system to continuously monitor the operation status of internal models and respond to and handle abnormal events in the external environment; Step 4: By integrating a multimodal audit engine, a security knowledge base, and an adversarial optimization module, information exchange and collaborative linkage are achieved between various modules such as the qualification and compliance module, the process protection module, and the risk operation system; based on the collaborative operation of modules such as the qualification and compliance module, a closed-loop governance process is formed.

[0018] This application provides a multi-module collaborative compliance governance method for the power industry, enabling security control throughout the entire lifecycle from data processing to service deployment. The qualification compliance module ensures that operating entities possess legal access qualifications, enhancing basic compliance assurance capabilities. The process protection module implements differentiated security strategies at each stage of data processing, model training, and service deployment, effectively preventing potential risks at each stage. The risk operation system continuously monitors the internal operating status of the model and responds quickly to external anomalies, enhancing the system's dynamic defense capabilities. The integration of a multimodal audit engine, security knowledge base, and adversarial optimization module not only supports joint auditing of various content types such as text, images, audio, and video, but also continuously optimizes model security through red team / blue team adversarial mechanisms, improving risk identification accuracy. The collaborative linkage of these modules forms a closed-loop governance process, breaking down the module silos of traditional solutions. This significantly improves the compliance, stability, and regulatory oversight of the power industry's AI system in complex environments, achieving an overall risk prevention and control coverage rate of nearly 100% and substantially reducing compliance and violation risks.

[0019] The S101 configuration qualification and compliance module verifies and manages the legally required qualifications of operating entities. As a front-end control unit for compliance governance of generative artificial intelligence systems in the power industry, this module first automates the verification of whether power operating companies possess legal qualifications such as algorithm registration and content service licenses, based on regulatory requirements in the critical information infrastructure sector, and establishes a dynamically updated enterprise qualification archive. Building upon this, the qualification and compliance module further integrates with the power company's data classification and grading system, dividing training data into several data levels such as production control, management information, and public services, ensuring that data of different security levels follows the corresponding compliance paths during use.

[0020] Preferably, the system automatically matches the corresponding qualification application path based on the data level classification. When the system identifies that the training data to be used by the model involves a specific business domain, it initiates a differentiated approval process based on the preset classification rule engine.

[0021] For example, for production control data, the system mandates that network security level protection certification of level 2 or above be completed, and compliance comparison is conducted with the technical clauses in the "Regulations on Security Protection of Power Monitoring Systems"; for management information data, an internal authorization approval chain and data usage log audit plan must be submitted; and for public service data, in addition to meeting the basic filing conditions, a public impact assessment review is also required.

[0022] When the model training data is identified as substation inspection image data, it is determined to be sensitive data, triggering a special filing process and generating data anonymization schemes, access control policies, and submission requirements for third-party security assessment reports. In specific implementation, the system identifies that such images belong to the "Production Control Zone II" category through metadata tags, then activates the high-risk data processing process, automatically generating a data anonymization implementation plan that includes pixel-level blurring or partial masking strategies. At the same time, a fine-grained access control matrix is ​​configured, restricting access to the relevant datasets to only authorized maintenance personnel on designated terminals.

[0023] Preferably, the system integrates with external security assessment agencies to push materials for review and track the issuance progress of third-party security assessment reports, ensuring that all prerequisites are met before entering the model training phase. This mechanism achieves fully automated response throughout the entire process, from data attribute identification to qualification path guidance, ensuring the orderly development of power AI applications within a legal and compliant framework.

[0024] The S102 construction process protection module implements corresponding security control strategies in the data processing, model training, and service deployment phases. As the core defense line for AI governance in the power industry, this module spans the entire lifecycle of generative models, setting measurable, traceable, and auditable security control points at each key stage. In the data processing phase, the corpus security screening submodule performs dual filtering of input data through automatic computer review and manual review, focusing on removing content containing bias, illegal, or sensitive information. In the model training phase, a security alignment mechanism and red-blue team exercises are introduced to optimize the process, proactively identifying and fixing potential vulnerabilities. In the service deployment phase, a real-time interception mechanism for output content and a mechanism for recording operational behavior are established to ensure that the external service process is controllable and manageable.

[0025] Preferably, during the construction of the process protection module, a regulatory strategy parsing engine is embedded to acquire policy documents in real time and use natural language processing technology to perform semantic analysis on the policy documents, extracting structured compliance rules, and then converting the structured compliance rules into executable verification logic. This engine continuously captures the latest regulations, notices, and technical guidelines issued by regulatory authorities, and through named entity recognition and dependency parsing, accurately extracts prohibitive clauses such as "prohibiting the use of AI to generate false load forecasts" and "not allowing unauthorized access to scheduling command data," and transforms them into formally expressed rule entries. For example, regarding the regulation that "overload operation of the main transformer shall not exceed 2 hours," the system automatically generates time-series logic judgment conditions with time window constraints and injects them into the review and control process.

[0026] Preferably, the verification logic is synchronized to the multimodal audit engine and the security knowledge base to update the corresponding audit rules. The security knowledge base interfaces with the power company's EMS energy management system and DMS distribution management system via API to obtain real-time data on grid topology, equipment status, and load levels, enabling audit decisions to have operational awareness capabilities. When the model output involves switching operation suggestions or power flow adjustment schemes, the multimodal audit engine dynamically calls the actual operating parameters of the current power grid as contextual basis during compliance verification to determine whether the suggestion violates the N-1 safety criterion or has a conflict with the five-prevention interlocking mechanism. Simultaneously, the process protection module establishes an interface with the power industry's algorithm trust registration platform to support on-chain storage and verification of model registration information. In the pre-deployment phase, the system automatically generates technical documents that comply with standards such as the "Technical Specification for Edge-Side Models of Power Artificial Intelligence" (T / CES 103-2022), including model input / output boundary definitions, training data source traceability tables, and security alignment test reports. These materials are submitted to the industry regulatory platform for pre-review via a standardized API, achieving integrated connection from internal control to external compliance. This mechanism effectively improves the timeliness and accuracy of process protection, ensuring the legal, safe, and reliable operation of the AI ​​system.

[0027] S103 establishes a risk operation system to continuously monitor the operational status of internal models and respond to abnormal events in the external environment. This system serves as the dynamic response hub for compliance governance in the power industry, integrating log collection, behavioral analysis, threat warning, and emergency response functions to achieve closed-loop monitoring covering the entire time domain of generative AI model operation. The system collects operational data in real time, including model input / output records, call frequency, and access subject identity, and identifies operational sequences deviating from normal patterns by combining this data with a preset behavioral baseline model. Simultaneously, it connects to external public opinion monitoring platforms and industry security notification systems to promptly detect policy changes, new attack methods, and social risk events, forming an internally and externally collaborative risk perception network.

[0028] Preferably, during the operation of the established risk operation system, it continuously receives regulatory feedback instructions and correlates these instructions with new attack patterns output by the red team / blue team optimization module, thereby dynamically updating the compliance check items in the multimodal audit engine. When a data poisoning attack targeting the power load forecasting model is detected, the system automatically triggers the review mechanism of the qualification and compliance module, suspends the function call permissions of the relevant model through the process protection module, and sends structured event reporting information containing elements such as attack time, data source path, and scope of impact to the industry regulatory platform via API interface, ensuring that major risk events are traceable, auditable, and interventionable.

[0029] Preferably, regulatory feedback instructions and detected attack behaviors received from the risk operation system are injected into the red-blue team optimization module to generate data poisoning attack samples and instruction obfuscation attack vectors targeting the power load forecasting model. This simulates an attack scenario where malicious users induce the model to output incorrect peak-shaving suggestions by injecting false load time-series data. Based on this, the red team updates its defense strategy using reinforcement learning algorithms, dynamically adjusting the model input verification rules and abnormal response thresholds to improve robustness against covert attacks. Simultaneously, the corpus security screening submodule is used to retrospectively analyze misjudgment cases generated by the multimodal audit engine in actual operation, focusing on mining cross-modal composite attack features, such as logical contradictions between switch position signals tampered with by tools like Photoshop in inspection images and their accompanying text reports. A training sample set containing composite features of visual occlusion and semantic camouflage is constructed to reverse-optimize the discriminative ability of the audit model. Furthermore, a rule extraction engine can perform natural divination processing on unstructured text such as accident reports and scheduling anomaly records. For example, it can extract typical event patterns such as "an erroneous cross-regional power supply command during a busbar maintenance period leads to an out-of-level trip," transforming them into formal expressions with temporal constraints and causal logic, and embedding them into a knowledge graph of the safety knowledge base in ontology form. This knowledge graph is further linked with real-time operational data from systems such as EMS and DMS, supporting context-aware compliance reasoning when generating operational suggestions, significantly enhancing the foresight and accuracy of risk identification. The above mechanism realizes the evolution from passive response to proactive defense, enabling the risk operation system to have the ability to continuously evolve.

[0030] S104 integrates a multimodal audit engine, a security knowledge base, and an adversarial optimization module to achieve information interaction and collaborative linkage among these modules. As the technical hub of the power industry's compliance governance system, this mechanism breaks through the limitations of isolated modules and delayed responses in traditional content auditing, constructing an intelligent collaborative architecture centered on "perception—judgment—decision—feedback." The multimodal audit engine is responsible for real-time parsing of all types of content input by users and output by models. Its processing deeply relies on laws, regulations, industry standards, and operating procedures collected in the security knowledge base, and continuously improves the ability to identify new attack patterns through bidirectional data exchange with the red team / blue team adversarial optimization module. All three components achieve state synchronization and instruction transmission through a unified message bus and rule scheduling center, ensuring consistent security policy execution even in complex business scenarios.

[0031] Preferably, when the multimodal audit engine performs audit operations, for text data in the power system, it calls the integrated power industry sensitive word library to identify abnormal semantic combinations and performs semantic analysis in conjunction with the context. For example, when a user input request contains the co-occurrence of keywords such as "relay protection setting modification" and "bypassing the approval process," the system determines it as a high-risk instruction inducement behavior and initiates an enhanced verification process. For image and / or video stream data, object detection and OCR technologies are used to detect whether there is equipment status tampering, illegal labeling, or alarm information obscuring in substation inspection videos. Specifically, by locating key equipment areas and combining OCR to extract numerical indicators and text labels from the screen, historical records are compared to determine whether parameter forgery exists. Furthermore, for audio data, voiceprint recognition distinguishes between authorized and unauthorized personnel, and simulated dispatch instructions generated by speech synthesis are detected. Spectral feature analysis and LSTM classifiers are used to identify whether there are traces of TTS generation, preventing attackers from impersonating dispatchers and issuing illegal instructions through voice cloning.

[0032] The results of the aforementioned multimodal analysis are written to the log database of the risk operation system in real time and injected as negative samples into the red-blue team optimization module to generate more realistic attack vectors. Simultaneously, all newly discovered violation patterns are analyzed by the rule extraction engine, transformed into structured expressions, and stored in the security knowledge base, forming reasonable compliance rule nodes to support contextual judgment in subsequent audit tasks. This collaborative mechanism significantly improves the semantic understanding depth and risk identification accuracy of the system in power industry scenarios, achieving an innovation from single-modal filtering to cross-modal joint analysis.

[0033] In another embodiment of the present invention, a closed-loop governance process can be formed through the collaborative operation of the qualification and compliance module, the process protection module, and the risk operation system. This closed-loop governance process spans the entire lifecycle of the generative artificial intelligence model in the power industry, achieving seamless integration from access control and process protection to dynamic response. Before the model goes live, the qualification and compliance module verifies the enterprise's qualifications and data usage permissions to ensure it has the legal qualifications to participate in key power grid operations, and automatically matches the corresponding filing path based on the data classification results. The process protection module simultaneously embeds the verification logic extracted by the regulatory strategy parsing engine, bringing compliance requirements forward to each stage of data processing, model training, and service deployment, forming a multi-layered security defense. After entering the operational phase, the risk operation system continuously collects model behavior logs, external attack signals, and regulatory feedback instructions, driving the multimodal audit engine and security knowledge base to dynamically update, improving the ability to identify new threats.

[0034] When the risk operations system detects abnormal events, such as data poisoning attacks targeting the load forecasting model or spoofing of dispatch instructions, it not only triggers real-time alarms and function suspension mechanisms, but also injects event characteristics back into the red-blue team optimization module and the corpus security screening submodule to enhance the quality control of subsequent training data and the iteration of defense strategies. Simultaneously, the event information, after structured processing, is sent back to the qualification and compliance module, triggering a review process for the relevant model qualifications. An audit package is also submitted to the industry regulatory platform via API, enabling dynamic calibration of compliance status. Throughout this process, the modules achieve data interoperability and strategy linkage through a unified rule engine, message queue, and knowledge graph, transforming governance actions from static approval to dynamic evolution. Ultimately, this constructs a closed-loop governance system that is "preventable beforehand, controllable during the event, traceable afterward, and manageable throughout the entire process," comprehensively improving the security, compliance, and sustainability of AI applications in the power industry.

[0035] In another embodiment of the present invention, preferably, the red-blue adversarial optimization module uses the following algorithm for generating data poisoning attack samples for the power load forecasting model: "FGSM gradient ascent poisoning + time series consistency correction"—the first step is to select the daily load data of the power grid in the past year; the second step is to input the samples into the load forecasting model, and then use the model + manual generation of poisoned samples; the third step is to avoid exposure of sudden load changes through time series smoothing, and finally inject 10% poisoned samples into the model training set to ensure that the model prediction deviation after poisoning is >10% and the DTW distance with the normal samples is <0.1 (the concealment meets the standard). The method for constructing instruction obfuscation attack vectors is as follows: A "term variation library" is built based on power industry business data, and a three-layer structure of "synonym substitution + syntax variation + format tampering" is adopted. Synonym substitution is achieved by selecting near-synonyms of scheduling terms through WordNet, with the substitution ratio controlled at 30%. Syntax variation is achieved by omitting key parameters and adding vague expressions (such as "adjusted to a reasonable range"). Format tampering is performed on the structured fields of scheduling instructions (such as "execution time limit" and "operation object ID"), and fine-tuning is carried out within the compliant format to ensure that the attack vector is syntactically compliant but semantically ambiguous. The Red Team's specific algorithm for updating its defense strategy based on reinforcement learning is as follows: It employs the Proximal Policy Optimization (PPO) algorithm, with a 2-layer MLP policy network. Core parameter configurations include a discount factor γ=0.99 (emphasizing long-term defense effectiveness), a clip parameter ε=0.2, and a GAE parameter λ=0.95. The state space is defined as [attack type (0 = data poisoning / 1 = instruction obfuscation), model accuracy, grid load level (0 = low / 1 = normal / 2 = high), and regulatory feedback label (0 = none / 1 = minor / 2 = severe)]. The action space includes four types of actions: "adjusting input verification thresholds, updating multimodal audit rules, supplementing security knowledge base attack patterns, and triggering qualification compliance module review." A strategy iteration is completed every 15 days. After iteration, the optimal defense strategy is encapsulated into a rule package and synchronized to modules such as process protection and multimodal auditing via a unified message bus to ensure dynamic adaptation between the defense strategy and attack patterns.

[0036] In another embodiment of the present invention, based on the real-time parsing of power system interaction content by the aforementioned multimodal audit engine, a deep semantic understanding and operational constraint verification mechanism based on business logic is further introduced to enhance the security control capability for critical scheduling operations. Specifically, when a user initiates a power grid control request via natural language, the system first calls the instruction semantic parsing model to transform the unstructured input into a structured operation instruction tree, clarifying elements such as the operation object, action type, target parameters, and execution sequence. For example, when a user requests to "adjust the load of a certain 220kV line to 80%", the system automatically breaks it down into an operation chain of "line selection—power adjustment—target value setting" and extracts the relevant equipment numbers and regional topology.

[0037] The operation instruction tree is then sent to the operation rule verification unit in the process protection module, which, in conjunction with the SCADA system, obtains the current real-time operation mode of the power grid and verifies whether the operation violates the N-1 safety criterion stipulated in the "Guidelines for the Safety and Stability of Power Systems". Simultaneously, time-series data analysis is performed based on historical operation logs to identify abnormal operation sequence patterns such as high-frequency continuous voltage regulation and cross-regional backfeeding, preventing malicious users from circumventing review through fragmented instructions. If a potential risk is detected, the system immediately blocks the request transmission path and returns a compliance warning to the client.

[0038] For the output content generated by the model, especially graphical suggestions related to power grid dispatch decision support, such as power flow diagrams, voltage distribution heatmaps, or switching operation diagrams, the multimodal review engine initiates a special parameter extraction process. Using image semantic segmentation technology, key areas in the diagrams are located, and core parameters such as power flow distribution values, voltage ranges, and load factor curves are automatically identified. These parameters are then compared with preset thresholds defined in relevant standards, such as equipment operating boundaries and static stability limits. If non-compliant situations such as main transformer overload exceeding limits or bus voltage exceeding limits are detected in the suggested solutions, the system determines the output as high-risk content, triggering an interception and correction mechanism to ensure that all externally provided auxiliary decision-making results comply with the actual operating constraints of the power system.

[0039] The aforementioned deep verification process relies on the ontological rule set modeled in the security knowledge base and maintains data synchronization with the EMS energy management system, enabling the audit behavior to have spatiotemporal context awareness. This mechanism not only improves the judgment accuracy of the multimodal audit engine in professional scenarios, but also strengthens the collaboration between the process protection module and the risk operation system, further improving the closed-loop governance chain from user input to model output.

[0040] Please see Figure 2 This is a schematic diagram of a multi-module collaborative compliance governance system for the power industry, provided in an embodiment of this invention. The governance system 100 includes: The Qualification and Compliance Module 110 is used to verify and manage the legal access qualifications of power industry operators. The Qualification and Compliance Module 110 interfaces with the data classification system of power companies, dividing the data used for model training into several data levels such as production control, management information, and public services, and automatically matching the corresponding qualification application path based on the classification results. For example, when substation inspection image data is identified as training data, it is determined to be a sensitive data type, triggering a special filing process and generating technical documents that include data anonymization schemes, access control policies, and requirements for submitting third-party security assessment reports.

[0041] The process protection module 120 is used to implement corresponding security control strategies in the data processing stage, model training stage, and service deployment stage. The process protection module 120 has an embedded regulatory policy parsing engine, which can obtain policy documents issued by the state or industry in real time, use natural language processing technology to perform semantic analysis on the policy text, extract structured compliance rules, and convert them into executable verification logic. The verification logic is synchronized to the multimodal audit engine and security knowledge base to dynamically update the audit rule set.

[0042] The risk operation system module 130 is used to continuously monitor the operation status of the internal artificial intelligence model and respond to abnormal events in the external environment. The risk operation system module 130 continuously receives feedback instructions from regulatory agencies, performs correlation analysis with the new attack patterns output by the red team / blue team optimization module, and dynamically adjusts the compliance check items in the multimodal audit engine based on the analysis results. When a data poisoning attack is detected against the power load forecasting model, the review mechanism of the qualification and compliance module 110 is triggered, and the service function of the relevant model is suspended through the process protection module 120. At the same time, the event reporting information is sent to the industry regulatory platform through the API interface.

[0043] The multimodal audit engine 140, integrated into the system core layer, is used to perform cross-modal compliance audit operations. For text data in the power system, it calls the built-in power industry sensitive word library to identify abnormal semantic combinations and perform deep semantic analysis in combination with the context. For image or video stream data, it uses object detection algorithms and OCR technology to jointly detect whether there are violations such as equipment status tampering, illegal annotation, or alarm information obscuring in substation inspection videos. For audio data, it uses voiceprint recognition technology to distinguish the identities of authorized and unauthorized personnel and detect whether there are simulated dispatch instructions generated by speech synthesis.

[0044] The security knowledge base 150 stores compliance rules for the power industry, historical accident cases, dispatching anomaly records, and knowledge graph information. The security knowledge base 150 is connected to the EMS energy management system and DMS distribution management system of power enterprises through APIs, and real-time obtains data on the power grid topology, equipment operation status, and load level, providing context support during the compliance verification performed by the multimodal audit engine 140. At the same time, the security knowledge base 150 receives the results output by the rule extraction engine, performs natural language processing on accident notifications and dispatching anomaly records, extracts event patterns with temporal constraints and causal logic, and embeds them in the knowledge graph in the form of an ontology to achieve linkage reasoning with real-time power grid data.

[0045] The adversarial optimization module 160 includes a red-blue adversarial sub-module and a corpus security screening sub-module. The red-blue adversarial sub-module receives the regulatory feedback instructions and known attack behaviors reported by the risk operation system module 130, and generates data poisoning attack samples and instruction obfuscation attack vectors for the power load forecasting model. The red side iteratively updates the defense strategy based on the reinforcement learning algorithm, and dynamically adjusts the model input verification rules and anomaly response thresholds. The corpus security screening sub-module is used to analyze the misjudgment cases of the multimodal audit engine 140, construct a training sample set containing composite features of visual masking and semantic camouflage, and improve the audit accuracy.

[0046] Furthermore, the governance system 100 can also be configured with an operation instruction parsing unit for parsing the natural language requests input by users into a structured operation instruction tree. The operation instruction tree is linked to the SCADA system for operation legality verification, determines whether safety guidelines are violated, and identifies potential abnormal operation sequences through temporal data analysis. For the graphical dispatching suggestions output by the model, the power flow distribution and voltage interval parameters are extracted and compared with the preset operation boundaries of the power system to ensure that the output content complies with safety specifications.

[0047] Furthermore, the process protection module 120 establishes a connection with the algorithm trust registration platform for the power industry through APIs, supporting the on-chain deposit and verification of model filing information. The system automatically generates technical documents, including the definition of model input and output boundaries, the training data source traceability table, and the security alignment test report, and automatically submits them to the industry supervision platform through APIs to complete the pre-review process.

[0048] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated here.

[0049] In the various embodiments provided in this application, it should be understood that the disclosed systems, apparatus, and methods can be implemented in other ways. The above are merely illustrative embodiments; for example, the division of functional modules is only a logical separation, and different integration methods may exist in actual implementation. Multiple modules may be merged into one unit or split into more sub-units. Coupling between modules can be achieved through electrical, mechanical, or communication interfaces, including direct or indirect connections.

[0050] Components described as independent units are not necessarily physically separated, and their locations are not limited to a single device; they can be distributed across multiple computing nodes as needed. If a functional unit is implemented in software and sold or used as a product, it can be stored in a non-volatile computer-readable storage medium. Accordingly, the technical solution of this application can essentially be embodied as a software product, stored in a storage medium, containing several instructions to cause an electronic device to execute all or part of the steps of the methods in the embodiments of this application. The storage medium includes media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0051] Finally, it should be noted that the above descriptions are merely specific embodiments of this application, used to illustrate the technical solutions of this application, and not to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications, substitutions, or changes can still be made to the technical solutions described in the foregoing embodiments without departing from the spirit and scope of this application; and such modifications, changes, or substitutions should all be covered within the protection scope of this application. Therefore, the protection scope of this application is determined by the scope defined in the claims.

Claims

1. A compliance governance method for the power industry based on multi-module collaboration, characterized in that, Includes the following steps: Step 1: Configure the qualification compliance module to verify and manage the access qualifications of operating entities; the qualification compliance module is connected to the data classification system of power companies to divide the training data into production control, management information and public service data levels; based on the data level classification, the corresponding qualification application path is automatically matched; Step 2: Construct a process protection module and implement corresponding security control strategies in the data processing stage, model training stage, and service deployment stage. Step 3: Establish a risk operation system to continuously monitor the operation status of internal models and respond to and handle abnormal events in the external environment; Step 4: By integrating the multimodal audit engine, security knowledge base, and adversarial optimization module, information interaction and collaborative linkage between the modules are achieved; When the model training data is identified as substation inspection image data, it is determined to be sensitive data, triggering a special filing process and generating requirements for submitting data anonymization schemes, access control policies, and third-party security assessment reports.

2. The power industry compliance governance method based on multi-module collaboration as described in claim 1, characterized in that, During the construction of the process protection module, a regulatory strategy parsing engine is embedded to obtain policy documents in real time. Natural language processing technology is used to perform semantic analysis on the policy document to extract structured compliance rules; The structured compliance rules are converted into executable verification logic; The verification logic is synchronized to the multimodal audit engine and security knowledge base to update the corresponding audit rules.

3. The power industry compliance governance method based on multi-module collaboration as described in claim 2, characterized in that, The safety knowledge base is connected to the power company's energy management system and power distribution management system via API to obtain real-time data on power grid topology, equipment status and load level. When the multimodal audit engine performs compliance verification, it calls the power grid topology, equipment status, and load level data as contextual basis. An interface was established between the process protection module and the algorithm trust registration platform of the power industry to support on-chain storage and verification of model filing information; Automatically generate technical documentation, including model input / output boundary definitions, training data source traceability tables, and security alignment test reports; The technical documentation was submitted to the industry regulatory platform via API for preliminary review.

4. The power industry compliance governance method based on multi-module collaboration according to claim 3, characterized in that, During the operation of the risk management system, we continuously receive feedback instructions from the regulatory side; The regulatory feedback instructions are correlated with the novel attack patterns output by the red-blue team optimization module; Based on the results of correlation analysis, the compliance check items in the multimodal audit engine are dynamically updated; When a data poisoning attack targeting the power load forecasting model is detected, the qualification and compliance module's review mechanism is triggered. The model's functionality is paused via the process protection module, and event reporting information is sent to the industry regulatory platform via the API interface.

5. The power industry compliance governance method based on multi-module collaboration according to claim 4, characterized in that, The user's natural language input request is parsed into an operation instruction tree, and the SCADA system is linked to verify whether the operation violates the N1 safety rule. The time series data analysis is used to determine whether there is an abnormal operation sequence. The graphical scheduling suggestions output by the model are used to extract power flow distribution and voltage range parameters, and then compared with the preset operating boundaries for compliance.

6. The power industry compliance governance method based on multi-module collaboration according to claim 4, characterized in that, The regulatory feedback instructions received in the risk operation system and the detected attack behaviors are injected into the red-blue team optimization module to generate data poisoning attack samples and instruction obfuscation attack vectors for the power load forecasting model. The red team updates its defense strategy based on reinforcement learning algorithms, adjusting the model input verification rules and abnormal response thresholds. The corpus security screening submodule is used to analyze the misjudgment cases of the multimodal review engine and construct a training sample set containing composite features of visual occlusion and semantic masquerading. The rule extraction engine performs natural language processing on accident reports and scheduling anomaly records to extract event patterns with temporal constraints and causal logic. The generated event patterns are embedded into the knowledge graph of the security knowledge base in the form of ontology, and linked with real-time power grid operation data to achieve linked reasoning.

7. The power industry compliance governance method based on multi-module collaboration according to claim 1, characterized in that, When the multimodal audit engine performs audit operations, it calls the integrated power industry sensitive word library for text data in the power system to identify abnormal semantic combinations and perform semantic analysis in combination with the context. For image and / or video stream data, target detection and OCR technology are used to detect whether there is equipment status tampering, illegal annotation or alarm information obscuring in substation inspection videos; For audio data, voiceprint recognition is used to distinguish between authorized and unauthorized personnel, and simulated dispatch instructions generated by speech synthesis are detected.

8. A compliance governance system based on multi-module collaboration, characterized in that, include: The qualification and compliance module is used to verify and manage the legal access qualifications of operating entities. The qualification and compliance module is connected to the data classification system of power companies, which divides the training data into production control, management information and public service data levels. Based on the data level classification, the corresponding qualification application path is automatically matched. The process protection module is used to implement corresponding security control strategies in the data processing stage, model training stage, and service deployment stage respectively. The risk operation system module is used to continuously monitor the operating status of internal models and respond to and handle abnormal events in the external environment. By integrating a multimodal audit engine, a security knowledge base, and an adversarial optimization module, information exchange and collaborative linkage are achieved among the qualification and compliance module, process protection module, and risk operation system module. When the model training data is identified as substation inspection image data, it is determined to be sensitive data, triggering a special filing process and generating data anonymization schemes, access control policies, and submission requirements for third-party security assessment reports.