Slope monitoring abnormal event attribution analysis method and system in combination with knowledge graph

By combining knowledge graph-based attribution analysis of abnormal events in slope monitoring, the problem of lack of predictability and accuracy in early warning in highway high slope monitoring has been solved, realizing intelligent prediction and early warning of abnormal events and improving the predictability and accuracy of monitoring.

CN121745263APending Publication Date: 2026-03-27XINJIANG UNIVERSITY +3
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-25
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing technologies lack proactiveness in monitoring high slopes along highways, making it difficult to accurately identify the causes of abnormal events and their duration, resulting in insufficient targeting and accuracy of monitoring and early warning.

Method used

A knowledge graph-based attribution analysis method for slope monitoring anomalies is adopted. By statistically analyzing the characteristic value array of the triggering factors through a preset time window, traversing these arrays as constraints, statistically analyzing the duration of anomaly triggers, and constructing an attribution knowledge graph for anomalies, intelligent prediction and early warning of slope monitoring anomalies are achieved.

Benefits of technology

It has enabled a shift from passive monitoring to proactive early warning, improving the predictability and accuracy of highway high slope monitoring, providing specific early warnings and duration predictions for abnormal events, and guiding the development of targeted monitoring strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121745263A_ABST
    Figure CN121745263A_ABST
Patent Text Reader

Abstract

The invention provides a slope monitoring abnormal event attribution analysis method and system in combination with a knowledge graph, and belongs to the field of highway high slope abnormal analysis. The method comprises the following steps: executing inducement statistics of a preset time window on a slope monitoring abnormal event to obtain a plurality of inducement characteristic value arrays; traversing the plurality of inducement characteristic value arrays, respectively setting the inducement characteristic value arrays as constraint conditions, and counting a plurality of abnormal triggering durations of the slope monitoring abnormal events; and obtaining a to-be-analyzed slope cause monitoring state, inputting an abnormal event attribution knowledge graph, executing cause matching, obtaining a similar surrounding entity set, and outputting a matched slope monitoring abnormal event and a matched abnormal triggering duration. The technical problems that in the prior art, highway high slope monitoring is lack of pre-performance, and abnormal event inducements and the triggering duration thereof are difficult to accurately recognize are solved, and the technical effects that highway high slope abnormal event early warning is achieved based on historical inducement correlation analysis, and the abnormal triggering duration under different inducement conditions is accurately predicted are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of anomaly analysis of high highway slopes, and more particularly to a method and system for attribution analysis of slope monitoring anomalies combined with knowledge graphs. Background Technology

[0002] High highway slopes are crucial engineering structures in highway engineering, characterized by their great height and complex geological conditions. Due to their complex structure and the influence of multiple factors such as geological conditions, hydrological environment, and meteorological factors, highway high slope instability accidents occur frequently, posing a serious threat to personnel safety and property. Therefore, establishing effective slope monitoring and early warning systems is of great significance.

[0003] For high highway slopes, existing methods mainly employ displacement monitoring, tilt monitoring, and stress-strain monitoring, deploying various sensors to acquire real-time slope condition data. When the monitored data exceeds preset thresholds, an early warning signal is issued. However, existing monitoring methods are mostly passive response modes, only issuing alarms when anomalies occur, lacking sufficient predictability. Furthermore, the causes of abnormal events on high highway slopes are complex and diverse, including internal and external factors such as rainfall, human disturbance, groundwater level changes, and the dynamic effects of high-intensity earthquakes. Existing technologies struggle to accurately identify the correlation between specific causes and abnormal events, and cannot predict the duration of anomaly triggers under different conditions, resulting in insufficient targeting and accuracy of monitoring and early warning systems. Summary of the Invention

[0004] This invention addresses the technical problems in existing highway high slope monitoring, such as the lack of predictability and difficulty in accurately identifying the causes and duration of abnormal events. It provides a method and system for attribution analysis of abnormal events in slope monitoring that combines knowledge graphs.

[0005] The technical solution of the present invention to solve the above-mentioned technical problems is as follows: In a first aspect, the present invention provides a method for attribution analysis of slope monitoring anomalies combined with a knowledge graph, comprising: performing causal statistics on slope monitoring anomalies within a preset time window to obtain several causal feature value arrays; traversing the several causal feature value arrays, setting them as constraints respectively, and statistically analyzing several abnormal trigger durations of the slope monitoring anomalies; taking the slope monitoring anomalies as the central entity and the several causal feature value arrays as surrounding entities, connecting the central entity and the surrounding entities based on causal relationships, and connecting the several abnormal trigger durations and the surrounding entities based on trigger duration relationships to obtain an anomaly event attribution knowledge graph; obtaining the slope causal monitoring status to be analyzed, inputting the anomaly event attribution knowledge graph, performing causal matching to obtain a set of similar surrounding entities; and outputting the matched slope monitoring anomalies and the matched abnormal trigger durations based on the set of similar surrounding entities.

[0006] Secondly, this invention provides a slope monitoring anomaly event attribution analysis system combined with a knowledge graph, comprising: a trigger statistics module, used to perform trigger statistics on slope monitoring anomalies within a preset time window to obtain several trigger feature value arrays; a trigger duration statistics module, used to traverse the several trigger feature value arrays, set them as constraints respectively, and count several abnormal trigger durations of the slope monitoring anomalies; a knowledge graph construction module, used to take the slope monitoring anomalies as the central entity, the several trigger feature value arrays as surrounding entities, connect the central entity and the surrounding entities based on trigger relationships, and connect the several abnormal trigger durations and the surrounding entities based on trigger duration relationships to obtain an anomaly event attribution knowledge graph; a trigger matching module, used to obtain the slope trigger monitoring status to be analyzed, input the anomaly event attribution knowledge graph, perform trigger matching, and obtain a set of similar surrounding entities; and a result output module, used to output the matched slope monitoring anomalies and the matched abnormal trigger durations based on the set of similar surrounding entities.

[0007] The beneficial effects of this invention are: For slope monitoring anomalies, a pre-defined time window is used to statistically analyze the causes, obtaining several arrays of cause characteristic values. This captures the various potential cause states within a certain period before the anomaly occurs, providing a data foundation for subsequent correlation analysis. The arrays of cause characteristic values ​​are traversed, each set as a constraint condition, and the trigger durations of several anomalies in the slope monitoring anomaly are statistically analyzed. The time characteristics from the appearance of the cause to the occurrence of the anomaly under different cause conditions are quantitatively analyzed, establishing a correspondence between the cause and the trigger duration. Using the slope monitoring anomaly as the central entity and the arrays of cause characteristic values ​​as surrounding entities, the central entity and surrounding entities are connected based on the cause relationship, and the trigger durations of several anomalies are connected based on the trigger duration relationship. By combining surrounding entities, an attribution knowledge graph of abnormal events is obtained, thereby constructing a structured knowledge network of historical abnormal events, causal characteristics, and trigger durations, enabling the visualization and storage of complex relationships. The monitoring status of the slope's causal factors to be analyzed is obtained, and the attribution knowledge graph of abnormal events is input. Causal matching is performed to obtain a set of similar surrounding entities, thereby finding similar causal patterns in the historical knowledge graph based on the current monitoring status, achieving intelligent reasoning from historical experience to current prediction. Based on the set of similar surrounding entities, the system outputs matched abnormal slope monitoring events and matched abnormal trigger durations, providing specific abnormal event warnings and duration predictions for the current slope status, guiding the formulation of targeted monitoring strategies.

[0008] The above technical solution enables attribution analysis of slope anomalies based on knowledge graphs, transforming passive monitoring into proactive early warning and effectively improving the predictability and accuracy of highway high slope monitoring. Attached Figure Description

[0009] Figure 1This is a flowchart illustrating the attribution analysis method for slope monitoring anomalies that incorporates knowledge graphs, as provided by this invention. Figure 2 This is a schematic diagram of the slope monitoring anomaly event attribution analysis system that incorporates knowledge graphs, as provided by the present invention.

[0010] In the attached diagram, the components represented by each number are as follows: Trigger statistics module 11, trigger duration statistics module 12, knowledge graph construction module 13, trigger matching module 14, and result output module 15. Detailed Implementation

[0011] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0012] In the description of this invention, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the stated features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0013] In the description of this invention, the term "for example" is used to mean "used as an example, illustration, or description." Any embodiment described as "for example" in this invention is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use the invention. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that the invention can be made without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid obscuring the description of the invention with unnecessary detail. Therefore, the invention is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed herein.

[0014] Example 1, as Figure 1 As shown, this embodiment of the invention provides a method for attribution analysis of slope monitoring anomalies combined with knowledge graphs, including: S1. For abnormal events monitored on the slope, perform cause statistics within a preset time window to obtain several cause characteristic value arrays.

[0015] Specifically, firstly, for anomaly events detected by the highway high slope monitoring system, a causal statistical analysis based on a preset time window is performed to obtain an array of causal characteristic values ​​representing the inducing factors of the anomaly. When the highway high slope monitoring system detects an anomaly, a preset time window is first determined. This preset time window is typically set to a period of time before the anomaly occurs, such as three months, to capture the evolution of various inducing factors that may lead to the anomaly. The length of this preset time window is determined based on the gradual evolution characteristics of the anomaly, which can fully capture the development process of the anomaly symptoms while avoiding data redundancy caused by an excessively long time span.

[0016] Within a predetermined time window, statistical analysis is performed on slope monitoring data to identify and extract key characteristic parameters that characterize the inducing factors of abnormal events. These inducing factors include changes in the internal structural characteristics of the slope and external environmental influencing factors. Changes in internal structural characteristics encompass structural state parameters such as displacement changes, stress distribution changes, and water content fluctuations; external environmental influencing factors include environmental state parameters such as rainfall changes, temperature fluctuations, and seismic activity intensity. These different categories of characteristic parameters are organized and quantified to form corresponding inducing factor characteristic value arrays, thus establishing a data foundation for subsequent attribution analysis of abnormal events.

[0017] By statistically processing the monitoring data within a preset time window, the characteristic parameters of various inducing factors are extracted and organized into a structured data form, namely, an array of inducing factor characteristic values. Each array of inducing factor characteristic values ​​contains a quantitative representation of a specific inducing factor within the time window, providing a data foundation for subsequent attribution analysis of abnormal events. The inducing mechanism of slope monitoring anomalies usually involves the combined effects of multiple factors, resulting in several different arrays of inducing factor characteristic values, each corresponding to different types or combinations of inducing factors.

[0018] S2. Traverse the array of several causal feature values, set them as constraints respectively, and count the duration of several abnormal triggering events of the slope monitoring abnormal events.

[0019] Specifically, firstly, each of the several causal characteristic value arrays is extracted sequentially and used as a specific constraint to analyze the triggering patterns of historical slope anomalies. During the setting of constraints, based on the combination of triggering factors represented by the causal characteristic value array, multiple historical anomaly cases that meet the same or similar causal conditions are retrieved from historical slope monitoring data.

[0020] For each constraint, the time interval between the occurrence of the trigger and the actual triggering of the abnormal event is statistically analyzed; this is known as the abnormal trigger duration. Because the mechanisms of slope anomalies are influenced by complex geological and environmental factors, the abnormal trigger duration may differ between different cases, even under the same trigger conditions. Therefore, statistical analysis of the trigger durations of multiple historical anomaly cases is necessary to obtain the abnormal trigger duration under specific trigger constraints.

[0021] By traversing and processing all the feature value arrays of the triggers, several anomaly trigger durations are finally obtained, each corresponding to a specific trigger constraint. These anomaly trigger durations provide temporal relationship information for the subsequent construction of anomaly event attribution knowledge graphs, enabling the establishment of a quantitative correlation between trigger conditions and anomaly trigger times.

[0022] S3. Using the slope monitoring abnormal event as the central entity and the array of several causal feature values ​​as the surrounding entities, connect the central entity and the surrounding entities based on the causal relationship, and connect the several abnormal trigger durations and the surrounding entities based on the trigger duration relationship to obtain an abnormal event attribution knowledge graph.

[0023] Specifically, taking slope monitoring anomalies as the central entity and several causal feature value arrays as surrounding entities, the association between entities is established through causal relationships and trigger duration relationships to construct an anomaly event attribution knowledge graph.

[0024] First, slope monitoring anomalies are designated as the central entity of the knowledge graph, representing the target anomalies for attribution analysis. Then, several arrays of causal feature values ​​are designated as surrounding entities, each representing a specific combination of causal factors. Two types of relationships are used to establish connections between entities. Specifically, first, the central entity is connected to each surrounding entity based on causal relationships, which characterize the causal association between specific causal feature value arrays and slope monitoring anomalies. Second, several statistically obtained anomaly trigger durations are connected to their corresponding surrounding entities based on trigger duration relationships, which quantify the temporal evolution characteristics of anomalies under specific causal conditions.

[0025] Through the aforementioned connections, a star-shaped knowledge graph structure centered on slope monitoring anomalies is formed. In this knowledge graph, the central entity is connected to multiple surrounding entities through causal relationships, and each surrounding entity is connected to corresponding anomaly trigger duration data through trigger duration relationships. This structured knowledge representation not only preserves the correlation information between causal factors and anomalies but also integrates trigger patterns over time, thus constituting a complete anomaly attribution knowledge graph, providing a structured knowledge foundation for subsequent anomaly prediction and attribution analysis.

[0026] S4. Obtain the monitoring status of the slope causes to be analyzed, input the abnormal event attribution knowledge graph, perform cause matching, and obtain the set of similar surrounding entities.

[0027] Specifically, the current cause monitoring status of the slope to be analyzed is obtained and input into the constructed abnormal event attribution knowledge graph. By performing cause matching, the set of surrounding entities similar to the current cause monitoring status of the slope to be analyzed is identified and obtained, thus obtaining the set of similar surrounding entities.

[0028] First, real-time monitoring data of the slope to be analyzed is collected to obtain the current monitoring status of the slope's causes. This monitoring status includes the slope's current internal structural state parameters and external environmental state parameters, and has the same data structure and parameter type as the extracted cause feature value array. Then, the obtained monitoring status of the slope's causes is used as a query condition and input into the anomaly event attribution knowledge graph for matching analysis. During the cause matching process, the current monitoring status of the slope's causes is compared with the cause feature value arrays represented by each surrounding entity in the knowledge graph. This comparison process comprehensively considers the degree of deviation between the internal structural state parameters and the external environmental state parameters, and evaluates the matching degree by calculating the feature similarity between the monitoring status and each surrounding entity. When the similarity between a surrounding entity and the current monitoring status of the slope's causes reaches a preset threshold, the surrounding entity is identified as a similar entity and added to the similar surrounding entity set.

[0029] By traversing all the surrounding entities in the attribution knowledge graph of anomalous events, a set of similar surrounding entities is obtained, which includes all historical cause patterns that match the current monitoring status of the slope causes to be analyzed, providing a basis of similar cases for subsequent anomalous event prediction.

[0030] S5. Based on the set of similar surrounding entities, output the matched slope monitoring abnormal events and the matched abnormal trigger duration.

[0031] Specifically, the surrounding entities in the set of similar surrounding entities are analyzed, and the causal relationships established in the anomaly attribution knowledge graph are used to trace the types of slope monitoring anomalies associated with each similar surrounding entity. Since multiple surrounding entities in the set of similar surrounding entities may correspond to the same type of anomaly, these anomalies are categorized and organized to determine the types of slope monitoring anomalies that may occur under the current slope causal monitoring conditions to be analyzed.

[0032] Simultaneously, by utilizing the trigger duration relationships established in the knowledge graph, the abnormal trigger duration corresponding to each similar surrounding entity is extracted. For each type of slope monitoring anomaly event, the abnormal trigger duration information of relevant surrounding entities is summarized, and the expected trigger duration of this type of slope monitoring anomaly event under the current monitoring state of the slope's inducing factors is obtained through statistical analysis.

[0033] The analysis then outputs two parts of information: first, the matched slope monitoring anomalies, which are the types of slope monitoring anomalies that may occur under the current slope induced by the analysis; and second, the matched anomaly trigger duration, which is the expected trigger duration of each type of slope monitoring anomaly under the current slope induced by the analysis. This analysis provides slope monitoring managers with predictive information on anomalies and timely warnings, helping to develop targeted monitoring strategies and preventative measures, and enabling proactive management of slope anomalies.

[0034] Furthermore, for abnormal events monitored on slopes, a pre-defined time window is used to perform causal statistics, obtaining several causal characteristic value arrays, including: S11. Select a set of slope monitoring anomaly events of the first slope anomaly type from the slope monitoring anomaly events, and extract the slope structure status record dataset and the slope environment status record dataset of the preset time window. S12. Perform frequent pattern mining on the slope structure state record dataset to obtain a set of intrinsic cause feature values. S13. Perform frequent pattern mining on the slope environmental state record dataset to obtain a set of external cause feature values; S14. Perform internal and external causal enumeration and combination on the set of internal causal characteristic value arrays and the set of external causal characteristic value arrays to obtain the plurality of causal characteristic value arrays, wherein each combination of internal and external causal factors includes at least one internal causal characteristic value array or one external causal characteristic value array.

[0035] In one feasible implementation, firstly, a set of slope monitoring anomaly events of a first slope anomaly type is selected from the slope monitoring anomaly events. Then, a slope structural state record dataset and a slope environmental state record dataset within a preset time window are extracted from this set of anomaly events. Specifically, slope monitoring anomaly events include various types, such as landslides, collapses, and deformations, and are classified according to slope anomaly type. Firstly, one type of slope anomaly is selected as the first slope anomaly type, and all anomaly events belonging to this type are selected from the slope monitoring anomaly events to form a slope monitoring anomaly event set. Subsequently, for each anomaly event in this set of anomaly events, within a preset time window before its occurrence, slope structural state monitoring data and environmental state monitoring data are extracted respectively to form corresponding datasets, namely, a slope structural state record dataset and a slope environmental state record dataset.

[0036] Then, frequent pattern mining is performed on the slope structure state record dataset to obtain a set of intrinsic cause feature values. Specifically, by analyzing the change patterns of internal structural state parameters in the slope structure state record dataset corresponding to the first slope anomaly type, the frequently occurring structural state feature combinations before the occurrence of the anomaly event of this first slope anomaly type are identified. These statistically significant feature patterns are extracted and organized into an intrinsic cause feature value array, forming a set of intrinsic cause feature value arrays.

[0037] Simultaneously, frequent pattern mining was performed on the slope environmental state record dataset to obtain a set of external cause feature values. Specifically, by analyzing the change patterns of external environmental state parameters of the slope in the set of external cause feature values ​​corresponding to the first slope anomaly type, the combinations of environmental state features that frequently occurred before the occurrence of the anomaly event of the first slope anomaly type were identified. These statistically significant feature patterns were extracted and organized into an external cause feature value array, forming a set of external cause feature value arrays.

[0038] Next, the sets of intrinsic and extrinsic causal characteristic value arrays are enumerated and combined to obtain several causal characteristic value arrays specific to the current first slope anomaly type. Specifically, all arrays in the sets of intrinsic and extrinsic causal characteristic value arrays are permuted and combined to generate all possible combinations. The enumeration and combination process includes three types of combinations: the first is a combination containing only intrinsic causal characteristic value arrays; the second is a combination containing only extrinsic causal characteristic value arrays; and the third is a mixed combination containing both intrinsic and extrinsic causal characteristic value arrays. Each of these combinations is generated sequentially, forming a new causal characteristic value array, where each combination includes at least one intrinsic or one extrinsic causal characteristic value array. Through complete enumeration and combination, all possible combinations of intrinsic and extrinsic causal factors can be exhausted, thereby obtaining several causal characteristic value arrays covering various causal patterns for this first slope anomaly type, providing a comprehensive causal pattern foundation for subsequent anomaly event attribution analysis.

[0039] For other slope anomaly types, the same processing flow from steps S11 to S14 is followed for analysis, and several corresponding causal characteristic value arrays are obtained respectively, providing a comprehensive causal pattern basis for subsequent anomaly event attribution analysis.

[0040] Furthermore, frequent pattern mining is performed on the aforementioned slope structure state record dataset to obtain a set of intrinsic cause feature values, including: S121. According to the preset time step, slide the preset time window from the start time to the end time, and cut the slope structure status record dataset to obtain the first time zone slope structure status record dataset up to the Nth time zone slope structure status record dataset. S122. Extract several structural status record data from the first time zone slope structural status record dataset, wherein each structural status record data includes multiple structural status attribute feature values. S123. Based on the multiple structural state attribute feature values, traverse the several structural state record data, and respectively count the proportion of record data where the structural state deviation is less than or equal to the deviation threshold, and set it as several frequencies. S124. From the first time zone slope structure state record dataset, extract multiple structure state attribute feature values ​​of the selected structure state record data of the first time zone with a frequency greater than or equal to the frequency threshold, construct the first time zone intrinsic cause feature value array, and add it to the intrinsic cause feature value array set. S125. Until the intrinsic causal feature value array of the Nth time zone is obtained, add it to the intrinsic causal feature value array set and then perform storage.

[0041] In a preferred embodiment, firstly, according to a preset time step, the slope structure status record dataset is time-series segmented by sliding from the start time to the end time within a preset time window, obtaining slope structure status record datasets from the first time zone to the Nth time zone. Specifically, since slope anomalies exhibit a gradual evolutionary characteristic, anomalies in different time periods may show different concentrated distribution patterns. If the data of the entire time window is analyzed uniformly, the accuracy of the analysis results may be reduced. Therefore, a time sliding window approach is adopted, dividing the preset time window into several consecutive time periods according to a preset time step, forming the first to the Nth time zones. Subsequently, based on the time range of each time zone, structural status record data belonging to the time range of each time zone are extracted from the slope structure status record dataset, forming slope structure status record datasets from the first time zone to the Nth time zone, respectively, for refined analysis by time period.

[0042] Subsequently, several structural state record data points were extracted from the first time zone slope structural state record dataset. Each structural state record data point includes multiple structural state attribute feature values. Specifically, within the first time zone, the highway high slope monitoring system collected slope structural state data at different time points, and the monitoring data at each time point constituted a structural state record data point. Each structural state record data point contains multiple structural state attribute feature values ​​at that time point, such as slope displacement, stress distribution, and water content—key parameters that characterize the internal structural state of the slope. These parameters constitute the multidimensional feature vector of each structural state record data point. Therefore, the first time zone slope structural state record dataset contains structural state record data from various time points within that time zone, forming several structural state record data points.

[0043] Subsequently, based on multiple structural state attribute feature values, several structural state record data sets are traversed, and the proportion of record data sets with structural state deviations less than or equal to a deviation threshold is statistically analyzed, and this proportion is set as a frequency. Specifically, each structural state record data set is compared with other record data sets for similarity, and the degree of deviation between structural state attribute feature values ​​is calculated. When the structural state deviation of a certain structural state record data set with other structural state record data sets is less than or equal to a preset deviation threshold, these structural state record data sets are considered to have similar structural state patterns. The frequency proportion of each structural state pattern appearing in the first time zone slope structural state record data set is statistically analyzed, and this frequency is used as the frequency of that pattern, thus obtaining several frequency values.

[0044] Subsequently, from the slope structural state record dataset of the first time zone, multiple structural state attribute feature values ​​of selected structural state records in the first time zone with a frequency greater than or equal to the frequency threshold were extracted. An array of intrinsic causal feature values ​​for the first time zone was constructed and added to the intrinsic causal feature value array set. Through frequency filtering, statistically significant structural state patterns within this time zone can be identified. These frequently occurring structural state features are combined, extracted, and organized into an array of intrinsic causal feature values.

[0045] Repeat steps S122 to S124, processing the slope structure state record datasets from the second time zone to the Nth time zone sequentially until the intrinsic causal feature value array for the Nth time zone is obtained. Then, add the intrinsic causal feature value arrays for all time zones to the intrinsic causal feature value array set and store the data. By processing each time zone separately, a complete intrinsic causal feature value array set covering the structural state change patterns across different time periods within the entire preset time window can be obtained.

[0046] The acquisition of the external causal feature value array set adopts the same processing method as that for the internal causal feature value array set. The slope environmental state record dataset is time-series segmented according to a preset time step to obtain the slope environmental state record datasets from the first time zone to the Nth time zone. Subsequently, environmental state record data for each time point is extracted from each time zone's environmental state record dataset. Each environmental state record data contains multiple environmental state attribute feature values ​​such as rainfall, temperature, and seismic activity intensity. By calculating the environmental state deviation and statistically analyzing the frequency of each environmental state pattern, environmental state record data with a frequency greater than or equal to a frequency threshold are extracted to construct the external causal feature value array for each time zone, ultimately forming a complete external causal feature value array set.

[0047] Furthermore, the system iterates through the aforementioned structural state record data, and calculates the percentage of records where the structural state deviation is less than or equal to a deviation threshold, setting this percentage as a certain frequency, including: S1231. Extract the first set of structural state attribute feature values ​​and the second set of structural state attribute feature values ​​from the several structural state record data. S1232. Perform same-attribute comparison on the first group of structural state attribute feature values ​​and the second group of structural state attribute feature values ​​to obtain a set of structural state attribute deviation values. The matching rules for the same attribute are as follows: when it is a type attribute, the deviation value is 0 if the types are the same and 1 if the types are different; when it is a numerical attribute, the deviation value is the normalized parameter of the numerical deviation. S1233. Using the set of deviation values ​​of the structural state attributes as the deviation distance of each dimension, calculate the Euclidean distance to obtain the first structural state deviation, and add it to the set of structural state deviations. S1234. Based on the structural state deviation set, calculate the proportion of records where the structural state deviation of each group of structural state attribute feature values ​​is less than or equal to the deviation threshold, and set it as a certain frequency.

[0048] In a preferred embodiment, firstly, a first set of structural state attribute feature values ​​and a second set of structural state attribute feature values ​​are extracted from several structural state record data. Specifically, two structural state record data are arbitrarily selected from the first time zone slope structural state record data dataset, and multiple structural state attribute feature values ​​contained therein are extracted to form a first set of structural state attribute feature values ​​and a second set of structural state attribute feature values, which are used for subsequent similarity comparison analysis. Then, the first set of structural state attribute feature values ​​and the second set of structural state attribute feature values ​​are compared using the same attribute to obtain a set of structural state attribute deviation values. This same attribute comparison adopts the following rules: when the attribute being compared is a type attribute, if the two sets of feature values ​​are of the same type, the deviation value is set to 0; if the types are different, the deviation value is set to 1. When the attribute being compared is a numerical attribute, the deviation value is set to the normalized parameter of the numerical deviation between the two sets of feature values. By comparing each corresponding attribute one by one, the system obtains a set of structural state attribute deviation values ​​containing all attribute deviation values.

[0049] Next, using the set of structural state attribute deviation values ​​as the deviation distance for each dimension in the multidimensional space, the Euclidean distance between two sets of structural state attribute feature values ​​is calculated to obtain the first structural state deviation, which is then added to the structural state deviation set. This Euclidean distance calculation process integrates multidimensional attribute deviations into a single distance metric, used to quantify the overall similarity between two structural state record data. Then, based on the structural state deviation set, the proportion of record data where the structural state deviation of each set of structural state attribute feature values ​​is less than or equal to a deviation threshold is calculated, and this proportion is set as a frequency. Specifically, each structural state record data is used as a reference pattern, and the number of other record data with a structural state deviation less than or equal to a preset deviation threshold relative to this reference pattern is counted, and their proportion in the total record data is calculated as the frequency of this reference pattern. By traversing all structural state record data, several frequencies corresponding to various structural state patterns are obtained.

[0050] Furthermore, the arrays of several causal feature values ​​are traversed, and each is set as a constraint condition. The duration of several abnormal triggering events of the slope monitoring is statistically analyzed, including: S21. Extract the first slope anomaly type from the slope monitoring anomaly events; S22. Extract a first induced feature value array from the plurality of induced feature value arrays, wherein the first induced feature value array includes a first intrinsic induced feature value array and a first extrinsic induced feature value array; S23. Using the first external cause feature value array as a long-term constraint and the first internal cause feature value array as a starting constraint, retrieve multiple anomaly detection interval durations for the first slope anomaly type, wherein the anomaly detection interval duration is the time interval between the anomaly detection time and the detection time of the first internal cause feature value array. S24. Perform a central trend evaluation on the multiple anomaly detection intervals to obtain the first anomaly trigger duration, and store it in association with the first slope anomaly type and the first cause feature value array.

[0051] In a preferred embodiment, firstly, a first slope anomaly type is extracted from slope monitoring anomaly events. Specifically, anomalies of the first slope anomaly type are selected from slope monitoring anomaly events as the analysis objects to ensure the relevance and accuracy of subsequent anomaly trigger duration statistics. Then, a first induced feature value array is extracted from several obtained induced feature value arrays, wherein the first induced feature value array includes a first intrinsic induced feature value array and a first extrinsic induced feature value array. The first intrinsic induced feature value array contains internal slope structural state parameters, and the first extrinsic induced feature value array contains external slope environmental state parameters; together, they constitute a complete description of the induced features.

[0052] Then, using the first external causal characteristic value array as a long-term constraint and the first internal causal characteristic value array as an initial constraint, multiple anomaly detection intervals for the first slope anomaly type are retrieved. Since external environmental factors typically exhibit long-term fluctuations, their continuous changes often make it difficult to accurately predict anomaly triggering durations. Therefore, the first external causal characteristic value array is set as a long-term constraint condition to limit the range of changes in the external environmental state. Simultaneously, using the first internal causal characteristic value array as an initial constraint condition for anomaly triggering, anomaly event cases satisfying the above constraints are retrieved from historical data. For each retrieved case, the time interval between the detection of the state corresponding to the first internal causal characteristic value array and the detection of the anomaly event is calculated; this is the anomaly detection interval duration, thus obtaining multiple anomaly detection interval durations.

[0053] Subsequently, a central tendency evaluation was performed on the anomaly detection intervals to obtain the first anomaly trigger duration, which was then associated and stored with the first slope anomaly type and the first trigger feature value array. Through central tendency evaluation, representative duration values ​​can be extracted from the anomaly detection intervals of multiple historical cases as the expected trigger duration of anomaly events of the first slope anomaly type under specific trigger conditions, i.e., the first anomaly trigger duration. The obtained first anomaly trigger duration is then associated with and stored with the corresponding first slope anomaly type and first trigger feature value array, providing temporal relationship data for subsequent knowledge graph construction.

[0054] Furthermore, a central tendency evaluation is performed on the durations of the multiple anomaly detection intervals to obtain the first anomaly trigger duration, including: S241. After deleting outliers from the multiple anomaly detection interval durations, a concentrated anomaly detection interval duration is obtained. S242. Take the minimum value of the interval between the centralized anomaly detections and set it as the first anomaly triggering duration.

[0055] In a preferred embodiment, when evaluating the central tendency of multiple anomaly detection interval durations, firstly, outlier removal is performed on the multiple anomaly detection interval durations to obtain a centralized anomaly detection interval duration. Specifically, since historical anomaly event cases may contain anomaly duration data due to special conditions or measurement errors, these outliers can affect the accuracy of trigger duration evaluation. Therefore, the statistical distribution characteristics of multiple anomaly detection interval durations are first calculated, including parameters such as mean, standard deviation, and quartiles. Subsequently, outlier detection methods such as box plots or Z-scores are used, and an outlier determination threshold is set to identify anomaly detection interval durations that significantly deviate from the central tendency of the data, as outlier data. The identified outlier data is then removed from the original multiple anomaly detection interval durations, retaining the anomaly detection interval duration data within the normal distribution range to obtain the centralized anomaly detection interval duration.

[0056] Subsequently, the minimum interval between detected anomalies is taken and set as the first anomaly trigger duration. This minimum value selection strategy is based on the conservative principle of monitoring and early warning, using the shortest trigger duration as the early warning reference standard, which ensures that anomaly early warnings are provided under the most stringent time conditions. By selecting the minimum trigger duration, the most conservative early warning time window can be provided for slope monitoring and management personnel, ensuring that abnormal states are not missed, thereby improving the predictability and reliability of slope monitoring.

[0057] Furthermore, the monitoring status of the slope's causal factors to be analyzed is obtained, the abnormal event attribution knowledge graph is input, causal matching is performed, and a set of similar surrounding entities is obtained, including: S41. From the abnormal event attribution knowledge graph, randomly extract the matching trigger feature value array of the surrounding entity to be matched, wherein the matching trigger feature value array includes the matching internal trigger feature value array and the matching external trigger feature value array. S42. Extract the monitoring feature values ​​of the internal causes to be analyzed from the monitoring status of the slope causes to be analyzed, and compare them with the array of internal causes to be matched to obtain the deviation of the internal causes monitoring feature values. S43. Extract the external factor monitoring feature value to be analyzed from the monitoring status of the slope inducing factors to be analyzed, and compare it with the external factor feature value array to be matched to obtain the external factor monitoring feature value deviation. S44. When the deviation of the intrinsic monitoring feature value is less than or equal to the first deviation threshold and the deviation of the extrinsic monitoring feature value is less than or equal to the second deviation threshold, the entity to be matched surrounding is added to the set of similar surrounding entities.

[0058] In a preferred embodiment, firstly, a feature value array of potential matching causes for surrounding entities is randomly extracted from the anomaly event attribution knowledge graph. This feature value array includes both an array of internal and external causal features. Specifically, all surrounding entities in the anomaly event attribution knowledge graph are traversed, and each surrounding entity is sequentially designated as a potential matching entity. The corresponding feature value array for that entity is then extracted. This feature value array consists of two parts: an array of internal causal features and an array of external causal features, representing the internal structural state characteristics of the slope and the external environmental state characteristics of the entity to be matched, respectively.

[0059] Then, the monitoring feature values ​​of the internal causes to be analyzed are extracted from the monitoring status of the slope's inducing factors, and compared with the array of internal inducing factor feature values ​​to be matched to obtain the deviation of the internal inducing factor monitoring feature values. Specifically, firstly, internal structural state parameters, such as displacement changes, stress distribution, and water content, are extracted from the real-time monitoring data of the current slope to form the monitoring feature values ​​of the internal causes to be analyzed. Subsequently, the monitoring feature values ​​of the internal causes to be analyzed are compared attribute by attribute with the array of internal inducing factor feature values ​​to be matched. For type attributes, the deviation value is 0 when the type of the feature value to be analyzed and the type of the feature value to be matched are the same, and the deviation value is 1 when the types are different; for numerical attributes, the deviation value is the normalized parameter of the numerical deviation between the two. By comparing each corresponding attribute one by one, the set of deviation values ​​of the internal inducing factor monitoring attributes is obtained, and the Euclidean distance is calculated as the deviation of the internal inducing factor monitoring feature values ​​using this set of deviation values ​​as the deviation distance of each dimension in the multidimensional space.

[0060] Simultaneously, the monitoring feature values ​​of external factors to be analyzed are extracted from the monitoring status of the slope's inducing factors, and compared with the array of external inducing factor feature values ​​to be matched to obtain the deviation of the external factor monitoring feature values. Specifically, external environmental state parameters, such as rainfall, temperature changes, and seismic activity intensity, are extracted from the current environmental monitoring data of the slope to form the monitoring feature values ​​of external factors to be analyzed. The comparison process is the same as that of internal factors; the monitoring feature values ​​of external factors to be analyzed are compared with the array of external inducing factor feature values ​​to be matched, and the same type attribute and numerical attribute processing rules are used to obtain the set of external factor monitoring attribute deviation values. Then, the Euclidean distance of this deviation value set is calculated to obtain the deviation of the external factor monitoring feature values ​​that characterizes the degree of similarity of the external environmental state.

[0061] When the deviation of the internal factor monitoring characteristic value is less than or equal to the first deviation threshold, and the deviation of the external factor monitoring characteristic value is less than or equal to the second deviation threshold, the surrounding entity to be matched is added to the similar surrounding entity set. By setting the deviation thresholds for internal and external factors, surrounding entities with high similarity to the current slope monitoring status in terms of both internal and external conditions can be screened out, forming a similar surrounding entity set, which provides a basis for similar cases for subsequent anomaly event prediction.

[0062] Furthermore, based on the set of similar surrounding entities, the system outputs matching slope monitoring anomaly events and matching anomaly trigger durations, including: S51. Cluster the set of similar surrounding entities according to the slope anomaly type to obtain multiple slope anomaly types and multiple clusters of similar surrounding entities; S52. Traverse the multiple clusters of similar surrounding entities, extract the minimum value of multiple abnormal trigger durations, and set it as multiple matching abnormal trigger durations; S53. Add the multiple slope anomaly types to the matching slope monitoring anomaly events, and add the multiple matching anomaly trigger durations to the matching anomaly trigger durations, wherein the multiple matching anomaly trigger durations correspond one-to-one with the multiple slope anomaly types.

[0063] In a preferred embodiment, firstly, the set of similar surrounding entities is clustered according to slope anomaly types to obtain multiple slope anomaly types and multiple clusters of similar surrounding entities. Specifically, since different surrounding entities in the set of similar surrounding entities may be associated with different types of slope anomaly events, they are classified and organized according to the types of anomaly events connected by the causal relationships between each surrounding entity. The slope anomaly type associated with each similar surrounding entity is extracted, and the similar surrounding entities are clustered according to the anomaly type to form several anomaly type clusters. Each anomaly type cluster contains multiple similar surrounding entities associated with the same slope anomaly type, thereby obtaining multiple slope anomaly types and their corresponding multiple clusters of similar surrounding entities.

[0064] Then, the process iterates through multiple clusters of similar surrounding entities, extracting the minimum abnormal trigger durations and setting them as multiple matching abnormal trigger durations. Specifically, each cluster of similar surrounding entities is processed sequentially. For each similar surrounding entity within a cluster, its corresponding abnormal trigger duration is extracted based on the trigger duration relationship. Since a cluster contains multiple similar surrounding entities, each similar surrounding entity has a corresponding abnormal trigger duration. The minimum value is selected from the abnormal trigger durations of each cluster and set as the matching abnormal trigger duration for that cluster. By iterating through multiple clusters of similar surrounding entities, multiple matching abnormal trigger durations are obtained.

[0065] Subsequently, multiple slope anomaly types were added to the matched slope monitoring anomaly events, and multiple matched anomaly trigger durations were added to the matched anomaly trigger durations, with each matched anomaly trigger duration corresponding one-to-one with a specific slope anomaly type. By establishing the correspondence between slope anomaly types and matched anomaly trigger durations, a complete predictive output was generated, providing slope monitoring managers with the types of anomalies that might occur under the current causal monitoring conditions and their expected trigger times.

[0066] Example 2, as Figure 2 As shown, based on the same inventive concept as the slope monitoring anomaly event attribution analysis method combining knowledge graphs provided in Embodiment 1, this embodiment of the invention also provides a slope monitoring anomaly event attribution analysis system combining knowledge graphs, including: The cause statistics module 11 is used to perform cause statistics on abnormal events in slope monitoring within a preset time window and obtain several cause feature value arrays. Trigger duration statistics module 12 is used to traverse the array of several causal feature values, set them as constraints, and count the several abnormal trigger durations of the slope monitoring abnormal events. The knowledge graph construction module 13 is used to take the slope monitoring abnormal event as the central entity, the array of several causal feature values ​​as the surrounding entity, connect the central entity and the surrounding entity based on the causal relationship, and connect the several abnormal trigger durations and the surrounding entity based on the trigger duration relationship to obtain an abnormal event attribution knowledge graph. The cause matching module 14 is used to obtain the monitoring status of the causes of the slope to be analyzed, input the abnormal event attribution knowledge graph, perform cause matching, and obtain a set of similar surrounding entities; The result output module 15 is used to output the matching slope monitoring abnormal events and the matching abnormal trigger duration based on the set of similar surrounding entities.

[0067] Furthermore, the execution steps of the cause statistics module 11 include: The slope monitoring anomaly event set is sorted into the first slope anomaly type from the slope monitoring anomaly events, and the slope structure status record dataset and slope environment status record dataset of the preset time window are extracted. For the aforementioned slope structure state record dataset, perform frequent pattern mining to obtain a set of intrinsic cause feature values. For the aforementioned slope environmental status record dataset, perform frequent pattern mining to obtain a set of external cause feature values. The set of intrinsic causal feature value arrays and the set of extrinsic causal feature value arrays are combined by enumerating and combining intrinsic and extrinsic causal features to obtain the plurality of causal feature value arrays. Each combination of intrinsic and extrinsic causal features includes at least one intrinsic causal feature value array or one extrinsic causal feature value array.

[0068] Furthermore, the execution steps of the cause statistics module 11 also include: According to a preset time step, the slope structure status record dataset is segmented by sliding from the start time to the end time in the preset time window to obtain the slope structure status record dataset of the first time zone up to the slope structure status record dataset of the Nth time zone. From the first time zone slope structure status record dataset, extract several structure status record data, where each structure status record data includes multiple structure status attribute feature values. Based on the multiple structural state attribute feature values, the several structural state record data are traversed, and the proportion of record data with structural state deviation less than or equal to the deviation threshold is counted and set as several frequencies. From the first time zone slope structure state record dataset, extract multiple structure state attribute feature values ​​of selected structure state record data in the first time zone with a frequency greater than or equal to a frequency threshold, construct an array of intrinsic cause feature values ​​in the first time zone, and add it to the set of intrinsic cause feature values. The process continues until the intrinsic causal characteristic value array of the Nth time zone is obtained, and then it is added to the intrinsic causal characteristic value array set before storage is performed.

[0069] Furthermore, the execution steps of the cause statistics module 11 also include: Extract the first set of structural state attribute feature values ​​and the second set of structural state attribute feature values ​​from the aforementioned structural state record data; Perform same-attribute comparison on the first group of structural state attribute feature values ​​and the second group of structural state attribute feature values ​​to obtain a set of structural state attribute deviation values; The matching rules for the same attribute are as follows: when it is a type attribute, the deviation value is 0 if the types are the same and 1 if the types are different; when it is a numerical attribute, the deviation value is the normalized parameter of the numerical deviation. Using the set of deviation values ​​of the structural state attributes as the deviation distance for each dimension, calculate the Euclidean distance to obtain the first structural state deviation, and add it to the set of structural state deviations. Based on the set of structural state deviations, the proportion of records where the structural state deviation of each set of structural state attribute feature values ​​is less than or equal to the deviation threshold is calculated and set as a certain frequency.

[0070] Furthermore, the execution steps of the trigger duration statistics module 12 include: Extract the first slope anomaly type from the slope monitoring anomaly events; From the plurality of causal feature value arrays, a first causal feature value array is extracted, wherein the first causal feature value array includes a first intrinsic causal feature value array and a first extrinsic causal feature value array; Using the first external cause feature value array as a long-term constraint and the first internal cause feature value array as a starting constraint, multiple anomaly detection interval durations of the first slope anomaly type are retrieved, wherein the anomaly detection interval duration is the time interval between the anomaly detection time and the detection time of the first internal cause feature value array. The central trend evaluation of the multiple anomaly detection intervals is performed to obtain the first anomaly trigger duration, which is then associated and stored with the first slope anomaly type and the first cause feature value array.

[0071] Furthermore, the execution steps of the trigger duration statistics module 12 also include: After removing outliers from the multiple anomaly detection intervals, the concentrated anomaly detection intervals are obtained. Take the minimum value of the interval between the centralized anomaly detections and set it as the first anomaly trigger duration.

[0072] Furthermore, the execution steps of the cause matching module 14 include: From the anomalous event attribution knowledge graph, randomly extract the feature value array of the surrounding entities to be matched, wherein the feature value array of the surrounding entities to be matched includes the feature value array of the internal triggers to be matched and the feature value array of the external triggers to be matched. From the monitoring status of the slope causes to be analyzed, the monitoring feature values ​​of the internal causes to be analyzed are extracted and compared with the array of internal cause feature values ​​to be matched to obtain the deviation of the internal cause monitoring feature values. From the monitoring status of the slope causes to be analyzed, the monitoring feature values ​​of the external causes to be analyzed are extracted and compared with the array of external cause feature values ​​to be matched to obtain the deviation of the external cause monitoring feature values. When the deviation of the intrinsic monitoring feature value is less than or equal to the first deviation threshold, and the deviation of the extrinsic monitoring feature value is less than or equal to the second deviation threshold, the entity to be matched surrounding is added to the set of similar surrounding entities.

[0073] Furthermore, the execution steps of the result output module 15 include: The set of similar surrounding entities is clustered according to the slope anomaly type to obtain multiple slope anomaly types and multiple clusters of similar surrounding entities; Traverse the multiple clusters of similar surrounding entities, extract the minimum value of multiple abnormal trigger durations, and set it as multiple matching abnormal trigger durations; The multiple slope anomaly types are added to the matched slope monitoring anomaly events, and the multiple matched anomaly trigger durations are added to the matched anomaly trigger durations, wherein the multiple matched anomaly trigger durations correspond one-to-one with the multiple slope anomaly types.

[0074] It should be noted that the descriptions of each embodiment in the above embodiments have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0075] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0076] This invention is described with reference to the flowcharts and / or block diagrams in the accompanying drawings. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowcharts and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0077] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0078] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0079] Although preferred embodiments of the invention have been described, those skilled in the art, once they have learned the basic inventive concept, can make other changes and modifications to these embodiments.

[0080] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of this invention and its equivalents, this invention also intends to include these modifications and variations.

Claims

1. A method for attribution analysis of slope monitoring anomalies using knowledge graphs, characterized in that: include: For abnormal events in slope monitoring, perform cause statistics within a preset time window to obtain several cause characteristic value arrays; Iterate through the array of several causal feature values, set them as constraints, and count the duration of several abnormal triggering events of the slope monitoring anomaly. Using the slope monitoring abnormal events as the central entity and the array of several causal feature values ​​as the surrounding entities, the central entity and the surrounding entities are connected based on the causal relationship, and the several abnormal trigger durations are connected with the surrounding entities based on the trigger duration relationship, thereby obtaining an abnormal event attribution knowledge graph. Obtain the monitoring status of the slope's inducing factors to be analyzed, input the abnormal event attribution knowledge graph, perform inducing factor matching, and obtain a set of similar surrounding entities; Based on the set of similar surrounding entities, output the matched slope monitoring abnormal events and the duration of the matched abnormality trigger.

2. The method as described in claim 1, characterized in that, For abnormal events monitored on slopes, perform causal statistics within a preset time window to obtain several causal characteristic value arrays, including: The slope monitoring anomaly event set is sorted into the first slope anomaly type from the slope monitoring anomaly events, and the slope structure status record dataset and slope environment status record dataset of the preset time window are extracted. For the aforementioned slope structure state record dataset, perform frequent pattern mining to obtain a set of intrinsic cause feature values. For the aforementioned slope environmental status record dataset, perform frequent pattern mining to obtain a set of external cause feature values. The set of intrinsic causal feature value arrays and the set of extrinsic causal feature value arrays are combined by enumerating and combining intrinsic and extrinsic causal features to obtain the plurality of causal feature value arrays. Each combination of intrinsic and extrinsic causal features includes at least one intrinsic causal feature value array or one extrinsic causal feature value array.

3. The method as described in claim 2, characterized in that, For the aforementioned slope structure state record dataset, frequent pattern mining is performed to obtain a set of intrinsic cause feature values, including: According to a preset time step, the slope structure status record dataset is segmented by sliding from the start time to the end time in the preset time window to obtain the slope structure status record dataset of the first time zone up to the slope structure status record dataset of the Nth time zone. From the first time zone slope structure status record dataset, extract several structure status record data, where each structure status record data includes multiple structure status attribute feature values. Based on the multiple structural state attribute feature values, the several structural state record data are traversed, and the proportion of record data with structural state deviation less than or equal to the deviation threshold is counted and set as several frequencies. From the first time zone slope structure state record dataset, extract multiple structure state attribute feature values ​​of selected structure state record data in the first time zone with a frequency greater than or equal to a frequency threshold, construct an array of intrinsic cause feature values ​​in the first time zone, and add it to the set of intrinsic cause feature values. The process continues until the intrinsic causal characteristic value array of the Nth time zone is obtained, and then it is added to the intrinsic causal characteristic value array set before storage is performed.

4. The method as described in claim 3, characterized in that, Based on the aforementioned multiple structural state attribute feature values, the data is traversed through the various structural state records. The percentage of records with structural state deviations less than or equal to a deviation threshold is calculated and set as several frequencies, including: Extract the first set of structural state attribute feature values ​​and the second set of structural state attribute feature values ​​from the aforementioned structural state record data; Perform same-attribute comparison on the first group of structural state attribute feature values ​​and the second group of structural state attribute feature values ​​to obtain a set of structural state attribute deviation values; The matching rules for the same attribute are as follows: when it is a type attribute, the deviation value is 0 if the types are the same and 1 if the types are different; when it is a numerical attribute, the deviation value is the normalized parameter of the numerical deviation. Using the set of deviation values ​​of the structural state attributes as the deviation distance for each dimension, calculate the Euclidean distance to obtain the first structural state deviation, and add it to the set of structural state deviations. Based on the set of structural state deviations, the proportion of records where the structural state deviation of each set of structural state attribute feature values ​​is less than or equal to the deviation threshold is calculated and set as a certain frequency.

5. The method as described in claim 1, characterized in that, Iterate through the arrays of several causal feature values, setting them as constraints, and statistically analyze the trigger durations of several abnormal events in the slope monitoring, including: Extract the first slope anomaly type from the slope monitoring anomaly events; From the plurality of causal feature value arrays, a first causal feature value array is extracted, wherein the first causal feature value array includes a first intrinsic causal feature value array and a first extrinsic causal feature value array; Using the first external cause feature value array as a long-term constraint and the first internal cause feature value array as a starting constraint, multiple anomaly detection interval durations of the first slope anomaly type are retrieved, wherein the anomaly detection interval duration is the time interval between the anomaly detection time and the detection time of the first internal cause feature value array. The central trend evaluation of the multiple anomaly detection intervals is performed to obtain the first anomaly trigger duration, which is then associated and stored with the first slope anomaly type and the first cause feature value array.

6. The method as described in claim 5, characterized in that, A central tendency evaluation is performed on the durations of the multiple anomaly detection intervals to obtain the first anomaly trigger duration, including: After removing outliers from the multiple anomaly detection intervals, the concentrated anomaly detection intervals are obtained. Take the minimum value of the interval between the centralized anomaly detections and set it as the first anomaly trigger duration.

7. The method as described in claim 1, characterized in that, Obtain the monitoring status of the slope's inducing factors to be analyzed, input the attribution knowledge graph of the abnormal events, perform inducing factor matching, and obtain a set of similar surrounding entities, including: From the anomalous event attribution knowledge graph, randomly extract the feature value array of the surrounding entities to be matched, wherein the feature value array of the surrounding entities to be matched includes the feature value array of the internal triggers to be matched and the feature value array of the external triggers to be matched. From the monitoring status of the slope causes to be analyzed, the monitoring feature values ​​of the internal causes to be analyzed are extracted and compared with the array of internal cause feature values ​​to be matched to obtain the deviation of the internal cause monitoring feature values. From the monitoring status of the slope causes to be analyzed, the monitoring feature values ​​of the external causes to be analyzed are extracted and compared with the array of external cause feature values ​​to be matched to obtain the deviation of the external cause monitoring feature values. When the deviation of the intrinsic monitoring feature value is less than or equal to the first deviation threshold, and the deviation of the extrinsic monitoring feature value is less than or equal to the second deviation threshold, the entity to be matched surrounding is added to the set of similar surrounding entities.

8. The method as described in claim 1, characterized in that, Based on the set of similar surrounding entities, the system outputs matching slope monitoring anomaly events and matching anomaly trigger durations, including: The set of similar surrounding entities is clustered according to the slope anomaly type to obtain multiple slope anomaly types and multiple clusters of similar surrounding entities; Traverse the multiple clusters of similar surrounding entities, extract the minimum value of multiple abnormal trigger durations, and set it as multiple matching abnormal trigger durations; The multiple slope anomaly types are added to the matched slope monitoring anomaly events, and the multiple matched anomaly trigger durations are added to the matched anomaly trigger durations, wherein the multiple matched anomaly trigger durations correspond one-to-one with the multiple slope anomaly types.

9. A method for attribution analysis of slope monitoring anomalies using knowledge graphs, characterized in that: For implementing the method as described in any one of claims 1 to 8, comprising: The cause statistics module is used to perform cause statistics on abnormal events in slope monitoring within a preset time window and obtain several cause feature value arrays. The trigger duration statistics module is used to traverse the array of several trigger feature values, set them as constraints, and count the several abnormal trigger durations of the slope monitoring abnormal events. The knowledge graph construction module is used to take the slope monitoring abnormal events as the central entity, the array of several causal feature values ​​as the surrounding entities, connect the central entity and the surrounding entities based on the causal relationship, and connect the several abnormal trigger durations and the surrounding entities based on the trigger duration relationship to obtain an abnormal event attribution knowledge graph. The cause matching module is used to obtain the monitoring status of the causes of the slope to be analyzed, input the abnormal event attribution knowledge graph, perform cause matching, and obtain a set of similar surrounding entities; The result output module is used to output the matching slope monitoring abnormal events and the matching abnormal trigger duration based on the set of similar surrounding entities.