Electricity utilization safety monitoring and power saving control method and platform

By collecting electricity consumption data to identify device access events, generating risk classification results and control access strategies, dynamically adjusting trigger gating parameters, executing trigger-based capture and integrity encapsulation, generating safety constraint power-saving control commands, and performing secondary risk verification, the system solves the problems of signal aliasing and equipment aging in the electricity management system, and realizes dynamic adjustment of safety boundaries and risk avoidance.

CN121813690APending Publication Date: 2026-04-07JIANGSU KUNYUN INTERNET TECH GRP CO LTD +2
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-12
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing power management systems suffer from signal aliasing and difficulty in decoupling in scenarios with strong action-observation coupling, as well as the inability of static constraints to adapt to the cumulative degradation of equipment. This can lead to control actions being misjudged as faults or triggering secondary risks.

Method used

By collecting raw power consumption data, identifying device access events, generating device risk classification results and control access strategies, dynamically adjusting trigger gating parameters, executing trigger-based capture and integrity encapsulation, generating safety constraint power-saving control commands, and performing secondary risk verification based on feedback data, a closed-loop safety power-saving control system with end-edge-cloud collaboration is achieved.

Benefits of technology

It breaks through the masking of minor risks by control actions, and relies on the contact health model to realize the dynamic tightening of safety boundaries as the equipment ages, avoiding secondary risks induced by power saving control, and solving the problems of signal aliasing decoupling and static constraints being unable to adapt to the cumulative degradation of equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121813690A_ABST
    Figure CN121813690A_ABST
Patent Text Reader

Abstract

The invention discloses a power utilization safety monitoring and power saving control method and platform. The method comprises the following steps: collecting power utilization data, identifying equipment access, and generating a risk grading result and a control access strategy according to an equipment portrait; triggering gating parameters are dynamically adjusted based on risk grading, triggering type capture is executed on the data, and a tamper-proof evidence chain is generated; the access strategy is read, and a power saving instruction is generated and issued in combination with a safety constraint condition dynamically generated based on the contact health degree; after the action is executed, an expected response reference trajectory in a fault-free state is constructed, a residual error between actual feedback and the expected trajectory is calculated to execute secondary risk verification, and a closed-loop evaluation result is output; and the model and constraint are updated through end-side cloud collaboratively. According to the method, the problem that the control action masks the weak risk is solved through the expected response residual analysis, the dynamic tightening of the safety boundary along with the equipment aging is realized by using the contact health degree model, and the probability that the power-saving control induces the secondary risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent monitoring and control technology for power systems, specifically to methods and platforms for power safety monitoring and energy-saving control. Background Technology

[0002] With the surge in new types of electrical loads, energy-saving control is gradually being implemented in demand-side management of the power grid. When implementing proactive energy-saving strategies such as power adjustment, intermittent periodicity, or soft start-stop, the control actions themselves generate strong transient disturbances to the electrical waveforms, while simultaneously accelerating the wear and tear of physical components such as relay contacts. Therefore, in environments with strong interference, it is crucial to detect subtle safety risks induced by control actions, establish adaptive control boundaries based on the physical state of equipment, and achieve monitoring without false alarms and control without damaging equipment. This can ensure the safety of low-voltage side power consumption and improve the level of energy efficiency synergy.

[0003] Existing power management systems operate safety monitoring and energy-saving control as two separate functional modules. In terms of safety monitoring, mainstream arc fault detection (AFCI) technology relies on analyzing the high-frequency characteristics or zero-crossing characteristics of steady-state current waveforms to identify faults. For energy-saving control, smart sockets or energy efficiency controllers typically perform on / off operations based on preset schedules, power thresholds, or cloud-based commands. In some scenarios, some integrated solutions attempt to add monitoring functionality to the controller, that is, collecting current and voltage data while executing control commands, and achieving overload or short-circuit protection by comparing real-time data with protection thresholds.

[0004] However, existing technologies suffer from signal aliasing and difficulty in decoupling in strongly coupled action-observation scenarios, as well as the inability of static constraints to adapt to cumulative device degradation. Therefore, further research and innovation are needed to address these issues in existing technologies. Summary of the Invention

[0005] Purpose of the invention: In order to solve the above-mentioned problems in the existing technology, a method and platform for monitoring electricity safety and controlling energy saving are provided.

[0006] Technical solution: First aspect, a method for monitoring electricity safety and controlling energy conservation, comprising:

[0007] Collect raw electricity consumption data, identify equipment access events, and generate equipment risk classification results and control access strategies by combining equipment profile baselines;

[0008] Based on the equipment risk classification results, the triggering gating parameters are dynamically adjusted, and trigger-based capture and integrity encapsulation are performed on the original power consumption sampling data to obtain evidence chain data.

[0009] Read the control access policy, combine it with safety constraints to generate safety constraint power-saving control commands, and issue them for execution;

[0010] Collect control execution feedback data for energy-saving control commands under safety constraints, and perform secondary risk verification based on the control execution feedback data and evidence chain data to obtain closed-loop safety energy-saving assessment results;

[0011] Upload the closed-loop safety energy-saving assessment results and evidence chain data to the cloud, and receive updated safety constraints based on cloud-based archived analysis.

[0012] Secondly, an electricity safety monitoring and energy-saving control platform includes:

[0013] Memory, used to store computer programs;

[0014] A processor for executing a computer program to implement the method as described in any of the first aspects.

[0015] Beneficial effects: This invention, through expected response residual analysis, breaks through the masking of minor risks by control actions, and relies on a contact health model to dynamically tighten the safety boundary as the equipment ages, avoiding secondary risks induced by power-saving control. It also solves the problems of signal aliasing decoupling under strong action-observation coupling and the inability of static constraints to adapt to cumulative equipment degradation. The related technical effects will be described in detail below with reference to specific embodiments. Attached Figure Description

[0016] Figure 1 A flowchart of an electricity safety monitoring and energy-saving control method provided in an embodiment of this application.

[0017] Figure 2 This is a flowchart illustrating the generation of device risk classification results and control access strategies based on device profile baselines, as provided in this application embodiment.

[0018] Figure 3 This is a flowchart illustrating the generation of safety constraint power-saving control instructions based on safety constraints, provided in an embodiment of this application.

[0019] Figure 4 A flowchart illustrating the generation of security constraints provided in the embodiments of this application.

[0020] Figure 5 A flowchart illustrating the proportional reduction of the upper limit of the action amplitude and the upper limit of the action frequency provided in this application embodiment. Detailed Implementation

[0021] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0022] It should be noted that the terms "first," "second," etc., in the specification and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0023] To address the aforementioned issues, the applicant conducted in-depth searches and analyses, and discovered:

[0024] Specifically, control actions, such as phase-switching power adjustment, can generate nonlinear transient disturbances that resemble faults. Existing monitoring methods struggle to separate the normal control response from the subtle secondary risks induced by the actions (such as early arcing), which can easily lead to misjudging normal actions as faults or missing real risks due to masking of action signals.

[0025] Furthermore, existing control strategies often employ factory-preset static safety boundaries, such as fixed upper limits for operating frequencies, ignoring the physical wear and tear and degradation of contact health that accumulates with historical operations. As equipment ages, these original safety boundaries may become ineffective, potentially leading to safety accidents such as contact overheating, sticking, or electrical fires even when executing commands that conform to static rules.

[0026] To solve these problems, combined with Figures 1 to 5 The present invention will be specifically described through the following embodiments.

[0027] On the one hand, an exemplary solution for electricity safety monitoring and energy-saving control is provided. This solution addresses the technical problem of traditional energy-saving control and safety monitoring being disconnected, leading to potential secondary risks from energy-saving actions and misjudging control actions as malfunctions. It achieves closed-loop management through an edge-cloud collaborative architecture. Specifically, it includes:

[0028] Step 101: Collect the original power consumption sampling data, identify the device access event, and generate the device risk grading result and control access policy based on the device portrait baseline.

[0029] In some other embodiments, collect the original power consumption sampling data, identify the device access event, and generate the device risk grading result and control access policy in combination with the device portrait baseline.

[0030] Correspondingly, the original power consumption sampling data refers to the current and voltage waveform data obtained through front-end sensing units such as current transformers and voltage sensors. Its sampling frequency can be set between 10 kHz and 50 kHz so that it can capture the microsecond-level electrical transient characteristics. The device access event refers to the process of the load switching from the disconnected state to the connected and operating state. The system identifies this event by monitoring the power step or waveform mutation.

[0031] On this basis, the system evaluates the risk attributes of the connected device according to the pre-constructed device portrait baseline. The device portrait baseline contains the electrical fingerprints and fault records of the device's historical operation. According to the evaluation results, the system generates the device risk grading result, for example, classifying it into low-risk, medium-risk or high-risk levels. At the same time, a control access policy is generated to clarify whether the device is allowed to be controlled, as well as the allowed control intensity and boundary conditions.

[0032] Step 102: Dynamically adjust the trigger gating parameters based on the device risk grading result, perform trigger-based capture and integrity encapsulation on the original power consumption sampling data, and obtain the evidence chain data.

[0033] In this step, the system adopts a risk-driven variable-granularity sampling mechanism to solve the storage and transmission pressure brought by full-volume high-frequency sampling. The trigger gating parameters include the capture window length, sampling fidelity, etc. For high-risk devices, the system automatically configures more sensitive trigger thresholds and longer high-fidelity windows; for low-risk devices, standard sampling configurations are adopted.

[0034] When the monitored data meets the trigger condition, the system performs trigger-based capture, intercepts the data segment of the critical period, and performs integrity encapsulation on it. Integrity encapsulation means binding the data segment with meta-information and using the hash algorithm for solidification to prevent the data from being tampered with or lost during transmission or storage. On this basis, the generated evidence chain data not only contains the waveform itself, but also contains the timestamp and check code for auditing.

[0035] Step 103: Read the control access policy, generate a security constraint power-saving control instruction in combination with the security constraint conditions, and issue it for execution.

[0036] Before generating control commands, the system reads the control access policy to confirm the controllability of the equipment. Furthermore, based on safety constraints, it generates specific safety constraint power-saving control commands. These safety constraints include not only static preset rules but also dynamically generated constraint boundaries based on the real-time status of the equipment. The safety constraint power-saving control commands specify the specific power-saving action type, such as power adjustment, intermittent periodicity, or soft start / stop, as well as the execution time and duration of the action.

[0037] Step 104: Collect control execution feedback data for the safety constraint energy-saving control command, perform secondary risk verification based on the control execution feedback data and evidence chain data, and obtain the closed-loop safety energy-saving assessment result.

[0038] After the control action is executed, the system synchronously collects control execution feedback data, namely the actual waveform response during and after the action. Furthermore, this feedback data is combined with evidence chain data as a reference benchmark or correlation index to perform secondary risk verification. This verification process distinguishes between normal control responses and secondary risks induced by the action, such as contact overheating or arcing caused by frequent switching. Further, a closed-loop safety and energy-saving assessment result is output to indicate whether the control was safe and effective.

[0039] Step 105: Upload the closed-loop safety energy saving assessment results and evidence chain data to the cloud, and receive the updated safety constraints based on cloud-based archive analysis.

[0040] Based on this, the edge device uploads the assessment results and key evidence chain data to the cloud server for archiving. The cloud utilizes massive amounts of historical data to perform cross-device and cross-scenario analysis, identify common failure modes or model biases, and update the edge device's safety constraints or baseline parameters accordingly, achieving a continuous evolution closed loop of monitoring-control-remonitoring.

[0041] In some embodiments, the method may also be performed using the following steps:

[0042] Collect electricity consumption data and identify connected devices, and generate risk classification results and control access strategies based on device profiles;

[0043] Based on risk classification, the trigger gate parameters are dynamically adjusted to perform trigger-based capture of data and generate a tamper-proof evidence chain.

[0044] Read the access control policy and combine it with the safety constraints dynamically generated based on contact health to generate and issue power-saving instructions;

[0045] After the action is executed, a reference trajectory of the expected response under fault-free conditions is constructed, and the residual between the actual feedback and the expected trajectory is calculated to perform a secondary risk verification and output the closed-loop evaluation result.

[0046] The model and constraints are updated collaboratively through the edge and cloud.

[0047] On the other hand, it describes the specific implementation process of perception, triggering, and evidence collection. Specifically, it covers risk classification based on physical consistency and how to utilize risk gating mechanisms to achieve data capture. Accordingly, this process can be carried out through the following steps:

[0048] Step 201: Extract the window before and after device access from the original power consumption sampling data, and extract the access incremental response data that represents this access behavior.

[0049] In this step, the system maintains a real-time scrolling sampling buffer window. When a step change in total power is detected and the change exceeds a preset threshold (e.g., 50W), it is determined to be a device access event. At this time, the system locks the access time, backtracks to capture the steady-state window before access, and forward to capture the transient and steady-state windows after access.

[0050] Furthermore, the system extracts the incremental response data after access through differential calculation. Specifically, the total current waveform after access is subtracted from the background current waveform before access (which requires phase alignment), and the interference from the background load is removed to obtain a pure incremental waveform containing only the characteristics of the newly accessed device. This processing ensures the accuracy of subsequent feature calculations, especially in complex scenarios with multiple loads operating in parallel.

[0051] Step 202: Calculate the multidimensional features of the access incremental response data and perform physical consistency screening. Physical consistency screening is used to eliminate abnormal features that do not meet electrical physical constraints.

[0052] After obtaining the incremental response data, the system calculates its multidimensional characteristics, including but not limited to the change in active power ΔP, the change in reactive power ΔQ, current harmonic content, and start-stop transient waveform characteristics. To prevent misjudgments caused by sensor noise or transient interference, the system performs a physical consistency screening. Specifically, the physical consistency screening includes the following rules:

[0053] Accordingly, active and reactive power ratio constraints are applied. Based on basic physics, the power factor should be within a reasonable range for typical household or commercial loads. The system checks whether |ΔQ / ΔP| is less than a preset physical limit value; for example, for purely resistive loads, this ratio should be close to 0.

[0054] Furthermore, matching constraints are applied between current harmonics and load type. If a strong even-order harmonic is detected, the load typically exhibits nonlinear rectification characteristics; if the corresponding active power exhibits purely resistive characteristics, it is determined to be a physical inconsistency, possibly due to sampling anomalies or artifacts.

[0055] For samples that fail the physical consistency screening, the system will reduce the confidence level of their features or directly trigger a resampling request to obtain more reliable data.

[0056] Step 203: Compare the screened features with the risk threshold to determine the risk level of the device, and generate a control access strategy containing a set of allowed action types based on the risk level.

[0057] Accordingly, the system has pre-set threshold tables for different risk types. For example, overload current thresholds, contact resistance thermal effect thresholds, and arc characteristic energy thresholds are set. The screened characteristics are compared with the thresholds to determine the risk level of the equipment.

[0058] Specifically, risk levels can be classified as follows:

[0059] Low risk, equipment is operating well, and characteristics are within normal range. Allows for all types of energy-saving actions.

[0060] Medium risk: Minor anomalies detected, such as slight harmonic distortion, but not meeting fault criteria. Only mild power-saving actions, such as soft start-stop, are permitted; high-frequency, intermittent periodic actions are prohibited.

[0061] High risk. A significant anomaly has been detected, such as signs of poor contact, indicating a potential risk of malfunction. Do not perform any active control actions; this will trigger an alert.

[0062] Control is prohibited if the equipment itself is a sensitive load (such as a ventilator or a precision instrument) or is already in a faulty state.

[0063] Based on this, the system generates a control access policy according to the determined risk level, and clearly defines the set of permitted action types (e.g., {power adjustment, soft start / stop} or {none}).

[0064] Optionally, a mapping relationship can be established between the equipment risk classification results and the trigger gating parameters, and a longer capture window length and higher sampling fidelity can be configured for high-risk equipment.

[0065] Accordingly, the system maintains a mapping table between risk levels and trigger gating parameters. For low-risk devices, standard parameters are configured, such as a capture window length of 200ms (covering 10 power frequency cycles) and a sampling rate of 10kHz.

[0066] For high-risk devices, configure high-risk parameters, such as extending the capture window length to 500ms or longer to cover potential intermittent faults; increasing the sampling rate to 50kHz or higher to capture high-frequency arc characteristics; and increasing the pre-read length before triggering to preserve the complete fault progression process.

[0067] Optionally, a ring buffer mechanism is used to monitor the raw power consumption sampling data in real time. When the triggering conditions are met, the data is locked according to the triggering gating parameters, and a short window high-fidelity acquisition segment is extracted.

[0068] The edge side employs a ring-shaped buffer mechanism. This buffer continuously stores raw high-frequency data from a recent period (e.g., 2 seconds). When the trigger determination logic (based on risk classification results and real-time waveform monitoring) issues a trigger signal, the system does not start recording from the current moment. Instead, based on the configured pre-read length, it locks the read pointer in the ring-shaped buffer and reads back to a point in time before the trigger moment. This ensures that the captured short-window high-fidelity acquisition segments cover the entire process from the fault progression phase to the trigger instant to the fault decay phase, avoiding the common problem of losing the initial data segment upon triggering. If signal clipping or saturation is detected during the acquisition process, the system can also automatically trigger a gain reduction compensation acquisition mechanism, adjusting the analog front-end gain and waiting for the next trigger.

[0069] Optionally, the short-window high-fidelity acquisition segment, the trusted timestamp of the triggering time, and the hash value of the previous block are encrypted and encapsulated to generate tamper-proof evidence chain data.

[0070] Furthermore, the system encapsulates the collected data into a chain of evidence. This chain of evidence data includes the following key fields:

[0071] The association key refers to the ID used to uniquely identify the event across edge and cloud platforms.

[0072] Payload digest refers to the hash value obtained by performing SHA-256 or other digest calculations on short-window high-fidelity acquisition segments.

[0073] A trusted timestamp refers to an accurate time stamp generated by a trusted time source (such as a BeiDou / GPS timing module).

[0074] The previous block hash refers to the hash value linked to the previous evidence chain node, forming a chain structure.

[0075] Tamper detection associated data refers to signature information used to verify data integrity.

[0076] Optionally, an evidence summary can be extracted from the evidence chain data to create a fast index, which is used to quickly locate the control fragment for subsequent secondary risk verification.

[0077] Accordingly, instead of directly unpacking the massive full waveform data, the system extracts a lightweight evidence summary. The evidence summary includes key characteristic indicators such as peak current deviation, harmonic distortion rate, and repetitive micro-transient counts.

[0078] Simultaneously, a fast index is established, containing reference keys and the physical offset of data in the storage medium. When subsequent control loops require retracing the state before the action, this index can be used to locate and read the corresponding reference segment—the data segment under the same operating conditions before the action—within microseconds, without traversing the entire file system.

[0079] On the other hand, this method provides optional implementation methods for candidate action generation and disturbance suppression in the energy-saving control process. It solves the problem of how to generate an initial control strategy that is engineering-feasible and has minimal impact on the power grid before performing specific hard constraint screening. Specifically, this method includes:

[0080] Step 301: Generate multiple sets of parameterized power-saving candidate actions based on the action types allowed by the control admission strategy.

[0081] In this embodiment, the access control policy specifies the set of action types that the current device is allowed to perform. These action types specifically include, but are not limited to:

[0082] Power adjustment actions, such as adjusting the duty cycle of PWM (Pulse Width Modulation) or the conduction angle of thyristors;

[0083] Periodic and discontinuous actions, such as intermittent switching on and off with a period of minutes;

[0084] Soft start-stop actions, such as voltage ramp start;

[0085] Load scheduling actions, such as delaying startup time.

[0086] To facilitate algorithm processing, the system uses a vectorized approach to define each power-saving candidate action. Specifically, a candidate action can be represented as a parameter vector u=[u _1 u _2 u _3 u _4 ], where u _1 The normalized amplitude of motion (e.g., 0.8 represents 80% of rated power), u _2 Indicates the duration of the action, u _3 Indicates the gradual slope, u _4 This indicates the action type encoding.

[0087] Furthermore, the system employs grid search or heuristic generation algorithms to generate multiple sets of parameterized energy-saving candidate actions within the allowed parameter space. For example, for electric heating equipment that allows power adjustment, the system may generate a conservative action with an amplitude of 90% and a duration of 10 minutes, as well as an aggressive action with an amplitude of 70% and a duration of 5 minutes, for subsequent evaluation and selection.

[0088] Step 302: Add disturbance suppression parameters to each power-saving candidate action. The disturbance suppression parameters include the gradient slope and the minimum action interval, which are used to smooth the transient impact of the control action on the waveform.

[0089] Accordingly, the system enforces a perturbation suppression mechanism for each candidate action. Specifically, the gradual slope (u) _3 This specifies a rate limit for power change. For example, when performing a power adjustment action, the system does not directly jump the power from 100% to 80%, but gradually transitions to the target value over 2 seconds through multiple small steps (such as decreasing by 2% every 200ms) based on a gradual slope. This soft operation can reduce transient inrush current and electromagnetic interference (EMI) during the action, protect relay contacts, and reduce harmonic pollution to the power grid.

[0090] The minimum interval for actions specifies the required silence time between two consecutive control actions. For example, a minimum interval of 30 seconds can be set. If the device has just performed a shutdown or adjustment operation, no new non-emergency actions are allowed for the next 30 seconds. This mechanism is primarily used to prevent frequent relay engagement caused by control logic oscillations, as frequent mechanical movements accelerate the physical wear of the contacts.

[0091] Step 303: Use safety constraints to screen the energy-saving candidate actions after adding disturbance suppression parameters, and solidify the actions that meet the conditions into safety constraint energy-saving control commands.

[0092] After generating and optimizing candidate actions, the system inputs them one by one into the safety constraint filter. Safety constraints act as filters, including hard boundaries such as the maximum allowable amplitude and frequency of actions at the current moment. Only when all parameters of a candidate action fall within these boundaries is the action deemed safe and feasible.

[0093] For actions that pass the screening, the system solidifies their parameters (including amplitude, timing, and gradient curve), generates the final safety constraint power-saving control command, and sends it to the execution unit (such as the drive circuit or relay controller).

[0094] In some optional implementations, if multiple candidate actions simultaneously meet the safety constraints, the system will calculate the expected energy saving of each action based on a preset energy saving benefit objective function, and select the one with the highest benefit as the final instruction.

[0095] An example illustrates a physical modeling method for contact health, a state update logic based on cumulative wear, and how to dynamically tighten safety boundaries using this state to address the technical problem that static constraints cannot cope with the risks of equipment aging. Further, it can be implemented as follows:

[0096] Step 401: Maintain the contact health status of the monitored object. The contact health status characterizes the degree of cumulative physical wear and tear on the contact components.

[0097] In this embodiment, the system establishes a digital twin variable, denoted as H, for each controlled device, especially those containing mechanical relays or easily damaged connectors. The value range of the variable H is normalized to [0, 1], where 1.0 represents that the device is in a brand new factory condition with good contact and no oxidation or wear; 0.0 represents that the device contacts have reached their life limit and there is a high risk of poor contact or adhesion.

[0098] The state H is not a physical quantity sampled in real time, but rather an estimate of various states that monotonically decreases over time (or is reset after maintenance). It reflects the wear of the coating on the contact surface, the fatigue of the contact springs, and the degree of carbide accumulation.

[0099] Step 402: Based on the motion loss model, calculate the motion loss value using historically executed safety constraint power-saving control commands, and update the contact health status accordingly (motion loss value).

[0100] This includes updating contact health status, specifically:

[0101] Optionally, the action type and action range in the safety constraint energy-saving control command can be extracted, and the secondary risk occurrence marker in the closed-loop safety energy-saving assessment result can be read.

[0102] After each action is completed, the system initiates a health update process. Accordingly, the following key parameters are extracted from the previously executed command:

[0103] Action type u _4 For example, whether it is a mechanical switch action or an electronic power adjustment action;

[0104] and range of motion u _1 For example, the magnitude of the current.

[0105] Simultaneously, the secondary risk occurrence marker I is read from the evaluation results fed back from the closed-loop verification process. _risk If a weak electric arc or abnormal thermal effect is detected during the verification process, then I _risk =1, otherwise I _risk =0.

[0106] Optionally, the motion loss value for this action can be calculated according to the following motion loss model, and the motion loss value can be subtracted from the current contact health status, as shown in the formula:

[0107] H _n+1 =H _n -α×g(u1)×h(u4)×(1+β×I_risk );

[0108] Among them, H _n+1 H is the updated contact health status. _n Given the current state, α is the basic loss coefficient, g(u1) is the amplitude loss factor related to the action amplitude, h(u4) is the type loss factor related to the action type, and I... _risk This is used to indicate the occurrence of secondary risks, and β is the risk amplification factor.

[0109] Alternatively, the system calculates the health deduction ΔH caused by this action based on the physical loss model. The update formula is as follows:

[0110] H _n+1 =H _n -α×g(u _1 )×h(u _4 )×(1+β×I _risk );

[0111] Among them, H _n This indicates the contact health level before the action. α represents the base loss coefficient, determined by the contact material; for example, 0.0001 for silver-nickel alloy contacts. g(u _1 ) is the amplitude loss factor, which can also be written as g(u1). Considering that Joule heating is proportional to the square of the current, and that the arc energy increases sharply when a large current is interrupted, this factor is usually designed as a piecewise nonlinear function. For example, when u _1 ≤0.3, g(u _1 )=0.5u _1 When 0.3 _1 ≤0.7, g(u _1 ) = 0.15 + 1.5(u _1 -0.3); when u _1 >0.7, g(u _1 ) = 0.75 + 2.5(u _1 -0.7); The above formula shows that when the amplitude of the movement u _1 When the voltage exceeds 0.7, or 70% of the rated power, the slope of the loss factor increases, reflecting the severe impact of high-current operation on lifespan.

[0112] Where h(u) _4 ) is the type loss factor, which can also be written as h(u4). For example, it is 0.1 for power adjustment action (soft switching), 1.0 for mechanical switching action (hard switching), and 1.5 for periodic intermittent action. β is the risk amplification coefficient, which can be set to 5.0 to 10.0. Based on this, once an action induces a secondary risk, such as arcing, the life loss due to this action will be several times that of a normal action.

[0113] ​For example, suppose the current H _n =0.95, base coefficient α=0.001. Perform one amplitude u... _1 =0.8 mechanical switch action (h=1.0).

[0114] If the risk (I) is not triggered _risk =0), then calculate g(0.8)=1.0, ΔH=0.001×1.0×1.0×1=0.001, and after updating H=0.949.

[0115] If the risk (I) is triggered _risk =1), and β=9, then ΔH=0.001×1.0×1.0×(1+9)=0.01, and after the update H=0.940. It can be seen that risk events will cause a cliff-like drop in health.

[0116] Step 403: When the health status decreases, the upper limit of the action amplitude and the upper limit of the action frequency are reduced proportionally according to the preset mapping relationship to obtain the dynamically tightened safety constraints.

[0117] The reduction of the upper limit of the range of motion and the upper limit of the frequency of motion, among other things, includes:

[0118] Optionally, a critical health threshold is set. When the contact health status is lower than the critical health threshold, the upper limit of the action range is linearly tightened in proportion to the contact health status.

[0119] Optionally, the system dynamically calculates the upper limit of the allowable action range u at the next moment based on the current H value. _1_max The system sets a critical health threshold H. _crit For example, 0.4. When H ≥ H _crit At that time, the equipment was considered to be in good condition and full-power operation was permitted. _1_max =1.0.

[0120] When H <H _crit At this point, the system enters a conservative control zone, and the upper limit of the range of motion tightens linearly with H. The calculation formula is as follows:

[0121] u _1_max (H)=u _1_max_0 ×H / H _crit ;

[0122] Among them, u _1_max_0 The upper limit of the operating range corresponding to the equipment's health status is set to 1.0. When the health status drops to 0.2 (below 0.4), the maximum allowable operating range will automatically decrease to 50% of the rated value. This prevents aging equipment from burning out completely under high current.

[0123] Optionally, an interval expansion index can be set to expand the minimum action interval constraint inversely proportional to the power of the contact health status, thereby reducing the action frequency per unit time.

[0124] In addition to limiting the amplitude, the system also reduces the risk of heat accumulation by extending the action interval. The system sets an interval extension index γ, for example, 0.5. The dynamic minimum interval T... _int_min The formula for calculating (H) is as follows:

[0125] T _int_min (H)=T _int_min_0 / (H γ );

[0126] Among them, T _int_min_0 The initial minimum interval is, for example, 30 seconds. As H decreases, the denominator decreases, and the calculated minimum interval increases. For example, when H drops to 0.25, the minimum interval may extend to 60 seconds. This mechanism forces the aging device to cool for a longer period between actions, achieving adaptive protection based on physical conditions.

[0127] Furthermore, the embodiment introduces a dynamic contact health model to address the issue that static constraints cannot adapt to the cumulative degradation of equipment. The system no longer relies on factory-preset fixed boundaries but instead tracks the physical wear and tear on contacts caused by historical actions in real time. Based on the decline in health status, the system automatically performs a linear tightening of the upper limit of the action amplitude and an inverse expansion of the action interval. This mechanism allows the control strategy to adaptively evolve with the aging of the equipment, avoiding the risks of overheating, adhesion, or electrical fires induced by aging equipment executing routine commands.

[0128] Another example describes how to use expected response reference trajectories and residual analysis to address the technical problem of identifying weak secondary risk signals under strong control disturbances. Accordingly, this includes:

[0129] Step 501: Based on the action parameters of the safety constraint power-saving control command, construct the expected response reference trajectory of this action under fault-free conditions.

[0130] After performing the action, the system does not directly analyze the original waveform, but instead constructs an ideal copy in mathematical space, namely the expected response reference trajectory y. _exp (t). This trajectory represents the waveform that the device should exhibit if it is healthy and free from external interference.

[0131] Constructing this trajectory requires the action parameters in the command (such as start time, action amplitude, and duration) and the baseline parameters in the device profile.

[0132] The process of constructing the expected response reference trajectory for this action under fault-free conditions includes:

[0133] Optionally, based on the timing of the power-saving control command under safety constraints, the time axis of the expected response reference trajectory is divided into an action initiation segment, an action duration segment, and an action recovery segment.

[0134] The system divides the timeline into three phases, applying a different physical model to each phase:

[0135] The initiation phase corresponds to the instantaneous execution of the action and the subsequent transient process.

[0136] The sustained phase corresponds to the steady-state operation process after the action is completed.

[0137] The recovery phase corresponds to the recovery process after an action is canceled.

[0138] Optionally, during the action initiation and action recovery phases, a preset transient response template is applied to generate a trajectory. The transient response template includes an exponential decay term and a damped oscillation term, which are used to characterize the transient characteristics of the circuit triggered by the switching action.

[0139] For the startup phase, the system uses the following mathematical model to generate the expected trajectory y. _j (t), that is:

[0140] y _j (t)=y _j_base +A _j ×(1-exp{-(tt _0 ) / τ _j})+B _j ×exp{-(tt _0 ) / τ _j ×sin(2πf _j (tt _0 )+φ _j );

[0141] Among them, the first term y _j_base The first term is the baseline value; the second term is the exponential response, characterizing the smooth build-up of power, τ. _j A is a time constant. _j For the corresponding transient amplitude, exp{…} corresponds to the exponential function, and t corresponds to time. _0 The corresponding start-up trigger time; the third term is the damped oscillation term, characterizing the ringing effect caused by the distributed inductance and capacitance of the circuit, B _j f is the oscillation amplitude. _j The oscillation frequency is π, which corresponds to the mathematical constant pi, and φ is the oscillation frequency. _j The initial phase of the oscillation corresponds to this. All parameters are from the model parameter library provided in the cloud. By introducing a damped oscillation term, this model can reproduce the impact spikes caused by normal switching actions, preventing them from being misjudged as arc faults.

[0142] Optionally, during the duration of the action, a preset steady-state response template is applied to generate a trajectory. The steady-state response template includes a baseline DC component and a random fluctuation component, which are used to characterize the power characteristics of the load during steady-state operation.

[0143] For the sustained segment, the model simplifies to a steady-state form:

[0144] y _j (t)=y _j_base +A _j +σ _j ×N(t);

[0145] Where, σ _j Let N(t) be the expected steady-state noise standard deviation, and let N(t) be a unit Gaussian white noise sequence. This reflects the inherent random fluctuations of the equipment during steady-state operation.

[0146] Step 502: Time-align the control execution feedback data with the expected response reference trajectory, calculate the difference between the two, and generate the residual trajectory.

[0147] Based on this, the system reads the actual collected control execution feedback data y _obs (t), and combine it with the generated y _exp (t) performs microsecond-level timing alignment, typically based on the trigger edge of the action command. Further, the residual trajectory r(t) = y is calculated. _obs (t)-y _exp (t); Through this subtraction operation, normal control responses, such as large current jumps and normal ringing, are canceled out, and only the components not predicted by the model are retained in the residual.

[0148] Step 503: Perform structural decomposition and causal attribution on the residual trajectory to determine whether secondary risks have been induced.

[0149] The structural decomposition and causal attribution of the residual trajectory include:

[0150] Accordingly, the residual trajectory is separated into a modeling bias component that characterizes system error, a random noise component that characterizes environmental disturbance, and an abnormal structure component that characterizes abrupt change characteristics using a signal decomposition algorithm.

[0151] The residual r(t) is not entirely a risk signal; it also includes modeling errors and background noise. The system uses Empirical Mode Decomposition (EMD) or wavelet transform to decompose r(t) into three parts:

[0152] Modeling bias components, low-frequency trend terms, originating from parameter τ _j Or A _j Tiny estimation error;

[0153] Random noise components, high-frequency components that conform to a Gaussian distribution;

[0154] Anomalous structural components, non-stationary, high-energy mutational structures, and risk signal carriers.

[0155] Furthermore, the time-frequency features of the abnormal structural components are extracted, and the matching distance between the time-frequency features and the preset physical fault templates is calculated. The physical fault templates at least cover contact degradation risks, arc risks, and relay vibration risks.

[0156] Accordingly, the system extracts the time-frequency feature vector F of the anomalous structural components, including energy temporal concentration, peak frequency distribution, and repetitive pulse interval. Further, this vector is compared with the preset three types of risk template features F. _k The weighted Euclidean distance D _k ,Right now:

[0157] D _k =∑w _i ×|F _i -F _i_k |;

[0158] Where i is the dimension index of the feature vector, for example, it can take values ​​from 1 to 3; F _i_k The preset reference value for the i-th time-frequency feature in the k-th risk template; w _i The weight coefficient corresponding to the i-th feature dimension.

[0159] The specific characteristics of the three types of templates are as follows:

[0160] Contact degradation type is characterized by periodic small spikes synchronized with the power frequency, and the energy increases slowly over time;

[0161] Arc-type noise is characterized by a wide-bandwidth flat-top noise and randomly occurring, severe spikes.

[0162] Relay jitter is characterized by dense, repetitive pulses with fixed intervals appearing near the operating edge.

[0163] Based on this, when the matching distance is less than the preset attribution threshold, it is determined that a secondary risk of the corresponding type has been induced.

[0164] Specifically, the system calculates the causal attribution confidence score. If the matching distance D of a certain template... _k If the risk is sufficiently small, meaning the causal attribution confidence level is higher than the threshold, then the action is determined to have triggered a secondary risk of this type.

[0165] For example, if the abnormal structure in the residuals highly matches the contact degradation class template, the system will output a secondary risk of True, with the type being contact degradation. This conclusion will be fed back to the health model, causing a significant decrease in the H value and automatically tightening the boundaries in the next control cycle.

[0166] For example, specific numerical examples are provided below to illustrate the optional implementation process of residual analysis.

[0167] Accordingly, assuming the system performs a power adjustment action, the action parameters are: action amplitude A = 0.8 (i.e., 80% rated power), and the start time t. _0 =0ms, transient time constant τ=50ms. Based on the pre-stored transient response template, the system generates the expected response reference trajectory y. _exp (t).

[0168] During the initial action phase (0-200ms), the expected current value is calculated using a transient response template. For example, at t=100ms, the expected current is:

[0169] y _exp (100ms)=y _base +0.8×(1-exp(-100 / 50))+B×exp(-100 / 50)×sin(2π×500×0.1); where the indexed baseline value y _j_base It can also be simplified to y _base The same applies to other items, so I won't go into details.

[0170] Assume y _base =5A, B=0.2A, then y _exp (100ms)≈5+0.8×0.865+0.2×0.135×sin(314)≈5.72A.

[0171] Actual collected feedback current y _obs If (100ms) = 5.85A, then the residual r(100ms) = 5.85 - 5.72 = 0.13A.

[0172] After performing EMD decomposition on the residual trajectory of the entire time window, if the energy concentration of the abnormal structure component is 0.85 and the peak frequency distribution matches the arc-type template, i.e. the matching distance is 0.12, which is less than the attribution threshold of 0.2, then the system determines that this action has induced an arc-type secondary risk.

[0173] Another example provides a different secondary risk verification scheme. The described pre- and post-action comparison verification method has low computational complexity and is suitable for edge nodes with limited computing power or linear scenarios with relatively simple load characteristics. Specifically, it includes:

[0174] Accordingly, performing secondary risk verification may also include:

[0175] Step 601: Locate the comparison segment before the action is executed in the evidence chain data and align it temporally with the segment after the action extracted from the control execution feedback data.

[0176] In this embodiment, the system does not rely on mathematical models to construct the expected trajectory, but instead directly uses historical data from physical existence as a reference. When it is necessary to verify whether the waveform after an action is abnormal, the system accesses the evidence chain data. Using the fast reference index contained therein, the system can quickly locate the most recent stable running cycle before the action was executed, and use it as a comparison segment.

[0177] Based on this, the system performs strict timing alignment. Specifically, the system uses the voltage zero-crossing point or the trigger edge of the control action as the reference anchor point, and shifts the reference segment before the action and the feedback segment after the action on the time axis to make their phases coincide. In addition, the system also performs structural segment type consistency checks to ensure that the two segments being compared are under the same load conditions, such as both being steady-state operation segments, thus avoiding incorrect comparisons between transient and steady-state waveforms.

[0178] Step 602: Calculate the differential increment of similar risk characteristics on the aligned segments. When the differential increment exceeds the preset safety tolerance, it is determined that a secondary risk has been induced.

[0179] After alignment, the system calculates the differential increments of the two segments on key risk characteristics. These risk characteristics specifically include the RMS current, total harmonic distortion (THD), and high-frequency noise energy.

[0180] The formula for calculating the differential increment ΔF in the system is as follows:

[0181] ΔF=|F _post -F _pre |;

[0182] Among them, F _post F represents the feature value of the segment after the action. _pre This is the feature value of the pre-action comparison segment. Further, the system compares this differential increment with a preset safety tolerance (i.e., a threshold).

[0183] For example, to address the risk of poor contact, the system focuses on monitoring high-frequency energy characteristics. If the high-frequency energy after the action increases by more than 50% compared to before the action, i.e., ΔF > 0.5 × F _pre If the increment persists after the action is completed, it is determined that the control action has induced contact instability, and a secondary risk warning is output. This method cannot isolate normal control disturbances, but it has high engineering practical value in steady-state load scenarios.

[0184] In some scenarios, specific implementation schemes for the cloud-based collaborative process are described. In particular, the offline training and online evolution process of the artificial intelligence model demonstrates the data-driven nature of this invention. Specifically, the expected response reference trajectory is generated based on a pre-built expected response generation model, which is obtained through cloud training in the following manner:

[0185] Step 701: Retrieve historical normal action records of similar devices from cloud archive data. Historical normal action records are action response data that have not triggered secondary risk verification.

[0186] On the cloud server, the system maintains massive amounts of equipment operation logs. To train a high-precision expected response generation model, the system performs sample screening. Based on equipment type tags, such as inverter air conditioners or resistance heaters, the system retrieves historical action data for similar equipment.

[0187] Based on this, the system uses the closed-loop evaluation results to clean the data, removing all samples marked as triggering secondary risks or suspected faults, and retaining only the action response data that did not trigger secondary risk verification. This data represents the standard response of the equipment to control commands in a healthy state, constituting the positive sample set for model training.

[0188] Step 702: Perform parameter fitting on the transient segment of the historical normal action record to determine the transient response template, and perform statistical analysis on the continuous steady-state segment to determine the steady-state fluctuation parameters.

[0189] Using the cleaned positive sample set, the cloud training engine optimizes the parameters of the physical model using the least squares method or genetic algorithm.

[0190] For the initial transient phase, the system fits the transient response template parameters. Specifically, the system seeks the optimal transient amplitude, time constant, oscillation amplitude, and oscillation frequency to minimize the mean square error between the template curve and the historical waveform.

[0191] For the sustained steady-state period, the system statistically analyzes the distribution pattern of current fluctuations, calculates the standard deviation of steady-state noise, and determines the steady-state fluctuation parameters. This process compresses historical waveform data into physical parameters.

[0192] Step 703: Encapsulate the transient response template and steady-state fluctuation parameters into model parameters and send them to the edge side.

[0193] After training is complete, the cloud encapsulates the above parameters into a versioned model update package and sends it to the edge controller via OTA (Over-The-Air) technology. After receiving and loading these parameters, the edge controller updates its local expected response generation model, making the residual calculation more accurate.

[0194] Step 704: Calculate the modeling deviation components of the residual trajectory generated in multiple action verifications.

[0195] During routine operation at the edge, residual decomposition continuously generates modeling bias components. These components characterize the systematic error between the expected model and the actual equipment. The system maintains a local statistics window, recording the modeling bias components for the most recent N (e.g., 50) actions.

[0196] It should be understood that this step describes the online monitoring mechanism of the model.

[0197] Step 705: When the mean of the modeling bias component shows a monotonically drifting trend, generate and issue model correction parameters to calibrate the baseline value of the expected response reference trajectory.

[0198] Accordingly, the system periodically analyzes the statistical characteristics of the modeling deviation components. If the mean value is found to exhibit a monotonically drifting trend over time, such as gradually drifting from 0 to 0.5A, it indicates that the equipment has undergone physical aging (such as capacitor value decay) or that environmental parameters have changed, causing the original model parameters to no longer be applicable.

[0199] At this point, the system does not need to wait for retraining in the cloud; instead, it directly generates model correction parameters at the edge, such as compensating for baseline values, to calibrate the expected response reference trajectory. If the drift exceeds the self-calibration range at the edge, the system will send a retraining request to the cloud, triggering a new round of closed-loop processing.

[0200] In addition, as an optional implementation, the cloud also performs failure mode clustering analysis. The cloud clusters all reported false alarms—risk alarms manually marked as normal by users—and analyzes the distribution of their feature vectors. If a certain type of false alarm is found to be concentrated in a specific action type or time period, the cloud will pinpoint the weaknesses in the strategy and update the security constraint rule data accordingly.

[0201] In other scenarios, a hardware architecture for electronic devices (or apparatuses) to implement the above methods is provided. Alternatively, an electricity safety monitoring and energy-saving control platform is provided.

[0202] This embodiment provides an electronic device, which may specifically be a smart circuit breaker, a smart socket, an edge computing gateway, or an embedded power controller. The device physically includes a memory and a processor, as well as sensing and actuation units necessary to implement monitoring and control functions.

[0203] The memory is used to store computer programs. Specifically, the memory may include high-speed random access memory (RAM), and may also include non-volatile memory (NVM), such as one or more disk storage devices, flash memory devices, or other non-volatile solid-state storage devices. The computer program contains instruction code for performing any of the methods of the embodiments of the present invention.

[0204] The processor is used to execute a computer program to implement the method described in any of the embodiments, and the processor is connected to a sensing and execution unit. Specifically, the processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices.

[0205] In this embodiment, the processor is also connected to a high-frequency data acquisition module. This module includes a high-precision analog-to-digital converter (ADC) for acquiring voltage and current signals at a sampling rate of 10 kHz or higher and writing the data into the processor's ring buffer.

[0206] Furthermore, the processor is also connected to a control execution module. This module specifically includes a relay drive circuit or a power electronic switch (such as a thyristor or MOSFET) drive circuit, used to respond to safety constraint power-saving control commands and perform on / off or power adjustment operations on the load circuit.

[0207] Furthermore, the processor is also connected to a communication module. This module supports Wi-Fi, 4G / 5G, LoRa, or Ethernet communication protocols, and is used to upload closed-loop safety power saving assessment results and evidence chain data to the cloud server, and receive model parameters and policy updates from the cloud.

[0208] In other words, the sensing and actuation unit includes a high-frequency data acquisition module, a control execution module, and a communication module, which are used to acquire electrical parameters, execute power-saving control commands, and realize data interaction and transmission. The electrical parameters can also be the original sampling data of electricity consumption.

[0209] In summary, this embodiment, through the tight integration of hardware and software, constructs a complete system with edge awareness, local decision-making, and cloud evolution capabilities, thus resolving the coupling conflict between power-saving control and safety monitoring in practical engineering applications.

[0210] In some other scenarios, an application scenario review is provided, specifically:

[0211] Correspondingly, in the intelligent power distribution system of a commercial building, a 3kW inverter air conditioner is connected to the power grid via a smart socket. This smart socket has been in operation for 6 months, accumulating approximately 5000 power adjustment actions, and its current contact health status H=0.65.

[0212] Optionally, the system collects the current waveform when the air conditioner starts up and identifies the device access event. Based on the device profile baseline, such as for inverter air conditioners, the startup surge characteristic matching degree is 0.92. The system classifies it as a medium-risk level and generates a control access policy: allowing power adjustment and soft start / stop, and prohibiting high-frequency intermittent operation.

[0213] Since the device is classified as medium-risk, the system is configured with a capture window length of 300ms and a sampling rate of 20kHz. When a power fluctuation exceeding a threshold is detected, high-fidelity acquisition is triggered, and evidence chain data is generated.

[0214] Furthermore, the cloud-based power-saving strategy reduces the air conditioner's power to 70%. The system reads the control access policy and confirms that the power adjustment is permitted. Since the current H=0.65>H... _crit =0.4, upper limit of action amplitude remains at 100%, minimum action interval remains at 30 seconds. The system generates a safety constraint power-saving control command: adjust power to 70%, gradual slope 2% / 200ms.

[0215] After the action is executed, the system collects feedback data and constructs a reference trajectory for the expected response. Through residual analysis, the energy of the abnormal structural components is below the threshold, and the matching distance is >0.5, indicating that no secondary risk has been induced.

[0216] Based on this, the loss value of this power adjustment action is ΔH = 0.001 × 0.85 × 0.1 × 1 = 0.000085, and after the update, H = 0.65 - 0.000085 ≈ 0.6499.

[0217] In summary, the system achieves energy-saving control of the air conditioner while ensuring electrical safety.

[0218] In this invention, the embodiments employ a residual analysis method based on a physical model. A reference trajectory for the expected response, incorporating transient and steady-state characteristics, is constructed. The system subtracts the expected signal from the actual observed signal, mathematically eliminating normal control disturbances such as harmonics generated by power adjustment or initiation surges. Furthermore, by performing structural decomposition and causal attribution on the residuals, weak secondary risk characteristics such as contact degradation or early arcing are extracted under strong interference environments. This solves the problem of false alarms and missed alarms caused by the inability of traditional methods to distinguish between normal actions and abnormal risks.

[0219] According to one aspect of this application, some methods of the present invention may also be:

[0220] Optionally, the corresponding access window of the device access event data in the original power consumption sampling data is read, and the access window aligned data is segmented to form access incremental response data;

[0221] Risk evidence elements are calculated based on incremental response data. Risk evidence elements include at least overload risk evidence, contact risk evidence, arc risk evidence and power quality disturbance evidence. Each evidence element is normalized into a unified dimension evidence score.

[0222] Perform evidence consistency verification to determine whether the evidence elements meet the physical consistency constraints. If not, reduce the confidence level of the corresponding evidence score or trigger a resampling request.

[0223] Based on the safety threshold strategy data, the evidence score is mapped to the risk level, which includes at least low risk, medium risk, high risk and prohibited control, generating equipment risk classification result data;

[0224] Based on risk level and risk type labels, control access strategy data is generated. The control access strategy data shall include at least the set of permitted action types, the upper limit of action range, the minimum action interval, the requirement to obtain proof and the emergency rollback conditions.

[0225] The key evidence scores, risk levels, access boundaries, and event identifiers from this access will be solidified into baseline data for device access, which will be used for subsequent gating and comparison before and after actions.

[0226] Furthermore, focusing on the disturbance mechanism of control actions on electrical connection states and waveform transients, a correspondence between observable evidence and physical mechanisms is constructed, thereby enumerating secondary risk triggering paths. Specifically:

[0227] Optionally, the equipment risk classification results data and control access strategy data can be read to determine the sensitive risk type and sensitive period of this load;

[0228] Optionally, read the event risk evidence summary, or its corresponding evidence summary, and extract evidence elements related to contact state, transient spikes, periodic discontinuities and harmonic distortion as observation entry points for secondary risk triggering;

[0229] Optionally, enumerate at least three typical triggering paths and establish an observable evidence mapping:

[0230] One type of path is that power adjustment or soft start-stop causes jitter at the action boundary of switching devices or relays, which causes a short-term increase in contact resistance and induces local hot spots. The observable evidence for this is a sudden increase in high-frequency energy, enhanced zero-crossing jitter, and an increase in the count of repetitive micro-transients within a short window.

[0231] The second type of path is that the surge current is repeated due to intermittent or frequent start-stop cycles, which aggravates the fretting wear of the connector and causes intermittent arcing. The observable evidence for this is that the peak current deviation increases, the transient duration is prolonged, and the short window structure segment is repeated.

[0232] The three paths are: peak shifting and peak offsetting cause multiple devices to start concurrently, resulting in voltage dips and harmonics superimposed on each other, which obscures or falsely triggers the evidence for arc detection. The observable evidence is mapped as an increase in power quality disturbance evidence and an increase in the frequency of failure to verify the consistency of risk evidence.

[0233] Optionally, the triggering conditions, observable evidence elements, and risk level escalation rules corresponding to each path can be written into the security constraint rule data for subsequent pre-assessment and post-action evidence determination.

[0234] In this step, a computable mapping is constructed from action parameters to incremental evidence elements, and the upper bound of the impact of candidate actions on secondary risk is calculated based on this mapping. Specifically:

[0235] Accordingly, the action type, action amplitude, action duration, gradient slope, action interval and backtracking path in the candidate action execution plan data are encoded into a set of action parameters;

[0236] Furthermore, the evidentiary elements and confidence levels in the event risk evidence summary, short-window quality assessment data, and equipment access baseline record data are encoded into a state evidence set;

[0237] Based on this, at least two schemes for implementing the mapping method are proposed:

[0238] One is piecewise linear and table-driven mapping, which maps the set of action parameters to incremental predictions of evidence elements according to the action type and working condition identification results, and calibrates the mapping parameters with the statistical quantiles in the baseline record data of historical similar devices and the cloud-side archived alignment data.

[0239] Secondly, lightweight learning mapping is used to form a supervision sample on the cloud side using closed-loop safety power saving assessment data and post-action risk review data, and train a prediction model to obtain the increment of action parameters to evidence elements. On the edge side, only inference is performed and the incremental prediction and uncertainty are output.

[0240] Furthermore, based on the mapping output, the perturbation sensitivity is calculated. The perturbation sensitivity includes at least the sensitivity to the magnitude and interval of the action. The sensitivity is used to screen candidate actions that are highly sensitive to risk evidence.

[0241] Furthermore, the incremental prediction data of action risk and the prediction data of conservative risk are output as candidate action risk assessment data for hard constraint screening.

[0242] According to another aspect of this application, the safety constraint rule data can also consist of a set of executable hard constraints and control switching logic following a violation, which are used as hard boundaries to directly eliminate actions during the candidate action screening stage. Specifically, this includes:

[0243] The constraints include at least the frequency of action constraints, the magnitude of action constraints, the minimum interval of action constraints, the requirement for proof to be delivered, and the observability protection constraints.

[0244] The frequency of actions is constrained to limit the maximum number of switching operations per unit of time, with stricter limits set for high-risk devices;

[0245] The constraints on the amplitude of movement limit the upper limit of the single power adjustment amplitude or the intensity of start-stop disturbance, and further tighten them for equipment with evidence of contact risk.

[0246] The requirement that the return certificate must be delivered means that after each issuance of safety constraint power-saving control command data, the action return certificate trigger signal data must be collected in a short window after triggering the action within a specified time sequence; otherwise, the candidate action will be directly eliminated.

[0247] The observability protection constraint requires that the action execution plan must not cover the key observation window specified by the trigger gating strategy data, so as to avoid monitoring distortion and lack of evidence caused by control actions;

[0248] For any violation of hard constraints, the controller must generate an emergency rollback or degrade execution instruction and write the reason for the violation into the control decision traceability log data.

[0249] According to another aspect of this application, the rules for consistency alignment of the return certificate after the execution of the action can also be as follows:

[0250] By comparing the changes in evidentiary elements before and after the action under the same working conditions and structural segment conditions, a secondary risk assessment result is formed by weighting the confidence level.

[0251] Accordingly, the reference fragment index data is read, and a reference fragment consistent with the current working condition is located from the evidence chain data before the action. The same type of structural segment is extracted from the short-window high-fidelity acquisition data after the action. The structural segments before and after the action are aligned according to the short-window structural segmentation data. The alignment includes at least trigger point alignment, period phase alignment and structural segment type consistency verification. The event risk evidence summary after the action is recalculated and compared with the event risk evidence summary before the action on the aligned structural segments to obtain the evidence element increment and confidence level.

[0252] If the increment of evidence elements exceeds the secondary risk judgment threshold in the security constraint rule data, or if repeated micro-transient accumulation occurs, the output secondary risk judgment result data will be considered as an increase in risk, triggering an emergency rollback or stopping execution; the alignment basis, differential result, threshold judgment and the referenced evidence chain quick reference index data will be written into the evidence chain association result data after the action to ensure traceability.

[0253] According to another aspect of this application, an optional implementation of the short-window capture and supplementary capture mechanism is provided, namely, employing multiple short-window lengths and multiple sampling fidelity levels, and determining whether to perform supplementary capture based on short-window quality assessment data. This can be done through the following methods:

[0254] The short window length should include at least three levels: standard, enhanced, and high-risk. The standard level is used for low-risk equipment, and the high-risk level is used for high-risk equipment. A pre-buffer is used to cover the progressive section before triggering, and a post-buffer is used to cover the attenuation section after triggering. The ratio of the pre-buffer to post-buffer should be adaptively adjusted according to the risk level. Short window quality indicators should include at least trigger point coverage integrity, signal-to-noise ratio, clipping saturation detection, point loss detection, and structural preservation.

[0255] Based on this, when the short window quality index does not meet the threshold, supplementary capture control is triggered. Supplementary capture includes at least extending the post-buffer, improving the sampling fidelity level, or improving the fidelity ratio of key structural segments. The reason for supplementary capture is written into the short window quality assessment data.

[0256] According to one aspect of this application, the event risk evidence summary can be: structured data consisting of an event identifier field, a trigger type field, an evidence element field, a quality field, and an index field.

[0257] The event identifier field includes at least the event identifier, device identifier, and timestamp; the trigger type field includes at least the trigger type, trigger strength, and gating judgment result; the evidence element field includes at least the peak current deviation, harmonic distortion indication, high-frequency energy indication, period discontinuity count, transient duration, repetitive micro-transient count, and corresponding confidence level; the quality field includes at least the short window quality level, clipping saturation flag, and supplementary capture flag; and the index field includes at least the reference key in the evidence chain fast reference index data and the compressed load association index to ensure fast citation.

[0258] Building upon this, the evidence chain data structure can also be a combination of a payload structure oriented towards closed-loop evidence retrieval and a chain-like tampering detection field, providing an index structure for rapid reference within the control closed loop. Specifically, each evidence chain record includes at least evidence chain association key data, a summary of preceding records, a payload summary, a trusted timestamp, and tampering detection association data; the payload includes at least discriminant information-preserving compressed payload data, event risk evidence summary data, short-window quality assessment data, and compression parameter descriptions; the evidence chain rapid reference index data includes at least a reference key, payload offset positioning information, and a quick mapping of the summary field, enabling the edge controller to locate the comparison fragment and summary field without unpacking the full payload; and establishing a one-to-one association between the evidence chain rapid reference index data and the control decision traceability record data ensures that actions are aligned before and after, and that evidence retrieval is traceable.

[0259] Furthermore, the candidate action generation mechanism can also be: constructing an action parameter grid or heuristic search space based on the action type set and action executable boundary data, and superimposing perturbation suppression parameters to generate candidate action execution plan data.

[0260] Accordingly, the action type set should include at least one or more of the following: power adjustment actions, periodic intermittent actions, soft start / stop actions, and load priority scheduling actions; the action parameters should include at least the action amplitude, action duration, gradient slope, action interval, and fallback path; candidate actions can be generated using the following methods:

[0261] Discrete gear exhaustive enumeration: within the action executable boundary data, combinations are enumerated by gear, and combinations that violate basic constraints are directly pruned.

[0262] Heuristic search prioritizes generating action combinations that offer high energy savings and minimal impact on location data for risk-sensitive segments, while retaining only conservative actions for high-risk equipment.

[0263] Furthermore, disturbance suppression parameter data and observability protection constraint data are superimposed on each candidate action to form candidate action execution plan data for preliminary evaluation.

[0264] As a possible contingency plan, the system may also include an exception handling mechanism, in which the system enters an offline conservative mode when communication between the edge and the cloud is interrupted. In this mode, the system continues to operate using the latest version of security constraints cached locally, but automatically reduces the upper limit of action magnitude by 20% and extends the minimum action interval by 50%, mitigating the risks that may arise from the inability to obtain cloud updates.

[0265] When abnormal sensor data is detected, such as zero readings for N consecutive sampling periods or readings exceeding the physical range, the system triggers a sensor self-test process. If the self-test confirms sensor failure, the system prohibits any active control actions and sends a fault alarm to the cloud or local display interface.

[0266] When the device's health status H drops to a preset minimum safety threshold, such as below 0.1, the system enters device lock mode, prohibiting any control actions and forcibly triggering a device maintenance reminder. The health status can only be reset with administrator privileges after manual confirmation that the device has been maintained or replaced.

[0267] The optional embodiments of the present invention have been described in detail above. However, the present invention is not limited to the specific details of the above embodiments. Within the scope of the technical concept of the present invention, various equivalent transformations can be made to the technical solution of the present invention, and these equivalent transformations all fall within the protection scope of the present invention.

Claims

1. A method for monitoring electrical safety and controlling energy conservation, characterized in that, include: Collect raw electricity consumption data, identify equipment access events, and generate equipment risk classification results and control access strategies by combining equipment profile baselines; Based on the equipment risk classification results, the triggering gating parameters are dynamically adjusted, and trigger-based capture and integrity encapsulation are performed on the original power consumption sampling data to obtain evidence chain data. Read the control access policy, combine it with safety constraints to generate safety constraint power-saving control commands, and issue them for execution; Collect control execution feedback data for energy-saving control commands under safety constraints, and perform secondary risk verification based on the control execution feedback data and evidence chain data to obtain closed-loop safety energy-saving assessment results; Upload the closed-loop safety energy-saving assessment results and evidence chain data to the cloud, and receive updated safety constraints based on cloud-based archived analysis.

2. The method according to claim 1, characterized in that, Based on the equipment profile baseline, equipment risk classification results and control access strategies are generated, specifically including: In the original electricity consumption sampling data, a window is extracted before and after the device is connected, and the incremental response data representing this connection behavior is extracted. Calculate the multidimensional features of the incremental response data and perform physical consistency screening. Physical consistency screening is used to eliminate abnormal features that do not meet electrical and physical constraints. The screened features are compared with risk thresholds to determine the risk level of the equipment, and a control access policy containing a set of permitted action types is generated based on the risk level.

3. The method according to claim 1, characterized in that, The triggering gating parameters are dynamically adjusted based on the equipment risk classification results, specifically including: Establish a mapping relationship between equipment risk classification results and trigger gating parameters, and configure longer capture window lengths and higher sampling fidelity for high-risk equipment; A ring buffer mechanism is used to monitor raw power consumption data in real time. When the triggering conditions are met, the data is locked according to the triggering gate parameters, and a short window high-fidelity acquisition segment is extracted.

4. The method according to claim 3, characterized in that, The evidence chain data obtained specifically includes: The short-window high-fidelity acquisition segment, the trusted timestamp of the trigger time, and the hash value of the previous block are encrypted and encapsulated to generate tamper-proof evidence chain data; Extract evidence summaries from the chain of evidence data and build a fast index.

5. The method according to claim 1, characterized in that, Generate safety constraint power-saving control commands based on safety constraints, including: Based on the action types allowed by the control admission policy, multiple sets of parameterized power-saving candidate actions are generated; Add disturbance suppression parameters to each power-saving candidate action. The disturbance suppression parameters include the gradient slope and the minimum action interval, which are used to smooth the transient impact of the control action on the waveform. By using safety constraints, candidate energy-saving actions after adding disturbance suppression parameters are screened, and actions that meet the conditions are solidified into safety constraint energy-saving control commands.

6. The method according to claim 1, characterized in that, Safety constraints include the upper limit on the range of actions allowed and the upper limit on the frequency of actions. The process of generating safety constraints includes: Maintain the contact health status of the monitored object, which characterizes the degree of cumulative physical wear and tear on the contact components; Based on the motion loss model, the motion loss value is calculated using historically executed safety constraint power-saving control commands, and the contact health status is updated accordingly. When the health status decreases, the upper limit of the action amplitude and the upper limit of the action frequency are reduced proportionally according to the preset mapping relationship, so as to obtain the dynamically tightened safety constraints.

7. The method according to claim 6, characterized in that, Update contact health status, specifically including: Extract the action type and action range from the safety constraint energy-saving control command, and read the secondary risk occurrence marker from the closed-loop safety energy-saving assessment result; The motion loss value for this action is calculated based on the motion loss model, and then subtracted from the current contact health status. The formula is as follows: H _n+1 =H _n -α×g(u1)×h(u4)×(1+β×I _risk ); Among them, H _n+1 H is the updated contact health status. _n Given the current state, α is the basic loss coefficient, g(u1) is the amplitude loss factor related to the action amplitude, h(u4) is the type loss factor related to the action type, and I... _risk This is used to indicate the occurrence of secondary risks, and β is the risk amplification factor.

8. The method according to claim 6, characterized in that, The upper limits for the range of motion and the frequency of motion will be reduced proportionally, including: Set a critical health threshold. When the contact health status is lower than the critical health threshold, the upper limit of the action range will be tightened linearly in proportion to the contact health status. Set the interval expansion index to expand the minimum action interval constraint inversely proportional to the power of the contact health status.

9. The method according to claim 1, characterized in that, Performing secondary risk verification specifically includes: Based on the action parameters of the safety constraint power-saving control command, construct the expected response reference trajectory of this action under fault-free conditions; The control execution feedback data is time-aligned with the expected response reference trajectory, and the difference between the two is calculated to generate the residual trajectory. Structural decomposition and causal attribution of the residual trajectory are performed to determine whether secondary risks have been induced.

10. An electricity safety monitoring and energy-saving control platform, characterized in that, include: Memory, used to store computer programs; A processor for executing a computer program to implement the method as described in any one of claims 1 to 9, the processor being connected to a sensing and execution unit; The sensing and execution unit is used to collect electrical parameters, execute power-saving control commands, and realize data interaction and transmission.

Citation Information

Patent Citations

  • Cable system full life cycle health management method based on digital twinning

    CN120611628A

  • Communication network operation state monitoring method and system

    CN120979971A

  • State monitoring and risk prediction method for high-voltage circuit breaker

    CN121279127A

  • Full-life-cycle intelligent monitoring and health assessment method and system for substation equipment

    CN121302168A