Operation and maintenance event processing method and system based on intelligent alarm management
By constructing a highway operation and maintenance data aggregation and monitoring system, intelligent clustering and root cause localization of alarm events were achieved. Combined with spatiotemporal environmental data, situational analysis was performed to generate risk evolution trend maps and automatically generate graded handling work orders. This solved the problems of alarm information overload and insufficient root cause localization in highway operation and maintenance, and improved operation and maintenance efficiency and intelligence level.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-10
- Publication Date
- 2026-04-10
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Highway maintenance suffers from problems such as alarm information overload and high false alarm rate, insufficient reliance on manual experience for root cause localization, lack of intelligent support, and inability to predict the trend and scope of fault spread, resulting in low maintenance efficiency.
A data aggregation and monitoring system for operation and maintenance is constructed to collect three-level operation and maintenance monitoring data streams in real time, perform alarm event clustering, build a root cause localization model based on historical alarm information, perform situational simulation by combining spatiotemporal correlation environmental data, generate a risk evolution situation map, construct a safety constraint matrix, and automatically generate graded handling work orders.
It enables intelligent clustering and precise root cause localization of alarm events, improving the response efficiency and intelligent handling of operation and maintenance events, reducing misjudgments and delays, and optimizing resource allocation and decision-making accuracy.
Smart Images

Figure CN121838484A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of expressway operation and maintenance technology, and in particular to an operation and maintenance event processing method and system based on intelligent alarm governance. BACKGROUND
[0002] With the continuous expansion of the scale of the expressway network and the continuous improvement of the intelligent level, its operation and maintenance monitoring system is increasingly complex, forming a three-level operation and maintenance monitoring architecture covering provincial centers, road section companies and toll stations. Under this architecture, a large amount of multi-source heterogeneous operation and maintenance monitoring data streams are generated by various mechanical and electrical equipment, information systems and environmental monitoring facilities. The traditional operation and maintenance event processing method mainly relies on manual experience for alarm screening, root cause positioning and disposal scheduling, and has the following outstanding problems: Firstly, the alarm information is overloaded and the false alarm rate is high. Due to the large number of devices and complex correlations, a large number of repeated or derivative alarms are often triggered by the same fault, which causes the effective information to be submerged, making it difficult for operation and maintenance personnel to quickly identify key events and affecting response efficiency. Secondly, root cause positioning relies on manual experience and lacks intelligent support. Existing methods are mostly based on simple rules or historical records for correlation analysis, which is difficult to accurately identify the fault propagation path and impact range, especially in complex device topology and intertwined environmental factors, which can easily cause misjudgment or delay in disposal. Finally, there is a lack of prediction capability for fault evolution trend. Traditional methods focus on post-disposal and fail to effectively integrate real-time environmental data such as weather and traffic flow, making it impossible to quantitatively deduce the fault diffusion trend and impact duration, resulting in a lack of foresight in resource allocation and disposal scheduling.
[0003] In the prior art, some research has attempted to optimize the alarm processing process through clustering analysis, knowledge graph or machine learning methods. However, these methods still have obvious limitations: on the one hand, they mostly process alarm data in isolation and fail to deeply integrate real-time environmental monitoring data, resulting in insufficient situational awareness; on the other hand, they lack a closed-loop optimization mechanism from situation deduction to disposal decision, and cannot adaptively generate the optimal disposal strategy according to dynamic risk evolution. In addition, existing solutions usually do not fully consider the unique three-level collaborative architecture of expressway operation and maintenance, making it difficult to achieve intelligent grading and precise pushing of disposal tasks.
[0004] Therefore, there is an urgent need for an operation and maintenance event processing method and system that can integrate multi-source operation and maintenance data, implement intelligent alarm governance, and support situation deduction and collaborative decision-making, in order to improve the overall disposal efficiency and intelligent level of expressway operation and maintenance events. SUMMARY
[0005] To solve at least one of the above technical problems, the present application proposes an operation and maintenance event processing method and system based on intelligent alarm governance.
[0006] The first aspect of the application provides a kind of based on intelligent alarm governance operation and maintenance event processing method, comprising: Construction operation and maintenance data convergence monitoring system, according to the real-time acquisition of the operation and maintenance data convergence monitoring system Provincial Center, road section company, toll station three-level highway operation and maintenance monitoring data flow, extract operation and maintenance alarm event, the same operation and maintenance alarm event health data stream is clustered, obtain the alarm event cluster belonging to the same operation and maintenance alarm event; Alarm event information extraction is carried out on the alarm event cluster, an alarm root cause positioning model is constructed based on historical alarm information disposal work order, and the root cause and influence range data of the alarm event information are determined according to the alarm root cause positioning model; Obtain the spatio-temporal correlation environmental monitoring data in the alarm event influence range, including meteorological monitoring data, traffic flow data, video monitoring data, according to the spatio-temporal correlation environmental monitoring data, the situation of the alarm event is deduced, the probability distribution and the expected influence time of the alarm event fault diffusion to the related road section in the future preset time period are calculated, and the risk evolution situation atlas is generated; According to the risk evolution situation atlas, the safety constraint matrix of the affected road section is constructed, and the optimal disposal time sequence and resource allocation strategy of each alarm event are determined according to the safety constraint matrix; According to the optimal disposal time sequence and resource allocation strategy, the operation and maintenance data convergence monitoring system is automatically driven to generate hierarchical disposal work order and push to the corresponding level operation and maintenance terminal.
[0007] In the scheme, the operation and maintenance data convergence monitoring system is constructed, the real-time acquisition of the operation and maintenance data convergence monitoring system Provincial Center, road section company, toll station three-level highway operation and maintenance monitoring data flow is carried out, operation and maintenance alarm event is extracted, the same operation and maintenance alarm event health data stream is clustered, and the alarm event cluster belonging to the same operation and maintenance alarm event is obtained, specifically: The operation and maintenance data convergence monitoring system of the highway is constructed, the real-time acquisition of the operation and maintenance data convergence monitoring system Provincial Center, road section company, toll station three-level highway operation and maintenance monitoring data flow is carried out, operation and maintenance alarm event is extracted, the alarm type, alarm occurrence time, alarm occurrence position and device identifier of each operation and maintenance alarm event are obtained; According to the alarm occurrence time, the time sequence characteristics of each operation and maintenance alarm event are calculated, and according to the alarm occurrence position, the spatial coordinate information of each operation and maintenance alarm event is extracted, and the alarm type, device identifier, time sequence characteristics and spatial coordinate information are combined into an alarm event feature vector; Density-based clustering algorithm is introduced, the neighborhood radius and minimum sample number threshold of clustering algorithm are set, and the density value of each alarm event feature vector in the neighborhood radius is calculated; According to the density value, core points, boundary points and noise points in the alarm event feature vector are identified, each core point and the boundary points reachable within the neighborhood radius of the core point are divided into the same cluster to form an initial alarm event cluster; Intra-cluster distance calculation is performed on the initial alarm event cluster to obtain the average distance of all alarm event feature vectors in each initial alarm event cluster, and if the average distance is greater than a preset distance threshold, secondary splitting operation is performed on the initial alarm event cluster, and the initial alarm event cluster is split into multiple sub-clusters based on the K-means clustering algorithm; Inter-cluster similarity calculation is performed on the split sub-clusters, and if the similarity of two sub-clusters is higher than a preset similarity threshold, the two sub-clusters are merged to obtain an optimized alarm event cluster; Alarm event label annotation is performed on the alarm event cluster, and alarm event clusters belonging to the same operation and maintenance alarm event are output.
[0008] In the scheme, the alarm event information of the alarm event cluster is extracted, an alarm root cause positioning model is constructed based on historical alarm information handling work orders, and the root cause and influence range data of the alarm event information are determined according to the alarm root cause positioning model, specifically: A highway mechanical and electrical equipment knowledge graph is constructed based on the technical manual of the highway mechanical and electrical equipment, the device topology connection relationship and the historical operation and maintenance records, wherein the nodes of the knowledge graph represent various types of mechanical and electrical equipment, and the edges represent the physical connection relationship, electrical dependency relationship or data flow relationship between the devices; The device type, stake number interval and business system attribution features of each alarm event in the alarm event cluster are extracted, and the device type, stake number interval and business system attribution features are matched with the node attributes in the highway mechanical and electrical equipment knowledge graph to identify the device nodes and associated paths related to the alarm event; According to the associated path, the context feature vector of the alarm event in the knowledge graph is extracted, and the context feature vector includes the number of directly associated devices of the alarm device, the upstream and downstream dependency level and the historical fault propagation path; The historical operation and maintenance work order handling records are obtained, the alarm features, handling measures and finally confirmed alarm occurrence root causes of historical alarm events are extracted from the historical operation and maintenance work order handling records, and a training sample set is constructed; The random forest classification model is trained as an alarm root cause positioning model by taking the alarm features and context feature vectors of historical alarm events as inputs and taking the finally confirmed alarm occurrence root causes as output labels; The context feature vector of the current alarm event is input into the trained alarm root cause positioning model, and the root cause of the current alarm device and its confidence distribution are output; According to the confidence distribution, the alarm event is annotated for root cause, and the influence range is determined based on the connection relationship of the alarm device in the knowledge graph, and the affected associated devices are marked for the influence range, to obtain the root cause and influence range data of the alarm event information.
[0009] In the scheme, the spatio-temporal associated environment monitoring data in the alarm event influence range is obtained, including meteorological monitoring data, traffic flow data, and video monitoring data, and the situation deduction of the alarm event is performed according to the spatio-temporal associated environment monitoring data, the probability distribution and the predicted influence time length of the alarm event fault diffusion to the associated road section in a future preset time period are calculated, and a risk evolution situation atlas is generated, specifically: Based on the alarm event influence range data, the stake number interval and the associated device list of the affected road section are extracted, the meteorological monitoring data, the traffic flow data, and the video monitoring data of the affected road section are obtained, the meteorological monitoring data, the traffic flow data, and the video monitoring data are spatio-temporally aligned according to the collection time and the spatial position, and a spatio-temporal associated environment monitoring data cube is constructed; Based on the alarm event influence range data, an initial fault diffusion source is determined, the initial fault diffusion source is a specific device position where the alarm event occurs, and a device connection path from the initial fault diffusion source to the associated road section is extracted according to the expressway mechanical and electrical equipment knowledge graph, and each device connection path is taken as a potential fault diffusion path; A fault diffusion probability model based on a spatio-temporal conditional random field is constructed, the spatio-temporal associated environment monitoring data cube is taken as an observation feature, a fault diffusion state is taken as a hidden state, and a state transition energy function and an observation energy function are defined; A confidence propagation algorithm is used to infer the fault diffusion probability model, the probability that the fault propagates to the associated road section along each potential diffusion path in a future preset time period is calculated, and the predicted influence time length of the fault propagation to each associated road section is calculated according to the number of devices on the path, the average repair time of the device, and the environmental influence factors; The probability distribution and the predicted influence time length are mapped onto the expressway electronic map, the fault diffusion probability is visualized in the form of a heat map, the influence time length is visualized in the form of an isochrone, a real-time environment monitoring data layer is superimposed, and a risk evolution situation atlas containing spatio-temporal multi-dimensional information is generated.
[0010] In the scheme, the safety constraint matrix of the affected road section is constructed according to the risk evolution situation atlas, the optimal disposal time sequence and resource allocation strategy of each alarm event are determined according to the safety constraint matrix, and specifically: According to the risk evolution situation map, the fault diffusion probability distribution, the expected influence time length and the environmental monitoring data of the affected road section are extracted, the safe operation threshold of each road section under different risk levels is set based on the expressway safe operation specification, and the safe capacity of the affected road section is calculated in combination with the real-time traffic flow data; A safety constraint matrix is constructed with road sections as rows and risk factors as columns, the risk factors including fault diffusion probability, influence time length, traffic flow deviation degree and meteorological condition coefficient, and the upper limit of the tolerance of each road section to each risk factor is taken as the matrix element value; A multi-objective optimization algorithm is introduced, the shortest total time and the highest resource utilization efficiency are taken as optimization objectives, the safety constraint matrix is taken as a constraint condition, and an alarm event disposal optimization model is established; The alarm event disposal optimization model is solved based on a genetic algorithm, an initial population is a different disposal time sequence and resource allocation scheme, a new population is generated through selection, crossover and mutation operations, and the satisfaction degree of each individual to the safety constraint matrix and the optimization objective function value are calculated; The disposal scheme is screened according to a Pareto optimal solution set, if there are multiple non-dominated solutions, a weighted decision is made in combination with the real-time risk level transition trend of the road section, and the optimal disposal time sequence and resource allocation strategy of each alarm event are output.
[0011] In the scheme, according to the optimal disposal time sequence and resource allocation strategy, the operation and maintenance data aggregation monitoring system automatically generates a hierarchical disposal work order and pushes it to a corresponding level operation and maintenance terminal, specifically as follows: Based on the optimal disposal time sequence and resource allocation strategy, the disposal priority, the required resource type and quantity, the target disposal road section and equipment information of each alarm event are extracted; According to the three-level operation and maintenance system structure, the disposal tasks are hierarchically mapped according to the provincial center, the road section company and the toll station, and the task division and responsibility range of each level are determined; A hierarchical disposal work order template is constructed, the disposal task information is filled into the template, and a standardized work order containing alarm event description, root cause analysis, disposal steps, resource list and completion time limit is generated; The standardized work order is distributed to the hierarchical operation and maintenance terminal of the disposal task based on the operation and maintenance data aggregation monitoring system.
[0012] The second aspect of the application also provides an operation and maintenance event processing system based on intelligent alarm governance, which comprises a memory and a processor, the memory comprises an operation and maintenance event processing method program based on intelligent alarm governance, and the operation and maintenance event processing method program based on intelligent alarm governance is executed by the processor to realize the following steps: A construction and operation data aggregation monitoring system is constructed, real-time collection of highway three-level operation and maintenance monitoring data streams of the provincial center, road section company and toll station is performed according to the operation and maintenance data aggregation monitoring system, operation and maintenance alarm events are extracted, clustering operation is performed on health data streams of the same operation and maintenance alarm events, and alarm event clusters belonging to the same operation and maintenance alarm event are obtained; Alarm event information extraction is performed on the alarm event clusters, an alarm root cause positioning model is constructed based on historical alarm information processing orders, and root cause and influence range data of the alarm event information are determined according to the alarm root cause positioning model; Temporal and spatial correlation environment monitoring data in the alarm event influence range are acquired, including meteorological monitoring data, traffic flow data and video monitoring data, situation deduction is performed on the alarm event according to the temporal and spatial correlation environment monitoring data, probability distribution and predicted influence time length of the alarm event fault diffusion to the associated road section in a future preset time period are calculated, and a risk evolution situation atlas is generated; A safety constraint matrix of the affected road section is constructed according to the risk evolution situation atlas, and the optimal processing time sequence and resource allocation strategy of each alarm event are determined according to the safety constraint matrix; According to the optimal processing time sequence and resource allocation strategy, the operation and maintenance data aggregation monitoring system is driven to automatically generate a hierarchical processing order and push it to the corresponding level operation and maintenance terminal.
[0013] The application discloses an operation and maintenance event processing method and system based on intelligent alarm management. By constructing an operation and maintenance data aggregation monitoring system, real-time collection of highway three-level operation and maintenance monitoring data streams is performed, operation and maintenance alarm events are extracted and clustered, and alarm event clusters are formed. A root cause positioning model is constructed based on historical alarm orders, the root cause and influence range of the alarm event are determined, situation deduction is performed on the alarm event in combination with temporal and spatial correlation environment data such as meteorological data, traffic flow data and video monitoring data, fault diffusion probability and predicted influence time length are calculated, a risk evolution situation atlas is generated, a safety constraint matrix is constructed according to the atlas, the optimal processing time sequence and resource allocation strategy are determined, and a hierarchical processing order is automatically generated and pushed to the corresponding operation and maintenance terminal according to the strategy. Intelligent clustering and accurate root cause positioning of alarm events are realized, and the response efficiency and intelligent processing level of highway operation and maintenance events are improved. BRIEF DESCRIPTION OF DRAWINGS
[0014] Figure 1 A flowchart of the operation and maintenance event processing method based on intelligent alarm management is shown; Figure 2 A flowchart of clustering operation on health data streams of the same operation and maintenance alarm event is shown; Figure 3 A flowchart of generating a risk evolution situation atlas is shown; Figure 4A block diagram of an operation and maintenance event processing system based on intelligent alarm governance of the present application is shown. DETAILED DESCRIPTION
[0015] In order to enable a more clear understanding of the above-mentioned objects, features and advantages of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that the embodiments of the present application and the features in the embodiments can be combined with each other without conflict.
[0016] In the following description, a large number of specific details are set forth in order to facilitate a thorough understanding of the present application, however, the present application can also be implemented in other ways different from those described herein, and therefore, the protection scope of the present application is not limited by the specific embodiments disclosed below.
[0017] Figure 1 A flowchart of an operation and maintenance event processing method based on intelligent alarm governance of the present application is shown.
[0018] As Figure 1 shown, the first aspect of the present application provides an operation and maintenance event processing method based on intelligent alarm governance, comprising: S102, constructing an operation and maintenance data aggregation monitoring system, collecting highway three-level operation and maintenance monitoring data streams of provincial centers, road section companies and toll stations in real time according to the operation and maintenance data aggregation monitoring system, extracting operation and maintenance alarm events, clustering health data streams of the same operation and maintenance alarm events to obtain alarm event clusters belonging to the same operation and maintenance alarm event; S104, extracting alarm event information from the alarm event clusters, constructing an alarm root cause positioning model based on historical alarm information disposal work orders, and determining root cause and impact range data of the alarm event information according to the alarm root cause positioning model; S106, acquiring spatio-temporal correlation environmental monitoring data in the alarm event impact range, including meteorological monitoring data, traffic flow data and video monitoring data, performing situation deduction on the alarm event according to the spatio-temporal correlation environmental monitoring data, calculating probability distribution and predicted impact duration of the alarm event fault spreading to the associated road section in a future preset time period, and generating a risk evolution situation graph; S108, constructing a safety constraint matrix of the affected road section according to the risk evolution situation graph, and determining the optimal disposal time sequence and resource deployment strategy of each alarm event according to the safety constraint matrix; S110, driving the operation and maintenance data aggregation monitoring system to automatically generate a hierarchical disposal work order and push it to the corresponding level operation and maintenance terminal according to the optimal disposal time sequence and resource deployment strategy.
[0019] It should be noted that by constructing the data aggregation monitoring system, the real-time collection and intelligent aggregation of massive, multi-source operation and maintenance alarm data are realized, the scattered and repeated alarm information is effectively summarized into the same event cluster, the interference of alarm storm and redundant data on the operation and maintenance personnel is significantly reduced, and the efficiency and accuracy of event identification are improved. Subsequently, a root cause positioning model is constructed based on historical knowledge, the root cause of the alarm is diagnosed and its influence range is defined, thereby avoiding misjudgment and delay caused by experience dependence. Further, by integrating the environmental monitoring data related to time and space, the situation is deduced, the scientific prediction of the dynamic diffusion path and potential influence of the fault is realized, and an intuitive risk evolution map is generated. Based on this, a safety constraint matrix is constructed and the optimal disposal strategy is solved, realizing the efficient and accurate configuration of limited operation and maintenance resources in the time and space dimensions. Finally, by automatically generating and pushing the hierarchical disposal work order, the efficient collaborative closed-loop response of the entire three-level operation and maintenance system is driven, and the intelligent level of highway operation and maintenance event disposal and the operation safety guarantee capability are improved as a whole.
[0020] Figure 2 A flowchart of the clustering operation of the health data stream of the same operation and maintenance alarm event is shown.
[0021] According to the embodiment of the present application, the operation and maintenance data aggregation monitoring system is constructed, the operation and maintenance monitoring data streams of the provincial center, the road section company and the toll station of the expressway are collected in real time according to the operation and maintenance data aggregation monitoring system, the operation and maintenance alarm events are extracted, the clustering operation of the health data stream of the same operation and maintenance alarm event is performed, and the alarm event cluster belonging to the same operation and maintenance alarm event is obtained, specifically: The operation and maintenance data aggregation monitoring system of the expressway is constructed, the operation and maintenance monitoring data streams of the provincial center, the road section company and the toll station of the expressway are collected in real time based on the operation and maintenance data aggregation monitoring system, the operation and maintenance alarm events are extracted, the alarm type, alarm occurrence time, alarm occurrence position and device identifier of each operation and maintenance alarm event are obtained; The time sequence characteristics of each operation and maintenance alarm event are calculated according to the alarm occurrence time, the spatial coordinate information of each operation and maintenance alarm event is extracted according to the alarm occurrence position, and the alarm type, device identifier, time sequence characteristics and spatial coordinate information are combined into an alarm event feature vector; A density-based clustering algorithm is introduced, the neighborhood radius and minimum sample number threshold of the clustering algorithm are set, and the density value of each alarm event feature vector within the neighborhood radius is calculated; The core point, boundary point and noise point in the alarm event feature vector are identified according to the density value, each core point and the boundary point with a density reachable within the neighborhood radius of the core point are divided into the same cluster, and an initial alarm event cluster is formed; The initial alarm event cluster is subjected to intra-cluster distance calculation, the average distance of all alarm event feature vectors in each initial alarm event cluster is obtained, if the average distance is greater than a preset distance threshold, a secondary splitting operation is performed on the initial alarm event cluster, and the initial alarm event cluster is split into a plurality of sub-clusters based on a K-means clustering algorithm; The sub-clusters after splitting are subjected to inter-cluster similarity calculation, if the similarity of two sub-clusters is higher than a preset similarity threshold, a merging operation is performed on the two sub-clusters, and an optimized alarm event cluster is obtained. The alarm event cluster is subjected to alarm event label annotation, and alarm event clusters belonging to the same operation and maintenance alarm event are output.
[0022] It should be noted that in the expressway operation and maintenance system, the occurrence of alarm events usually has significant time and space correlation. A bottom-layer device failure or system anomaly can trigger a series of alarm information of its associated devices and upstream and downstream business systems within a short time. Although these alarms differ in alarm types and specific parameters, they essentially originate from the same root event. These alarms closely related in time and space are reported from the toll station, road section company and provincial center three-level monitoring nodes simultaneously or successively in the form of data streams, forming an alarm event cluster that appears to be independent but is actually related. How to accurately identify and aggregate the alarm set belonging to the same operation and maintenance alarm event from these interwoven and similar feature data streams is the primary problem to be solved in intelligent alarm management. The application can accurately identify and aggregate all alarm events caused by the same root fault from complex data streams by constructing a unified gathering system, standardizing multi-source alarms into feature vectors, and adopting an innovative two-level clustering strategy of "density clustering initial division, dynamic splitting and merging optimization", forming a complete alarm event cluster, thereby providing a clear and reliable event object for subsequent root cause positioning and collaborative disposal, and realizing intelligent conversion from chaotic alarm streams to structured management objects.
[0023] According to the embodiment of the application, the alarm event information of the alarm event cluster is extracted, an alarm root cause positioning model is constructed based on historical alarm information disposal work orders, and the root cause and influence range data of the alarm event information are determined according to the alarm root cause positioning model, specifically as follows: A highway electromechanical equipment knowledge graph is constructed based on a technical manual of highway electromechanical equipment, a device topology connection relationship and historical operation and maintenance records, wherein the nodes of the knowledge graph represent various types of electromechanical equipment, and the edges represent physical connection relationships, electrical dependency relationships or data flow relationships between devices. extracting a device type, a stake number interval, and a service system belonging feature of each alarm event in the alarm event cluster, matching the device type, the stake number interval, and the service system belonging feature with a node attribute in the expressway electromechanical equipment knowledge graph, and identifying a device node and an associated path related to the alarm event; extracting a context feature vector of the alarm event in the knowledge graph according to the associated path, the context feature vector including a number of directly associated devices of the alarm device, an upstream and downstream dependency level, and a historical fault propagation path; obtaining historical operation and maintenance work order disposition records, extracting alarm features, disposition measures, and finally confirmed alarm occurrence root causes of historical alarm events from the historical operation and maintenance work order disposition records, and constructing a training sample set; taking the alarm features and the context feature vector of the historical alarm event as input and taking the finally confirmed alarm occurrence root cause as output label, training a random forest classification model as an alarm root cause positioning model; inputting the context feature vector of the current alarm event into the trained alarm root cause positioning model, and outputting a root cause of the current alarm device and a confidence distribution thereof; annotating the root cause of the alarm event according to the confidence distribution, determining an influence range based on a connection relationship of the alarm device in the knowledge graph, marking the influence range of the affected associated devices, and obtaining root cause and influence range data of the alarm event information.
[0024] It should be noted that, in the present application, by extracting alarm event information from the alarm event cluster and constructing an alarm root cause positioning model based on historical alarm handling work orders, the root cause and influence range data of the alarm event are determined, avoiding the misjudgment and repeated processing problems caused by only relying on single-point alarm or manual experience in the traditional operation and maintenance process. By analyzing the topological relationship and dependency relationship of the alarm device in combination with the highway electromechanical equipment knowledge graph, and using a machine learning model to automatically identify the alarm root cause, the real fault source causing the alarm can be accurately identified from the multi-source alarm, and the propagation influence boundary of the fault in the device level and the road section range is also clear. Not only the accuracy and consistency of the alarm root cause positioning are improved, but also the fault handling range is effectively reduced, avoiding the misoperation or resource waste of irrelevant devices, thereby improving the pertinence and scientificity of the operation and maintenance decision, reducing the operation and maintenance response time, and enhancing the overall stability and operation safety of the highway operation and maintenance system in complex alarm scenarios. The highway electromechanical equipment knowledge graph is a structured semantic network, which digitizes the physical properties, topological connection relationships, electrical dependencies and historical operation and maintenance data of various electromechanical equipment such as toll, monitoring, communication and lighting in the form of "node-edge-attribute". The graph can intuitively reveal the hierarchy, dependency and influence path between devices; the associated path refers to one or more connected sequences formed by other device nodes that can be traced or radiated from the current alarm device node in the highway electromechanical equipment knowledge graph according to the physical connection, electrical dependency or data flow relationship. It represents the potential propagation channel and actual influence link of the fault or alarm information in the device network; the alarm features include the alarm event's own identifying information (such as alarm type, device identifier, stake position, occurrence time, etc.) and the device context information extracted from the knowledge graph (such as the number of associated devices, dependency level, historical fault path, etc.), which together form the input vector for machine recognition and judgment.
[0025] Figure 3 A flowchart of generating a risk evolution situation graph according to the present application is shown.
[0026] According to the present application, the time and space associated environmental monitoring data in the alarm event influence range is obtained, including meteorological monitoring data, traffic flow data and video monitoring data, the situation of the alarm event is deduced according to the time and space associated environmental monitoring data, the probability distribution and the expected influence time of the alarm event fault spreading to the associated road section in the future preset time period are calculated, and the risk evolution situation graph is generated, specifically: extract the stake number interval of the affected road section and the associated device list based on the alarm event influence range data, obtain the meteorological monitoring data, traffic flow data, and video monitoring data of the affected road section, perform spatio-temporal alignment on the meteorological monitoring data, traffic flow data, and video monitoring data according to the collection time and spatial position, and construct a spatio-temporal associated environmental monitoring data cube; determine an initial fault diffusion source based on the alarm event influence range data, the initial fault diffusion source being a specific device position where the alarm event occurs, extract a device connection path from the initial fault diffusion source to the associated road section according to the expressway mechanical and electrical device knowledge graph, and take each device connection path as a potential fault diffusion path; construct a fault diffusion probability model based on a spatio-temporal conditional random field, take the spatio-temporal associated environmental monitoring data cube as an observation feature, take a fault diffusion state as a hidden state, and define a state transition energy function and an observation energy function; infer the fault diffusion probability model by using a belief propagation algorithm, calculate the probability that the fault propagates to the associated road section along each potential diffusion path within a preset time period in the future, and calculate the predicted influence duration of the fault propagation to each associated road section according to the number of devices on the path, the average repair time of the devices, and environmental impact factors; map the probability distribution and the predicted influence duration to an expressway electronic map, visualize the fault diffusion probability in the form of a heat map, visualize the influence duration in the form of an isochrone, superimpose a real-time environmental monitoring data layer, and generate a risk evolution trend atlas containing spatio-temporal multi-dimensional information.
[0027] It should be noted that in the operation of the expressway, the influence of the alarm event is not isolated and static, and its subsequent risk evolution is highly dependent on real-time spatio-temporal environment. For example, severe weather (such as heavy fog and heavy rain) can exacerbate the impact of external device failure on traffic, and traffic flow during peak hours can amplify the congestion risk caused by device failure. Traditional methods usually only perform logical inference based on device topology, and lack consideration of dynamic changes in the environment, so they cannot quantitatively predict the real diffusion trend and influence of the fault, resulting in insufficient foresight of operation and maintenance decisions.
[0028] By constructing the spatio-temporal correlated environment monitoring data cube, the meteorological data, traffic flow data, video data and other multi-source data are fused in a unified spatio-temporal framework to provide a comprehensive environmental context for situation deduction. The spatio-temporal conditional random field model can effectively depict two key dependent relationships in the fault diffusion process: in the spatial dimension, the possibility of fault propagation along the device connection path is affected by structural factors such as path length and device reliability; in the time dimension, the dynamic process of such propagation is closely related to the environmental state (such as adverse weather accelerating device aging and high traffic flow increasing system load). The model defines each 'occurrence or not' state of the fault on each path as a hidden state, and uses real-time environmental data as observation evidence. Through the defined state transition function, the model can learn the rules of fault state propagation in the device network (space) and time sequence; through the defined observation function, the model can evaluate the support strength of the current environmental evidence for different propagation states.
[0029] The confidence propagation algorithm is used to infer the probability graph model, which can comprehensively calculate the overall probability of fault propagation to a specific associated road section at a certain time in the future in all possible fault state sequences, which is essentially a global optimal probability estimation after considering all spatio-temporal environmental evidence. At the same time, the path device repair time and environmental impact factors (such as weather causing repair delay) are integrated into the time length calculation model, so that the final output of the predicted impact time is a deduction result that integrates static knowledge (average repair time of devices) and dynamic environment (current and predicted weather, traffic conditions). Therefore, the model can generate a probabilistic dynamic risk map beyond simple topological analysis.
[0030] Real-time meteorological monitoring data in the influence range is obtained through meteorological monitoring sensors, and the meteorological monitoring data includes visibility, wind speed and precipitation; real-time traffic flow data in the influence range is obtained through traffic flow detectors, and the traffic flow data includes vehicle flow, average vehicle speed and lane occupancy rate; real-time video monitoring data in the influence range is obtained through video monitoring equipment, and the moving vehicle trajectory and abnormal events in the video are extracted based on a background subtraction algorithm; three dimensions of the data cube are time dimension, space dimension and monitoring index dimension; the state transition energy function considers device connection relationship, historical fault propagation record and environmental impact factor, and the observation energy function integrates the influence of real-time meteorological monitoring data on device operation stability, the pressure of traffic flow data on device load, and the inducing effect of abnormal events in the video monitoring data on device fault.
[0031] According to the embodiment of the present application, the safety constraint matrix of the affected road section is constructed according to the risk evolution situation map, and the optimal disposal time sequence and resource allocation strategy of each alarm event are determined according to the safety constraint matrix, specifically: According to the risk evolution situation map, fault diffusion probability distribution, predicted influence time length and environment monitoring data of the affected road section are extracted, safety operation thresholds of each road section under different risk levels are set based on the expressway safety operation specification, and the safety capacity of the affected road section is calculated in combination with real-time traffic flow data; A safety constraint matrix is constructed with road sections as rows and risk factors as columns, the risk factors including fault diffusion probability, influence time length, traffic flow deviation degree and meteorological condition coefficient, and the upper limit of tolerance of each road section to each risk factor is taken as a matrix element value; A multi-objective optimization algorithm is introduced, the optimization objectives are to handle the total time in the shortest time and the resource utilization efficiency in the highest, the safety constraint matrix is taken as a constraint condition, and an alarm event handling optimization model is established; The alarm event handling optimization model is solved based on a genetic algorithm, an initial population is a different handling time sequence and resource allocation scheme, a new population is generated through selection, crossover and mutation operations, and the satisfaction degree of each individual to the safety constraint matrix and the optimization objective function value are calculated; The handling scheme is screened according to a Pareto optimal solution set, if there are multiple non-dominated solutions, a weighted decision is made in combination with the real-time risk level transition trend of the road section, and the optimal handling time sequence and resource allocation strategy of each alarm event are output.
[0032] It should be noted that the dynamic risk situation is converted into a structured safety constraint, and the connection from risk prediction to handling decision is realized. By constructing a safety constraint matrix that integrates multi-dimensional risk factors, an explicit and quantitative safety boundary is set for subsequent optimization, ensuring that all handling schemes are within the range allowed by the safety operation specification. The introduction of the multi-objective optimization model and the genetic algorithm enables efficient optimization between the conflicting objectives of handling time and resource efficiency, intelligently screening strategies that achieve the best balance point in terms of time cost and resource consumption from a large number of possible handling schemes. The final output of the optimal handling time sequence and resource allocation strategy is a refined scheduling scheme that considers real-time risk evolution, road safety carrying limit and global resource constraints, thereby maximizing the efficiency and resource utilization of coordinated handling under large-scale concurrent alarm events while ensuring the overall operation safety of the expressway. The safety capacity refers to the maximum traffic flow or upper limit of service level that a road section can allow to pass through in a unit of time under certain risk conditions (such as equipment failure, adverse weather, etc.) to ensure safe operation.
[0033] According to the embodiment of the present application, the optimal handling time sequence and resource allocation strategy are used to drive the operation and maintenance data aggregation and monitoring system to automatically generate hierarchical handling work orders and push them to corresponding level operation and maintenance terminals, specifically: Based on the optimal handling sequence and resource allocation strategy, the handling priority, required resource type and quantity, target handling road segment and equipment information of each alarm event are extracted; Based on the three-tier operation and maintenance system of expressways, the handling tasks are mapped hierarchically according to the provincial center, road section company, and toll station, and the task division and responsibility scope of each level are determined. Construct a tiered handling work order template, fill in the handling task information into the template, and generate a standard work order that includes an alarm event description, root cause analysis, handling steps, resource list, and completion deadline; The standardized work orders are distributed to the operation and maintenance terminals at the level to which the task belongs, based on the operation and maintenance data aggregation and monitoring system.
[0034] It should be noted that resource allocation includes human resources, material resources (such as backup equipment, maintenance tools, and vehicles), and information resources (such as handling plans, authorization instructions, and coordination instructions). By mapping and assigning tasks according to the three-tiered operation and maintenance system architecture, the authority and clear responsibilities of work orders are ensured. Standardized work orders containing complete analysis, clear steps, and time limits are generated, greatly reducing the errors and delays that may occur from manual interpretation and translation of decision results. This enables front-end operation and maintenance personnel to quickly and accurately understand the full picture of the task and execute it. Finally, through automatic system push to the corresponding level of terminals, the entire province, road section, and toll station three-tiered operation and maintenance resources are driven to efficiently coordinate and link according to a unified and optimized plan, thereby transforming the intelligent analysis value of the preceding steps into a comprehensive improvement in actual operation and maintenance efficiency and safety assurance capabilities.
[0035] According to an embodiment of the present invention, it further includes: A real-time device status probe network is constructed and embedded in the data acquisition stream of the operation and maintenance data aggregation and monitoring system. It is used to continuously monitor and collect the physical connection status signals, electrical parameters and logical adjacency relationships of each electromechanical device, and generate a real-time connectivity verification data stream. Based on the real-time connectivity verification data stream and the static highway electromechanical equipment knowledge graph, abnormal change events in the physical connection relationship, electrical dependency relationship or data stream relationship between graph nodes are identified. The abnormal change events include connection interruption, parameter out-of-bounds or new logical links. Based on the incremental update of the knowledge graph topology triggered by the abnormal change event, a dynamic knowledge subgraph synchronized with the real-time network state is generated by creating temporary logical edges or marking invalid physical edges. When performing root cause localization on alarm event clusters, the context feature vector of the alarm event cluster is input into the alarm root cause localization model, and the dynamic knowledge subgraph is superimposed and introduced. The search space of the root cause reasoning path is corrected according to the real-time topological constraints provided by the dynamic knowledge subgraph. Based on the corrected search space, the alarm root cause localization model prioritizes calculating the probability of fault propagation along valid correlation paths that have been verified in real time, and outputs the root cause, confidence level, and impact range data of the current alarm event based on the real-time topology.
[0036] It is important to note that in the practical application of intelligent operation and maintenance on highways, the lag in the topological structure of static knowledge graphs is a key bottleneck restricting the accuracy of root cause localization. Relying on periodically maintained static knowledge graphs fails to detect real-time changes in physical connections and logical dependencies caused by temporary construction, equipment replacement, or network adjustments. This lag causes the root cause analysis model to reason along failed topological paths, leading not only to incorrect root cause conclusions but also to misjudgments of the fault's impact range. Consequently, subsequent risk situation simulations and resource scheduling decisions are based on inaccuracies, severely reducing the reliability and timeliness of the entire intelligent alarm management system. By constructing a real-time device status probe network and generating dynamic knowledge subgraphs, the above problems are effectively solved. This solution can continuously perceive the real-time status of physical and logical connections without interrupting business operations and dynamically correct the reasoning path constraints of the knowledge graph. Its technical advantage lies in ensuring that the alarm root cause localization model always performs fault propagation analysis based on the latest, validated, and effective network topology, thereby significantly improving the accuracy of root cause localization and the precision of impact range assessment. This lays a solid foundation for generating realistic and reliable risk evolution patterns and optimizing response strategies, enabling the entire operation and maintenance response system to dynamically adapt to real-time changes in infrastructure and improving the system's adaptability and decision-making intelligence.
[0037] Figure 4 A block diagram of an operation and maintenance event processing system based on intelligent alarm management according to the present invention is shown.
[0038] A second aspect of the present invention also provides an operation and maintenance event processing system based on intelligent alarm management. The system includes: a memory 401, a processor 402, and a communication interface 403. The memory includes a method program for handling operation and maintenance events based on intelligent alarm management. The communication interface is used for data connection and communication between the memory and the processor. When the method program for handling operation and maintenance events based on intelligent alarm management is executed by the processor, it performs the following steps: A maintenance data aggregation and monitoring system is constructed. Based on the real-time collection of highway maintenance monitoring data streams from the provincial center, road section company, and toll station, maintenance alarm events are extracted. Health data streams with the same maintenance alarm events are clustered to obtain alarm event clusters belonging to the same maintenance alarm event. Alarm event information is extracted from the alarm event cluster, an alarm root cause localization model is constructed based on historical alarm information processing work orders, and the root cause and impact range data of the alarm event information are determined according to the alarm root cause localization model. Acquire spatiotemporal environmental monitoring data within the impact range of the alarm event, including meteorological monitoring data, traffic flow data, and video monitoring data. Based on the spatiotemporal environmental monitoring data, perform situational analysis on the alarm event, calculate the probability distribution and expected impact duration of the alarm event fault spreading to related road sections within a preset time period, and generate a risk evolution situation map. Based on the risk evolution situation map, a safety constraint matrix for the affected road sections is constructed, and the optimal handling sequence and resource allocation strategy for each alarm event are determined based on the safety constraint matrix. Based on the optimal handling sequence and resource allocation strategy, the operation and maintenance data aggregation and monitoring system is driven to automatically generate hierarchical handling work orders and push them to the corresponding level of operation and maintenance terminals.
[0039] This invention discloses a method and system for handling operation and maintenance events based on intelligent alarm governance. By constructing an operation and maintenance data aggregation and monitoring system, real-time collection of three-level highway operation and maintenance monitoring data streams is achieved. Operation and maintenance alarm events are extracted and clustered to form alarm event clusters. A root cause localization model is constructed based on historical alarm work orders to determine the root cause and impact range of alarm events. Combined with spatiotemporally correlated environmental data such as meteorological, traffic flow, and video monitoring, the situation of alarm events is simulated, the probability of fault propagation and the expected duration of impact are calculated, and a risk evolution trend map is generated. A safety constraint matrix is constructed based on the map to determine the optimal handling sequence and resource allocation strategy. Based on the strategy, hierarchical handling work orders are automatically generated and pushed to the corresponding operation and maintenance terminals. This achieves intelligent clustering of alarm events and accurate root cause localization, improving the response efficiency and intelligent handling level of highway operation and maintenance events.
[0040] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0041] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.
[0042] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for handling operation and maintenance events based on intelligent alarm management, characterized in that, Includes the following steps: A maintenance data aggregation and monitoring system is constructed. Based on the real-time collection of highway maintenance monitoring data streams from the provincial center, road section company, and toll station, maintenance alarm events are extracted. Health data streams with the same maintenance alarm events are clustered to obtain alarm event clusters belonging to the same maintenance alarm event. Alarm event information is extracted from the alarm event cluster, an alarm root cause localization model is constructed based on historical alarm information processing work orders, and the root cause and impact range data of the alarm event information are determined according to the alarm root cause localization model. Acquire spatiotemporal environmental monitoring data within the impact range of the alarm event, including meteorological monitoring data, traffic flow data, and video monitoring data. Based on the spatiotemporal environmental monitoring data, perform situational analysis on the alarm event, calculate the probability distribution and expected impact duration of the alarm event fault spreading to related road sections within a preset time period, and generate a risk evolution situation map. Based on the risk evolution situation map, a safety constraint matrix for the affected road sections is constructed, and the optimal handling sequence and resource allocation strategy for each alarm event are determined based on the safety constraint matrix. Based on the optimal handling sequence and resource allocation strategy, the operation and maintenance data aggregation and monitoring system is driven to automatically generate hierarchical handling work orders and push them to the corresponding level of operation and maintenance terminals.
2. The operation and maintenance event handling method based on intelligent alarm management according to claim 1, characterized in that, The aforementioned construction of the operation and maintenance data aggregation and monitoring system involves real-time collection of highway three-level operation and maintenance monitoring data streams from the provincial center, road section company, and toll station. Operation and maintenance alarm events are extracted, and health data streams with the same operation and maintenance alarm events are clustered to obtain alarm event clusters belonging to the same operation and maintenance alarm event. Specifically: Construct a highway operation and maintenance data aggregation and monitoring system. Based on the operation and maintenance data aggregation and monitoring system, collect highway three-level operation and maintenance monitoring data streams from the provincial center, road section company, and toll station in real time, extract operation and maintenance alarm events, and obtain the alarm type, alarm occurrence time, alarm occurrence location, and device identifier for each operation and maintenance alarm event. Calculate the time series characteristics of each operation and maintenance alarm event based on the alarm occurrence time, extract the spatial coordinate information of each operation and maintenance alarm event based on the alarm occurrence location, and combine the alarm type, device identifier, time series characteristics, and spatial coordinate information into an alarm event feature vector; A density-based clustering algorithm is introduced, and the neighborhood radius and minimum sample number threshold of the clustering algorithm are set to calculate the density value of the feature vector of each alarm event within the neighborhood radius. Based on the density value, identify the core points, boundary points and noise points in the feature vector of the alarm event, and divide each core point and the boundary points within its neighborhood radius that can be reached by density into the same cluster to form an initial alarm event cluster. The initial alarm event cluster is subjected to intra-cluster distance calculation to obtain the average distance of all alarm event feature vectors in each initial alarm event cluster. If the average distance is greater than a preset distance threshold, the initial alarm event cluster is subjected to a secondary splitting operation, and the initial alarm event cluster is split into multiple sub-clusters based on the K-means clustering algorithm. The similarity between the split sub-clusters is calculated. If the similarity between two sub-clusters is higher than a preset similarity threshold, the two sub-clusters are merged to obtain an optimized alarm event cluster. The alarm event clusters are labeled with alarm event tags, and alarm event clusters belonging to the same operation and maintenance alarm event are output.
3. The operation and maintenance event handling method based on intelligent alarm management according to claim 1, characterized in that, The process of extracting alarm event information from the alarm event cluster, constructing an alarm root cause localization model based on historical alarm information processing work orders, and determining the root cause and impact range data of the alarm event information according to the alarm root cause localization model are specifically as follows: A knowledge graph of highway electromechanical equipment is constructed based on the technical manuals, equipment topology connections, and historical operation and maintenance records of highway electromechanical equipment. The nodes of the knowledge graph represent various types of electromechanical equipment, and the edges represent the physical connection relationships, electrical dependencies, or data flow relationships between the equipment. Extract the device type, station range, and business system affiliation features of each alarm event in the alarm event cluster, and match the device type, station range, and business system affiliation features with the node attributes in the highway electromechanical equipment knowledge graph to identify the device nodes and associated paths related to the alarm events; Based on the association path, extract the context feature vector of the alarm event in the knowledge graph. The context feature vector includes the number of directly associated devices of the alarm device, the upstream and downstream dependency levels, and the historical fault propagation path. Obtain historical operation and maintenance work order handling records, extract alarm characteristics, handling measures, and finally confirmed root causes of alarm occurrences from the historical operation and maintenance work order handling records, and construct a training sample set; Using the alarm features and context feature vectors of historical alarm events as input, and the finally confirmed root cause of the alarm as the output label, a random forest classification model is trained as an alarm root cause localization model. Input the context feature vector of the current alarm event into the trained alarm root cause localization model, and output the root cause of the current alarm device and its confidence distribution. The root cause of the alarm event is labeled according to the confidence distribution, and the scope of influence is determined based on the connection relationship of the alarm devices in the knowledge graph. The scope of influence of the affected related devices is marked to obtain the root cause and scope of influence data of the alarm event information.
4. The operation and maintenance event handling method based on intelligent alarm management according to claim 1, characterized in that, The acquisition of spatiotemporally correlated environmental monitoring data within the impact range of the alarm event includes meteorological monitoring data, traffic flow data, and video monitoring data. Based on the spatiotemporally correlated environmental monitoring data, the alarm event is situationally extrapolated, and the probability distribution and expected impact duration of the alarm event's fault spreading to related road sections within a preset time period are calculated to generate a risk evolution situation map. Specifically: Based on the alarm event impact range data, extract the chainage interval and associated equipment list of the affected road section, obtain the meteorological monitoring data, traffic flow data and video monitoring data of the affected road section, and align the meteorological monitoring data, traffic flow data and video monitoring data in time and space according to the collection time and spatial location to construct a spatiotemporally correlated environmental monitoring data cube; Based on the alarm event impact range data, the initial fault propagation source is determined. The initial fault propagation source is the specific equipment location where the alarm event occurred. Based on the highway electromechanical equipment knowledge graph, the equipment connection path from the initial fault propagation source to the associated road segment is extracted, and each equipment connection path is taken as a potential fault propagation path. A fault propagation probability model based on spatiotemporal conditional random field is constructed, using the spatiotemporal correlated environmental monitoring data cube as the observation feature and the fault propagation state as the hidden state, defining the state transition energy function and the observation energy function. The confidence propagation algorithm is used to reason about the fault propagation probability model, calculate the probability that the fault will propagate to the associated road segment along each potential propagation path within a preset time period in the future, and calculate the expected impact duration of the fault propagation to each associated road segment based on the number of devices on the path, the average repair time of device faults, and environmental impact factors. The probability distribution and expected impact duration are mapped onto the highway electronic map, and the probability of fault spread is visualized in the form of a heat map and the impact duration is visualized in the form of an isochronous line. A real-time environmental monitoring data layer is overlaid to generate a risk evolution trend map containing spatiotemporal multidimensional information.
5. The operation and maintenance event handling method based on intelligent alarm management according to claim 1, characterized in that, The step involves constructing a safety constraint matrix for the affected road segments based on the risk evolution map, and determining the optimal handling sequence and resource allocation strategy for each alarm event based on the safety constraint matrix. Specifically: Based on the risk evolution trend map, the probability distribution of fault spread, the expected duration of impact and environmental monitoring data of the affected road sections are extracted. Based on the highway safety operation specifications, the safety operation thresholds of each road section under different risk levels are set, and the safety capacity of the affected road sections is calculated by combining real-time traffic flow data. Construct a safety constraint matrix with road segments as rows and risk factors as columns. The risk factors include fault propagation probability, impact duration, traffic flow deviation, and meteorological condition coefficient. The tolerance limit of each road segment to each risk factor is used as the matrix element value. A multi-objective optimization algorithm is introduced, with the shortest total processing time and the highest resource utilization efficiency as the optimization objectives, and the aforementioned security constraint matrix as the constraint condition, to establish an alarm event handling optimization model; The alarm event handling optimization model is solved based on the genetic algorithm. The population is initialized with different handling sequences and resource allocation schemes. A new population is generated iteratively through selection, crossover, and mutation operations. The degree of satisfaction of each individual with the safety constraint matrix and the value of the optimization objective function are calculated. Based on the Pareto optimal solution set, if there are multiple non-dominated solutions, a weighted decision is made by combining the real-time risk level transition trend of the road segment, and the optimal handling sequence and resource allocation strategy for each alarm event are output.
6. The operation and maintenance event handling method based on intelligent alarm management according to claim 1, characterized in that, The step of automatically generating tiered handling work orders and pushing them to corresponding level operation and maintenance terminals based on the optimal handling sequence and resource allocation strategy is as follows: Based on the optimal handling sequence and resource allocation strategy, the handling priority, required resource type and quantity, target handling road segment and equipment information of each alarm event are extracted; Based on the three-tier operation and maintenance system of expressways, the handling tasks are mapped hierarchically according to the provincial center, road section company, and toll station, and the task division and responsibility scope of each level are determined. Construct a tiered handling work order template, fill in the handling task information into the template, and generate a standard work order that includes an alarm event description, root cause analysis, handling steps, resource list, and completion deadline; The standardized work orders are distributed to the operation and maintenance terminals at the level to which the task belongs, based on the operation and maintenance data aggregation and monitoring system.
7. A maintenance event handling system based on intelligent alarm management, characterized in that, The operation and maintenance event handling system based on intelligent alarm governance includes a storage device and a processor. The storage device includes an operation and maintenance event handling method program based on intelligent alarm governance. When the operation and maintenance event handling method program based on intelligent alarm governance is executed by the processor, it performs the following steps: A maintenance data aggregation and monitoring system is constructed. Based on the real-time collection of highway maintenance monitoring data streams from the provincial center, road section company, and toll station, maintenance alarm events are extracted. Health data streams with the same maintenance alarm events are clustered to obtain alarm event clusters belonging to the same maintenance alarm event. Alarm event information is extracted from the alarm event cluster, an alarm root cause localization model is constructed based on historical alarm information processing work orders, and the root cause and impact range data of the alarm event information are determined according to the alarm root cause localization model. Acquire spatiotemporal environmental monitoring data within the impact range of the alarm event, including meteorological monitoring data, traffic flow data, and video monitoring data. Based on the spatiotemporal environmental monitoring data, perform situational analysis on the alarm event, calculate the probability distribution and expected impact duration of the alarm event fault spreading to related road sections within a preset time period, and generate a risk evolution situation map. Based on the risk evolution situation map, a safety constraint matrix for the affected road sections is constructed, and the optimal handling sequence and resource allocation strategy for each alarm event are determined based on the safety constraint matrix. Based on the optimal handling sequence and resource allocation strategy, the operation and maintenance data aggregation and monitoring system is driven to automatically generate hierarchical handling work orders and push them to the corresponding level of operation and maintenance terminals.