Power grid big data security online patrol and risk pre-control method based on three-library linkage

By constructing a power grid big data system that links three databases, and dynamically generating inspection paths, the problem of insufficient data source coupling analysis in the power grid risk early warning mechanism has been solved. This enables accurate characterization and real-time response to power grid equipment risks, thereby improving the safety of power grid operation and inspection efficiency.

CN121901940APending Publication Date: 2026-04-21GUANGDONG POWER GRID CO LTD INFORMATION CENT
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-12
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing power grid risk early warning or inspection mechanisms lack coupling analysis between data sources, making it difficult to establish a dynamic response prediction mechanism between equipment status, abnormal alarms and the external environment. This results in a lag in abnormal event identification and a lack of real-time perception and optimization of inspection paths and resource scheduling.

Method used

Construct an equipment status database, an operational alarm database, and an environmental factor database. Through the linkage of these three databases, establish an equipment evolution trajectory model, a fault trigger sequence model, and a dynamic environmental response model. Combine this with a multi-objective optimization algorithm to generate an inspection priority scheduling diagram, dynamically generate inspection paths and update them in real time, and optimize risk prevention and control schemes.

Benefits of technology

It enables joint modeling of multi-source heterogeneous data and dynamic perception of risk indicators, improving the accuracy of risk identification and the real-time performance of response. It also has the capabilities of path adaptive adjustment, intelligent resource allocation and anomaly pre-control, thereby improving the safety of power grid operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121901940A_ABST
    Figure CN121901940A_ABST
Patent Text Reader

Abstract

The invention discloses a power grid big data security online patrol and risk pre-control method based on three-library linkage, and particularly relates to the technical field of risk pre-control. By constructing an equipment evolution trajectory model, a fault trigger sequence model and a dynamic environment response model, multi-source risk features are extracted, a multi-dimensional risk feature vector is formed, and a patrol priority scheduling graph is generated in combination with a multi-objective optimization algorithm. On the premise of meeting patrol frequency constraints, a patrol path is dynamically generated by adopting an adaptive evolution algorithm, and real-time adjustment is performed according to risk changes, so that closed-loop control of risk prediction, path optimization and resource allocation can be realized, the accuracy of power grid anomaly recognition and the intelligent level of patrol decision are improved, and the power grid patrol efficiency is improved. The method is suitable for power grid safety management and active prevention and control in a complex operation environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of risk prevention and control technology, specifically to a method for online inspection and risk prevention and control of power grid security based on the linkage of three databases. Background Technology

[0002] With the gradual construction of new power systems, the scale of power grid equipment is becoming increasingly large and the operating environment is becoming more complex. The access of multi-source heterogeneous data makes it difficult for traditional manual inspections and static alarm mechanisms to cover systemic abnormal changes. Especially in the context of sudden weather, complex load disturbances, and intermittent renewable energy access, the risks of power grid operation are more dynamic and interconnected.

[0003] Existing power grid risk early warning or inspection mechanisms typically rely on fixed rule bases or independent indicator modeling, lacking coupled analysis between data sources, and particularly failing to establish a dynamic response prediction mechanism between equipment status, abnormal alarms, and the external environment. This may result in the identification of abnormal events often lagging behind the occurrence of faults, and a lack of real-time perception and priority optimization for inspection paths and resource scheduling. Furthermore, risk prevention and control mainly rely on static rules, making it difficult to adapt to continuously evolving system situations. Summary of the Invention

[0004] The purpose of this invention is to provide a method for online inspection and risk prevention and control of power grid big data based on the linkage of three databases, so as to solve the shortcomings of the background technology.

[0005] To achieve the above objectives, this invention provides the following technical solution: a method for online security inspection and risk prevention and control of power grids based on three-database linkage, comprising: Three types of data warehouses are constructed, including equipment status database, operation alarm database and environmental factor database, and corresponding time series data are collected and stored respectively; Based on the time series data in the state database, a device evolution trajectory model M1 is constructed, and the potential degradation trend of the device under the set operating conditions is identified according to the model M1. Historical related event chains are extracted from the alarm database to establish a fault trigger sequence model M2, which is used to characterize the temporal sequence and progressive features of the anomaly cascading process. Spatial heterogeneous factors are extracted from the environmental database to establish a dynamic environmental response model M3, which includes the joint sensitivity of environmental variables to equipment status and alarm frequency. Models M1, M2 and M3 are linked to calculate and construct a multi-dimensional risk feature vector W that integrates multiple influencing factors. Combined with a multi-objective optimization algorithm, an inspection priority scheduling diagram P is constructed under the current power grid operation status. Based on the patrol priority scheduling graph P, the adaptive patrol evolution algorithm is invoked to dynamically generate the patrol path L under the patrol frequency constraint, and P is reconstructed in real time according to the new input during operation; Patrol according to path L and update the data in the three databases; if any risk dimension in W is in a high threshold state for n consecutive rounds, then trace back the alarm chain and predict the potential fault location. Based on the predicted location, path dynamic cost, and remaining resources, adjust the scheduling diagram P and update the inspection path L to optimize the risk prevention and control plan.

[0006] Preferably, the construction of the device evolution trajectory model M1 based on time series data in the state database includes: The original time series data in the equipment status database is segmented and smoothed, and a sequence of status change nodes is established based on the data fluctuation threshold. A set of device operating state vectors is constructed based on the sequence of state change nodes, and the rate of change between adjacent state vectors is calculated. The rate of change is input into the time-series recursive regression model to generate the evolution trajectory model M1 of the equipment state over time, and its trend slope and abnormal offset are calculated. When the trend slope exceeds the degradation threshold under the set operating conditions, the corresponding equipment is automatically identified as a potential degradation unit, and the identification result is written back to the status database.

[0007] Preferably, the step of extracting historical related event chains from the alarm database and establishing a fault triggering sequence model M2 includes: Select multi-source alarm records that are continuous in time and correlated in space from the running alarm database, and establish an initial event chain set based on the topological mapping relationship between devices; A time-window-based directed graph construction method is adopted, which uses each alarm event as a graph node and the order of alarms as the edge weight relationship to generate a time-series directed graph that reflects the fault propagation path. The shortest path and frequency clustering algorithm is applied to the time sequence diagram to extract typical high-frequency triggering sequences and assign sequence numbers to them, forming a fault triggering sequence template set with causal relationships; The current alarm event stream is matched with the template set for similarity. If the similarity exceeds the set threshold, the current event is determined to be in the early stage of a certain sequence, and a set of subsequent abnormal nodes that may evolve are output.

[0008] Preferably, the step of extracting spatially heterogeneous factors from the environmental database and establishing a dynamic environmental response model M3 includes: Historical meteorological data, electromagnetic interference information and geographical factors of the target area are extracted from the environmental database to construct a time series matrix of environmental variables with spatial coordinate labels. Correlation analysis was performed on environmental variables, equipment status parameters, and alarm event frequency. The Pearson coefficient was used to calculate the joint sensitivity score between variables. A multivariate regression model was constructed based on the sensitivity score to form a device-environment mapping relationship, and a spatial attenuation factor was introduced to construct an environmental response model M3 applicable to different regions; When environmental variables fluctuate abnormally and the model prediction results exceed the set offset threshold, the relevant areas are automatically marked as environmentally sensitive areas, and a list of high-risk equipment associated with them is output.

[0009] Preferably, the step of linking models M1, M2, and M3 to construct a multi-dimensional risk feature vector W that integrates multiple influencing factors includes: For the same target device, call the output results of models M1, M2 and M3 respectively, and extract the corresponding degradation trend index, fault sequence matching score and environmental sensitivity score; The data is normalized, and a multidimensional risk feature vector W is constructed, which includes trend score, sequence risk weight and environmental disturbance coefficient. The risk feature vectors of all devices are input into a multi-objective optimization-based scheduling algorithm. Taking into account risk level, inspection cost and geographical path length, an inspection priority scheduling graph P is constructed. Based on the priority ranking results of the scheduling diagram P, determine the optimal allocation scheme for each patrol resource and output the corresponding dynamic patrol path plan.

[0010] Preferably, the construction of the patrol priority scheduling graph P includes: The risk level, failure probability and environmental interference weight in the risk feature vector W of each device are weighted and fused to generate a comprehensive risk score Ri for the device. Collect the geographical coordinates and inspection cost parameters of each device, and construct an inspection map structure G with path distance and resource consumption weights; Using the comprehensive risk score Ri as the scheduling priority weight, a multi-objective optimization function is constructed that includes risk minimization, path shortestization, and cost constraints. An improved particle swarm optimization algorithm is applied to solve the optimization function, and the output is a scheduling graph P with optimal inspection order and inspection weight level.

[0011] Preferably, the step of dynamically generating a patrol path L based on the patrol priority scheduling graph P and invoking an adaptive patrol evolution algorithm under patrol frequency constraints includes: Based on the risk level, geographical location and inspection resource status of each device node in the scheduling diagram P, set an initial set of inspection frequency constraint parameters; An adaptive patrol evolution algorithm is invoked, which integrates genetic algorithm and dynamic priority strategy to construct an initial solution for risk-responsive patrol path; During the inspection process, the equipment status and environmental factor inputs are monitored in real time. If the risk score of any equipment fluctuates significantly, the path reconstruction mechanism is triggered. Based on the updated scheduling graph P′, the path L′ is recalculated while retaining the key inspection nodes, thereby achieving local optimization and dynamic evolution of the original path.

[0012] Preferably, the alarm chain is traced back and potential fault locations are predicted: The system performs data collection tasks according to the inspection path L, and writes the collected equipment status parameters, environmental information and alarm data into the status database, environment database and alarm database in real time. The updated risk feature vector W is dynamically evaluated. If any dimension exceeds its corresponding high-risk threshold for n consecutive rounds, a fault warning flag is triggered. The fault trigger sequence model M2 is invoked to perform alarm chain backtracking analysis on the marked devices and identify their predecessor event nodes and associated devices in the historical fault path. Based on alarm propagation paths and risk vector similarity, the system predicts the direction and location of potential fault propagation and outputs a list of target devices for early intervention.

[0013] Preferably, the step of adjusting the scheduling graph P and updating the inspection path L based on the predicted location, path dynamic cost, and remaining resources to optimize the risk prevention and control scheme includes: Receive the potential fault locations and high-risk equipment list output by the fault trigger sequence model M2, and use it as a new set of high-priority nodes in the scheduling graph P; Calculate the dynamic cost increment of adding a new node to the current patrol path, including path distance, time overhead, and resource consumption weights; Assess the remaining available patrol resources. If they can meet the coverage requirements of the new nodes, then make incremental priority adjustments to the scheduling graph P while retaining the original key nodes. Based on the adjusted scheduling graph P′, the updated inspection path L′ is regenerated.

[0014] The technical effects and advantages provided by the present invention in the above technical solution are as follows: 1. This invention constructs a three-database linkage system—equipment status database, operational alarm database, and environmental factor database—and integrates three types of models: equipment operation trend modeling, alarm chain time-series backtracking, and environmental sensitivity analysis. This enables joint modeling of multi-source heterogeneous data and dynamic perception of risk indicators, accurately depicting the risk evolution path and potential anomaly mechanisms of power grid equipment. Based on this, the system constructs a multi-dimensional risk feature vector and uses an adaptive optimization algorithm to dynamically plan inspection priorities and paths, significantly improving the accuracy of risk identification and the real-time performance of response.

[0015] 2. Compared with existing static inspection mechanisms that rely on fixed rules or a single data source, this invention introduces multiple objective factors such as risk-driven factors, resource constraints, and evolutionary prediction into the scheduling decision-making process, possessing capabilities such as adaptive path adjustment, intelligent resource allocation, and closed-loop anomaly prevention and control. This method can achieve refined execution of inspection tasks and proactive risk intervention under complex backgrounds of frequent fluctuations in power grid operating status and intensified external environmental disturbances, thereby improving system security. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0017] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] For examples, please refer to Figure 1 As shown in this embodiment, the power grid big data security online inspection and risk prevention and control method based on three databases linkage includes: Three types of data warehouses are constructed, including equipment status database, operation alarm database and environmental factor database, and corresponding time series data are collected and stored respectively; Based on the time series data in the state database, a device evolution trajectory model M1 is constructed, and the potential degradation trend of the device under the set operating conditions is identified according to the model M1. Historical related event chains are extracted from the alarm database to establish a fault trigger sequence model M2, which is used to characterize the temporal sequence and progressive features of the anomaly cascading process. Spatial heterogeneous factors are extracted from the environmental database to establish a dynamic environmental response model M3, which includes the joint sensitivity of environmental variables to equipment status and alarm frequency. Models M1, M2 and M3 are linked to calculate and construct a multi-dimensional risk feature vector W that integrates multiple influencing factors. Combined with a multi-objective optimization algorithm, an inspection priority scheduling diagram P is constructed under the current power grid operation status. Based on the patrol priority scheduling graph P, the adaptive patrol evolution algorithm is invoked to dynamically generate the patrol path L under the patrol frequency constraint, and P is reconstructed in real time according to the new input during operation; Patrol according to path L and update the data in the three databases; if any risk dimension in W is in a high threshold state for n consecutive rounds, then trace back the alarm chain and predict the potential fault location. Based on the predicted location, path dynamic cost, and remaining resources, adjust the scheduling diagram P and update the inspection path L to optimize the risk prevention and control plan.

[0020] In this invention, three key data warehouses need to be constructed first: the equipment status database (StateBase), the operation alarm database (AlertBase), and the environmental factor database (EnvBase) to realize the orderly collection, classified storage, and time-series management of multi-source heterogeneous data related to power grid operation, providing data support for subsequent risk identification and inspection scheduling.

[0021] The equipment status database stores operational status information for various key equipment in the power grid, including but not limited to key operating parameters such as current, voltage, power factor, load rate, temperature, vibration, oil temperature, gas concentration, communication status, and start / stop records for transformers, circuit breakers, switchgear, cable lines, and distribution terminals. This data is collected in real-time through dispatching systems, SCADA systems, condition monitoring devices, or sensing terminals, and categorized using unique equipment identifiers as indexes to form a time-series status dataset sorted by timestamps. Through data archiving and compression algorithms, the equipment status database supports real-time writing and historical backtracking of high-frequency, massive amounts of data.

[0022] The alarm database is used to record various anomalies, faults, alarms, and early warning events generated during power grid operation, and to attribute and label these events. It includes: alarm type (e.g., overvoltage, undervoltage, short circuit, insulation abnormality, etc.); alarm trigger time and duration; alarm source device identification and location; associated event sequence (e.g., a sudden current change followed by a trip); and manual processing records and response time. This database supports the reconstruction and time-series archiving of multi-source event streams, forming alarm event stream models with causal logic. Furthermore, through alarm level and repetition frequency analysis, it can be used to construct prior models of potential equipment risks, providing causal evidence for risk prediction.

[0023] The environmental factor database is used to record external environmental parameters closely related to power grid operation, including: meteorological data (temperature, humidity, wind speed, precipitation, electromagnetic interference, etc.); geological data (topography, altitude, geological activity, etc.); external disturbance information (construction, electromagnetic interference sources, external force damage events, etc.); and time-periodic factors (sunshine duration, seasonal fluctuations, etc.).

[0024] Data sources may include authoritative third-party data platforms, meteorological service APIs, and on-site deployed environmental monitoring sensors. All environmental data are indexed primarily by collection time and categorized by spatial location coordinates to construct a spatiotemporal matrix of environmental factors with geographic labels, which will be used for subsequent spatial-temporal risk coupling analysis in the model.

[0025] In this invention, a device evolution trajectory model M1 is constructed based on time-series data in a state database, and the potential degradation trend of the device under set operating conditions is identified based on model M1. The specific steps are as follows: First, the raw time-series data of each target device in the device status database is preprocessed. Specifically, key indicators representing device operation (such as current, voltage, temperature, load rate, etc.) are selected to construct the raw multidimensional time series. To address potential measurement errors or transient interference in the raw data, a piecewise moving average filtering algorithm is used for smoothing, with the processing window width adaptively adjusted according to the data sampling frequency.

[0026] Then, based on the fluctuation range in the smoothed numerical sequence, a state change threshold ΔT is set (this threshold can be obtained by adding the historical fluctuation mean and standard deviation) to identify significant change nodes in the sequence and extract the sequence of state change nodes. Each node records the current time point, the state value before and after the change, and the magnitude of the change.

[0027] After obtaining the sequence of state change nodes, a set of state change vectors is constructed based on the state change amounts and time intervals between adjacent nodes. Each state vector represents the evolution characteristics of the device's operating state within a certain time interval.

[0028] Let two adjacent nodes be N1 and N2, with corresponding times t1 and t2, and state value vectors V1 and V2. Then their state change rate R can be expressed as the vector difference divided by the time interval, i.e.: rate of change. The above calculation results will be used in the subsequent trend modeling process.

[0029] Using the aforementioned sequence of changes in the continuous state vectors, a time-series recursive regression model is employed to fit the equipment state evolution process. This model uses weighted least squares (WLS) for recursive modeling, introducing a time decay factor λ (0 < λ ≤ 1) to give higher weight to recent data, thus improving the responsiveness to sudden changes. This recursive regression model uses time t as the independent variable and state parameter values ​​as the dependent variable, continuously fitting and generating a trend function of the equipment operating state evolving over time, thus forming the evolution trajectory model M1.

[0030] The model output includes: trend slope β: representing the average direction and speed of change of the state value per unit time; anomaly offset δ: representing the degree of deviation of the actual state value from the model prediction value, reflecting potential abnormal fluctuations.

[0031] Based on the set maximum allowable degradation trend slope threshold of the equipment under the established operating conditions. (This can be determined through analysis of the equipment's historical degradation cycle) Comparison and judgment are then performed: If the trend slope Or the abnormal offset δ exceeds the set deviation threshold δ for multiple consecutive periods. t The system determined that the current equipment is experiencing continuous operational abnormalities and is classified as a potentially deteriorating unit.

[0032] Once a potentially deteriorating device is identified, the system automatically records the device's identifier, current trend parameters, identification time, and related indicators, and writes the identification results back to the device status database as a structured record.

[0033] In this invention, historical related event chains are extracted from the alarm database to establish a fault triggering sequence model M2, which is used to characterize the temporal sequence and progressive features of the anomaly cascading process. Specifically, the following steps are included: First, extract historical abnormal alarm data from the operational alarm database, including but not limited to: overvoltage, undervoltage, short circuit, overload, tripping, communication interruption, protection action, and other types of events. Each alarm record contains the following fields: event type; timestamp of occurrence; device number; geographical location; device topology connection information.

[0034] Subsequently, a time continuity window Δt (e.g., 10 minutes) and a spatial correlation radius R (e.g., 1 kilometer or the same feeder segment) are set to determine whether alarm events are spatiotemporally correlated. If multiple events occur sequentially within the time interval Δt and there is a direct or indirect topological connection between the corresponding devices, they are grouped into an initial event chain to form a historical alarm event chain set.

[0035] Based on the aforementioned event chain set, a directed graph modeling method is used to construct a time-series alarm graph. Specifically, each alarm event is treated as a node in the graph; if event A occurs earlier than event B, and the device containing event A is electrically connected to the device containing event B, then a directed edge is added between nodes A and B; the weight of the edge represents the time difference Δt between the two events, serving as a measure of event propagation delay. The constructed directed graph G presents the possible propagation paths of alarm events while preserving temporal sequence information.

[0036] Based on the constructed time-series directed graph, the following two types of algorithms are applied to extract high-value alarm sequences: Shortest path algorithm: used to extract the shortest trigger chain propagating from the first alarm event to the end device; Frequency clustering algorithm: performing cluster analysis on paths with high frequency in all historical event chains and merging them into typical alarm trigger sequences. The resulting set of high-frequency alarm sequences is then used as a template set. Each template is marked with a unique number and contains information such as node sequence, time interval, and device relationship chain, forming a fault trigger template library with causality and reconfigurability.

[0037] During actual operation, the system continuously monitors the real-time alarm event stream. and combine it with the fault trigger template set The system matches each template within the sequence. The matching process employs a time-series similarity calculation method, comprehensively considering event type similarity, occurrence time interval similarity, and device structure matching. A similarity threshold θ is set (e.g., 0.8). If the similarity calculation result S ≥ θ between a template and the current event stream, it is determined that the current system may be in an early stage of that template sequence.

[0038] In this invention, spatial heterogeneity factors are extracted from an environmental database to establish a dynamic environmental response model M3, which includes the joint sensitivity of environmental variables to equipment status and alarm frequency. This process includes the following steps: First, historical environmental variable data for the target area are extracted from an environmental factor database, including but not limited to: Meteorological variables: temperature, humidity, wind speed, precipitation, frequency of thunderstorms; Electromagnetic interference information: Records of external radio frequency, electromagnetic pulse, and power line harmonic interference; Geographical factors: terrain type, altitude, green coverage, geological activity level, etc.

[0039] The above data is time-series converted according to a uniform time granularity (such as every 10 minutes or 1 hour), and the spatial coordinate information of each group of data is bound together to construct a three-dimensional structured matrix of environment variables-spatial coordinates-time stamps for subsequent model construction.

[0040] Equipment operating status parameters (such as temperature, current, and load rate) and alarm event frequency records for the corresponding area are extracted from the status database and alarm database, and correlation analysis is performed with environmental variable sequences. The Pearson correlation coefficient method is used to calculate the sensitivity score for each pair of "environmental variable – equipment parameter" and "environmental variable – alarm frequency," with the specific definitions as follows: Joint Sensitivity Score =Pearson coefficient ;in, Let i be the time series of the i-th environment variable. Let be the time series of the behavior parameter of the j-th device, with a scoring range of -1 to 1. The closer the absolute value is to 1, the stronger the correlation. Based on the scoring results, select those with high sensitivity (e.g., A set of variable pairs used for model training.

[0041] Based on the aforementioned pairs of sensitive variables, a response model of equipment behavior to environmental changes is constructed using multivariate linear regression or ridge regression methods. Let Y be the predicted value of the equipment parameters. to If the selected environment variables are used, the model structure is as follows: Where α is the regression coefficient and ε is the disturbance term. To accommodate spatial heterogeneity, a spatial attenuation factor γ is introduced into the model to reflect the diminishing effect of geographical distance on environmental variables. The spatial attenuation factor can be defined using a Gaussian kernel function or an inverse distance weighting method, for example: Where d represents the spatial distance between the device and the environmental monitoring point, and λ is the spatial attenuation coefficient (obtained through back-training using historical fitting errors). The final model M3 can predict the device's response trend in real time based on its specific location and environmental parameters.

[0042] During operation, environmental variables are continuously monitored. When the change in one or more environmental variables ΔX exceeds the range of its historical mean μ plus twice the standard deviation σ within a set time window T, that is: If so, it is considered an abnormal environmental fluctuation.

[0043] At this point, input the current environmental variable values ​​into model M3. If the deviation between the predicted result and the actual equipment status or alarm frequency exceeds the set error threshold... If (e.g., 20%), the corresponding spatial area will be marked as an environmentally sensitive area, and a list of affected equipment will be automatically generated as a priority target for high-risk inspections.

[0044] In this invention, models M1, M2, and M3 are linked for calculation to construct a multi-dimensional risk feature vector W that integrates multiple influencing factors. A multi-objective optimization algorithm is then used to construct an inspection priority scheduling diagram P under the current power grid operating state, specifically including: First, for the target devices involved in the status database, alarm database, and environment database, the aforementioned models M1, M2, and M3 are invoked respectively to extract key risk characterization indicators for each device, as follows: The device degradation trend indicator β is obtained from model M1, representing the slope of the rate of change in the device's operating state; the fault trigger sequence matching score S_f is obtained from model M2, used to characterize the similarity between the current alarm event stream and historical high-frequency fault sequences; and the environmental sensitivity score S_e is obtained from model M3, reflecting the intensity of interference from external environmental changes on the device's behavior. These raw scores may have issues such as inconsistent dimensions and numerical ranges, therefore, normalization processing is required.

[0045] To facilitate multidimensional calculations and standardized comparisons, the three risk dimensions above are normalized using the Min-Max normalization method, normalizing all scores to the [0,1] interval: Normalized trend score Normalized sequence risk weights Normalized environmental disturbance coefficient After normalization, a three-dimensional risk feature vector for device i is constructed. : Each vector represents the distribution of multi-source risk characteristics of the current device, which is used for subsequent scheduling strategy generation.

[0046] To establish scheduling priority ranking rules, the W vector is weighted and fused to generate a comprehensive risk score. .set up The weighting coefficients for trend indicators, fault sequences, and environmental disturbances are respectively, satisfying... The comprehensive risk score is calculated as follows: The value of the weight q can be set based on historical experience, expert knowledge, or through the AHP (Analog-Philosophy of Things) method. A common ratio is... =0.4、 =0.35、 =0.25.

[0047] Simultaneously, the geographical location information and unit inspection resource consumption cost of all devices are collected to construct an inspection graph structure G=(V,E), where: V represents all device nodes that need to be inspected; E represents the connecting path between devices; each edge e(i,j) is assigned two weight attributes: geographical distance D(i,j) and resource cost C(i,j). This graph structure is used to establish an inspection path optimization model.

[0048] Based on the existing equipment risk score Rᵢ and graph structure G, a three-objective optimization function is constructed, with the following objectives: Objective 1: Minimize total risk by prioritizing the inspection of high-risk equipment; Objective 2: Shorten the total path length to optimize inspection efficiency; Objective 3: Constrain resource consumption by not exceeding the total inspection capacity budget B. Let the equipment set be N, and the path be the inspection sequence L. The optimization function is defined as: Constraint condition: ΣC(i,j)≤B; where, The weighting coefficients for optimizing the objectives represent the degree of attention paid to risk priority, path efficiency, and resource control, respectively.

[0049] An improved particle swarm optimization (IPSO) algorithm is used to solve the function. Unlike traditional PSO, IPSO introduces a risk gradient-based distribution strategy during the population initialization phase and adds a local perturbation term ε to the global optimum during the iteration process to prevent getting trapped in local minima.

[0050] The final output is: Inspection Priority Scheduling Chart P, in which devices are sorted according to risk level and path rationality; each device node is labeled with a scheduling priority weight for use by the dynamic path generation module.

[0051] Based on the priority order in the scheduling diagram P, and combined with the current schedulable resource quantity, patrol personnel configuration, and geographical accessibility, several dynamic patrol paths are automatically generated. .

[0052] The path generation process uses a spatially reachable path planning method based on an improved A* algorithm to ensure that the path is optimal under physically feasible and resource-constrained conditions. It also supports path reconfiguration; when the risk level of any device changes or environmental disturbances occur, the scheduling graph P can be updated and the path dynamically adjusted. Each path outputs the following: a list of covered devices; estimated inspection time; resource allocation ratio; and priority label.

[0053] Based on the patrol priority scheduling graph P, an adaptive patrol evolution algorithm is invoked to dynamically generate patrol paths L under patrol frequency constraints, and P is reconstructed in real time based on new inputs during operation. This process includes the following four key steps: First, based on the comprehensive risk score of each device node in the aforementioned patrol priority scheduling diagram P. Geographical coordinates and the number of patrol resources currently available. Set the initial set of inspection frequency constraint parameters. ,in: This indicates the minimum inspection frequency set for device i (unit: times / day or times / hour). The settings are directly proportional to the equipment's risk level; for example: if If the risk level is greater than or equal to the high-risk threshold θ1, then ;like ,but ;like ,but .in, and These are the scoring boundaries for high risk and medium risk, with values ​​as follows: =0.8, =0.5. f_max, f_mid, and f_min are the preset minimum patrol frequencies corresponding to different risk levels, such as 4, 2, and 1 times / day, respectively. This constraint set will serve as the input constraints for the patrol path generation algorithm, ensuring that high-risk equipment is patrolled frequently and resources are allocated reasonably.

[0054] After the frequency constraints are set, the Adaptive Patrol Evolution Algorithm (APEA) is invoked. Using the risk priority of devices in the scheduling graph P as the core driving factor, and combining a genetic algorithm with a dynamic priority adjustment strategy, an initial solution for risk-responsive patrol paths is generated. This algorithm integrates two core mechanisms: a genetic algorithm mechanism; encoding method: using path sequence encoding, where each chromosome represents a device patrol order; fitness function: defined as a weighted function considering the total length of the patrol path, risk coverage efficiency, and frequency satisfaction; evolutionary operations: including crossover (at the sub-path segment level), mutation (randomly inserting high-risk nodes), and selection (retaining the optimal path); stopping condition: the fitness does not significantly improve within N consecutive iterations or reaches the maximum number of iterations. In each iteration, the patrol weights are dynamically adjusted based on the real-time risk scores of the devices covered by the current path; if a node's risk score increases by more than δ (e.g., 20%) after the last patrol, its priority weight in the path is increased in the current generation. Finally, a set of initial solutions L0 for patrol paths that meet the frequency constraints and have efficient risk response is output, which serves as the patrol task execution path for the current time period.

[0055] Patrol route During implementation, the system continuously receives real-time data updates from three databases (status database, alarm database, and environment database) and monitors changes in the following risk indicators: equipment risk score. The alarm event is newly added or evolved (triggering fault sequence identification); environmental variables fluctuate significantly (such as a sudden increase in wind speed or enhanced electromagnetic interference). If the risk score of any device changes... If the value is set to 0.2, or if the alarm status changes from "normal" to "warning" or "abnormal", the path reconstruction mechanism is triggered. At this time, the current scheduling graph P is dynamically updated to P′, and the path recalculation process is started.

[0056] After triggering path reconstruction, to avoid frequent and large-scale replanning of the entire path, which would affect inspection efficiency and stability, the system adopts a "local evolution + global evaluation" strategy: retaining existing high-priority nodes in the path to ensure that high-risk equipment is not missed; partially replacing newly added high-risk nodes or equipment with increased risk levels; using a rolling optimization strategy for path recalculation, only re-optimizing the affected segments of the path; and employing a time window limitation mechanism, such as limiting it to the current remaining time period. The path change range is ≤30%. Path recalculation is still performed by the APEA algorithm, which outputs a new path L′ based on the scheduling graph P′, using the current resource status, risk ranking, and frequency constraints as parameters.

[0057] The path L′ includes the updated inspection sequence, the corresponding inspection time plan, and the equipment priority label, and supports connection with the previous inspection path. The difference comparison and incremental adjustment record.

[0058] In this invention, inspections are conducted according to path L, and data in the three databases are updated; if any risk dimension in W is in a high-threshold state for n consecutive rounds, the alarm chain is traced back and the potential fault location is predicted; specifically including: Based on the inspection path L generated by the aforementioned optimization algorithm, corresponding manual or unmanned inspection units (such as GPS-equipped drones, robots, or remote monitoring units) are assigned to perform inspection tasks on the target equipment along the path. The inspection tasks include the following operations: collecting equipment operating status parameters (such as voltage, current, temperature, vibration, and load rate); acquiring environmental factor data (such as wind speed, humidity, and electromagnetic interference intensity); and detecting local alarm events (such as protection device triggering and tripping events). All collected data is accessed to the system through the data access module and written to the following databases according to the corresponding timestamps and device IDs: StateBase: stores real-time operating status; EnvBase: records the environmental data of the equipment; and AlertBase: records alarm events and characteristics collected on-site. The written data format is a structured record, including: collection time, device ID, parameter type, value, and collection source identifier, ensuring the integrity and traceability of subsequent processing.

[0059] After the three databases are updated, the system calls the previously constructed multi-dimensional risk feature vector W to perform a dynamic risk assessment on all inspected equipment. W includes the following three main dimensions: condition degradation trend score β′; fault sequence matching score S′_f; and environmental sensitivity score S′_e. After each round of inspection data updates, the updated W is recorded in the risk sequence cache table W_hist, and a time-series sliding window of length n is established for each dimension to determine risk continuity. The judgment conditions are as follows: If any risk score dimension of a device exceeds the set high-risk threshold θ in n consecutive inspections (e.g., n=3), it is considered to be in a continuous abnormal state. θ can be set as follows: β′ high-risk threshold θ_β=0.75; S′_f high-risk threshold θ_f=0.80; S′_e high-risk threshold θ_e=0.70. Once any dimension meets the above conditions, the system automatically tags the device with a "fault warning" label and records the risk evolution trajectory and corresponding time points.

[0060] For device nodes marked as "fault warning," the fault trigger sequence model M2 is immediately invoked to perform an alarm chain backtracking operation, analyzing its evolution path in the historical event chain. The specific operation procedure is as follows: Retrieve alarm events that occurred on the device within the past T time window (e.g., the last 72 hours) from the alarm database; match similar alarm paths in the established fault sequence template library (e.g., path matching degree greater than the set threshold θ_m=0.7); extract the preceding event node of the current device in the matching sequence, i.e., the device node that often acts as a "precursor anomaly source" in the historical event chain; at the same time, identify the topological relationship between the device and other nodes, and look for possible anomaly propagation paths. If similar alarm chain structures appear in multiple historical templates, and the current device node is in the middle or later stage, further strengthen the risk analysis of its preceding node, considering it a potential fault source.

[0061] After completing alarm chain tracing and predecessor node identification, the system combines the following two types of information to predict potential fault locations: propagation path structure analysis: Based on the current device and its predecessor nodes in the historical alarm chain, a directed propagation path graph is drawn; risk vector similarity calculation: For all devices with electrical connections to the current node, the cosine similarity or Euclidean distance between their risk feature vectors and the current device is calculated. Let the risk vector of the current device be... If the target device is W_b, then its similarity S_sim can be defined as: If the similarity S_sim≥0.85 and the target device is located in the predecessor position of the current node in the propagation path graph, then the device is determined to be a potential source of failure or an abnormal starting point.

[0062] In this invention, the scheduling graph P is adjusted and the inspection path L is updated based on the predicted location, path dynamic cost, and remaining resources to optimize the risk prevention and control scheme, specifically including: After executing the fault-triggered sequence model M2, its output potential fault locations and high-risk equipment list are used as new high-priority target devices. The specific operation is as follows: For the newly identified set of devices... The risk level of each device is marked as "early warning" or "extremely high." Based on the frequency of the device in the historical fault propagation path and its position in the alarm chain, a higher risk weight R_new is assigned to it. This set of devices is then added as a new node set to the scheduling graph P, denoted as V_add⊂P′, where P′ is the updated scheduling graph. This step ensures that potential fault sources are prioritized for inclusion in the next round of inspection and scheduling, achieving risk-driven dynamic evolution.

[0063] After introducing new nodes, to avoid excessive resource consumption caused by blindly expanding patrol paths, it is necessary to quantify the path costs of these nodes. The dynamic path cost ΔC(i) of the newly added node i is defined as including the following three parts: distance increment D_inc(i): representing the shortest distance from the original path to the new node; time increment T_inc(i): representing the increased patrol time required due to the insertion of this node; and resource consumption R_inc(i): representing the increased manpower or equipment resources required to access this node. The comprehensive cost can then be calculated as follows: ;in, The weighting coefficients for each cost can be set according to the actual inspection and maintenance strategy (e.g., =0.4, =0.3, =0.3). Traverse the newly added node set V_add, and calculate ΔC(i) for each node as the basis for judging its schedulability.

[0064] Assess the remaining patrol resources R_sur for the current time period, including: the remaining available time window T_sur (e.g., 6 hours); and the number of schedulable manual / unmanned patrol units. Maximum loadable path length or upper limit of the number of devices L_max. If ΣΔC(i)≤R_sur, that is, the comprehensive cost of adding a new node is within the resource carrying capacity, then perform incremental priority update of the scheduling graph.

[0065] The update strategy includes: adding all newly added nodes V_add to the scheduling graph P′; updating the R_new value to the current highest risk level of the node; reordering all nodes in the scheduling graph P′ according to the new risk score R_total (original risk score plus predicted impact factor); and retaining high-priority nodes in the original path to avoid excessive task jitter.

[0066] After obtaining the adjusted scheduling graph P′, the system invokes the path optimization algorithm to reconstruct the paths for the new set of target devices, generating the updated inspection path L′. The path optimization method employs the Rolling Window Optimization algorithm, which has the following characteristics: Only newly added nodes or nodes with significant priority changes are reordered; partial reconstruction is performed based on the previous path L to avoid overall path disturbance; the optimization objective function comprehensively considers shortest path, maximum risk coverage, and optimal resource allocation. The objective function is illustrated below: Where D(i,j) is the path segment distance, and R_total(i) is the node's comprehensive risk score. The final output L′ includes: the updated patrol order; the estimated patrol time for each node; and the assigned patrol resource identifier.

[0067] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A method for online inspection and risk prevention and control of power grid security based on three databases, characterized by: include: Three types of data warehouses are constructed, including equipment status database, operation alarm database and environmental factor database, and corresponding time series data are collected and stored respectively; Based on the time series data in the state database, a device evolution trajectory model M1 is constructed, and the potential degradation trend of the device under the set operating conditions is identified according to the model M1. Historical related event chains are extracted from the alarm database to establish a fault trigger sequence model M2, which is used to characterize the temporal sequence and progressive features of the anomaly cascading process. Spatial heterogeneous factors are extracted from the environmental database to establish a dynamic environmental response model M3, which includes the joint sensitivity of environmental variables to equipment status and alarm frequency. Models M1, M2 and M3 are linked to calculate and construct a multi-dimensional risk feature vector W that integrates multiple influencing factors. Combined with a multi-objective optimization algorithm, an inspection priority scheduling diagram P is constructed under the current power grid operation status. Based on the patrol priority scheduling graph P, the adaptive patrol evolution algorithm is invoked to dynamically generate the patrol path L under the patrol frequency constraint, and P is reconstructed in real time according to the new input during operation; Patrol according to path L and update the data in the three databases; if any risk dimension in W is in a high threshold state for n consecutive rounds, then trace back the alarm chain and predict the potential fault location. Based on the predicted location, path dynamic cost, and remaining resources, adjust the scheduling diagram P and update the inspection path L to optimize the risk prevention and control plan.

2. The method for online inspection and risk prevention and control of power grid big data security based on three databases linkage as described in claim 1, characterized in that: The construction of the device evolution trajectory model M1 based on time series data in the state database includes: The original time series data in the equipment status database is segmented and smoothed, and a sequence of status change nodes is established based on the data fluctuation threshold. A set of device operating state vectors is constructed based on the sequence of state change nodes, and the rate of change between adjacent state vectors is calculated. The rate of change is input into the time-series recursive regression model to generate the evolution trajectory model M1 of the equipment state over time, and its trend slope and abnormal offset are calculated. When the trend slope exceeds the degradation threshold under the set operating conditions, the corresponding equipment is automatically identified as a potential degradation unit, and the identification result is written back to the status database.

3. The method for online inspection and risk prevention and control of power grid big data security based on three databases linkage as described in claim 1, characterized in that: The step of extracting historical related event chains from the alarm database and establishing a fault trigger sequence model M2 includes: Select multi-source alarm records that are continuous in time and correlated in space from the running alarm database, and establish an initial event chain set based on the topological mapping relationship between devices; A time-window-based directed graph construction method is adopted, which uses each alarm event as a graph node and the order of alarms as the edge weight relationship to generate a time-series directed graph that reflects the fault propagation path. The shortest path and frequency clustering algorithm is applied to the time sequence diagram to extract typical high-frequency triggering sequences and assign sequence numbers to them, forming a fault triggering sequence template set with causal relationships; The current alarm event stream is matched with the template set for similarity. If the similarity exceeds the set threshold, the current event is determined to be in the early stage of a certain sequence, and a set of subsequent abnormal nodes that may evolve are output.

4. The method for online inspection and risk prevention and control of power grid big data security based on three databases linkage as described in claim 1, characterized in that: The step of extracting spatially heterogeneous factors from the environmental database and establishing a dynamic environmental response model M3 includes: Historical meteorological data, electromagnetic interference information and geographical factors of the target area are extracted from the environmental database to construct a time series matrix of environmental variables with spatial coordinate labels. Correlation analysis was performed on environmental variables, equipment status parameters, and alarm event frequency. The Pearson coefficient was used to calculate the joint sensitivity score between variables. A multivariate regression model was constructed based on the sensitivity score to form a device-environment mapping relationship, and a spatial attenuation factor was introduced to construct an environmental response model M3 applicable to different regions; When environmental variables fluctuate abnormally and the model prediction results exceed the set offset threshold, the relevant areas are automatically marked as environmentally sensitive areas, and a list of high-risk equipment associated with them is output.

5. The method for online inspection and risk prevention and control of power grid big data security based on the linkage of three databases as described in claim 1, characterized in that: The step of linking models M1, M2, and M3 to construct a multi-dimensional risk feature vector W that integrates multiple influencing factors includes: For the same target device, call the output results of models M1, M2 and M3 respectively, and extract the corresponding degradation trend index, fault sequence matching score and environmental sensitivity score; The data is normalized, and a multidimensional risk feature vector W is constructed, which includes trend score, sequence risk weight and environmental disturbance coefficient. The risk feature vectors of all devices are input into a multi-objective optimization-based scheduling algorithm. Taking into account risk level, inspection cost and geographical path length, an inspection priority scheduling graph P is constructed. Based on the priority ranking results of the scheduling diagram P, determine the optimal allocation scheme for each patrol resource and output the corresponding dynamic patrol path plan.

6. The method for online inspection and risk prevention and control of power grid big data security based on three-database linkage as described in claim 5, characterized in that: The construction of the patrol priority scheduling graph P includes: The risk level, failure probability and environmental interference weight in the risk feature vector W of each device are weighted and fused to generate a comprehensive risk score Ri for the device. Collect the geographical coordinates and inspection cost parameters of each device, and construct an inspection map structure G with path distance and resource consumption weights; Using the comprehensive risk score Ri as the scheduling priority weight, a multi-objective optimization function is constructed that includes risk minimization, path shortestization, and cost constraints. An improved particle swarm optimization algorithm is applied to solve the optimization function, and the output is a scheduling graph P with optimal inspection order and inspection weight level.

7. The method for online inspection and risk prevention and control of power grid big data security based on three databases linkage as described in claim 1, characterized in that: The process of dynamically generating patrol paths L based on the patrol priority scheduling graph P and invoking an adaptive patrol evolution algorithm under patrol frequency constraints includes: Based on the risk level, geographical location and inspection resource status of each device node in the scheduling diagram P, set an initial set of inspection frequency constraint parameters; An adaptive patrol evolution algorithm is invoked, which integrates genetic algorithm and dynamic priority strategy to construct an initial solution for risk-responsive patrol path; During the inspection process, the equipment status and environmental factor inputs are monitored in real time. If the risk score of any equipment fluctuates significantly, the path reconstruction mechanism is triggered. Based on the updated scheduling graph P′, the path L′ is recalculated while retaining the key inspection nodes, thereby achieving local optimization and dynamic evolution of the original path.

8. The method for online inspection and risk prevention and control of power grid big data security based on three databases linkage as described in claim 1, characterized in that: The alarm chain is traced back and potential fault locations are predicted: The system performs data collection tasks according to the inspection path L, and writes the collected equipment status parameters, environmental information and alarm data into the status database, environment database and alarm database in real time. The updated risk feature vector W is dynamically evaluated. If any dimension exceeds its corresponding high-risk threshold for n consecutive rounds, a fault warning flag is triggered. The fault trigger sequence model M2 is invoked to perform alarm chain backtracking analysis on the marked devices and identify their predecessor event nodes and associated devices in the historical fault path. Based on alarm propagation paths and risk vector similarity, the system predicts the direction and location of potential fault propagation and outputs a list of target devices for early intervention.

9. The method for online inspection and risk prevention and control of power grid big data security based on three databases linkage as described in claim 1, characterized in that: The step of adjusting the scheduling graph P and updating the inspection path L based on the predicted location, path dynamic cost, and remaining resources, and optimizing the risk prevention and control scheme, includes: Receive the potential fault locations and high-risk equipment list output by the fault trigger sequence model M2, and use it as a new set of high-priority nodes in the scheduling graph P; Calculate the dynamic cost increment of adding a new node to the current patrol path, including path distance, time overhead, and resource consumption weights; Assess the remaining available patrol resources. If they can meet the coverage requirements of the new nodes, then make incremental priority adjustments to the scheduling graph P while retaining the original key nodes. Based on the adjusted scheduling graph P′, the updated inspection path L′ is regenerated.